Security & Trust
What we access in Slack, what we store, and how we handle it.
Last updated: September 9, 2026
Ticketping stores customer and internal support conversations. This page describes how that data is handled today — what we access in Slack, what we store, and which services we use.
For the legal terms of collection and use, see the Privacy Policy.
Infrastructure
The Ticketping application and email pipeline run on Amazon Web Services (AWS). The public website is served on Vercel.
Application servers are not reachable from the public internet. API traffic enters through an AWS Application Load Balancer. People who operate production systems connect through a jump host, not directly to those servers.
Traffic between your browser, Slack, and Ticketping uses HTTPS/TLS.
Support attachments are stored in a private Amazon S3 bucket. The bucket blocks public access, requires HTTPS, and encrypts objects at rest with AES-256. Downloads go through Ticketping, not public S3 links.
Secrets and API credentials are loaded from the environment. They are not stored in application source.
Slack
Ticketping connects to your workspace with Slack’s official OAuth flow and Events API. Incoming Slack requests are verified with Slack’s signing secret.
Ticketping cannot read private direct messages between two people in your workspace. Slack does not give apps that access.
Ticketping can read:
- Messages people send to the Ticketping bot — that is how Slack DM tickets are created
- Messages in channels the bot is added to, including private channels
- Files attached to those conversations
- Basic profile data, including names, Slack user IDs, and email addresses, so we can identify customers and teammates
Messages become tickets only when they arrive as:
- A DM to the Ticketping bot
- A message in a channel you have configured for monitoring
- A reply in your team’s Ticketping Slack channel on an existing ticket
You can remove Ticketping from Slack at any time in your workspace app settings.
Data we process
Depending on the features you use, Ticketping may process:
- Slack messages and files used to create or update tickets
- Ticket replies, status, assignment, and related metadata
- Names, email addresses, Slack user IDs, and profile photos
- Customer emails sent to Ticketping-managed support addresses
- Messages submitted through the chat widget or help-center forms
- Workspace and channel metadata needed for the Slack integration
- Team knowledge-base articles used by the optional chat agent
- Billing details handled by our payments provider
- Product analytics and error reports used to operate the service
We do not sell customer data. We do not use support conversations for advertising.
Access to customer data
Access to production systems is limited to people who operate Ticketping. We look at customer data when we need to run the service, debug an issue, answer a support request, or investigate abuse.
Authentication
Agents sign in with an email one-time code, a password, or Google. Public sign-in and ticket forms are protected with Cloudflare Turnstile.
API access defaults to authenticated users. Team data is scoped to the workspace you belong to. Workspace owners and admins can issue API keys.
Application practices
- Encrypted connections for application traffic
- Secrets kept out of source control
- File uploads checked for type and size — images and PDFs, 10 MB limit
- Slack and inbound-email webhooks verified before they create tickets
- Development and production environments kept separate
AI features
Some Ticketping features send text to OpenAI’s API:
- One-line ticket summaries
- Deciding whether a new Slack channel message is a follow-up to an open ticket
- An optional chat widget agent that answers from your team’s knowledge base
When those features run, we send the relevant message text. The chat agent also receives your knowledge-base articles. Ticket text sent for summaries is truncated.
Ticketping does not use your support conversations to train its own models. We use OpenAI’s API, which does not use API inputs or outputs to train OpenAI’s models by default.
Third-party services
Ticketping uses a small set of providers to run the product:
- Amazon Web Services — application hosting, object storage, and email
- Vercel — public website hosting
- Slack — workspace integration
- OpenAI — ticket summaries, follow-up classification, and the optional chat agent
- Cloudflare — DNS, Turnstile bot protection, and image hosting
- Resend — authentication and transactional email
- Dodo Payments — billing
- Sentry — error monitoring
- PostHog — product analytics
- Google — optional sign-in
We use these services because the product depends on them, not to sell or advertise your data.
Data retention and deletion
We keep workspace data while you use Ticketping.
There is no self-serve workspace wipe today. Email security@ticketping.com to request deletion of your workspace and associated customer data. We will process that in a reasonable timeframe, except records we are required to keep — for example, billing.
Security incidents
If we learn of a security incident that materially affects customer data, we will investigate and notify affected customers when appropriate.
Compliance
Ticketping is an early-stage product and is not SOC 2 certified.
We would rather say that plainly than imply a report we do not have.
If your organization needs a security questionnaire during evaluation, email security@ticketping.com.
Responsible disclosure
If you believe you have found a security vulnerability in Ticketping, email security@ticketping.com.
Include enough information for us to reproduce the issue. Please do not publish it until we have had a reasonable chance to investigate and fix it.
Security questions
For security reviews, vendor questionnaires, deletion requests, or other security questions, contact security@ticketping.com.
Account and product questions go to support@ticketping.com.