Products · Security & access control
Security & Access Control

End-to-end / Client-side Encryption

In normal mode Zoom encrypts the meeting with keys from its own servers. In E2EE mode the keys are born on participants' devices, and nobody in the middle can decrypt the stream, Zoom included. The price: some features are switched off.

What it is

Every Zoom meeting is encrypted by default: audio, video and screen sharing travel under 256-bit AES-GCM. The difference is where the keys live. In normal mode they are generated and kept by Zoom servers, so the cloud can decrypt the stream to record the meeting, transcribe it or summarise it. In end-to-end mode the keys are generated with public key cryptography on participants' devices. The data passes through Zoom servers undecipherable: Zoom has no key.

The mode can be checked by eye. In the meeting window there is a green shield with a padlock, and the host can read out a security code that participants compare with their own. If it matches, there is nobody in the middle.

This is paid for in features. An E2EE meeting has no cloud recording, no live transcription, no Zoom AI features, no polls and surveys, no chat before and after the meeting, no streaming, no Zoom Apps, no notes and no whiteboard. Joining is possible only from the app on a computer or phone or from Zoom Rooms: not by telephone and not from SIP and H.323 devices. The limit is 1,000 participants. The administrator enables it at account, group or individual user level.

Limits of the mode
  • Keys only on participants' devices
  • A green shield and a security code to compare
  • Up to 1,000 participants
  • App and Zoom Rooms only, no phone or SIP
  • No cloud recording, transcription or Zoom AI

Encryption you do not have to take on trust

Ordinary encryption protects against whoever listens on the wire. End-to-end protects against whoever holds the server too.

The key never leaves the device

Meeting keys are generated by participants. The Zoom server relays the stream without being able to open it, and this can be checked with the security code.

Post-quantum protection

From app version 6.0.10 and 6.1.0 in Zoom Rooms, end-to-end encryption uses post-quantum algorithms. Recording intercepted traffic for later will not help.

The honest price of the mode

Recording, transcription, AI, polls, dial-in are off. For negotiations where that is acceptable the mode is worth it. For a webinar with a thousand attendees it is not.

Capabilities

What end-to-end encryption gives you

How it works, what you see, what is switched off

Participants' keys

Public key cryptography, keys born on the devices. Encrypted data passing through Zoom servers is undecipherable for Zoom.

The green shield

A green shield with a padlock in the meeting window. The difference from ordinary encryption is visible to every participant without any settings.

The security code

The host reads out the code, participants compare it with their own screen. A mismatch means someone is in the middle.

Post-quantum algorithms

The app from version 6.0.10, Zoom Rooms from 6.1.0. Protection against the "record now, decrypt later" scenario.

Up to 1,000 participants

The limit of the mode. Larger audiences stay on ordinary encryption.

Who can join

The Zoom app on a computer and phone, Zoom Rooms. Dial-in by telephone and SIP/H.323 devices do not work in an E2EE meeting.

What is switched off

Cloud recording, live transcription, Zoom AI features, polls and surveys, chat before and after the meeting, streaming, Zoom Apps, Zoom Notes, Zoom Whiteboard.

Enabled by level

The administrator enables the mode for the account, a group or a user. The host chooses it for a specific meeting.

Phone too

Zoom Phone calls have their own end-to-end encryption, enabled separately.

Requirements and availability

No separate licence. Current app versions for all participants and the setting enabled. Ordinary 256-bit encryption stays on for every other meeting.

Scenes

Where it works

Wherever the conversation matters more than the recording

01

The board of directors

Discussing a deal with no recording and no transcript, by the rules. The security code is compared at the start.

02

Lawyers and clients

Legal privilege. The keys are with the parties, the platform has none, and that is provable.

03

Healthcare

A case conference on a patient where cloud recording is forbidden by the rules. E2EE mode closes the question with technology, not a memo.

04

Security and investigations

An internal investigation that even the cloud must not know about. Only the app, only the participants.

05

Merger negotiations

A narrow circle, up to a thousand participants with room to spare, no AI summaries. A green shield for everyone.

06

Deployment with RightConf

We work out which groups need the mode and which it gets in the way of, enable it by level, check app and Zoom Rooms versions, and teach hosts to compare the code. Then support in Russian.

How it worked for others

An example deployment

An Israeli insurance company

Health insurance

They needed stronger data protection in a difficult geopolitical environment.

  • End-to-end encryption enabled: keys are known only to participants' devices
  • Even Zoom's servers have no access to meeting content
  • Customer Managed Key added extra protection for data stored in the cloud

What to keep in mind

Limitations of the mode
  • Cloud meeting recording is unavailable
  • Features that need access to content do not work
  • Joining by regular phone is limited
  • All participants must use a client that supports the mode

Try Zoom today

We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.

Please note: we work with legal entities only.

Leave a request

Our specialists will find the right solution for your needs.

We reply within one business day By sending this form you agree that we may contact you at the phone number and email you provided. See our privacy policy for how we handle your data.
Made on
Tilda