Skip to main content
Skip to main content

Zoom Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Zoom before Zoom sends a questionnaire or a security document.

Zoom's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Zoom — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Zoom's own trust page.

FedRAMP Certified — Class C (Moderate) Checked August 2026.

Zoom for Government is FedRAMP Certified at Class C (Moderate) via the JAB path (package FR1825941347A). Commercial Zoom accounts are not covered.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
89 / 133 answered
67% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟡IP Reputation: Abuse score: 11%, 4 reports🟡SSL/TLS: TLSv1.3🟢Infrastructure: 2 open ports, 0 CVEs🟢Sanctions: Clear — 5 matches checked, none confirmed
FedRAMP Status
Zoom is not listed on the FedRAMP Marketplace (checked August 2026).
SOC 2 Status
Zoom — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Zoom returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Zoom a Moderate Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The Zoom assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Zoom Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

89 questions answered before Zoom responds.

ThirdProof used public evidence to pre-fill 67% of a 133-question vendor security questionnaire — without waiting for Zoom. The remaining 44 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

PCI DSS compliance claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

GDPR compliance / DPA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

HIPAA compliance / BAA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Data at rest including stored meeting recordings, transcripts, and cloud content is encrypted with AES-256 GCM using either Zoom-managed keys or Customer Managed Keys (CMK).

Public evidencehigh confidence

+ 84 additional evidence-backed answers

Get the Complete Zoom Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Zoom sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Vendor Commits to Not Training on Customer Data
  • Clean domain reputation
  • Clean Safe Browsing Status

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Data Security — 7 of 14 questions need vendor input
  • Access Control — 6 of 12 questions need vendor input
  • Incident Response — 5 of 10 questions need vendor input
  • Vulnerability Management — 3 of 8 questions need vendor input

Reviewing Zoom for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Zoom

Zoom is a widely-deployed video conferencing and collaboration platform serving millions of users globally.

Area Requiring Attention

The company demonstrates strong foundational security practices with valid TLS encryption, a clean domain reputation, and an explicit commitment to not training AI models on customer data. However, the assessment identifies moderate concerns that require attention: significant gaps in HTTP security headers (HTTP security scanner grade D), a recent class action lawsuit related to CCPA privacy compliance, recent critical security vulnerabilities affecting screen-sharing functionality, and an inability to independently verify multiple compliance certifications claimed on the vendor's trust page.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from external data sources without vendor participation, including public registries, threat intelligence feeds, domain analysis, compliance page scans, adverse media archives, and third-party security tools.

Investigation Findings

4 findings identified for Zoom

1 medium3 low
medium

Significant security header gaps

HTTP security scanner security header scan returned a grade of D (35/100) for zoom.us, indicating multiple missing HTTP security headers. Missing protections include Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options. …

low

Adverse media coverage detected

A class action lawsuit against Zoom was reported in early 2026 alleging CCPA privacy violations. This represents a legal risk and potential regulatory exposure for customers who rely on Zoom for data processing. …

low

Subprocessor list could not be parsed

Zoom's subprocessor page (https://zoom.us/subprocessors) exists but automated parsing could not extract individual subprocessor entries, likely due to a non-standard page format or rendering method. This prevents automated verification of Zoom's third-party data processing chain and raises questions about transparency and ease of compliance review.

low

10 certifications claimed but not independently verified

Zoom's [compliance page](https://zoom.us/compliance) claims 10 certifications (SOC 2, ISO 27001, ISO 27017, HITRUST, PCI DSS, FedRAMP, HIPAA, GDPR, CSA STAR, Cyber Essentials), but none could be independently verified through public certification registries. These are vendor-attested claims only. …

Showing the 4 most severe of 6 findings.

Security Strengths

Evidence that positively supports Zoom's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Vendor Commits to Not Training on Customer Data

AI Data Usage Policy

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Clean Website Security Scan

Website Security Scan

Established Web Presence (24+ years)

Web Archive History

Zoom complete vendor assessment

Tier 3
Moderate Risk
89 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Frequently asked about Zoom

Is Zoom FedRAMP authorized?+
Zoom was not found in the FedRAMP Marketplace when it was checked on August 10, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Does Zoom have SOC 2 Type II?+
Zoom states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Zoom on the OFAC sanctions list?+
Zoom returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Zoom's vendor risk tier?+
ThirdProof assigned Zoom a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Zoom.
Has Zoom had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 1 incident-related finding for Zoom. The most severe concerns adverse media coverage detected. Each finding states whether the incident affected Zoom's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is Zoom PCI DSS compliant?+
PCI DSS compliance claim found on trust page (Vendor attested) ThirdProof records this from Zoom's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Zoom support HIPAA and sign BAAs?+
HIPAA compliance / BAA claim found on trust page (Vendor attested) If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Zoom security questionnaire?+
Yes. ThirdProof answered 89 of 133 questions (67%) about Zoom from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 44 are listed as open, so the follow-up you send Zoom is short and specific.

If Zoom is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Zoom assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required