Zendesk Can't Redact Images: What Support Teams Do Instead
Zendesk's redaction tool works on text, not on image attachments of any kind. When a customer's personal data is baked into a screenshot, the native fix is to delete the whole ticket. Here is what support teams do instead.
If you run support in Zendesk, you have hit this wall. A customer's screenshot lands in a ticket with a full name, an email, maybe a card number visible in it. You need to redact that before it gets escalated to engineering or archived. You open Zendesk's redaction tool and discover it will not touch the image at all.
The gap is documented, not imagined
Zendesk's native redaction "only works on text and not on attachments of any kind" (strac.io/blog/how-to-redact-zendesk-tickets). That includes pictures, images, and screenshots. So when the personal data is inside an attached image, the tool that is supposed to solve this simply does not apply.
Zendesk clearly treats PII in tickets as a real problem worth money: it sells an Advanced Data Privacy and Protection add-on for redacting identified PII in ticket comments (support.zendesk.com/hc/en-us/articles/10474374743450). But that add-on works on text, and the image side stays unsolved natively. The commonly documented workaround when PII is baked into a screenshot is drastic: delete the entire ticket, losing the conversation history with it.
The short version: Zendesk can redact the words in a ticket. It cannot redact what is inside the picture attached to it.
Why this is a compliance issue, not just an annoyance
Forwarding a customer's screenshot to engineering or a third-party vendor is "processing" personal data. Zendesk publishes its own guidance on complying with privacy and data protection law in Support (support.zendesk.com/hc/en-us/articles/4408823195930). An unredacted account screenshot moving from your queue into a Slack channel or a bug tracker is exactly the kind of quiet data flow those rules are about.
What support teams actually do instead
1. Redact by hand before it spreads
The reliable manual move is to redact the image the moment it arrives, before it goes anywhere. On a Mac, open the attachment in Preview, use Markup, draw a rectangle with a solid black fill over the sensitive area, and export to a flat PNG so nothing sits underneath. This works. It just depends on every agent doing it every time, which is the hard part on a busy queue.
2. Standardize on a redaction tool
Some teams buy a dedicated tool so redaction is not improvised. Snagit's Smart Redact, for example, auto-detects addresses, credit cards, dates, emails, faces, IP addresses, phone numbers, Social Security numbers, and URLs, all processed locally. It is a full capture-and-edit suite sold by subscription, at $39 per year for an individual and $48 per year for business, and it has been subscription-only since 2025 (techsmith.com/snagit/features/smart-redact; screensnap.pro/blog/snagit-pricing).
3. Make redaction automatic
The pattern that survives a real queue is the one that does not rely on memory. If screenshots are redacted the instant they are saved, the protection happens whether or not a rushed agent remembers. That is the job Whiteout is built for.
Close the image-redaction gap Zendesk leaves open
Whiteout watches your Mac's screenshots folder and covers detected PII with solid black boxes automatically, before an agent ever drags the file into a ticket, a Slack thread, or a bug report. Nothing is uploaded; it all happens on the machine.
Try Whiteout free for 7 days$19 one-time after the trial. Fully offline, no account. macOS.
Building it into the workflow, not the willpower
The failure mode with manual redaction on a support team is not that agents do not care. It is that redaction lives in individual willpower instead of in the process. A few practical ways to move it into the process:
- Write it into the escalation macro. If your "escalate to engineering" macro or internal note template includes a one-line reminder to redact attachments, the prompt arrives at the exact moment it is needed.
- Redact before it fans out, not after. Once an image is copied into Slack, a bug tracker, and an email thread, you are chasing three copies. Handle it the moment it lands in the ticket.
- Avoid the delete-the-ticket reflex where you can. Deleting the whole ticket to remove one screenshot also destroys the conversation history your team may need. Redacting the image and keeping the thread is almost always the better outcome, which is precisely what the native tool cannot do for you.
- Prefer a method that does not require noticing. The dangerous screenshots are the ones where the PII is incidental, in a sidebar or a tab. Automatic redaction protects those too.
Where support teams compare notes on this
You are not the only lead wrestling with this. Support Driven, a community dedicated to customer support as a career, has more than 30,000 members and an active Slack and newsletter (supportdriven.com). It is a good place to see how other teams handle PII in tickets without turning every escalation into a manual chore.
Zendesk is excellent at a great many things. Redacting the inside of a screenshot is not one of them, and it does not pretend otherwise. The fix is to handle the image before it enters the workflow, ideally in a way that does not depend on anyone remembering.
Sources
strac.io/blog/how-to-redact-zendesk-tickets (native redaction "only works on text and not on attachments of any kind"); support.zendesk.com/hc/en-us/articles/10474374743450 (Advanced Data Privacy and Protection add-on redacts PII in ticket text); support.zendesk.com/hc/en-us/articles/4408823195930 (complying with privacy and data protection law in Zendesk Support); techsmith.com/snagit/features/smart-redact and screensnap.pro/blog/snagit-pricing (Snagit Smart Redact detectors and pricing); supportdriven.com (30,000+ member customer support community).