whats-best.ai

Customer Service & Helpdesk

Zammad

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 2 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Zammad GmbH · zammad.com

Compare with Freshdesk → Compare with OTRS → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Skeptic

Weighted verdict

Counts the channel logos on the marketing page, then asks which of them share one queue and one history. Reads for the tier where SLA policies begin, what a "light agent" may actually do, and whether the AI summariser is included or metered.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Skeptic

Ticketing, queues & SLA

How this is scored

The engine: how work is routed, prioritised, escalated and measured — and whether an agent can find the ticket they need among ten thousand.

0 — A shared mailbox with labels; no ownership, no status model, no history beyond the thread.

3 — Tickets with assignment and open/closed status, but routing is manual, there are no SLA timers and search covers subject lines only.

5 — Queues with rules-based routing, priorities, a working status model, SLA timers with breach warnings, and full-text search across ticket bodies.

8 — Business-hours-aware SLA policies per queue or customer, escalation chains, macros and triggers, merge and split, and reporting on first-response and resolution time by agent and queue.

10 — The workload is managed rather than merely tracked: capacity-aware assignment, SLA per contract with reporting an account manager could show a customer, audit of every status change, and search that finds the ticket from a half-remembered phrase.

Report an error

The Skeptic

States, assignment, escalations, SLAs, macros, templates and automation rules are all named, and I can read exactly which tier SLAs start at — Professional v2. But nothing evidences business-hours-aware SLA policies, merge/split, first-response reporting by agent and queue, or full-text search across ticket bodies — the bullets are marketing nouns, so I stop just past the anchor-5 line. 2 3

Report an error

Channels in one queue

How this is scored

Email, chat, phone, portal, messengers and social — judged on what actually lands in the same queue with the same history, not on how many channel logos the marketing page carries.

0 — Email only.

3 — Email plus one more channel, but the second lives in its own inbox: no shared history, and a customer who switches channel starts again.

5 — Email, a web form or portal and live chat all landing as tickets in one queue, with the customer's history visible whichever channel they used.

8 — The above plus telephony integration with call logging, at least one messenger (WhatsApp, Signal or similar) with its consent handling stated, and a customer portal where a requester can see their own tickets.

10 — Channel is an implementation detail: every channel including voice and messengers writes to one conversation with one history, agents answer from one screen, and the customer can move between channels mid-issue without repeating themselves.

Report an error

The Skeptic

Seven channels are named per tier — Email, Web Form, SMS, Chat, Telegram, Facebook, WhatsApp — plus 'Telephony integration', and the 'unified structured ticket view with history' claims one history. My follow-ups go unanswered: no evidence of call logging behind the telephony bullet, no consent handling stated for WhatsApp, and no requester portal where a customer sees their own tickets — the help centre is a knowledge base, not a ticket portal. 2 3

Report an error

Knowledge base & deflection

How this is scored

Whether the product reduces the number of tickets as well as organising them: public help centre, article workflow, suggestions to agents and to customers.

0 — No knowledge base; answers live in agents' heads and old tickets.

3 — A basic article list, public or internal, with no editorial workflow, no versioning and no link between articles and tickets.

5 — A searchable public help centre with categories, draft and publish states, and agents able to insert an article into a reply.

8 — Article suggestions to the customer before they submit and to the agent while they answer, multilingual articles, review dates that flag stale content, and reporting on which articles deflect.

10 — Knowledge is a managed asset: gaps identified from unanswered tickets, article performance measured against ticket volume by topic, versioned content with approval, and deflection reported as a number the team can act on.

Report an error

The Skeptic

A help centre and knowledge base exist, multilingual from the Plus tier. Deflection is asserted — 'without opening a ticket' — but never instrumented: no draft/publish workflow, no article-insert into a reply, no suggestions before submission, and no reporting on which articles deflect. That's a basic article list with a language setting, a step above rubric level 3 and clearly short of rubric level 5. 2 3

Report an error

Customer data protection

How this is scored

A ticket archive is personal data written by the data subject. Retention, deletion, access control, subject rights, and what the vendor does with attachments — judged on what executes rather than what is promised.

0 — No retention policy stated, no deletion path, agents all see everything, and no DPA is published.

3 — A DPA on request and coarse roles; deletion is described as something the customer arranges, and there is no stated retention period.

5 — A signable DPA published, configurable agent roles and queue-level visibility, a stated retention period, and deletion of a requester's data that can actually be executed.

8 — Automatic retention rules per queue or data category, attachment handling stated, an audit log of who opened which ticket, documented support for access and erasure requests, and pseudonymisation or redaction of ticket content.

10 — Built for a data-protection audit: retention executed and evidenced per category, field-level redaction, full audit trail, subprocessor list published, and the vendor's own support access to customer instances documented and consent-gated.

Report an error

The Skeptic

The GDPR rights list and auto-deletion in cover Zammad's own website inquiries, not the customer's ticket archive — that policy was last changed in 2020. Product-side I have 'Permissions' and individual roles at Professional, 2FA and an ISO27001 data centre, but no published DPA, no stated retention period for tickets, no audit log of who opened which ticket, and nothing on attachment handling or redaction. 2 3 5

Report an error

Integrations & API

How this is scored

The systems a helpdesk has to reach — CRM, shop, order management, identity — and whether the API is documented for building or gated behind a partner conversation.

0 — No API and no named integrations; context is copied in by hand.

3 — A handful of native integrations and a read-mostly API, with no webhooks and no documented rate limits.

5 — Named integrations for common CRM and shop systems, a documented REST API with keys, webhooks for the core ticket events, and SSO.

8 — Maintained bidirectional integrations, customer context from other systems shown inside the ticket, SCIM provisioning, documented rate limits and a sandbox.

10 — A component rather than a destination: versioned API with a deprecation policy, event streaming both directions, an app framework for in-ticket extensions, and integrations the vendor maintains rather than lists.

Report an error

The Skeptic

'Open APIs and ready-to-use integrations' plus exactly two named non-channel integrations — GitHub/GitLab and Grafana/Elasticsearch. That's a handful of natives and an API asserted in marketing language: no webhooks, no documented rate limits, no SSO, and no CRM or shop system named anywhere on the evidence. 1 2 3

Report an error

European sovereignty

How this is scored

Where the ticket archive lives, who the contracting entity is, which subprocessors touch it, and whether vendor support can read customer data. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — support tooling, analytics, AI features — are non-EU without an explained safeguard.

8 — EU or DACH hosting with a named data-centre provider, EU contracting entity, full subprocessor list published, and any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor in the EU, certification published, and a self-hosted or private-cloud option for buyers who need the archive on their own infrastructure.

Report an error

The Skeptic

The contracting entity is nailed down — Zammad GmbH, Marienstraße 18 Berlin, HRB 163946 B — with 'Made & hosted in Germany' and an ISO27001-certified German data centre, plus a genuine self-hosted option. But the data-centre provider is unnamed, the only published subprocessors are the website's Matomo and Moosend Ltd rather than the product chain's, and the metered AI feature never states who processes it or where — so rubric level 8's named-provider and full-subprocessor-list bar isn't met. 2 3 4 5

Report an error

Pricing transparency

How this is scored

Whether a support lead can compute the real annual invoice for their agent count — including the channels and features they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-agent headline exists, but the tier where the needed channel or SLA feature begins is unstated, or light-agent and contact limits are not mentioned.

5 — Per-agent prices public for the main tiers with billing period stated, but at least one commonly needed capability (telephony, messengers, SLA policies) sits in an unpriced bundle.

8 — Every tier and add-on priced publicly with per-agent maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.

10 — Complete price computability: a calculator or table producing the annual invoice for a given agent count and channel selection, including usage-metered channels and overage.

Report an error

The Skeptic

Three tiers priced per agent with agent limits, VAT treatment, storage caps and even the AI meter at €0.03 per call are all public — unusually honest on the AI. But there's no billing period or annual option, no minimum term, no light-agent pricing, and the usage-metered channels (SMS from Starter upward, telephony) carry no price at all, so I can't compute the invoice for a chat-plus-SMS team. 2

Report an error

European sovereignty — proven facts

2 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency EU only ⚠ unverified 3/3 pts 2 Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (13)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage zammad.com Checked 15 Sep 2026 Details →
  2. 2 Pricing zammad.com Checked 15 Sep 2026 Details →
  3. 3 Product overview zammad.com Checked 15 Sep 2026 Details →
  4. 4 Imprint zammad.com Checked 15 Sep 2026 Details →
  5. 5 Privacy policy zammad.com Checked 15 Sep 2026 Details →
  6. 6 Security / trust page zammad.com Checked 30 Sep 2026 Details →
  7. 7 Ticketing, queues & SLA — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  8. 8 Channels in one queue — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  9. 9 Channels in one queue — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  10. 10 Knowledge base & deflection — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  11. 11 Customer data protection — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  12. 12 Integrations & API — found from sitemap zammad.com Checked 1 Oct 2026 Details →
  13. 13 Integrations & API — found from sitemap zammad.com Checked 1 Oct 2026 Details →