Zoom Video Communications

zoom.us

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
62 / 100C
Procurement decision
Approve with conditions
1 condition outstanding
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Substantial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Zoom's privacy statement commits that customer communications content is not used to train Zoom's or third-party AI models.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
!How long do they keep your data?Ask the vendor

Retention is criteria-based — for as long as required for the described uses, account lifetime, legal obligation or legal position — with no fixed retention windows stated for customer content generally.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.
Who else can access your data?Clear

Zoom publishes a formal, dated subprocessor register (effective 29 April 2026) with a change log back to 2020, listing each subprocessor's purpose, data shared, locations and international transfer mechanism.

Evidence
Effective: 29 April 2026
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs
Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union
Where is your data processed?Clear

Processing locations are disclosed per subprocessor (AWS across nine countries including Australia; AI model providers largely in the United States), with SCCs or BCRs named as the transfer mechanism for every entry.

Evidence
Australia, Brazil, Canada, Europe, India, Japan, Singapore, Taiwan, United States SCCs
What happens in a security incident?Clear

Zoom publishes a security.txt with a vulnerability report form, a security-reports email, a PGP key and a published reporting policy.

Evidence
Vendor publishedzoom.usretrieved Aug 21, 2026
Contact: https://www.zoom.com/en/trust/vulnerability-disclosure/submit-vulnerability-report
Vendor publishedSecurity | Zoomretrieved Aug 21, 2026
Work with confidence knowing the tools you use every day undergo proactive reviews — even after release — to identify and minimize vulnerabilities before they become a problem.

Key findingsclick a row for the evidence

Formal, dated subprocessor register names every AI model providerStrong

Zoom publishes a subprocessor register (effective 29 April 2026) with a change log back to 2020, naming its AI model providers individually — Anthropic, OpenAI, Perplexity, Google, Suki AI, Sumit-AI, Eleven Labs — with purpose, data shared, locations and transfer mechanism per entry, and AI processing conditional on features being enabled.

This is the disclosure most AI vendors withhold. A buyer can see exactly which model providers can touch customer content, under what condition, and on what legal basis — and the change log makes drift visible.

Evidence
Effective: 29 April 2026
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs
Explicit no-training commitment covering first- and third-party modelsStrong

The privacy statement states that customer communications content is not used to train Zoom's or third-party AI models.

Directly answers the first question buyers ask of an AI-enabled vendor, and extends the commitment to the third-party model providers named in the subprocessor register.

Question for vendor: Confirm the no-training commitment is contractual (DPA/order form), not only a policy statement.

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
!No AI-specific management-system certification claimedGap

The compliance library is extensive (ISO 27001/27017/27018/27701, SOC 2 Type 2, CSA STAR Level 2, FedRAMP, IRAP) but names no ISO/IEC 42001 or equivalent AI-management-system certification, and no certificate scope details appear on the page.

Zoom's AI governance claims currently rest on information-security and privacy certifications rather than an audited AI management system.

Question for vendor: Is an ISO/IEC 42001 (or equivalent) certification planned, and can certificate scope statements for the claimed certifications be provided?

Evidence
Vendor publishedCompliance | Zoomretrieved Aug 21, 2026
ISO 27001 Globally recognized security standard for implementing an ISMS
Vendor publishedSecurity | Zoomretrieved Aug 21, 2026
Security begins at the earliest stages of design, including our AI/Machine Learning security strategy and secure product development lifecycle.
!Retention is criteria-based, without fixed windows for customer contentGap

Retention is described by criteria (relationship length, user deletion, legal obligation, legal position) rather than fixed periods; only biometric feature data gets a concrete two-year rule.

A buyer cannot derive a deletion date for their content from the public statement alone — it depends on account configuration and Zoom's legal-position judgement.

Question for vendor: What are the concrete retention and deletion windows, in days, for customer content, AI inputs and AI outputs?

Evidence
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.
?Stripe observed but not named in public materialsObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider, which the vendor's public trust materials do not name.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Stripe appears to be involved as a service provider — can you confirm and disclose this relationship?

Evidence
Effective: 29 April 2026
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Effective: 29 April 2026
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs
Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Effective: 29 April 2026
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs
Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedCompliance | Zoomretrieved Aug 21, 2026
AI Dataset Disclosure How Zoom uses datasets for AI training. Learn more Learn more More Privacy at Zoom Learn more Learn more Legal Resources Learn more Learn more Zoom Security and Compliance FAQ Learn more Learn more Penetration Test Reports
Vendor publishedZoom’s Approach to AI Privacy & Security | Zoomretrieved Aug 21, 2026
hear from Zoom’s Chief Information Security Officer, Michael Adams, and Chief Privacy Officer, Lisa Owings, as they discuss Zoom’s data security, privacy, and compliance strategy,
AI system15% of the score40
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedCompliance | Zoomretrieved Aug 21, 2026
AI Dataset Disclosure How Zoom uses datasets for AI training. Learn more Learn more More Privacy at Zoom Learn more Learn more Legal Resources Learn more Learn more Zoom Security and Compliance FAQ Learn more Learn more Penetration Test Reports
Vendor publishedSecurity | Zoomretrieved Aug 21, 2026
Security begins at the earliest stages of design, including our AI/Machine Learning security strategy and secure product development lifecycle.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
We will provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under contractual agreement, along with posting such updates here.
Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union
Externally corroboratedZoom Third-Party Subprocessors & Zoom Affiliates | Zoomretrieved Aug 21, 2026
Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context United States SCCs

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score85
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, cannot be used to identify you, and is only used to generate the selected effects.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.
Australia, Brazil, Canada, Europe, India, Japan, Singapore, Taiwan, United States SCCs
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.
Vendor publishedZoom Privacy Statement | Zoomretrieved Aug 21, 2026
This data will be deleted when no longer necessary, adequate, or relevant to offering the features or when two years have passed since your last interaction with Zoom, whichever occurs first.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Eleven Labs Inc. Intelligent Features Service Provider (Text to Speech,Voice Cloning, Dubbing) Audio files United States, European Union
Effective: 29 April 2026

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score85
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedzoom.usretrieved Aug 21, 2026
Contact: https://www.zoom.com/en/trust/vulnerability-disclosure/submit-vulnerability-report
Vendor publishedSecurity | Zoomretrieved Aug 21, 2026
Work with confidence knowing the tools you use every day undergo proactive reviews — even after release — to identify and minimize vulnerabilities before they become a problem.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the score85
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
Vendor publishedCompliance | Zoomretrieved Aug 21, 2026
ISO 27001 Globally recognized security standard for implementing an ISMS

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 21, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 21, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27001retrieved Aug 21, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27701retrieved Aug 21, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Capped at 85: none of the corroborated certifications is AI-specific — this is security attestation, not AI-management-system assurance.

Independent assurance: vendor-evidenced, not yet independently corroborated.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score40
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Zoom requires its subprocessors to satisfy equivalent obligations as those required from Zoom (as a Data Processor) as outlined in Zoom’s Data Processing Agreement

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Governance & accountability disclosureOrganisation 4060
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 85100
+2Have Customer data treatment disclosures independently corroboratedData 85100
+2Have Model provider transparency disclosures independently corroboratedModel 6075
+2Have Subprocessors & supply chain disclosures independently corroboratedSupply Chain 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 62 → up to 81 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTUREZoom Video CommunicationsZoom Video CommunicationsZoom AI CompanionZoom AI CompanionAnthropicAnthropicOpenAIOpenAIPerplexityPerplexityGoogle Cloud PlatformGoogle Cloud PlatformAWSAWSMicrosoft AzureMicrosoft AzureOracleOracle
View as list
Zoom Video Communications Uses AI Service Anthropic
Zoom Video Communications Uses AI Service OpenAI
Zoom Video Communications Uses AI Service Perplexity
Zoom Video Communications Uses AI Service Google Cloud Platform
Zoom Video Communications Uses Infrastructure AWS
Zoom Video Communications Uses Infrastructure Microsoft Azure
Zoom Video Communications Uses Infrastructure Oracle

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 9 — registry checks and verification ladders, click to view
ISO/IEC 27001Claimed & corroborated

ISO/IEC 27001:2022. Scope covers the Zoom UCaaS Platform and Workvivo. Certificate 1407508-7, issued by Schellman Compliance LLC, accredited by ANAB; record last updated 12 August 2026.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Dec 4, 2027

Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry

ISO/IEC 27701Claimed & corroborated

Corroborated within the same Schellman/ANAB certificate 1407508-7 (ISO/IEC 27001:2022, Active): the Zoom UCaaS Platform scope extends to ISO/IEC 27701:2019 PIMS as a PII processor, inclusive of ISO/IEC 27017:2015 and ISO/IEC 27018:2025.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Dec 4, 2027

Checked against ISO/IEC 27701:2019 scope within Schellman certificate 1407508-7 (Zoom trust portal), Aug 24, 2026: Verified on the registry

SOC 2 Type 2Claimed & corroborated

SOC 2 Type 2 by Schellman & Company, system: the Zoom UCaaS Platform - the same boundary as the 27001 certificate; period 16 Oct 2024 - 15 Oct 2025, unqualified. FOUR trust services criteria: security, availability, confidentiality and privacy. Type 2, so design and operating effectiveness across the period. The report period ended 15 Oct 2025, so it sits inside the usual twelve-month reliance window as at Aug 2026 but will need refreshing. Report held in the TrustyCyber vault.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

FedRAMP ModerateClaimed & corroborated

Authorization covers Zoom for Government (SaaS), not the commercial Zoom service; the vendor's own compliance page lists FedRAMP under its Zoom for Government section, consistent with the registry.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 21, 2026: Verified on the registry

IRAPClaimed & corroborated

IRAP security assessment by Schellman, lead assessor Greg Mansill (IRAP 00068), report dated 18 May 2026 v1.0, against the Australian Government ISM June 2025 release, assessed to the PROTECTED level (COI 000776). NOTABLE FOR AN AI ASSESSMENT: the in-scope products include AI Notetaker, which transcribes, records and summarises meetings across third-party platforms - so this is an independent assessment of an AI FEATURE against Australian government security controls, not merely of the underlying platform. It is NOT an AI-management-system certification: it assesses an AI product against security controls, not the governance system that produces AI products, so it does not substitute for ISO/IEC 42001. Report held in the TrustyCyber vault.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IRAP security assessment report held in the TrustyCyber vault (Zoom trust portal), Aug 24, 2026: Verified on the registry

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 19 — click to view
Zoom’s Approach to AI Privacy & Security | Zoom
AI Documentation · Vendor · retrieved Aug 21, 2026
Navigating legal and privacy challenges in AI implementation | Zoom
AI Documentation · Vendor · retrieved Aug 21, 2026
Zoom Trust Center | Zoom
Trust Or Security Page · Vendor · retrieved Aug 21, 2026
Security | Zoom
Trust Or Security Page · Vendor · retrieved Aug 21, 2026
https://zoom.us/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Aug 21, 2026
Zoom Third-Party Subprocessors & Zoom Affiliates | Zoom
Subprocessor List · Vendor · retrieved Aug 21, 2026
Zoom Privacy Statement | Zoom
Privacy Notice · Vendor · retrieved Aug 21, 2026
Compliance | Zoom
Certification Or Compliance Page · Vendor · retrieved Aug 21, 2026
Zoom's Trust Center Resources | Zoom
Terms · Vendor · retrieved Aug 21, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Moderate
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
IAF CertSearch record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
IAF CertSearch record — ISO/IEC 27701
External Registry Or Certification Evidence · Registry · retrieved Aug 21, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (Zoom trust portal) record — SOC 2 Type 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
IRAP security assessment report held in the TrustyCyber vault (Zoom trust portal) record — IRAP
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Zoom Video Communications at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.