Products · Security & access control
Security & Access Control

Encryption by default

Nothing needs switching on. Audio, video and screen of every meeting are encrypted with 256-bit AES-GCM from the moment a participant joins. The green shield in the meeting window confirms it.

What it is

Every Zoom meeting and webinar is encrypted by default. Audio, video and screen sharing travel between participants' apps, Zoom Rooms and connectors under 256-bit AES in GCM mode. It is the same class of encryption as in banking systems, and it is on for every account, free ones included. Since 30 May 2020 Zoom admits only apps of version 5.0 and later, which support this mode, into meetings.

The keys for ordinary mode are generated and kept by Zoom servers. That is what lets the cloud do what a business needs: record the meeting, transcribe and summarise it, connect participants by telephone and from SIP devices. If the keys must belong to the participants alone, there is end-to-end mode: stricter, and it switches some features off.

The confirmation is not only in the meeting window. Zoom holds a SOC 2 Type 2 report, a SOC 2 with HITRUST variant for healthcare, a BAA under HIPAA, completed CSA CAIQ and SIG Core questionnaires. How the encryption works in detail is described in Zoom's document "Understanding encryption in the Zoom Workplace platform".

What is protected
  • Audio, video and screen sharing in real time
  • 256-bit AES-GCM between apps and connectors
  • The green shield in the meeting window
  • Computers, phones, Zoom Rooms
  • SOC 2 Type 2, HITRUST, HIPAA BAA

Security that does not depend on a setting

The most reliable protection is the one that cannot be forgotten.

On for everyone

Encryption applies on any plan and for any participant. A guest joining by link is protected the same as an employee.

Visible to everyone

A green shield in the corner of the meeting window. The participant checks the mode themselves, without asking IT.

Confirmed by audit

SOC 2 Type 2 and SOC 2 with HITRUST reports, a BAA under HIPAA. The security team has something to put in the folder.

Capabilities

What encryption by default gives you

Algorithm, coverage, confirmations and limits

256-bit AES-GCM

The standard for audio, video and screen sharing in transit. GCM mode protects against both eavesdropping and tampering.

Meetings and webinars

The same mode for meetings, webinars and connections from meeting rooms. Nothing to configure separately.

Every entry point

Apps on computers and phones, Zoom Rooms, connectors for SIP and H.323. The stream is encrypted on every leg of the route.

The green shield

The indicator in the meeting window shows encryption is active. In end-to-end mode a padlock appears on the shield.

A mandatory version

Since 30 May 2020 only apps from version 5.0 join meetings. An outdated app cannot lower the protection of the whole meeting.

What stays available

Keys on Zoom servers allow cloud recording, transcription, Zoom AI summaries, dial-in by telephone and from SIP devices. End-to-end mode switches these off.

Certifications and reports

SOC 2 Type 2 with a bridge letter, SOC 2 + HITRUST, a BAA under HIPAA, CSA CAIQ and SIG Core questionnaires. Documents are provided on request.

Details in Zoom's documents

"Understanding encryption in the Zoom Workplace platform" and the "Zoom Cryptography Whitepaper" describe the algorithms and key handling. We pass them to the customer's security team.

Requirements and availability

Nothing to buy or enable. Participants need current app versions. End-to-end mode is enabled separately and has its own limits.

Scenes

Where it works

Wherever security is asked about before the purchase

01

The security team's review

The answer to "how is it encrypted" is ready: algorithm, coverage, reports. The conversation moves on to policies and single sign-on.

02

Working with external participants

Guests, contractors, candidates join by link and are protected by the same mode. Nothing needs explaining to them.

03

Healthcare

SOC 2 with HITRUST and a BAA under HIPAA as the basis for consultations and case conferences in Zoom.

04

Tenders and regulators

Specific standards and reports go into the customer's questionnaire, not "there is encryption".

05

When ordinary mode is not enough

Conversations where the keys must belong only to the participants move to end-to-end mode, with an understanding of what switches off.

06

Deployment with RightConf

We answer security questionnaires together with the customer, hand over Zoom's documents, and help decide where end-to-end mode is needed. Then support in Russian.

Where it is used

Typical scenarios

The baseline

The starting point for any conversation about protecting communications.

An answer for the auditor

Formal confirmation that the channel and media are encrypted.

Foundation

End-to-end encryption and your own keys are built on it.

What you need to get started

Requirements
  • Nothing: it works by default for every user

Try Zoom today

We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.

Please note: we work with legal entities only.

Leave a request

Our specialists will find the right solution for your needs.

We reply within one business day By sending this form you agree that we may contact you at the phone number and email you provided. See our privacy policy for how we handle your data.
Made on
Tilda