A support ticket is a data breach waiting to happen
On 23 April 2026, attackers compromised a third-party service management platform that EY used for tax work. The reported prize was not a database of card numbers. It was support tickets: the day to day back and forth that quietly accumulates client tax and financial detail. ShinyHunters then added EY to its leak site with a 31 July deadline.
Read that again as an MSP owner. The breach did not start at a firewall. It started in the ticket queue.
Why tickets are the soft target
Think about what lands in your tickets on a normal week. Password resets with context. Invoice queries with account numbers. Screenshots a client pasted in a hurry. Forwarded email chains with names, addresses, and “here is the thing you asked for”. Tickets are where PII and financial detail leak, because nobody treats a support thread like a data store. But that is exactly what it is.
Now stack that with where most PSA tickets actually live: a multi-tenant SaaS platform holding thousands of firms in one system. That platform is a single high-value target. One vendor compromise, one shared plane, and everyone’s book is exposed at once. Verizon’s breach research has flagged for a while that third-party involvement in breaches keeps climbing. The EY pattern is that trend in one headline.
The question the breach forces
Where do your tickets live? If the honest answer is “on a vendor’s shared platform”, then the vendor’s blast radius is your blast radius. You did not choose that risk. You inherited it when you signed up per seat.
Self-hosted and single-tenant changes the maths
Opentra is a self-hosted, single-tenant PSA. Your tickets, contracts, time entries and billing history sit on infrastructure you control, one tenant, your box. There is no shared platform holding a hundred other MSPs next to you, so there is no shared platform to become the one target attackers race to crack.
That is pillar one, and it is the whole point. Deploy it in an afternoon with docker compose, or run Opentra Cloud if you would rather we host it. Either way it is one tenant: yours. If Opentra ever disappeared, nothing stops, because you own and can export your data.
To be clear on scope: we are PSA-only. We do not do monitoring or RMM. Your monitoring stays yours. What we own end to end is the system your work runs on, from first email to paid invoice.
Reduce the surface you do not need
You cannot patch a risk you do not control. Moving your ticket history off a shared platform and onto your own infrastructure removes an entire class of “the vendor got breached” from your incident plan.
See how single-tenant works on our security page, and compare flat pricing (Community free self-host, Pro $149/mo, Cloud $249/mo) on the pricing calculator.