The Zendesk SOC 2 Report

The Zendesk SOC 2 report is what procurement asks for and almost nobody reads past the cover page. The genuinely useful part sits near the back.

What a SOC 2 report actually is

A SOC 2 is an attestation report produced by an independent audit firm against criteria published by the AICPA, known as the trust services criteria: security, and optionally availability, processing integrity, confidentiality and privacy. Security is the one everyone includes. The others are a choice the vendor made.

It isn't a certificate. There's no pass mark, no expiry sticker, and the logo means less than people think. It's a document in which a company describes the controls it says it operates, and an auditor gives an opinion on them after testing.

That framing changes how you read it. You're not checking whether a box was ticked. You're reading somebody else's homework and deciding whether the marking was strict.

Type I versus Type II

Type IType II
What it testsWhether controls are designed appropriatelyWhether controls actually operated over time
CoverageA single point in timeA stated period, commonly several months or a year
Effort for the vendorLowerSubstantially higher
When it is acceptableA young company on its first audit cycleWhat you should expect from an established vendor

How to request the Zendesk SOC 2 report

These reports contain detail vendors don't publish openly, so they're almost always released under an NDA rather than downloaded from a website.

There are three routes and any of them work. A trust centre with a request form, your account manager, or the salesperson if you're mid procurement. That last one is fastest, because they have done it a hundred times.

Ask for two things, not one. The most recent report, and a bridge letter covering the gap between the report end date and today. Without the bridge letter you are relying on a document that might describe a period which ended eight months ago.

What a reviewer should actually look for

Scope. Which systems and which products are covered. A vendor with several products may not have every one of them in scope, and the one you're buying could be the exception.
The period. For a Type II, check the window is current and that consecutive reports do not leave a gap between them.
The opinion. Unqualified is what you want. Qualified means the auditor found something worth flagging, and you should read exactly what.
The exceptions in the testing tables. Buried near the back, and this is where the information is. Which control tests found deviations, how many, and what management said in response.
Complementary user entity controls. A list of the things the report assumes you are doing. It is the vendor telling you which parts of the security model are your job. Almost nobody reads it. Read it.
Sub-service organisations, and whether they are carved out or included. Carved out means those controls were not tested here, so you need their report too.

What SOC 2 will never tell you

It says nothing about your configuration. Your roles, your API tokens, your retention settings and your installed apps sit outside every audit scope except your own. That's the half security reviews actually find problems in, and there's a checklist for it in the security and compliance guide.

It's also not GDPR compliance. Even when the privacy criterion is included, a SOC 2 is not a substitute for a processing agreement, see the Zendesk DPA.

And it doesn't guarantee nothing goes wrong. It says a defined set of controls was tested by one firm over a stated period and mostly held. Treat it as evidence rather than as an answer, and if the contract is large enough, have your own auditor read it instead of taking a summary on trust. None of this is legal advice.

The other acronyms you will be handed

SOC 2 rarely arrives alone, and knowing what else is in the envelope saves you asking for the wrong document.

SOC 1 covers controls relevant to financial reporting. Different question entirely. This is the one your finance auditor wants when a vendor sits inside a financial process, and it tells you almost nothing about security.
SOC 3 is a short public summary of a SOC 2, publishable without an NDA. Fine for a first pass in a vendor shortlist. Useless for an actual review, because all the detail worth reading has been removed.
ISO 27001 certifies an information security management system through an accredited body. It attests to the system for managing security rather than testing individual controls the way a Type II does. Plenty of vendors hold both, and they answer different questions.
Penetration test letters. Usually a summary rather than the full report. Ask what scope was tested, when, and whether findings were retested afterwards.

None of them substitute for each other, and a reviewer who knows the difference asks sharper questions and finishes faster. If you're the one assembling this for a customer of your own, the same list is what they'll ask you for.

FAQ

Frequently asked questions

How do you request the SOC 2 report?

Through the Zendesk trust center, usually under NDA. Ask specifically for the Zendesk SOC2 Type 2 audit report rather than a summary, and the same page lists the other Zendesk certifications.

Does Zendesk have a SOC 2 report?

Certification and attestation statuses change, and scopes change with them, so the only reliable answer comes from Zendesk directly. Request current documentation through their trust centre or your account team rather than relying on any third-party page.

Should we ask for Type I or Type II?

Type II. A Type I describes how controls looked on one day. A Type II tests whether they kept working across a period, which is the question you actually care about.

Is SOC 2 a certification?

No, it's an attestation. An independent firm gives an opinion on described controls. There's no certificate and no formal pass mark.

How long is a SOC 2 report valid for?

It isn't valid or invalid, it describes a period. Once that period is a few months behind you, ask for a bridge letter or the next report.

Can we share the report internally?

Check the NDA you signed to receive it. Sharing is usually limited to people who need it for the assessment, and posting it anywhere wider is normally a breach.

The vendor half and your half

Audit reports cover the vendor. Your configuration is yours, and a queue full of duplicate tickets is a data footprint you chose without meaning to.

Start free trial

14-day free trial. No credit card required.