In normal mode Zoom encrypts the meeting with keys from its own servers. In E2EE mode the keys are born on participants' devices, and nobody in the middle can decrypt the stream, Zoom included. The price: some features are switched off.
Every Zoom meeting is encrypted by default: audio, video and screen sharing travel under 256-bit AES-GCM. The difference is where the keys live. In normal mode they are generated and kept by Zoom servers, so the cloud can decrypt the stream to record the meeting, transcribe it or summarise it. In end-to-end mode the keys are generated with public key cryptography on participants' devices. The data passes through Zoom servers undecipherable: Zoom has no key.
The mode can be checked by eye. In the meeting window there is a green shield with a padlock, and the host can read out a security code that participants compare with their own. If it matches, there is nobody in the middle.
This is paid for in features. An E2EE meeting has no cloud recording, no live transcription, no Zoom AI features, no polls and surveys, no chat before and after the meeting, no streaming, no Zoom Apps, no notes and no whiteboard. Joining is possible only from the app on a computer or phone or from Zoom Rooms: not by telephone and not from SIP and H.323 devices. The limit is 1,000 participants. The administrator enables it at account, group or individual user level.
Ordinary encryption protects against whoever listens on the wire. End-to-end protects against whoever holds the server too.
Meeting keys are generated by participants. The Zoom server relays the stream without being able to open it, and this can be checked with the security code.
From app version 6.0.10 and 6.1.0 in Zoom Rooms, end-to-end encryption uses post-quantum algorithms. Recording intercepted traffic for later will not help.
Recording, transcription, AI, polls, dial-in are off. For negotiations where that is acceptable the mode is worth it. For a webinar with a thousand attendees it is not.
How it works, what you see, what is switched off
Public key cryptography, keys born on the devices. Encrypted data passing through Zoom servers is undecipherable for Zoom.
A green shield with a padlock in the meeting window. The difference from ordinary encryption is visible to every participant without any settings.
The host reads out the code, participants compare it with their own screen. A mismatch means someone is in the middle.
The app from version 6.0.10, Zoom Rooms from 6.1.0. Protection against the "record now, decrypt later" scenario.
The limit of the mode. Larger audiences stay on ordinary encryption.
The Zoom app on a computer and phone, Zoom Rooms. Dial-in by telephone and SIP/H.323 devices do not work in an E2EE meeting.
Cloud recording, live transcription, Zoom AI features, polls and surveys, chat before and after the meeting, streaming, Zoom Apps, Zoom Notes, Zoom Whiteboard.
The administrator enables the mode for the account, a group or a user. The host chooses it for a specific meeting.
Zoom Phone calls have their own end-to-end encryption, enabled separately.
No separate licence. Current app versions for all participants and the setting enabled. Ordinary 256-bit encryption stays on for every other meeting.
Wherever the conversation matters more than the recording
Discussing a deal with no recording and no transcript, by the rules. The security code is compared at the start.
Legal privilege. The keys are with the parties, the platform has none, and that is provable.
A case conference on a patient where cloud recording is forbidden by the rules. E2EE mode closes the question with technology, not a memo.
An internal investigation that even the cloud must not know about. Only the app, only the participants.
A narrow circle, up to a thousand participants with room to spare, no AI summaries. A green shield for everyone.
We work out which groups need the mode and which it gets in the way of, enable it by level, check app and Zoom Rooms versions, and teach hosts to compare the code. Then support in Russian.
They needed stronger data protection in a difficult geopolitical environment.
We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.
Please note: we work with legal entities only.