Zendesk Redaction

Customers paste card numbers into support tickets. They always have. Zendesk redaction is how you get that out of your helpdesk, and it's narrower than most people assume.

What Zendesk redaction does

Redaction permanently replaces selected text in a ticket comment with black blocks. It isn't hiding, it isn't a permission change, and it can't be reversed. The original characters are gone from the ticket, including from the ticket audit history that normally records everything.

An agent does it from the comment itself, selecting the offending text and choosing to redact it. Depending on your plan, this is either built into the agent interface or provided by the ticket redaction app, and on some plans the ability is restricted to administrators. Check which applies to your account before you write it into a policy, because a policy nobody can execute is worse than no policy.

Attachments work differently. You do not partially redact a file, you remove it. An agent deletes the attachment from the ticket and the file goes, leaving a note that something was removed. That covers the screenshot of a bank statement and the CSV of customer records that a well-meaning client sent you.

Credit card numbers specifically

This is why most people search for redaction in the first place, and there are three layers to it.

Automatic redaction. Zendesk can detect and mask credit card numbers in incoming ticket comments automatically. It is a setting, it's not on by default in every account, and it pattern-matches card formats. Turn it on. It catches the common case with no human involved.
A dedicated field. If you genuinely need to collect card data, and you should think hard about whether you do, Zendesk offers a credit card field type that stores only the last digits rather than putting the full number in a comment.
Agent habit. Automatic detection misses numbers split across lines, written in words, sitting inside an image, or pasted into a subject line. Agents need to know the manual redaction path exists and that using it is expected, not exceptional.

The honest position: automatic redaction reduces your exposure, it does not make your helpdesk PCI compliant, and no vendor setting will. Compliance is a scope question about your whole process, and the safest answer is that card numbers should never arrive in a ticket at all.

What redaction doesn't remove

This is the part that catches people out during an audit.

The original email. If the message arrived by mail, a copy may still exist on your mail server, in the sender sent items, and in any archive or journaling system you run. Redacting the ticket does nothing to those.
Anything already exported. A CSV somebody downloaded last week, a copy pulled through the API into a data warehouse, a message posted into Slack by an integration. Redaction acts on the ticket, not on everything downstream of it.
Side conversations and connected systems. If the number was forwarded to a supplier or copied into a Jira issue, redaction in Zendesk does not follow it there.
Archived tickets. Tickets closed long enough ago move to archive storage, and what you can do to them is more limited. Redact early rather than during a quarterly clean-up.
Ticket fields and subject lines, depending on your setup. Redaction is built around comment text, so check whether a custom field or subject containing personal data is actually covered before you assume it is.

Redaction is not erasure

A customer exercising a right to be forgotten is asking for something bigger than a black box over a comment.

That request usually means deleting the end user record, which removes their profile and, depending on how you do it, their tickets. Zendesk provides user deletion and permanent deletion paths for exactly this, and they are separate from redaction.

Redaction is the surgical tool: this specific string should not be in this specific ticket. Deletion is the blunt one: this person should not be in the system. Knowing which one a request calls for is most of handling it correctly. There is more context in the security and compliance guide.

Making it routine

Three things turn redaction from a feature into a practice.

Write down what must be redacted. Card numbers, national insurance or social security numbers, passwords, full bank details, medical information. If the list is vague, agents will guess, and they'll guess low.

Tell customers not to send it. A line in your auto-acknowledgement asking people never to include card details in a message prevents more exposure than any redaction workflow, because it stops the data arriving.

Audit occasionally. Search your tickets for number patterns once a quarter. It takes an hour and it is the only way you find out whether the policy is real.

FAQ

Frequently asked questions

Does redaction cover attachments and make us PCI compliant?

Partly, and no. To redact an attachment Zendesk removes the file rather than editing it, and redact personal data Zendesk-side is manual unless you script it. Zendesk PCI compliance is about your whole process, not one feature.

How do you redact a ticket in Zendesk?

Select the text in a comment and use the redact action, which is how Zendesk redact ticket workflows start. Zendesk credit card redaction can run automatically on detection, and you redact an attachment by removing the file rather than editing it.

Can Zendesk redaction be undone?

No. Redaction is permanent, including in the ticket audit trail. Redact the wrong text and it's gone.

Does Zendesk redact credit card numbers automatically?

It can. There is a setting that detects and masks card number patterns in ticket comments. It misses split, spelled-out and image-embedded numbers, so agents still need the manual path.

Can I redact an attachment?

Not partially. You delete the attachment from the ticket, which removes the file and leaves a record that something was removed.

Does redaction make us PCI compliant?

No. It reduces exposure. Compliance depends on your whole process, and the real fix is keeping card data out of tickets entirely.

Who can redact in Zendesk?

It depends on your plan. On some it is any agent, on others it is restricted to administrators or requires the redaction app. Confirm before writing it into a procedure.

Redact once, not twice

Sensitive data in a duplicate ticket has to be redacted twice, and the second copy is the one people forget.

Start free trial

14-day free trial. No credit card required.