VendorScore · Meetings · Data-access posture
A plain-language answer from Zoom's public E2EE and trust docs. Default meeting encryption and E2EE are different things.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Yes for default meetings: Zoom generates and manages keys and can access meeting content for cloud features. Mostly no for E2EE meetings, where Zoom servers relay ciphertext without meeting keys (with feature tradeoffs).
Scored configuration: Zoom meetings with optional End-to-End Encryption (E2EE) enabled for sensitive meetings.
A default-only score (Zoom-managed keys) would drop Overall to ~50–55, per the report.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
In default meetings, Zoom's cloud generates the encryption keys and distributes them to participants, so Zoom can access content as needed for cloud recording, transcription and similar features.
Evidence: Zoom E2EE announcementWith E2EE, participants generate the keys and Zoom says its servers "become oblivious relays and never see the encryption keys". In return, cloud recording, live transcription, breakout rooms and other features are disabled or limited.
Evidence: Zoom E2EE announcement, Zoom E2EE support articleOur report flags these gaps in Zoom's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes for default meetings: Zoom generates and manages keys and can access meeting content for cloud features. Mostly no for E2EE meetings, where Zoom servers relay ciphertext without meeting keys (with feature tradeoffs). VendorScore rates Zoom 75/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Zoom meetings with optional End-to-End Encryption (E2EE) enabled for sensitive meetings.
Only if you turn E2EE on. In default meetings Zoom generates and manages the keys. With Zoom E2EE, participants generate the keys and Zoom's servers relay encrypted data without seeing them, so Zoom mostly can't see those meetings. The trade-off: cloud recording, live transcription, breakout rooms and other features are disabled or limited, and every participant needs a supported client. Cloud recordings stored outside the E2EE path can still be read by Zoom and account admins.
Zoom limits this by policy. Its Privacy Statement says: "Zoom employees do not access or use Customer Content without the authorization of the hosting account owner, or as required for legal, safety, security or support reasons." That is a policy commitment, not a cryptographic barrier: outside E2EE meetings, Zoom manages the keys.
No, per Zoom's Privacy Statement: "Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models." AI features still process that content to work, and Zoom's subprocessor list names OpenAI and Anthropic for AI features (see below).
VendorScore doesn't certify compliance; Zoom publishes a DPA at https://media.zoom.com/download/assets/zoom-global-dpa.pdf/dd327ebea27e11efb613d6ba63ed4cee. It is Zoom's Global Data Processing Addendum, which relies on the EU Standard Contractual Clauses for international transfers. Whether your own use meets GDPR depends on your configuration and contracts.
Zoom publishes its subprocessor list at https://www.zoom.com/en/trust/subprocessors/. It lists Anthropic (United States) and OpenAI (United States, European Union) as subprocessors that may process "Customer Content and context" if AI features are enabled, with SCCs as the transfer mechanism.
For EU Education and Enterprise customers, largely yes. Zoom offers dedicated Zoom EU Infrastructure for EU customers who don't want personal data transferred outside the EU. Zoom says personal data is not transferred outside of or accessed from outside that infrastructure unless agreed with the customer or a listed exception applies.
Every URL cited on this page. Score and key findings: VendorScore report (zoom.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.