01Trust Score

Zoom

CONDITIONAL

Week 2026-W20 May 17, 2026 Vendor-Neutral
70 /100 Mostly Positive
↑ 40 vs 2026-W17
2.7/5 (5452)
↓ PDF Report
WHY THIS SCORE

The overall trust score of 54 reflects a mixed profile for enterprise procurement. Security scored 35/35 due to verified SOC 2 Type II, ISO 27001, and GDPR DPA availability, indicating a robust compliance posture. Legal risk, re-evaluated to 65, benefits from an explicit policy against using customer content for AI model training, but is tempered by undisclosed indemnification and liability terms. Financial health is strong at 78, reflecting Zoom's public company status. Community trust, at 60, is impacted by recent user complaints regarding UI usability, audio issues, and billing transparency. A key action to improve the score would be to publicly disclose comprehensive data export and deletion policies, and to offer clearer SLA terms.

AUDITOR SUMMARY
Strength: Zoom demonstrates a robust security and compliance posture, holding SOC 2 Type II and ISO 27001 certifications, and explicitly stating that customer content is not used for AI model training. This provides a strong foundation for enterprise trust.
Trust Score 70/100 CONDITIONAL
Est. Annual Cost $21,996/year for 100 users (Business tier) 100 users / yr
Top Risk HIGH Reliability Overall: Medium
Priority Action Request a comprehensive DPA and MSA detailing data export, retention, and SLA terms. ↓ PDF  · TCO  · Hardening
Enterprise: DPA ✓ · Residency: Customer-Controlled · Lock-in: Medium (65/100)

Verified Compliance Facts

Cited and timestamped — every claim traceable to an official vendor source.

Base price
Not yet verified
Source ↗ Checked: May 17, 2026 ~ Evidence found
Data residency
Not yet verified
Source ↗ Checked: May 17, 2026 ~ Evidence found
Data Processing Addendum
Source ↗ Checked: May 17, 2026 ✓ Verified
GDPR
✓ Verified
Source ↗ Checked: May 17, 2026 ✓ Verified
HIPAA
✓ Verified
Source ↗ Checked: May 17, 2026 ✓ Verified
IP indemnification
Not yet verified
Source ↗ Checked: May 17, 2026 ~ Evidence found
ISO/IEC 27001
✓ Verified
Source ↗ Checked: May 17, 2026 ✓ Verified
SOC 2
✓ Verified
Source ↗ Checked: May 17, 2026 ✓ Verified
Sub-processors
  • Amazon Web Services
  • Anthropic
  • Authzed, Inc.
  • Cloudflare
  • Eleven Labs Inc.
…and 18 more
Source ↗ Checked: May 17, 2026 ~ Evidence found
Trains on customer data
Not yet verified
Source ↗ Checked: May 17, 2026 ~ Evidence found

Enterprise Verdict

! Conditional Approval
Risk: Medium Confidence: medium 50 sources

CONDITIONAL

The adoption recommendation is 'conditional_proceed' primarily due to the lack of publicly disclosed comprehensive data export and deletion policies, alongside community reports of UI and audio issues. For Zoom to receive an 'approved' verdict, the vendor must provide explicit contractual guarantees for data portability and a clear, publicly available SLA.
Key Strength

Verified SOC 2 Type II, ISO 27001, and GDPR DPA certifications.

Top Risk

Opaque data export and deletion policies, increasing vendor lock-in risk.

Priority Action

Request a comprehensive DPA and MSA detailing data export, retention, and SLA terms.

This report updates every week. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
02Top Risks

Risk Assessment

Seven-category enterprise risk analysis derived from community and vendor signals. Each card shows the evidence tier and the underlying finding.

High Reliability Community Data

Public documentation buyers may want to verify availability of specific uptime commitments or reliability history.

Medium Cost Predictability Community Data

Enterprises should negotiate fixed-rate contracts and monitor pricing changes for overage risks.

High Vendor Lock-in Community Data

Data export status unclear. Integration score: 0/100. Webhooks available, reducing lock-in risk.

Medium Support Quality Community Data

Average community support/satisfaction rating: 3.5/5.0 based on 159 user reviews.

Medium Data Privacy Community Data

Compliance score: 100/100. GDPR status: dpa_available. Encryption at rest: yes.

Low Compliance Posture Community Data

SOC 2: type_ii. ISO 27001: certified. Overall compliance score: 100/100.

Medium AI Transparency Verified

No training on user data detected. Code ownership terms unclear. Legal/ToS risk score: 65/100.

Verified — Confirmed by vendor documentation Community — Derived from community reports

Due Diligence Alerts

Priority reviews, recommended inquiries, and verified strengths — based on 86+ community data points

Recommended Inquiry High SLA Terms Not Publicly Disclosed — Request MSA Before Procurement
Recommended Inquiry High Opaque Data Lifecycle — Data Export and Deletion Policies Undisclosed
Recommended Inquiry Medium China Data Routing Risk for Non-Enterprise Tiers
Recommended Inquiry Medium Community Reports of Persistent Audio and UI Issues
03Security & Compliance

Security & Compliance

GDPR ~ DPA
SOC 2 ✓ Type II
HIPAA Not documented
FedRAMP ⏳ In Progress
ISO 27001 ✓ Certified

External Registry Verification

Data Security

Data Residency: US EU
Encryption (At Rest): AES-256
Encryption (In Transit): TLS 1.3

Security Features

SSO SAML
MFA TOTP
Vulnerability Disclosure

Enterprise Contract Intelligence

DPA availability, data residency, and contract risk signals for procurement teams

DPA ✓ Residency: Customer-Controlled Lock-in: Medium (65/100)
📄 Data Processing Agreement Available
View DPA ↗

A GDPR Data Processing Addendum (DPA) is publicly available, which includes Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) for data transfers. However, a public list of sub-processors is available separately.

🌐 Data Residency Customer-Controlled
Default: US (unless specified otherwise in Enterprise contract)
United StatesEU/EEAUnited KingdomCanadaAustralia

Zoom offers data residency options for primary regions, with customer control available on the Enterprise tier. However, the platform has a known risk of data routing through China for non-Enterprise tiers, which is a critical concern for EU/regulated buyers. SCCs and BCRs are in place for cross-border transfers.

⚠️ Contract Risk Medium Lock-in (65/100)
Auto-renewal: Yes ⚠ Unilateral change right: Yes ⚠ Data export on exit: No ⚠ Notice: 30 days
⚠ 5 contract risk flags — click to review
⚠ Arbitration clause and class-action waiver.
⚠ Unilateral right to modify Terms of Service.
⚠ Non-cancelable and non-refundable charges for subscription terms.
⚠ Opaque data export and deletion policies.
⚠ Customer liability for End User actions.

The contract risk is medium-high due to auto-renewal clauses, Zoom's unilateral right to modify terms, and non-refundable charges. The lack of explicit data portability guarantees and undisclosed indemnification terms further increase lock-in and legal exposure. A 30-day termination notice period is standard.

Compliance & Document Matrix

🛡️ Security Certifications AI-enhanced

Certification Status Auditor Valid Until Source
⏳ Scanning in progress — check back after next weekly audit.

🔒 Data Privacy Documents

Document Status URL AI Assessment
Sub-processors ✅ Active Link ✅ Publicly documented
AI/Model Training Policy ❌ Not Found ✅ No training by default
Data Retention Policy ❌ Not Found 🟡 Described, no formal doc
Data Flow Diagram ❌ Not Found
GDPR Compliance Statement ✅ Active Link ✅ Publicly documented
KVKK Compliance Statement ❌ Not Found ⚪ Not disclosed
CCPA Compliance Statement ❌ Not Found ✅ Publicly documented

⚖️ Legal Contracts

See Legal & IP Assessment section above for full analysis of ToS, DPA, MSA, SLA, EULA, and AUP.

🔧 Operational Readiness

Document Status URL AI Assessment
Business Continuity Plan (BCP) ❌ Not Found ⚪ Not disclosed
Disaster Recovery Plan (DRP) ❌ Not Found ⚪ Not disclosed
Incident Response Plan ❌ Not Found ⚪ Not disclosed
3rd Party Penetration Test ❌ Not Found 🟡 Described, no formal doc

📋 Technical Transparency

Document Status URL AI Assessment
SBOM ❌ Not Found ⚪ Not disclosed
OSS License Inventory ❌ Not Found ⚪ Not disclosed
Vulnerability Management Policy ✅ Active Link ✅ Publicly documented
Patch Management Policy ❌ Not Found ⚪ Not disclosed
Offboarding / Data Export Guide ❌ Not Found ⚪ Not disclosed
SIG Questionnaire ❌ Not Found
CAIQ ❌ Not Found

💰 Financial Resilience

Item Status Details
Cyber Liability Insurance ❌ Not Found ⚪ Not disclosed
TCO Disclosed ✅ Available Annual: $21,996/year for 100 users (Business tier)
New risk signals detected weekly. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.
04Community Signals

Community Intelligence

Recurring issues and curated signals from GitHub, Hacker News, Reddit, Stack Overflow, web sources, and enterprise review platforms.

Intelligence Synthesis

Community discussion this week highlights a mixed user experience with Zoom, focusing on persistent audio and microphone issues, alongside frustrations with the mobile application's user interface and disappearing controls. While many users praise Zoom's ease of use and collaborative capabilities, concerns about unexpected overage fees on Zoom Phone and inconsistent browser microphone permissions have also surfaced. The vendor continues to announce new AI-powered features and maintain a strong market position, but these operational and transparency issues remain points of friction for users.

Recurring Issues

Audio and Microphone Connectivity Issues 🟠 Community 3 mentions high → Stable

Enterprise Impact: Persistent audio issues can severely disrupt critical business meetings and negatively impact productivity and external communication.

Zoom should investigate and provide clearer troubleshooting for microphone and audio connectivity, potentially with in-app diagnostics or improved support resources.

User Interface and Usability Challenges 🟠 Community 4 mentions medium ↗ Worsening

Enterprise Impact: Poor UI/UX can lead to user frustration, reduced adoption, and increased support requests within an enterprise, especially for less tech-savvy employees.

Zoom should conduct user experience research, particularly for mobile interfaces, to simplify controls and improve the intuitiveness of core features.

Unexpected Overage Fees and Billing Surprises 🟠 Community 1 mentions medium → Stable

Enterprise Impact: Unforeseen billing charges can lead to budget overruns and administrative burden for enterprise procurement and finance teams.

Zoom should provide clearer documentation on what constitutes 'metered calling' and offer more transparent real-time usage tracking and alerts for Zoom Phone services.

Sources: Reddit
Inconsistent Microphone Permission Handling in Chrome 🟠 Community 1 mentions medium → Stable

Enterprise Impact: Inconsistent permission handling can create security and privacy concerns, as well as lead to user confusion and potential bypasses of IT-mandated browser settings.

Zoom should clarify its approach to browser permissions and ensure consistent, transparent behavior that aligns with standard web API practices, or document any special browser integrations.

Sources: SO

Source Signals

05Financial Impact

Financial Impact Panel

Cost intelligence and pricing signals for enterprise procurement decisions

Base price sourced from: official pricing page ↗

Pricing data from public sources — enterprise rates differ. Verify with vendor.

TCO Calculator

Calculate the real monthly cost for your team. Adjust seats, usage, and pricing tier below.

Estimated Monthly Cost

Base Subscription $0
AI Credits / Tokens $0
Hidden Costs (onboarding, overages, support) $0
Total Monthly TCO $0
Per User / Month $0
Annual Projection $0

Estimated Annual TCO — 100 Users ±20% confidence band

SMB / Pay-as-you-go
$0 – $23034 /yr
Midpoint: $0
Assumptions
  • Free tier used as SMB baseline.
  • If free tier insufficient: Pro at $13/seat/mo → $15,996/yr base for 100 users.
Mid-market / Per-seat
$16891 – $25336 /yr
Midpoint: $21114
Assumptions
  • Based on 'Pro' tier at $13.33/seat/month.
  • Base (license): $15,996/yr for 100 users.
  • +32% overhead (impl+training+support) → $21,114/yr.
Enterprise / Provisioned
Pricing not disclosed
Assumptions
  • Pricing not publicly disclosed — contact vendor for quote.

Estimates from publicly scraped pricing data.

Don't evaluate blind next quarter. Weekly AI vendor intelligence — trust scores, contract red flags, competitive shifts.

Synthesized from 20+ independent public sources: developer forums & repositories, security databases, vendor disclosures, regulatory filings, and community review platforms. Not affiliated with any vendor. Corrections?

Download PDF Report

Create a free account to download the full enterprise audit PDF.

Sign up — it's free →

Already have an account? Log in