Security
What we do to protect your support data
A support desk holds your customers' names, their email addresses and everything they ever wrote to you. This page says what is actually in place — and, at the bottom, what is not. The second list is the more useful one, and most vendors do not publish it.
Can another customer see my data?
No. Separation is enforced at the data-access layer, not by each screen remembering to filter — so a new feature inherits it by default rather than by somebody remembering. A dedicated set of automated tests asserts that one workspace cannot reach another's tickets, customers, files or settings, and those run on every change.
What if you lose the database?
Backups run nightly, encrypted with AES-256, stored away from the application server. More to the point: the restore has been rehearsed, into a scratch database, and the result recorded. An untested backup is a belief rather than a safeguard, and we treat it that way.
In detail
Access and authentication
- Passwords are hashed and never stored in a form anybody can read — including us.
- Two-factor authentication is available for every staff account, and can be required for platform administrators.
- Role-based permissions, plus an option to restrict an agent to only the tickets assigned to them.
- Customers sign in to your portal with a magic link, so there is no customer password to leak.
- Sign-in, password reset and ticket submission are rate limited against brute force.
Encryption
- TLS on everything in transit.
- Third-party credentials you enter — mail provider, payment gateway, AI keys — are encrypted at rest, not merely hidden on screen.
- Backups are encrypted with AES-256. If a passphrase is configured and the server cannot encrypt, the backup fails rather than silently writing a readable archive.
Files from strangers
- A support desk receives files from people you have never met — that is its purpose, not an edge case.
- Uploads are checked by reading the bytes, not by trusting the extension or the browser-supplied type. A script renamed to invoice.pdf is refused.
- Executables, scripts and SVG are refused outright whatever else says. SVG catches people out: every tool treats it as an image, and it is a document that can run script.
Outbound requests
- Webhook destinations are resolved and checked before every send, so the service cannot be pointed at internal infrastructure or a cloud metadata endpoint.
- Checked again at delivery, not only when saved — a hostname can be re-pointed afterwards.
- Payloads are signed over a timestamp and the exact body sent, so your endpoint can prove a request came from us and reject a replayed one.
- Internal notes are never included in any outbound payload.
Accountability
- An audit trail of significant actions, with who did it, when, and from which address — kept for the life of the workspace.
- Downloading a backup or an export is recorded, because those are the actions worth being able to account for later.
- A delivery log for outbound email and webhooks, so "it never arrived" is answerable rather than a matter of opinion.
Deleting things
- Deleting a workspace waits seven cancellable days, then destroys it irreversibly — tickets, customers, attachments and archived email.
- A single customer can be erased on request: their details anonymised, everything they wrote replaced, their address removed from the mail log.
- Encrypted backups still contain data for up to 14 days after erasure, and our Privacy Policy says so rather than quietly omitting it.
- Export is available on every plan, including the free one. Your data is never leverage in a billing dispute.
AI, specifically
Where AI drafting is switched on, ticket text is sent to Anthropic to draft a reply and to Voyage AI to build the search index. A person on your team reads and edits every draft before anything reaches a customer — the AI never replies to anybody on its own.
Prompts and responses are kept for 30 days so a bad draft can be investigated, then deleted automatically.
It is optional and off by default. A workspace that never enables it sends nothing to either provider — which is the simplest answer if your own policy rules them out.
What we do not have
If any of these is a requirement for you, better to know now than three emails into procurement.
- SOC 2 or ISO 27001 — Neither, today. We can answer a security questionnaire and provide this page and our DPA; we cannot provide an audit report.
- An independent penetration test — Not yet commissioned. The application is covered by automated tests that specifically target isolation, access control and outbound-request safety, which is not the same thing and we will not pretend it is.
- A bug bounty — No formal programme. If you find something, email us and we will act on it — see below.
- A contractual uptime SLA — Available on Studio. Other plans are best-effort with a public status page.
- Single sign-on (SAML/SCIM) — Not built. Google sign-in is available for staff accounts.
- Data residency choices — One region. If you need data held somewhere specific, ask before you buy.
Found something?
Email support@ticketmodules.com with enough detail to reproduce it. We will acknowledge within two working days and tell you what we are doing about it.
Please do not test against another customer's workspace or against real customer data. Ask us and we will set you up somewhere you can.
We will tell affected customers about a breach without undue delay, and notify the relevant authority within 72 hours where the law requires it.