Security center

Security & data handling

CSAI Monitor sits on your existing Zendesk stack. Explore what we access, what we store, and how we protect it.

Last updated: 30 August 2026

What lands in CSAI Monitor?

Toggle transcript storage to see the difference.

Store full transcripts

Default mode: metadata only — enough for CSAT, escalations, topics, and cost.

  • CSAT score
  • Topic / intent
  • Escalation flag
  • Sentiment
  • Cost fields
  • Full transcript textopt-in
  • Customer PII in messagesopt-in

Security practices

Encryption

TLS 1.3 in transit. AES-256 at rest.

  • All dashboard and API traffic uses TLS 1.3
  • Database and object storage encrypted at rest (AES-256)
  • API keys shown once at creation — stored hashed server-side

What we store

Metadata by default. Transcripts only if you opt in.

Access controls

Scoped API keys and account-level authentication.

Zendesk integration

You authorize webhooks. We do not replace your stack.

Retention & deletion

Plan-based retention with export and deletion on closure.

Data retention by plan

Select a plan to see how long we keep your analytics data.

90 days

Conversation metadata retained on Professional

Compliance & contacts

We align privacy practices with GDPR. See our Privacy Policy for collection, use, and your rights.

Amazon Web Services

Infrastructure & database hosting

US (default)

Stripe

Payment processing

PCI DSS (Stripe)

SOC 2 Type II is on our roadmap — not certified today. Enterprise buyers can request our current security questionnaire.

Security FAQ

No. CSAI Monitor analyzes your data to show you metrics and patterns. We do not use your customer conversations to train third-party foundation models.

Ready to connect Zendesk?

7-day trial on all paid plans. ~15-minute webhook setup.

Start 7-day trial