VendorScore · Team chat & meetings · Data-access posture
A plain-language answer from Cisco's Webex Help Center, security technical papers, AI transparency notes and Master DPA. Zero-Trust E2EE covers meetings only; messaging stays decryptable by the Webex cloud for core services.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, unless you enable Zero-Trust E2EE (meetings only): Webex's cloud can decrypt standard meetings and all messaging; Zero-Trust meetings keep media keys with participants but disable cloud recording and AI.
Scored configuration: Webex Suite org with Zero-Trust E2EE meetings for sensitive meetings, a customer main key (HSM or your AWS KMS) or Hybrid Data Security for messaging and meeting content, EU data residency (new org) and Control Hub audit logs.
Default setup (standard meetings, Cisco cloud KMS) scores lower; the report estimates Overall ~61.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Zero-Trust E2EE meetings use MLS/SFrame; the Webex service can't access the meeting key, but cloud recording, transcription, AI Assistant, PSTN/SIP and the web app aren't supported.
Evidence: Webex E2EE for Meetings & CallingCisco's 'Webex End-to-End Encryption' label for KMS-based messaging and meeting content isn't zero-knowledge: the Webex cloud can decrypt that content for indexing, DLP, transcoding, eDiscovery and archival.
Evidence: Webex App SecurityHybrid Data Security moves KMS, indexing and compliance on-premises; a customer main key can sit in an HSM or your AWS KMS.
Evidence: Webex Hybrid Data Security guide, Manage your own customer main keyOur report flags these gaps in Webex's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, unless you enable Zero-Trust E2EE (meetings only): Webex's cloud can decrypt standard meetings and all messaging; Zero-Trust meetings keep media keys with participants but disable cloud recording and AI. VendorScore rates Webex 73/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Webex Suite org with Zero-Trust E2EE meetings for sensitive meetings, a customer main key (HSM or your AWS KMS) or Hybrid Data Security for messaging and meeting content, EU data residency (new org) and Control Hub audit logs.
Only Zero-Trust E2EE meetings keep keys away from Cisco. They use MLS key exchange and SFrame media, and Cisco says "The Webex service can't access the meeting key". That covers meeting audio and video, in-meeting chat, files and whiteboards, but not saving them to the cloud, cloud recording, transcription, the in-meeting AI Assistant, the web app, PSTN or SIP. In standard meetings with Adaptive Security, the meeting falls back from Zero Trust when an unsupported endpoint or a cloud service joins, because Webex gains access to the keys. Messaging is never covered: Cisco brands its KMS-based messaging and content encryption "Webex End-to-End Encryption", but the Webex cloud can decrypt that content for search indexing, DLP, transcoding, eDiscovery and archival, so it isn't zero-knowledge. Webex Calling 1:1 E2EE is off by default.
Cisco says: "Cisco employees do not access customer data unless access is requested by the customer for support reasons." Access needs manager approval, with segregation of duties and need-to-know, and we found no customer-visible log of Cisco staff support access. Separately, the Webex cloud itself decrypts messaging and standard-meeting content for core services such as indexing, DLP, eDiscovery and archival.
Not by default. Cisco's AI Transparency notes say: "By default, Webex does not use customer content to train models. Instead, Webex uses off the shelf datasets, Cisco-internal data, or synthetic data." No opt-in programme is described in the pages we read. Cisco says its model provider, Microsoft, "does not access, monitor, or store Cisco customer data", and that Cisco doesn't retain input data after inference. Call AI Assistant summaries, action items and transcripts are stored for 365 days. These AI documents date from 2024.
VendorScore doesn't certify compliance; Cisco publishes a DPA at https://trustportal.cisco.com/c/dam/r/ctp/docs/dataprotection/cisco-master-data-protection-agreement.pdf. Cisco's Master Data Protection Agreement promises at least 30 days' advance notice of new subprocessors; if you object within 10 days and it isn't resolved within 30 days of notice, you can terminate the affected service.
Cisco lists Webex subprocessors in its privacy data sheet at https://trustportal.cisco.com/c/dam/r/ctp/docs/privacydatasheet/collaboration/cisco-webex-app-and-messaging-privacy-data-sheet.pdf, which redirects to the JavaScript Cisco Trust Portal. We could confirm it only via a search index, so we couldn't read the list content directly and don't repeat names from it. Cisco's Help Center says most Webex services run in Cisco data centres, with AWS and Azure used for some, and names Microsoft Azure OpenAI as the AI model provider.
Yes, for new orgs. Identities, encryption keys, user-generated content and AI-generated content are stored in-region, and Meetings data for EU time zones sits in Frankfurt. Control Hub admin activity logs are kept for 12 months.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (webex.md), evidence dated 2026-10-07.