Nothing needs switching on. Audio, video and screen of every meeting are encrypted with 256-bit AES-GCM from the moment a participant joins. The green shield in the meeting window confirms it.
Every Zoom meeting and webinar is encrypted by default. Audio, video and screen sharing travel between participants' apps, Zoom Rooms and connectors under 256-bit AES in GCM mode. It is the same class of encryption as in banking systems, and it is on for every account, free ones included. Since 30 May 2020 Zoom admits only apps of version 5.0 and later, which support this mode, into meetings.
The keys for ordinary mode are generated and kept by Zoom servers. That is what lets the cloud do what a business needs: record the meeting, transcribe and summarise it, connect participants by telephone and from SIP devices. If the keys must belong to the participants alone, there is end-to-end mode: stricter, and it switches some features off.
The confirmation is not only in the meeting window. Zoom holds a SOC 2 Type 2 report, a SOC 2 with HITRUST variant for healthcare, a BAA under HIPAA, completed CSA CAIQ and SIG Core questionnaires. How the encryption works in detail is described in Zoom's document "Understanding encryption in the Zoom Workplace platform".
The most reliable protection is the one that cannot be forgotten.
Encryption applies on any plan and for any participant. A guest joining by link is protected the same as an employee.
A green shield in the corner of the meeting window. The participant checks the mode themselves, without asking IT.
SOC 2 Type 2 and SOC 2 with HITRUST reports, a BAA under HIPAA. The security team has something to put in the folder.
Algorithm, coverage, confirmations and limits
The standard for audio, video and screen sharing in transit. GCM mode protects against both eavesdropping and tampering.
The same mode for meetings, webinars and connections from meeting rooms. Nothing to configure separately.
Apps on computers and phones, Zoom Rooms, connectors for SIP and H.323. The stream is encrypted on every leg of the route.
The indicator in the meeting window shows encryption is active. In end-to-end mode a padlock appears on the shield.
Since 30 May 2020 only apps from version 5.0 join meetings. An outdated app cannot lower the protection of the whole meeting.
Keys on Zoom servers allow cloud recording, transcription, Zoom AI summaries, dial-in by telephone and from SIP devices. End-to-end mode switches these off.
SOC 2 Type 2 with a bridge letter, SOC 2 + HITRUST, a BAA under HIPAA, CSA CAIQ and SIG Core questionnaires. Documents are provided on request.
"Understanding encryption in the Zoom Workplace platform" and the "Zoom Cryptography Whitepaper" describe the algorithms and key handling. We pass them to the customer's security team.
Nothing to buy or enable. Participants need current app versions. End-to-end mode is enabled separately and has its own limits.
Wherever security is asked about before the purchase
The answer to "how is it encrypted" is ready: algorithm, coverage, reports. The conversation moves on to policies and single sign-on.
Guests, contractors, candidates join by link and are protected by the same mode. Nothing needs explaining to them.
SOC 2 with HITRUST and a BAA under HIPAA as the basis for consultations and case conferences in Zoom.
Specific standards and reports go into the customer's questionnaire, not "there is encryption".
Conversations where the keys must belong only to the participants move to end-to-end mode, with an understanding of what switches off.
We answer security questionnaires together with the customer, hand over Zoom's documents, and help decide where end-to-end mode is needed. Then support in Russian.
The starting point for any conversation about protecting communications.
Formal confirmation that the channel and media are encrypted.
End-to-end encryption and your own keys are built on it.
We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.
Please note: we work with legal entities only.