Zoom AI Companion
zoom.com
Public evidence identified as at Aug 31, 2026
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
Approve with conditions
A score is only published when there is evidence to score.
Before you sign
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Zoom states it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train its own or third-party AI models.
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
!How long do they keep your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
✓Who else can access your data?Clear
OpenAI is registered as an Intelligent Features Service Provider that may process customer content and context when AI features are enabled, in the US and EU under SCCs.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!What happens in a security incident?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
Confirm in writing: Ask the vendor to state this in writing before signing.
Key findingsclick a row for the evidence
✓An explicit, unqualified commitment not to train on customer communicationsStrong
Zoom's privacy statement says plainly that it does not use audio, video, chat, screen sharing, attachments or other communications-like customer content to train its own or third-party AI models.
This is the question buyers ask first, and Zoom has public history on it. The commitment is stated without a tier carve-out or a settings condition, which is stronger than most comparable vendors offer — and being in the privacy statement, it is the version Zoom is held to.
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
✓AI model providers are named contractually, not just describedStrong
OpenAI and Anthropic are both registered as Intelligent Features Service Providers that may process customer content and context, with processing locations and SCCs stated.
Naming model providers in the subprocessor register puts them inside the DPA's change-notification machinery, so the AI supply chain can be tracked through the agreement rather than by watching a webpage.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
!No AI Companion-specific documentation reached this collectionGap
Zoom publishes AI Companion whitepapers ("AI Companion security and privacy", "AI Companion data privacy lifecycle") and a legal and compliance guide, none of which were retrievable here. The evidence above is organisation-wide and applies to AI Companion, but nothing product-specific was collected.
The organisation-wide no-training commitment is the load-bearing one and it covers the product. What is missing is AI Companion's own retention periods, human-review practice and admin controls — needed to operationalise a deployment, not to decide whether the posture is sound.
Question for vendor: Please provide the AI Companion data privacy lifecycle whitepaper, covering retention periods and whether any human review of AI Companion content occurs.
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
✓AI processing depends on a customer-controlled settingStrong
The register conditions each AI provider's processing on AI features being enabled, so content reaches OpenAI or Anthropic only on a customer decision.
It supports a staged rollout: AI processing can be held off while governance approval is obtained, without leaving the platform.
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
!Declared OpenAI, technically observed GoogleGap
The vendor's own materials name OpenAI as the model provider, but DNS, certificate, or HTTP evidence points to Google in that role instead.
A supply-chain claim that doesn't match what is technically observable is a disclosure question worth raising directly, not assuming either side is wrong.
Question for vendor: Can you confirm whether OpenAI or Google is the actual model provider?
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
?Technical dependency observed: Microsoft AzureObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft Azure as a platform provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft Azure appears to be involved as a platform provider: confirm whether this dependency exists, and whether it processes customer data.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
?Technical dependency observed: IntercomObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Intercom as a application builder. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Intercom appears to be involved as a application builder: confirm whether this dependency exists, and whether it processes customer data.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
AI System Assurance Report Cardscored per assurance object — organisational assurance is not product, model or agent assurance
Derived from the dimensions below — expand any row for the evidence behind its grade.
Organisation & AI governance15% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
Governance & accountability: not publicly evidenced.
AI system15% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
AI system description: not publicly evidenced.
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the scoreorganisation-level evidence72
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Zoom does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom’s or its third-party artificial intelligence models.”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence60
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“OpenAI Intelligent Features Service Provider OpenAI may process the following data if AI features are enabled: Customer Content and context United States, European Union”
“Anthropic Intelligent Features Service Provider Anthropic may process the following data if AI features are enabled: Customer Content and context”
“OpenAI may process the following data if AI features are enabled: Customer Content and context”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the scoreorganisation-level evidence24
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the scoreorganisation-level evidence63
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
Legal & contractual transparency: not publicly evidenced.
Not graded: Agent — not applicable to this scan.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 4 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 31, 2026: Verified on the registry
Checked against CSA STAR Registry, Aug 31, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry
Sources 15 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
