It's secured by the external systems policies itself. No data transfers to Zendesk or Sparkly.
Data doesn't leave your browser. If an agent has access to the external system in the browser, the security remains the same.
For example: an agent clicks a shortcut to Stripe. A new window opens. And the relevant information passes via a URL. Like this: https://stripe.com?q=james@example.com