Skip to content

Security and data

Where your data goes, said plainly.

What DeskAI stores, exactly what it sends to the AI and when, and the controls you have over both.

Where it runs

Our cloud or your servers.

The same product either way. Self-hosting keeps ticket data inside your network, apart from the requests DeskAI makes to the services you connect.

  • Deskyon cloud

    We provision and run your workspace, so there is nothing for you to install or patch.

    • Set up with you by our team
    • US or EU data residency
    • Your workspace's own Anthropic API key
  • Your own infrastructure

    Run DeskAI with Docker Compose on servers you control, next to a PostgreSQL database you own.

    • Your database, your backups
    • Your own Anthropic API key
    • Outside calls only to services you connect: Anthropic, your mail server, and Slack, Teams or Azure AD if you set them up

What the AI sees

Every AI request, and what is in it.

DeskAI uses Anthropic's Claude models. Requests go from DeskAI's server straight to Anthropic's API with your workspace's own key, with no other AI provider in between. Triage, draft replies and the AI agent each have their own switch under Admin Portal → AI Settings.

What DeskAI sends to Anthropic, by feature
FeatureWhat is sentWhen
AI triageThe ticket's subject and body, the requester's name and email, and excerpts of matching knowledge base articlesEach new ticket, while auto-triage is on
Draft repliesThe ticket's subject and body, the requester's name, and the fix triage suggestedEach new ticket, while draft replies are on
AI agentThe ticket's subject and body, the requester's name, and matching knowledge base excerptsOnly if you turn the AI agent on (it is off by default), or when an admin sends it a test ticket
Email InboxThe email's sender, subject and bodyWhen an agent opens an email (summary) or asks for an AI draft
AI assistantThe conversation, with the ticket and knowledge base context it was opened withWhen an agent uses the assistant
Article writingThe topic you typeWhen someone clicks Generate in the knowledge base
AI workflowsThe ticket's subject and body, the requester's email, its current priority and category, and the instruction an admin wrote for that stepEach time an automation rule with an AI check or AI action runs. Only rules an admin creates have AI steps
AI tuningYour team's written instructions, and the subjects of up to six similar past tickets where an agent changed the AI's priority or categoryAdded to triage, drafts and AI workflow steps once tuning is set up. Learning from corrections can be switched off
TranslationThe subject and body of a ticket raised with the New Ticket form, and later the agent's reply to itOn those tickets, to detect the language; a non-English ticket is translated to English and replies are translated back. There is no switch for this yet

Anthropic's commercial terms cover how it handles API data; by default it does not train its models on API inputs and outputs. Smart routing, knowledge base suggestions and SLA alerts run inside DeskAI and send nothing to the AI.

Who can see what

Access that follows the job.

  • Sign-in

    Passwords are stored as bcrypt hashes, never as text. On Business and Enterprise, agents can sign in through your identity provider with SAML, and you can require it. On Enterprise, SCIM deactivates people who leave, and their sessions stop working within seconds.

  • Roles

    Agents work tickets, admins manage the workspace, and only the MSP admin role can see across clients.

  • Client isolation

    For MSPs, each client's tickets, articles, analytics, automations, catalogue and assets stay inside that client's workspace and portal.

  • Audit logs

    Ticket actions are logged: created, triaged, assigned, replied, noted, edited, resolved and reopened. On Business and Enterprise, a security log adds sign-ins, refused sign-ins, SSO, SCIM and integration changes. Both export to CSV.

  • API keys and webhooks

    On Enterprise, API keys are scoped to one company and to the permissions an admin picks, limited to 120 requests a minute, stored only as a fingerprint and revocable at once. Webhooks can be signed so your systems can check they came from DeskAI.

  • Approval links

    A manager's approval email carries a signed link that works for 30 days and only for that request. Opening it decides nothing.

  • Employee portal

    Employees raise tickets, follow them and read your help articles without a DeskAI login, so they never get access to the agent workspace.

And the test drives on this site

They run in your browser on invented sample data, so nothing you do in them is saved. When a drive uses live AI, the text you type is sent to Anthropic on our own key and is not stored. The per-visitor limit on live tries keeps a one-way hash of your IP address, never the address itself.

See the test drives

Questions

Ask us anything specific.

Security reviews, data processing questions, how self-hosting fits your network: a person who knows the product answers.