Zendesk vs Intercom: Security & Compliance Comparison
Summary
- Zendesk holds 14 certifications. Intercom holds 10 certifications.
- Both are certified for: SOC 2, ISO 27001, ISO 27018, ISO 27701, ISO 42001, GDPR, CCPA, UK GDPR, EU-US DPF, Swiss-US DPF.
- Zendesk has but Intercom doesn't: SOC 3, ISO 27017, CSA STAR, FedRAMP.
Side-by-side: all 32 frameworks
| Framework | Zendesk | Intercom |
|---|---|---|
| Security & General Standards | ||
| SOC 2 | ✓Annual audits against AICPA Trust Services Criteria | ✓ |
| SOC 3 | ✓Listed in Conveyor trust center badges | ?Not documented in trust center |
| SOC 1 | ?Not documented in trust center | ?Not documented in trust center |
| ISO 27001 | ✓ISO/IEC 27001:2022 | ✓ISO/IEC 27001:2022 |
| ISO 27017 | ✓ISO/IEC 27017:2015 | ?Not documented in trust center |
| ISO 27018 | ✓ISO/IEC 27018:2019 | ✓ISO/IEC 27018 |
| ISO 27701 | ✓ISO/IEC 27701:2019 | ✓ISO/IEC 27701 |
| ISO 42001 | ✓ISO/IEC 42001:2023 | ✓ISO/IEC 42001:2023 |
| ISO 9001 | ?Not documented in trust center | ?Not documented in trust center |
| CSA STAR | ✓CSA STAR AI Levels 1 & 2 | ?Not documented in trust center |
| HITRUST | ?Not documented in trust center | ?Not documented in trust center |
| BSI C5 | ?Not documented in trust center | ?Not documented in trust center |
| Privacy & Data Transfer | ||
| GDPR | ✓ | ✓ |
| CCPA | ✓ | ✓ |
| UK GDPR | ✓ | ✓Not documented in trust center |
| LGPD | ?Not documented in trust center | ?Not documented in trust center |
| PIPEDA | ?Not documented in trust center | ?Not documented in trust center |
| DPDP Act | ?Not documented in trust center | ?Not documented in trust center |
| PIPL | ?Not documented in trust center | ?Not documented in trust center |
| EU-US DPF | ✓Not documented in trust center | ✓Fin participates in EU-U.S. Data Privacy Framework |
| Swiss-US DPF | ✓Not documented in trust center | ✓Fin participates in Swiss-U.S. Data Privacy Framework |
| Global CBPR | ?Not documented in trust center | ?Not documented in trust center |
| Global PRP | ?Not documented in trust center | ?Not documented in trust center |
| Industry & Government | ||
| HIPAA | ~Requires purchase of Advanced Security or Advanced Compliance add-on and execution of BAA | ~HIPAA compliant only on Expert plan with proper configuration and BAA execution |
| PCI DSS | ~Tools provided for secure payment data handling; AWS data centers certified PCI DSS Level 1 | ?Not documented in trust center |
| FedRAMP | ✓FedRAMP LI-SaaS authorized | ?Not documented in trust center |
| StateRAMP | ?Not documented in trust center | ?Not documented in trust center |
| DORA | ?Not documented in trust center | ?Not documented in trust center |
| CJIS | ?Not documented in trust center | ?Not documented in trust center |
| FINRA | ?Not documented in trust center | ?Not documented in trust center |
| IRAP | ?Not documented in trust center | ?Not documented in trust center |
| Emerging & Strategic | ||
| NIST CSF | ?Not documented in trust center | ?Not documented in trust center |
✓ Certified~ Partial / conditional— Not certified? Not publicly documented
Need help choosing?
Join our waitlist for compliance alerts and expert comparisons.
Join the waitlist →