VendorScore · Team chat & meetings · Data-access posture

Can Webex read your meetings and messages?

A plain-language answer from Cisco's Webex Help Center, security technical papers, AI transparency notes and Master DPA. Zero-Trust E2EE covers meetings only; messaging stays decryptable by the Webex cloud for core services.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, unless you enable Zero-Trust E2EE (meetings only): Webex's cloud can decrypt standard meetings and all messaging; Zero-Trust meetings keep media keys with participants but disable cloud recording and AI.

73 / 100 overall

Scored configuration: Webex Suite org with Zero-Trust E2EE meetings for sensitive meetings, a customer main key (HSM or your AWS KMS) or Hybrid Data Security for messaging and meeting content, EU data residency (new org) and Control Hub audit logs.

Default setup (standard meetings, Cisco cloud KMS) scores lower; the report estimates Overall ~61.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Webex's public documentation:

  • Current Webex privacy data sheets (subprocessor detail) sit behind the JavaScript Cisco Trust Portal and were confirmed via a search index only; we don't repeat names from them.
  • Cisco's AI privacy article (2024-09) and AI Transparency notes (2024) predate the evidence date.
  • No customer-visible log of Cisco staff support access is documented.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Webex data access, AI training, GDPR and residency

Can Webex read your meetings and messages?

Yes, unless you enable Zero-Trust E2EE (meetings only): Webex's cloud can decrypt standard meetings and all messaging; Zero-Trust meetings keep media keys with participants but disable cloud recording and AI. VendorScore rates Webex 73/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Webex Suite org with Zero-Trust E2EE meetings for sensitive meetings, a customer main key (HSM or your AWS KMS) or Hybrid Data Security for messaging and meeting content, EU data residency (new org) and Control Hub audit logs.

Is Webex end-to-end encrypted? What does Zero-Trust E2EE cover?

Only Zero-Trust E2EE meetings keep keys away from Cisco. They use MLS key exchange and SFrame media, and Cisco says "The Webex service can't access the meeting key". That covers meeting audio and video, in-meeting chat, files and whiteboards, but not saving them to the cloud, cloud recording, transcription, the in-meeting AI Assistant, the web app, PSTN or SIP. In standard meetings with Adaptive Security, the meeting falls back from Zero Trust when an unsupported endpoint or a cloud service joins, because Webex gains access to the keys. Messaging is never covered: Cisco brands its KMS-based messaging and content encryption "Webex End-to-End Encryption", but the Webex cloud can decrypt that content for search indexing, DLP, transcoding, eDiscovery and archival, so it isn't zero-knowledge. Webex Calling 1:1 E2EE is off by default.

Can Cisco employees access my Webex meetings and messages?

Cisco says: "Cisco employees do not access customer data unless access is requested by the customer for support reasons." Access needs manager approval, with segregation of duties and need-to-know, and we found no customer-visible log of Cisco staff support access. Separately, the Webex cloud itself decrypts messaging and standard-meeting content for core services such as indexing, DLP, eDiscovery and archival.

Does Webex train AI on my meetings?

Not by default. Cisco's AI Transparency notes say: "By default, Webex does not use customer content to train models. Instead, Webex uses off the shelf datasets, Cisco-internal data, or synthetic data." No opt-in programme is described in the pages we read. Cisco says its model provider, Microsoft, "does not access, monitor, or store Cisco customer data", and that Cisco doesn't retain input data after inference. Call AI Assistant summaries, action items and transcripts are stored for 365 days. These AI documents date from 2024.

Is Webex GDPR compliant? Where is the Cisco DPA?

VendorScore doesn't certify compliance; Cisco publishes a DPA at https://trustportal.cisco.com/c/dam/r/ctp/docs/dataprotection/cisco-master-data-protection-agreement.pdf. Cisco's Master Data Protection Agreement promises at least 30 days' advance notice of new subprocessors; if you object within 10 days and it isn't resolved within 30 days of notice, you can terminate the affected service.

Who are Webex's subprocessors?

Cisco lists Webex subprocessors in its privacy data sheet at https://trustportal.cisco.com/c/dam/r/ctp/docs/privacydatasheet/collaboration/cisco-webex-app-and-messaging-privacy-data-sheet.pdf, which redirects to the JavaScript Cisco Trust Portal. We could confirm it only via a search index, so we couldn't read the list content directly and don't repeat names from it. Cisco's Help Center says most Webex services run in Cisco data centres, with AWS and Azure used for some, and names Microsoft Azure OpenAI as the AI model provider.

Can I keep Webex data in the EU (data residency)?

Yes, for new orgs. Identities, encryption keys, user-generated content and AI-generated content are stored in-region, and Meetings data for EU time zones sits in Frankfurt. Control Hub admin activity logs are kept for 12 months.

Compare Webex

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (webex.md), evidence dated 2026-10-07.