Trust

Security and data handling, without vague promises.

The current architecture, concrete controls, service providers, known limitations, and route for reporting a security concern.

Current safeguards

  • TLS for the website, app, API, and provider webhook traffic.
  • Application encryption for Resend API keys and webhook secrets, backed by managed production key storage.
  • Workspace-scoped authorization and explicit owner, admin, agent, and viewer permissions.
  • Resend webhook signature checks and provider-message deduplication before messages are stored.
  • Inbound HTML sanitization before customer email is displayed in the app.
  • Masked website analytics with no session recording and no customer message content.
Providers and subprocessors

Who supports the service and what they receive.

ProviderPurposeProcessing scope
Microsoft AzureAPI, PostgreSQL database, application secrets, and production operationsPrimary workspace data is deployed in North Europe.
CloudflareWebsite and app delivery, TLS, caching, and edge securityRequests may pass through Cloudflare's global edge network.
ResendProduct email and customer-directed inbound and outbound email integrationMessage processing follows the connected Resend account and workspace configuration.
GoogleOptional account sign-inUsed only when a person chooses Google authentication.
PaddleMerchant of record, checkout, taxes, invoices, and subscription billingPaddle is an independent controller for payment and transaction records.
PostHog EU CloudMasked public-site analytics and aggregate Core Web VitalsNo session recording, visible page text, URL queries, or workspace message content.

Retention and deletion

Workspace data is kept while the service is active and for the limited closure, security, billing, and legal period described in the privacy policy. Verified owners can request export or deletion; self-service export is not yet available.

Incident handling

Confirmed incidents are contained, investigated, documented, and communicated to affected customers without undue delay when workspace personal data is involved.

Security reports

Report a suspected vulnerability through the contact page with reproduction steps and impact. Do not access other customers' data or run disruptive tests.

Current assurance level

ReTicketDesk does not currently claim its own SOC 2 or ISO 27001 certification. It uses managed providers with established security programs, but provider certifications do not automatically certify ReTicketDesk. Customers with a formal review can request current architecture and control answers without sending production secrets over email.

Contractual processing terms are available in the public DPA and data-use details are in the privacy policy.