BoldDesk Security and Compliance Overview
BoldDesk takes your privacy, data, and security as our highest priority. Below is an overview of BoldDesk’s security and compliance measures. You can find more detailed information in the links provided.
- SOC 2 Type 2 Certified: BoldDesk is SOC 2 Type 2 certified, demonstrating our commitment to industry-standard security, availability, and confidentiality practices.
- GDPR Compliance: BoldDesk follows GDPR regulations to ensure proper handling and protection of personal data.
- Data Encryption: All customer data is encrypted both at rest and in transit using industry-standard encryption protocols.
- Access Control: We employ strict access control measures, including multifactor authentication and role-based permissions, to safeguard sensitive data.
- Third-Party Sub-Processors: We use trusted third-party sub-processors to help process, store, and secure information. Details about these Sub-processors.
- Data Processing Amendment (DPA): A Data Processing Amendment is available for customers who require it.
- Secure Payment Processing: All payment transactions are securely handled by Stripe, a PCI-compliant payment processor responsible for encrypting and processing credit card information.
- HIPAA Compliance: BoldDesk is a HIPAA‑compliant help desk and ticketing system designed to securely handle Protected Health Information (PHI) for healthcare organizations and business associates. Explore HIPAA Onboarding and Security Guidelines for BoldDesk Users.
For more detailed information, please check: BoldDesk Security and Compliance Details
If you need additional information, please contact your sales representative.
- BoldDesk is offered as a fully managed, cloud-native SaaS solution. BoldDesk does not support self-hosted, single-tenant, or customer-controlled deployment in a customer’s own Azure, AWS, GCP, or private cloud tenant.
- BoldDesk manages the application infrastructure, platform operations, security controls, and maintenance. Customer data is securely isolated and protected using security controls such as encryption in transit and at rest, access control, and compliance-aligned practices.
Infrastructure, Logging, and Security Monitoring
BoldDesk is a fully managed SaaS solution hosted on Google Cloud Platform (GCP). The database is hosted in an India-based GCP region, while application-level data processing is performed through infrastructure hosted in the United States. The application and its supporting cloud infrastructure are owned and managed by the BoldDesk engineering and operations teams. BoldDesk is built on a cloud-native, scalable architecture; however, detailed internal architecture information is not publicly disclosed for security reasons.
BoldDesk maintains application and security logging within its managed cloud environment. The platform internally captures and monitors application activity logs, error and exception logs, authentication and authorization events, API access logs, administrative and configuration-change events, infrastructure and service logs, database operational logs, and audit-related events.
Log Storage and Retention
- Application and security logs are stored within the BoldDesk-managed cloud environment.
- Logs are retained for 15 days.
- Log storage locations, log formats, sample log files, and other internal logging implementation details are not shared externally.
SIEM and External Log Integration
As part of the managed SaaS environment, BoldDesk currently does not support:
- Direct customer access to application or security logs.
- Log export capabilities.
- Log forwarding to external monitoring platforms.
- Integration with customer-managed SIEM, XSIAM, or similar log-ingestion solutions.
- Customer-configurable log collection agents.
Logging, monitoring, and security analysis are performed through BoldDesk’s internal cloud-based monitoring and security mechanisms.
All application and security logging activities are managed internally by BoldDesk. Customers cannot access, export, or forward logs to third-party monitoring or security analysis platforms.
Frequently Asked Questions
-
Does BoldDesk encrypt data and attachments?
Yes. BoldDesk encrypts all customer data and file attachments in transit and at rest using industry-standard protocols. -
Is encryption enabled by default, or does it require setup?
Encryption is enabled by default. No additional configuration is required. -
Can users upload attachments securely through portals or email?
Yes. Files added through the agent portal, customer portal, or email are encrypted once uploaded. -
Do customers get direct access to application or security logs?
No. Customers cannot directly access application or security logs in BoldDesk. -
Can BoldDesk export logs or forward logs to a customer SIEM/XSIAM?
No. BoldDesk currently does not support log export, log forwarding, or integration with customer-managed SIEM/XSIAM platforms. -
How long does BoldDesk retain application and security logs?
BoldDesk retains logs for 15 days. -
Does BoldDesk support self-hosting or customer-tenant hosting (AWS/Azure/GCP)?
No. BoldDesk is a fully managed SaaS service and does not support self-hosted, single-tenant, or customer-controlled deployment in a customer’s own cloud tenant. -
Does BoldDesk require a specific Consent Management Platform (CMP) for GDPR?
No. BoldDesk does not require or recommend a specific CMP. CMP selection and configuration are handled by the customer organization.