Zoom Video Communications
zoom.us
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.”
“This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.”
“may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Zoom's privacy statement commits that customer communications content is not used to train Zoom's or third-party AI models.
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
“communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
!How long do they keep your data?Ask the vendor
Retention is criteria-based — for as long as required for the described uses, account lifetime, legal obligation or legal position — with no fixed retention windows stated for customer content generally.
Requires written confirmation — see Before you sign ↓
“We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.”
“This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.”
“may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.”
✓Who else can access your data?Clear
Zoom publishes a formal, dated subprocessor register (effective 29 April 2026) with a change log back to 2020, listing each subprocessor's purpose, data shared, locations and international transfer mechanism.
“Effective: 29 April 2026”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
“Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union”
✓Where is your data processed?Clear
Processing locations are disclosed per subprocessor (AWS across nine countries including Australia; AI model providers largely in the United States), with SCCs or BCRs named as the transfer mechanism for every entry.
“Australia, Brazil, Canada, Europe, India, Japan, Singapore, Taiwan, United States SCCs”
✓What happens in a security incident?Clear
Zoom publishes a security.txt with a vulnerability report form, a security-reports email, a PGP key and a published reporting policy.
“Contact: https://www.zoom.com/en/trust/vulnerability-disclosure/submit-vulnerability-report”
“Work with confidence knowing the tools you use every day undergo proactive reviews — even after release — to identify and minimize vulnerabilities before they become a problem.”
Key findingsclick a row for the evidence
✓Formal, dated subprocessor register names every AI model providerStrong
Zoom publishes a subprocessor register (effective 29 April 2026) with a change log back to 2020, naming its AI model providers individually — Anthropic, OpenAI, Perplexity, Google, Suki AI, Sumit-AI, Eleven Labs — with purpose, data shared, locations and transfer mechanism per entry, and AI processing conditional on features being enabled.
This is the disclosure most AI vendors withhold. A buyer can see exactly which model providers can touch customer content, under what condition, and on what legal basis — and the change log makes drift visible.
“Effective: 29 April 2026”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
✓Explicit no-training commitment covering first- and third-party modelsStrong
The privacy statement states that customer communications content is not used to train Zoom's or third-party AI models.
Directly answers the first question buyers ask of an AI-enabled vendor, and extends the commitment to the third-party model providers named in the subprocessor register.
Question for vendor: Confirm the no-training commitment is contractual (DPA/order form), not only a policy statement.
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
!No AI-specific management-system certification claimedGap
The compliance library is extensive (ISO 27001/27017/27018/27701, SOC 2 Type 2, CSA STAR Level 2, FedRAMP, IRAP) but names no ISO/IEC 42001 or equivalent AI-management-system certification, and no certificate scope details appear on the page.
Zoom's AI governance claims currently rest on information-security and privacy certifications rather than an audited AI management system.
Question for vendor: Is an ISO/IEC 42001 (or equivalent) certification planned, and can certificate scope statements for the claimed certifications be provided?
“ISO 27001 Globally recognized security standard for implementing an ISMS”
“Security begins at the earliest stages of design, including our AI/Machine Learning security strategy and secure product development lifecycle.”
!Retention is criteria-based, without fixed windows for customer contentGap
Retention is described by criteria (relationship length, user deletion, legal obligation, legal position) rather than fixed periods; only biometric feature data gets a concrete two-year rule.
A buyer cannot derive a deletion date for their content from the public statement alone — it depends on account configuration and Zoom's legal-position judgement.
Question for vendor: What are the concrete retention and deletion windows, in days, for customer content, AI inputs and AI outputs?
“We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.”
“This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.”
?Stripe observed but not named in public materialsObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider, which the vendor's public trust materials do not name.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Stripe appears to be involved as a service provider — can you confirm and disclose this relationship?
“Effective: 29 April 2026”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Effective: 29 April 2026”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
“Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Effective: 29 April 2026”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
“Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score40
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“AI Dataset Disclosure How Zoom uses datasets for AI training. Learn more Learn more More Privacy at Zoom Learn more Learn more Legal Resources Learn more Learn more Zoom Security and Compliance FAQ Learn more Learn more Penetration Test Reports”
“hear from Zoom’s Chief Information Security Officer, Michael Adams, and Chief Privacy Officer, Lisa Owings, as they discuss Zoom’s data security, privacy, and compliance strategy,”
AI system15% of the score40
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“AI Dataset Disclosure How Zoom uses datasets for AI training. Learn more Learn more More Privacy at Zoom Learn more Learn more Legal Resources Learn more Learn more Zoom Security and Compliance FAQ Learn more Learn more Penetration Test Reports”
“Security begins at the earliest stages of design, including our AI/Machine Learning security strategy and secure product development lifecycle.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“We will provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under contractual agreement, along with posting such updates here.”
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score85
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
“may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.”
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
“Australia, Brazil, Canada, Europe, India, Japan, Singapore, Taiwan, United States SCCs”
“We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.”
“This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union”
“Effective: 29 April 2026”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the score85
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Contact: https://www.zoom.com/en/trust/vulnerability-disclosure/submit-vulnerability-report”
“Work with confidence knowing the tools you use every day undergo proactive reviews — even after release — to identify and minimize vulnerabilities before they become a problem.”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the score85
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“ISO 27001 Globally recognized security standard for implementing an ISMS”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.
Independent assurance: vendor-evidenced, not yet independently corroborated.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score40
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“Zoom requires its subprocessors to satisfy equivalent obligations as those required from Zoom (as a Data Processor) as outlined in Zoom’s Data Processing Agreement”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 62 → up to 81 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 9 — registry checks and verification ladders, click to view
ISO/IEC 27001:2022. Scope covers the Zoom UCaaS Platform and Workvivo. Certificate 1407508-7, issued by Schellman Compliance LLC, accredited by ANAB; record last updated 12 August 2026.
Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry
Corroborated within the same Schellman/ANAB certificate 1407508-7 (ISO/IEC 27001:2022, Active): the Zoom UCaaS Platform scope extends to ISO/IEC 27701:2019 PIMS as a PII processor, inclusive of ISO/IEC 27017:2015 and ISO/IEC 27018:2025.
Checked against ISO/IEC 27701:2019 scope within Schellman certificate 1407508-7 (Zoom trust portal), Aug 24, 2026: Verified on the registry
SOC 2 Type 2 by Schellman & Company, system: the Zoom UCaaS Platform - the same boundary as the 27001 certificate; period 16 Oct 2024 - 15 Oct 2025, unqualified. FOUR trust services criteria: security, availability, confidentiality and privacy. Type 2, so design and operating effectiveness across the period. The report period ended 15 Oct 2025, so it sits inside the usual twelve-month reliance window as at Aug 2026 but will need refreshing. Report held in the TrustyCyber vault.
Checked against SOC 2 Type 2 report held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry
Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry
Authorization covers Zoom for Government (SaaS), not the commercial Zoom service; the vendor's own compliance page lists FedRAMP under its Zoom for Government section, consistent with the registry.
Checked against FedRAMP Marketplace (fedramp.gov), Aug 21, 2026: Verified on the registry
IRAP security assessment by Schellman, lead assessor Greg Mansill (IRAP 00068), report dated 18 May 2026 v1.0, against the Australian Government ISM June 2025 release, assessed to the PROTECTED level (COI 000776). NOTABLE FOR AN AI ASSESSMENT: the in-scope products include AI Notetaker, which transcribes, records and summarises meetings across third-party platforms - so this is an independent assessment of an AI FEATURE against Australian government security controls, not merely of the underlying platform. It is NOT an AI-management-system certification: it assesses an AI product against security controls, not the governance system that produces AI products, so it does not substitute for ISO/IEC 42001. Report held in the TrustyCyber vault.
Checked against IRAP security assessment report held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry
Sources 19 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Zoom Video Communications at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
