A short, checkable answer for anyone reviewing Raiseaticket before they put customer data in it.
Raiseaticket is operated by Fonicom Limited from Malta, in the European Union, and customer data is hosted in EU-based data centres.
The hosting facilities hold ISO 27001, ISO 9001, ISO 14001 and ISO 50001. To be precise about what that means: those certifications are held by the data centres, not by Raiseaticket itself. It is worth stating plainly, because a security questionnaire will eventually ask.
Data is encrypted in transit and at rest.
Access is controlled by role. There are four - Super Admin, Admin, Agent and User - and agents see their own group's tickets rather than everything. Multi-factor authentication is available on every account including the free plan, and single sign-on is available as a premium capability through the Microsoft 365 or Google Workspace integration.
Actions are recorded in audit logs, and each ticket carries its own history of who changed what and when.
Regular backups keep service data recoverable.
Raiseaticket is built to be GDPR-compliant, and your data can be exported - including the data held about an individual user, which is what a subject access request needs.
If your review needs uptime commitments, retention periods, a sub-processor list, penetration testing results or a completed security questionnaire, those are not published here. Contact us and we will answer directly rather than leave you guessing.