Security
Last updated October 6, 2026
What protects your tickets, what your admins control, and what Flatdesk doesn't have yet. If you're reviewing Flatdesk as a vendor, this page, the data processing addendum and the privacy policy are the documents to read.
What Flatdesk doesn't have yet
Read this first, so nothing below reads as more than it is.
- SOC 2 or ISO 27001 report. Flatdesk is new and hasn't been audited.
- An independent penetration test.
- Single sign-on (SAML or OIDC) and SCIM provisioning.
- An uptime commitment with service credits.
- A choice of data region.
- HIPAA or PCI scope. Don't send health records or card numbers through Flatdesk.
If one of these is a requirement for you, Flatdesk isn't the right fit today. Tell us which, at flatdeskmain@gmail.com, because it decides what we build next.
Controls your admins have
- Required two-step verification. An admin can require it for the whole team. Anyone without an authenticator app on their account is stopped before the help desk opens until they add one.
- An off switch for AI. With “Allow AI features” off, nothing from your team is sent to the AI provider: no AI answers, drafts, summaries, AI macros or test drive. Every call to the AI goes through one check, so no feature can skip it. You can try Flatdesk this way and turn AI on later, or never.
- An audit log. Settings changes, seat changes, exports, imports, AI answer refunds, deleted macros and people joining, with who and when. Admins see it in Settings, and it's in the full export.
- Roles. Admins change settings and billing. Agents answer tickets. Viewers can read but not change anything, and aren't billed. Removing someone from the team in Flatdesk ends their access.
- A full export, any time. One download has every ticket, message, customer, macro, help article, the audit log, and every attachment as its original file. Admins don't need to ask us.
How data is handled
- Data is encrypted in transit (HTTPS only) and at rest by our hosting and database providers.
- Every team's data is kept apart in the database by team, and every page and action checks the signed-in person's team before reading anything. Automated tests check that one team can't reach another team's tickets, files or settings.
- Attachments can be downloaded only by your team, and by the chat visitor they were sent to.
- API tokens for importing from your old help desk are encrypted while the import runs and erased when it ends.
- Sign-in is handled by Clerk. Flatdesk never sees or stores passwords.
- Card details go to Stripe and never reach Flatdesk.
- The chat widget, ratings and sign-up forms are rate limited, and store a one-way hash of the sender's IP address rather than the address.
The AI
AI features use Anthropic's API. Under Anthropic's commercial terms, data sent through the API isn't used to train its models. Flatdesk doesn't use your conversations to train anything either. What's sent: the ticket being answered, your team's AI notes, macros and help articles. AI answers to customers are on for new teams, but nothing reaches a customer until you forward your support email or add the chat widget, and an admin can switch AI answers, or all AI processing, off first.
Who processes your data
Vercel (hosting), Neon (database and files), Clerk (sign-in), Stripe (payments), Resend (email) and Anthropic (AI). Each one's role and privacy policy is listed in the privacy policy. We give 30 days' notice before adding a new one (see the DPA).
If something goes wrong
If we learn of a breach affecting your data, we'll tell your team's admins without undue delay and within 72 hours, with what we know and what we're doing about it. Deleting your account removes your data within 30 days.
Report a vulnerability
Email flatdeskmain@gmail.com with the details. We'll reply within two business days and won't take legal action against good-faith research that avoids other teams' data and doesn't disrupt the service.