Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about Zoom before Zoom sends a questionnaire or a security document.
Zoom's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Zoom — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Zoom's own trust page.
✓ FedRAMP Certified — Class C (Moderate) Checked August 2026.
Zoom for Government is FedRAMP Certified at Class C (Moderate) via the JAB path (package FR1825941347A). Commercial Zoom accounts are not covered.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Zoom assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Zoom Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 67% of a 133-question vendor security questionnaire — without waiting for Zoom. The remaining 44 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q23
Data at rest including stored meeting recordings, transcripts, and cloud content is encrypted with AES-256 GCM using either Zoom-managed keys or Customer Managed Keys (CMK).
+ 84 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Zoom for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Zoom
Zoom is a widely-deployed video conferencing and collaboration platform serving millions of users globally.
The company demonstrates strong foundational security practices with valid TLS encryption, a clean domain reputation, and an explicit commitment to not training AI models on customer data. However, the assessment identifies moderate concerns that require attention: significant gaps in HTTP security headers (HTTP security scanner grade D), a recent class action lawsuit related to CCPA privacy compliance, recent critical security vulnerabilities affecting screen-sharing functionality, and an inability to independently verify multiple compliance certifications claimed on the vendor's trust page.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from external data sources without vendor participation, including public registries, threat intelligence feeds, domain analysis, compliance page scans, adverse media archives, and third-party security tools.
4 findings identified for Zoom
HTTP security scanner security header scan returned a grade of D (35/100) for zoom.us, indicating multiple missing HTTP security headers. Missing protections include Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), and X-Frame-Options. …
A class action lawsuit against Zoom was reported in early 2026 alleging CCPA privacy violations. This represents a legal risk and potential regulatory exposure for customers who rely on Zoom for data processing. …
Zoom's subprocessor page (https://zoom.us/subprocessors) exists but automated parsing could not extract individual subprocessor entries, likely due to a non-standard page format or rendering method. This prevents automated verification of Zoom's third-party data processing chain and raises questions about transparency and ease of compliance review.
Zoom's [compliance page](https://zoom.us/compliance) claims 10 certifications (SOC 2, ISO 27001, ISO 27017, HITRUST, PCI DSS, FedRAMP, HIPAA, GDPR, CSA STAR, Cyber Essentials), but none could be independently verified through public certification registries. These are vendor-attested claims only. …
Showing the 4 most severe of 6 findings.
Evidence that positively supports Zoom's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →Established Web Presence (24+ years)
Web Archive History →Zoom complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Zoom? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Zoom assessment above is already written; ask for it and it lands in your inbox.