Software companies
Support tickets with attachments and screenshots: what to do before licensing
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Before licensing support tickets with attachments and screenshots, inventory attachments by file type, exclude them by default, and bring back only the types that add value and can be cleaned, usually error logs and stack traces. Screenshots, browser HAR files, customer spreadsheets and scanned documents carry personal and confidential details that text redaction never reaches.
Key takeaways
- Text redaction works on ticket bodies; attachments are separate files that need their own inventory and rules.
- Inventory attachments from metadata first, by file type, before downloading a single file.
- Exclude attachments by default and reinstate only file types whose value justifies the cleaning, such as application logs.
- Browser HAR files can hold cookies, session tokens and authorization headers, so treat them as credential material.
- Replace each removed attachment with a short placeholder so the conversation still reads correctly.
Why do attachments need their own review?#
Attachments need their own review because the tools and settings that clean ticket text do not open the files attached to it. A ticket body may be fully redacted while the screenshot beneath it still shows an end user's name, an account balance or another customer's records in your product's interface.
Attachments also change whose data you are handling. A customer who uploads a CSV export from their own system to report an import error has given your support team their customers' or employees' records. In that situation your company usually processes the data on the customer's behalf, and licensing it may fall outside what the customer contract allows.
Agents add attachments as well. Macros attach onboarding guides, and agents sometimes attach spreadsheets of account settings or user lists pulled from internal admin tools to show a customer what changed. Those files can contain more customer data than anything the customer sent, so include agent uploads in the inventory.
Checklist: inventory attachments by file type#
The inventory runs on attachment metadata, which most help desks expose through their API or export: file name, content type, size, ticket ID and date. Working from metadata keeps the files themselves inside the help desk until a decision is made about each type.
Export routes differ by vendor and plan, so confirm yours before scheduling the work. Zendesk's account data exports are not turned on by default and the account owner must ask Zendesk support to enable them, although the REST API is available on every plan. Intercom's Data Export to Amazon S3 offers attachments as a separate option from conversations data, which makes it practical to export conversations first and hold attachments back.
- Export attachment metadata for every ticket in scope without downloading the files.
- Group attachments by file type, and note which come from customers, agents and automated systems.
- Count attachments per type and per year, so the effort of any review is visible before it starts.
- Open a small sample of each type in a controlled environment and note what it typically contains.
- Set a default rule per type: exclude, review or include.
- Record inline images pasted into ticket bodies and email signatures as a separate group, since they hide inside the text.
- Write the rules and sample findings into the privacy record before any files are copied.
Default treatment by file type#
Exclusion is the right default for nearly every attachment type, because most carry identifiers or third-party data and add little to the support conversation. The exceptions are files that explain a technical fault and can be cleaned with reasonable effort.
| File type | What it usually contains | Default | When to reconsider |
|---|---|---|---|
| Screenshots | Product screens with end-user names, emails and account data; browser tabs and notifications | Exclude | High-value interface bugs, after image redaction and a human check |
| Screen recordings | The same as screenshots, in motion, sometimes with audio | Exclude | Rarely worth the review effort |
| HAR files and network captures | Cookies, session tokens, authorization headers and request bodies | Exclude | Almost never; treat as credential material |
| Application and server logs | Stack traces, error codes, IP addresses, emails and IDs | Review | When scrubbed of identifiers and secrets, they explain the fix |
| Customer data exports | Spreadsheets of the customer's own customers, products or staff | Exclude | Not usually yours to license |
| Documents and scans | Invoices, contracts, purchase orders, identity documents | Exclude | Product guides your company wrote |
| Forwarded emails | Third-party conversations and signatures | Exclude | Rarely |
| Config files and code snippets | Settings, integration details, sometimes secrets | Review | After a secrets scan and customer-name check |
How do you keep tickets readable after removal?#
Tickets stay readable when each removed attachment is replaced with a short placeholder that states its type and purpose, for example a note that a screenshot of a billing page error was removed. The agent's reply usually describes what the screenshot showed, so the conversation still makes sense to a reader or a model.
Inline images need the same treatment. Pasted screenshots in email replies and logo images in signatures appear as image references inside the HTML body, and a text-only cleaner may leave the reference or the image link intact. Strip them and add the placeholder in the same pass.
Keep only the metadata that helps a reader. File type and purpose are useful in a placeholder; original file names usually are not, because names such as a customer's payroll export with its company name and month identify the customer as clearly as the file itself.
Cleaning the attachments you keep#
Attachments you keep need layered cleaning, because no single detector catches everything. For logs, run a secrets scanner and a personal details detector, then replace IP addresses, emails, hostnames and account IDs with consistent pseudonyms. TruffleHog, for example, scans logs, chats and wikis as well as Git.
For screenshots, image redaction tools read text from the image and black out what they detect. Presidio includes a module that redacts personal details in images, and Google's Sensitive Data Protection works on text and images. Presidio's documentation warns that automated detection cannot guarantee it finds all sensitive information, so a person should check a sample of every cleaned type before it is approved.
Keep the original files untouched in the help desk and do all cleaning on copies in company storage. That way a cleaning error can be corrected by rerunning the process rather than by trying to recover lost data.
Illustrative: an inventory software vendor sorts its Zendesk attachments#
Illustrative: a fictional inventory management software company plans to license its Zendesk ticket history. The metadata export shows that most attachments are screenshots, followed by log files, CSV product catalogs that failed to import, and HAR files that agents requested for login problems.
The COO sets the rules: exclude every screenshot, HAR file and CSV, since the catalogs include customers' supplier pricing, and review log files. Engineers scrub the logs of hostnames, account IDs and emails, a privacy reviewer checks a sample, and each removed file is replaced with a placeholder. The licensed ticket threads still read naturally, and the privacy record lists every excluded file type and the reason.
How SourceX approaches ticket attachments#
SourceX treats attachments as excluded unless the supplier approves a specific file type for inclusion. The fit check uses only metadata, such as the help desk in use, years of history and the mix of attachment types, and no files are shared at that stage.
In the Preparation step of the SourceX five-step transaction, the rules per file type, the cleaning methods and the sample review results are recorded in the privacy record of the SourceX Evidence Packet.
Frequently asked questions
Do help desk redaction features remove attachments?
Not always. Redaction features differ by vendor and plan, and some act on ticket text only, need a separate action for attachments, or apply only to new tickets. Check your vendor's documentation, and assume older tickets were never processed unless you can confirm otherwise.
What about attachment links inside exported ticket data?
Strip them. Some help desk exports include links to attachments rather than the files, and depending on account settings those links may open without signing in. A licensed copy should carry neither the files you excluded nor working links to them, so replace every attachment URL with the same placeholder used for the file.
Can we keep screenshots of our own product that show no customer data?
Yes, after review. Screenshots taken by agents in a demo or test environment, showing synthetic data, can add useful context to a fix. Mark them in the inventory by source, since agent-generated screenshots from internal environments are easier to clear than customer uploads.
Do we need customer consent to license tickets with attachments?
It depends on your customer contracts, your privacy notice and the laws that may apply to the people in the records, which counsel assesses deal by deal. Excluding attachments removes much of the third-party data and narrows that question, but it does not settle it.
Should we delete attachments from the help desk after preparation?
No. Preparing a licensed copy does not require changing the source system. Retention of attachments in the help desk is a separate decision under your own retention policy and customer commitments, and deleting files mid-project can break the audit trail for what was excluded.
What about call recordings and voicemails attached to tickets?
Exclude the audio by default. Recordings carry voices, names and account details spoken aloud, and they are much harder to clean than text. If calls are valuable, handle them as a separate transcript project with its own redaction and review, rather than as ticket attachments.
Sources
- Zendesk data exports are not turned on by default and the account owner must contact Zendesk Customer Support to enable them; customers on every plan can export data through the Zendesk REST API. Source
- Intercom's Data Export sends Conversations data to the customer's Amazon S3 bucket, with Historical and Periodic exports and Attachments as separate options. Source
- Presidio is an open-source SDK for PII identification and anonymization in text and images, including a module that redacts PII in images; its documentation warns there is no guarantee it will find all sensitive information. Source
- Google's DLP API v2 definition states that Sensitive Data Protection provides an inspection, classification and de-identification platform that works on text, images and Google Cloud storage repositories. Source
- TruffleHog is an open-source secret scanner that scans sources including Git, chats, wikis, logs, object stores and filesystems. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.