Products assessed
A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.
Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
ISO/IEC 27001:2022. Scope covers the Zoom UCaaS Platform and Workvivo. Certificate 1407508-7, issued by Schellman Compliance LLC, accredited by ANAB; record last updated 12 August 2026.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (Zoom trust portal) · checked Aug 24, 2026
Valid until Dec 4, 2027
Corroborated within the same Schellman/ANAB certificate 1407508-7 (ISO/IEC 27001:2022, Active): the Zoom UCaaS Platform scope extends to ISO/IEC 27701:2019 PIMS as a PII processor, inclusive of ISO/IEC 27017:2015 and ISO/IEC 27018:2025.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27701:2019 scope within Schellman certificate 1407508-7 (Zoom trust portal) · checked Aug 24, 2026
Valid until Dec 4, 2027
SOC 2 Type 2 by Schellman & Company, system: the Zoom UCaaS Platform - the same boundary as the 27001 certificate; period 16 Oct 2024 - 15 Oct 2025, unqualified. FOUR trust services criteria: security, availability, confidentiality and privacy. Type 2, so design and operating effectiveness across the period. The report period ended 15 Oct 2025, so it sits inside the usual twelve-month reliance window as at Aug 2026 but will need refreshing. Report held in the TrustyCyber vault.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- — Current
Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (Zoom trust portal) · checked Aug 24, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Aug 28, 2026
Authorization covers Zoom for Government (SaaS), not the commercial Zoom service; the vendor's own compliance page lists FedRAMP under its Zoom for Government section, consistent with the registry.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 21, 2026
IRAP security assessment by Schellman, lead assessor Greg Mansill (IRAP 00068), report dated 18 May 2026 v1.0, against the Australian Government ISM June 2025 release, assessed to the PROTECTED level (COI 000776). NOTABLE FOR AN AI ASSESSMENT: the in-scope products include AI Notetaker, which transcribes, records and summarises meetings across third-party platforms - so this is an independent assessment of an AI FEATURE against Australian government security controls, not merely of the underlying platform. It is NOT an AI-management-system certification: it assesses an AI product against security controls, not the governance system that produces AI products, so it does not substitute for ISO/IEC 42001. Report held in the TrustyCyber vault.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- — Current
Verified on the registry · IRAP security assessment report held in the TrustyCyber vault (Zoom trust portal) · checked Aug 24, 2026
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
- — Vendor claimed
- — Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 28, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 28, 2026
Supply chain
Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.
