VendorScore · Comparison · Data-access posture

Zoom vs Microsoft Teams vs Webex: which can read your meetings?

Get the full 5-dimension PDFs — join the waitlist

Evidence dated 2026-10-06 to 2026-10-07, public docs only, not legal advice.

Short answer

All three can read standard meetings by default, and each offers an optional end-to-end encrypted meeting mode with a narrower scope. In the scored configurations, Zoom (75/100) has the least inherent vendor read access, then Webex (73/100) and Microsoft Teams (70/100); customer-held keys (Webex customer main key or Hybrid Data Security, Teams Customer Key) add custody, not zero access.

Higher score = less inherent vendor read access in the scored configuration, not a more secure product. Each score comes from that vendor's VendorScore page.

Last reviewed: · Evidence date: Zoom 2026-10-06, Microsoft Teams 2026-10-07, Webex 2026-10-07 (from each vendor page) · Sources

Side by side

Zoom Microsoft Teams Webex
Overall score 75/100 70/100 73/100
Scored configuration Zoom meetings with optional End-to-End Encryption (E2EE) enabled for sensitive meetings. Teams in a Microsoft 365 enterprise tenant with Purview Customer Key (multi-workload DEP), Customer Lockbox, and E2EE enabled for one-to-one VoIP calls and (Teams Premium) meetings that require it. Webex Suite org with Zero-Trust E2EE meetings for sensitive meetings, a customer main key (HSM or your AWS KMS) or Hybrid Data Security for messaging and meeting content, EU data residency (new org) and Control Hub audit logs.
Key custody option Default meetings: Zoom generates and manages the keys. With E2EE meetings, participants generate the keys and Zoom's servers never see them. Purview Customer Key: Teams chat, media messages and recordings in Teams storage use your Azure Key Vault root keys; Microsoft keeps an availability key. Customer Lockbox gates engineer access. Customer main key in an HSM or your AWS KMS, or Hybrid Data Security (on-premises KMS), for messaging and meeting content; Zero-Trust meetings use keys generated among participants.
E2EE / CSE scope Optional E2EE meetings: Zoom's servers relay encrypted data without the keys. Cloud recording, live transcription, breakout rooms and other features are disabled or limited; cloud recordings outside the E2EE path can still be read by Zoom. Only audio, video and screen sharing in one-to-one VoIP calls and meetings set to require E2EE (Teams Premium); call E2EE is off by default. Never chat, files, recordings or transcripts. Zero-Trust E2EE meetings only: meeting media, in-meeting chat, files and whiteboards, falling back when an unsupported endpoint or cloud service joins. Cisco's messaging 'Webex End-to-End Encryption' isn't zero-knowledge: the cloud can decrypt it for search, DLP and eDiscovery.
AI training default (scored config) Not used for training by default. Zoom says it doesn't use audio, video, chat, screen sharing, attachments or other communications-like Customer Content to train its or third-party AI models. Not used for training by default. Microsoft says prompts, responses and Microsoft Graph data, which includes Teams chats and meetings, aren't used to train foundation LLMs. Not used for training by default. Cisco says Webex doesn't use customer content to train models by default; no opt-in programme is described. Call AI Assistant outputs are stored for 365 days.
EU residency For EU Education and Enterprise customers: dedicated Zoom EU Infrastructure keeps personal data in the EU unless agreed with the customer or a listed exception applies. Yes: Teams stores data in your tenant's geography (including France, Germany and the EMEA region), and Microsoft 365 is an EU Data Boundary service. Yes, for new orgs: identities, encryption keys, user-generated and AI-generated content are stored in-region; Meetings data for EU time zones sits in Frankfurt.
DPA link Zoom DPA Microsoft DPA Cisco DPA

Dimension scores (key custody, plaintext access, encryption claims, subprocessors, auditability) stay in the full PDFs.

What this means

Get the full 5-dimension PDFs — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Zoom vs Microsoft Teams vs Webex

Are Zoom, Microsoft Teams or Webex meetings end-to-end encrypted?

Only in optional modes. In Zoom E2EE meetings, participants generate the keys and Zoom's servers relay encrypted data without seeing them; cloud recording, live transcription and breakout rooms are disabled or limited. Teams E2EE covers audio, video and screen sharing in one-to-one VoIP calls and scheduled meetings set to require E2EE (the organizer needs Teams Premium), and call E2EE is off by default. Webex Zero-Trust E2EE meetings cover meeting media, in-meeting chat, files and whiteboards, but not cloud recording, transcription, the AI Assistant, the web app, PSTN or SIP.

Which can read my meetings least: Zoom, Teams or Webex?

In the scored configurations, Zoom scores 75/100 (E2EE enabled for sensitive meetings), Webex 73/100 (Zero-Trust E2EE meetings plus a customer main key or Hybrid Data Security) and Microsoft Teams 70/100 (Customer Key, Customer Lockbox and E2EE where enabled), so Zoom has the least inherent vendor read access. The scores are close, and a higher score means more customer control, not a guarantee that the vendor can't access content.

Is Teams or Webex chat end-to-end encrypted?

Not in a way that keeps the vendor out. Teams E2EE never covers chat messages, files, recordings or transcripts. Cisco brands its KMS-based Webex messaging encryption 'Webex End-to-End Encryption', but the Webex cloud can decrypt that content for search indexing, DLP, transcoding, eDiscovery and archival, so it isn't zero-knowledge; a customer main key or Hybrid Data Security moves key control to you.

Can Zoom, Microsoft or Cisco employees access my meetings?

Zoom says employees don't access Customer Content without the hosting account owner's authorization, or as required for legal, safety, security or support reasons. Microsoft says engineers have no default access, and Customer Lockbox lets you approve requests covering Teams chats, files, meeting recordings and transcripts. Cisco says its employees don't access customer data unless the customer requests it for support; we found no customer-visible log of that access.

Do Zoom, Microsoft Teams or Webex train AI on my meetings?

Zoom says it doesn't use audio, video, chat, screen sharing, attachments or other communications-like Customer Content to train its or third-party AI models. Microsoft says prompts, responses and Microsoft Graph data, which includes Teams chats and meetings, aren't used to train foundation LLMs. Cisco says Webex doesn't use customer content to train models by default, and call AI Assistant outputs are stored for 365 days.

Can I keep Zoom, Teams or Webex data in the EU?

Zoom offers dedicated Zoom EU Infrastructure for EU Education and Enterprise customers. Teams stores data in your tenant's geography (including France, Germany and the EMEA region), and Microsoft 365 is an EU Data Boundary service. Webex stores identities, keys and content in-region for new orgs, with Meetings data for EU time zones in Frankfurt.

Sources

Every URL cited on this page. Scores, configurations and facts come from the linked VendorScore vendor pages and their reports; nothing here goes beyond them.

Disclaimer

This comparison restates the vendor pages for the scored configurations only; default setups usually score lower. A higher score means less inherent vendor read access in that configuration, not a safety rating. VendorScore doesn't certify compliance. Public-docs review only. Not a pen test, not legal advice, not a SOC 2 substitute.