TECHNOLOGIES: ZENDESK

Zendesk Security Review

Zendesk enforces exactly the roles and app permissions your admins configure, gaps included. We test your custom roles, light agents, organisation visibility and app secure settings for what each can reach. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Zendesk Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
197

Zendesk lets an Enterprise account define up to 197 custom agent roles, each combining its own mix of ticket, people, channel and Help Centre permissions. We test whether your roles, and the light agents beneath them, actually hold only the access their job needs.

Why a Zendesk finding is a role or app setting, not a Zendesk flaw

Zendesk’s own custom roles documentation caps an Enterprise account at 197 custom agent roles, each choosing its own mix of permissions across tickets, people, groups, channels, business rules, routing, security, Help Centre and analytics, on top of predefined Advisor, Staff and Team lead templates. A light agent sits below every one of those roles: they can be CC’d on a ticket, view tickets in their groups and add a private comment, but Zendesk’s own terms prohibit using the API to give a light agent reach their role does not carry in the agent interface. We test whether every custom role and every light agent actually holds only the access its job needs.

Zendesk is removing API tokens as an authentication method: unused tokens deactivate automatically from 28 July 2026, and every remaining token stops working by 30 April 2027, leaving OAuth access tokens, each scoped to a single instance, as the route in. An integration built for more than one Zendesk customer has to authenticate with a global OAuth client instead of a personal token or account-specific OAuth client, since Zendesk’s Developer Terms forbid sharing API credentials with a third party. We test which authentication method every integration in your account actually uses today, and what it can reach.

Putting end users into an organisation is optional, but a setting on it can let every member see every other member’s tickets, and a separate sharing agreement can hand a ticket to a different Zendesk Support account entirely, with its status and comments kept in sync. A private app’s secure parameter is substituted into a request by Zendesk’s own proxy so only a placeholder reaches the browser, and a domain allowlist on that app is what actually stops the setting being redirected somewhere else. Single sign-on covers SAML, JWT and OpenID Connect, and Zendesk’s own guidance makes verifying user identity and email addresses the account owner’s job, not Zendesk’s. We test organisation visibility, sharing agreements, app secure settings and SSO configuration against exactly that standard.

SCOPE

What we pen test on a Zendesk tenant

ZD-01

Team Member Roles and Product Access

Admin Center groups every team member into a Support role: Admin, who manages every Support setting except billing; Agent on Team, Growth and Professional plans; Contributor on Chat-only accounts; and Light agent, available from Suite Growth upward. We test whether every team member’s assigned role still matches the access their job actually needs.

ZD-02

Custom Agent Roles

On Enterprise plans, an account can define up to 197 custom agent roles, each combining permissions across tickets, people, groups, channels, business rules, routing, security, Help Centre and analytics on top of predefined Advisor, Staff and Team lead templates. We test whether every custom role in your account actually holds only the permissions its job needs, not what its starting template carried.

ZD-03

Light Agent Permissions

A light agent can be CC’d on a ticket, view tickets in their groups and add a private comment, but cannot be assigned a ticket or edit one, and Zendesk’s terms prohibit using the API to give a light agent access their role does not carry in the agent interface. We test whether every light agent in your account is actually held to those limits, including through any custom integration.

ZD-04

Organisation-Based Ticket Visibility

Putting end users into an organisation is optional, but a setting on that organisation can let every member see every other member’s tickets, and Professional and Enterprise plans allow a single user to belong to up to 300 organisations at once. We test whether that visibility setting is actually switched on only where your business intended it.

ZD-05

Cross-Account Ticket Sharing Agreements

A sharing agreement hands a ticket to a different Zendesk Support account entirely, keeping its status and comments synced between both sides while each account keeps its own separate business rules. We test who can create a sharing agreement, which fields it exposes to the receiving account, and what that account’s agents can actually see.

ZD-06

API Token and OAuth Authentication

Zendesk is removing API tokens as an authentication method: unused tokens deactivate automatically from 28 July 2026 and every remaining token stops working by 30 April 2027, leaving OAuth access tokens, each scoped to a single instance, as the way in. We test which authentication method every integration in your account actually uses today, and what it can reach if it leaks.

ZD-07

Global OAuth Clients for Distributed Integrations

An integration built for more than one Zendesk customer has to authenticate with a global OAuth client rather than a token or OAuth client tied to a single account, since Zendesk’s Developer Terms forbid sharing API credentials with a third party. We test whether every third-party integration in your account is actually using the credential type it is supposed to.

ZD-08

App Secure Parameters and Domain Allowlisting

A private app’s secure parameter is substituted into a request by Zendesk’s own proxy server, so only the placeholder ever reaches the browser’s developer tools, and a domain allowlist on that app is what stops the setting being redirected to another domain where the underlying token or password could be read. We test every app’s secure parameters and domain allowlist for exactly that gap.

ZD-09

Third-Party OAuth in Marketplace Apps

An app’s manifest can carry an OAuth setting for a third-party service, but Zendesk only supports the authorisation code grant type for it, and an admin has to complete that OAuth flow during installation before the app can use it. We test what a connected app’s third-party OAuth grant actually exposes and how it is stored once issued.

ZD-10

Help Centre Access and Single Sign-On

A Help Centre can be restricted to signed-in users only, and a user segment built from tags, groups, organisations or individual users then controls which articles each signed-in user or agent can actually see. Single sign-on covers SAML, JWT and OpenID Connect, and Zendesk’s own guidance makes verifying user identity and email addresses the account owner’s responsibility; we test whether every signed-in path and SSO configuration in scope is actually held to that standard.

OUR PROCESS

Zendesk Tenant and Integration Security Review: From Scope to Attestation

01

Scope and Access

We agree which Zendesk plan, roles, organisations, apps and sharing agreements are in scope, plus an admin test account and a regular agent or light agent account for a couple of your roles.

02

Role and Permission Mapping

We map your Support roles, custom roles, light agent configuration, organisation visibility and app OAuth or secure settings across the account before manual testing starts.

03

Manual Testing

A CREST-certified tester manually tests role and permission boundaries, ticket sharing agreements, app secure settings and API authentication, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Zendesk pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Zendesk Tenant and Integration Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Zendesk Tenant and Integration Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Zendesk account?

We need an admin test account for scoping, plus a regular agent account and, if you use them, a light agent account, so we can test what each role can actually reach. If you run private or public apps, or have organisations, sharing agreements or a Help Centre in scope, tell us during scoping so we can agree exactly what to test.

Will testing touch our live data?

We test whichever Zendesk account you nominate. A sandbox or trial account avoids any risk to live ticket data, and if we test your production account, we agree exclusions, such as sending real customer-facing notifications, before testing starts.

How long does a Zendesk security review take?

A single Zendesk tenant sits in our 3-day single-tenant scope, with a report typically landing around 6 to 8 working days after kickoff. An account with several custom roles, sharing agreements, a large app footprint or an extensive Help Centre can move into a wider scope.

Zendesk is a hosted SaaS platform. What are you actually testing?

Zendesk’s own infrastructure and multi-tenant platform are never in scope; that is Zendesk’s responsibility, not yours. We test the roles, light agents, organisation and sharing settings, private apps, API authentication and Help Centre configuration your team has set up inside the account.

What is out of scope for a single-tenant Zendesk review?

Zendesk’s own infrastructure and multi-tenant hosting are never in scope. A separate system that only happens to integrate through the API, a sharing agreement partner account, or a distinct Zendesk product such as Sell or Chat used independently, is scoped and quoted separately.

Do you need our app source code?

We do not need Zendesk’s own platform code, since that belongs to Zendesk. For a private app your team has built, a grey-box option where we review its manifest, secure parameters and OAuth configuration alongside testing is available if you want deeper coverage.

Does Zendesk have a customer penetration-testing policy we need to follow?

Zendesk’s Trust Centre describes its own annual third-party penetration testing programme against Zendesk’s production and corporate networks, plus a Responsible Disclosure and Bug Bounty programme run through HackerOne for vulnerabilities in the Zendesk platform itself. Testing your own tenant’s configuration is a separate activity, and we confirm Zendesk’s current terms during scoping before testing starts.

Do you test our Help Centre and sign-in restrictions?

Yes. If your Help Centre is restricted to signed-in users, or uses user segments to control which articles specific agents or end users can see, we test whether that access actually holds up against a request that tries to skip it.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Zendesk tenant

Zendesk enforces exactly the roles and app permissions your admins configure, gaps included. We test your custom roles, light agents, organisation visibility and app secure settings for what each can reach. CREST-certified testers, fixed price from £4,180 for a 3-day single-tenant scope, quoted within 24 hours.