Video Conferencing
Webex
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Cisco Systems, Inc. · www.webex.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Webex reaches this bench on a nearly empty record: the evidence registry holds a single Cisco privacy policy, captured as a path guess, and no product page at all. Its strongest score is the meeting itself at 0–1, where two judges granted a point because the category label 'Video Conferencing' shows meetings exist, while the other four scored 0 because a call product whose evidence never claims it makes calls; that is the only split, and flagged splits found none above threshold. Every other criterion sits at 0: no documented encryption, key handling or admission control; no evidence of browser joining, dial-in, captions or an accessibility statement; silent recording rights, notification, storage and retention; no SSO, calendar, API or self-hosted option. Sovereignty 0 of 10 — Cisco Systems, Inc. of San Jose, California, with legal entity, ownership, data residency and subprocessors all marked unknown. Pricing is likewise unevidenced, though excluded from weighted verdicts by bench note. This verdict measures the capture: the bench scores what is documented, and the evidence documents almost nothing.
Speaks for it
- Stated CCPA commitment not to sell the Personal Data of California consumers
- Stated commitment not to discriminate against individuals exercising their privacy rights
- Category confirmed as Video Conferencing, the sole basis for the bench's only nonzero score (the meeting itself, 0–1)
- No disagreements above threshold were computed, so the near-zero scoring pattern is not contested
Held against it
- Evidence registry is a single privacy-policy page captured as a path guess, with no product page on capacity, screen sharing, breakout rooms, moderation or degraded-connection behaviour
- Encryption & meeting access scored 0: no documented TLS, at-rest or end-to-end encryption, key handling, lobby, passcode or admission control
- Reach & accessibility scored 0: no evidence of browser joining, dial-in, guest access, captions, keyboard operation or an accessibility statement
- Recordings, retention & admin control and integrations each scored 0: who may record, notification, storage region and retention are silent, and no calendar, SSO, API or self-hosted option appears
- sovereignty 0 of 10: contracting entity Cisco Systems, Inc. of San Jose, California, with legal-entity jurisdiction, ownership, data residency and subprocessor exposure all marked unknown
Best for
- You need a video conferencing product from Cisco Systems, Inc. and the category label alone covers your requirement — it is the entire basis for the bench's lone point (the meeting itself, 0–1)
- You are a California consumer weighing CCPA commitments — the evidence's only confirmed affirmative facts are no sale of personal data and no discrimination for exercising privacy rights
- You are preparing vendor discussions and want a documented inventory of what the public capture fails to evidence (capacity, encryption, recording policy, SSO, residency) to demand in writing
Avoid if
- You deploy video conferencing behind SSO — ask the vendor: the public pages we read do not show it
- Your organization requires an EU contracting entity or confirmed data residency — sovereignty 0 of 10, with the vendor in San Jose, California and residency, ownership and subprocessor exposure all marked unknown
- You answer to a works council or DPO on recordings — ask the vendor: the public pages we read do not show it
- You need participants to join without accounts, installs or strong bandwidth — ask the vendor: the public pages we read do not show it
The scores
The meeting itself
Show reasoningHide reasoning
How this is scored
Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.
0 — Small meetings only, no screen sharing worth the name, no moderation controls, and the call degrades without telling anyone.
3 — Standard meetings with screen sharing and mute-all, but low participant limits, no breakout rooms and no bandwidth adaptation stated.
5 — Meetings at the scale most teams need with screen sharing, breakout rooms, host moderation, and documented behaviour on constrained connections.
8 — Large meetings and webinars with published capacity limits, per-participant moderation and waiting rooms, layout control, simulcast or adaptive bitrate stated, and reliable behaviour on mobile networks.
10 — Scale and control are engineering claims the vendor stands behind: capacity published per plan and per region, selective forwarding with adaptive quality documented, live streaming, hardware-room support, and diagnostics an admin can read after a bad call.
The IT Administrator
The category line says 'video conferencing' and that is the entire capability record — no participant limit, no screen sharing, no moderation, no bandwidth behaviour, nothing on degradation or diagnostics. I cannot put a board meeting on a product whose sheet won't even state capacity, so this sits just above the floor. 1
The Security Officer
The evidence contains nothing on capacity, quality under load, screen sharing, breakout rooms, moderation or degraded connections — the sole captured document is a privacy policy, not a product document. Absence is the finding, and the anchor for it is zero. 1
The Works Council Advocate
The only captured page is a privacy policy; there is not a single fact about participant capacity, moderation, screen sharing, or behaviour on a constrained connection. Nothing above the bottom anchor is evidenced, so I cannot credit that the call even works at team scale. 1
The Educator
The evidence contains nothing at all about capacity, screen sharing, breakout rooms, moderation, or behaviour on a weak connection — the things my class lives or dies by. Anchor zero for total silence: no capability of the call itself is evidenced, so I cannot credit a single one. 1
The Accessibility Advocate
The only capture is a privacy policy; no product page on capacity, screen sharing, breakout rooms, moderation or bad-connection behaviour was captured at all. The evidence's single capability-bearing fact is the category label 'Video Conferencing' — meetings exist — and that is the entire basis for the meeting working, so a point for existing and nothing more. 1
The Skeptic
The registry holds a single privacy-policy page and says nothing about meetings: no participant capacity, no screen sharing, no breakout rooms, no moderation, nothing on behaviour when the connection degrades. I cannot score a call product whose evidence never claims it makes calls — that is the 0 anchor. 1
Encryption & meeting access
Show reasoningHide reasoning
How this is scored
What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".
0 — Transport encryption only, undocumented; meetings joinable by anyone with a link and no lobby.
3 — TLS in transit and encryption at rest, with the vendor holding all keys; access control is a passcode.
5 — The above plus a lobby or waiting room, host-controlled admission, per-meeting passcodes, and a clear statement that the vendor can technically access media.
8 — Optional end-to-end encryption for meetings with the trade-offs named (which features stop working), documented key handling, SSO-gated joining, and per-meeting access policies.
10 — End-to-end encryption available without surrendering the product — its cryptography documented or open source, key management explained, identity verification for participants, and the vendor stating plainly what it can and cannot see.
The IT Administrator
The only confirmed facts are that Cisco does not sell California consumers' personal data and does not discriminate on privacy rights — nothing on TLS, encryption at rest, E2EE, lobbies, passcodes or key handling. Encryption and access control are entirely undocumented, which is the bottom anchor. 1
The Security Officer
Not one word on what is encrypted, against whom, who holds keys, or what stops anyone with a link from walking in. I read 'encrypted' as a question; here I don't even get the word, so there is no documented mechanism to credit. 1
The Works Council Advocate
No documented mechanism at all — not even a TLS claim, let alone key handling or lobby and admission control. The criterion is judged on documented mechanism, and this sheet documents none. 1
The Educator
No documented mechanism for encryption, key handling, waiting rooms, or admission control appears anywhere; the only captured page is a privacy-policy path guess saying Cisco does not sell Californians' data. Undocumented is undocumented — the lowest anchor applies. 1
The Accessibility Advocate
Nothing documented on TLS, at-rest encryption, end-to-end encryption, lobbies or host admission — the sole registry entry is a CCPA fragment about not selling California consumers' data, which is a privacy footnote, not an encryption or access mechanism. 'Undocumented' is the anchor's own word for this floor. 1
The Skeptic
The word 'encrypted' does not appear once in the captured evidence — no TLS statement, no key handling, no lobby, no passcode, no admission control. Judged on documented mechanism, there is no mechanism documented, so the bottom anchor stands. 1
Reach & accessibility
Show reasoningHide reasoning
How this is scored
Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.
0 — A desktop client is the only way in; guests must create an account.
3 — Browser joining exists but is degraded, guests can join by link, and there is no dial-in and no accessibility statement.
5 — Full-feature browser joining without an install, guest access by link, mobile apps, and a stated accessibility posture.
8 — Telephone dial-in with numbers listed, live captions, keyboard-navigable and screen-reader-tested interface, and documented low-bandwidth behaviour.
10 — Reach is designed for: browser parity with the client, dial-in across the regions the customer operates in, live captions and translation, a published accessibility conformance report, and a usable experience on a poor mobile connection.
The IT Administrator
No browser joining, dial-in, guest access, captions, keyboard navigation or accessibility statement appears anywhere in the evidence. I have no evidence even a second way in exists, so reach is unevidenced end to end. 1
The Security Officer
No evidence of browser joining, dial-in, captions, keyboard operation or any accessibility statement. A the evidence this silent cannot show that guests, phone users or low-bandwidth participants can get in at all. 1
The Works Council Advocate
No browser joining, dial-in, guest access, captions, or accessibility statement appears anywhere in the registry. I cannot say that a colleague without an install, without an account, or on a poor connection can take part at all. 1
The Educator
Nothing confirms browser joining without an install, guests joining without an account, dial-in, captions, or low-bandwidth behaviour — precisely what decides whether everyone in my classroom gets in. Absence of every reach fact scores by the lowest anchor. 1
The Accessibility Advocate
This is my home ground and the evidence offers nothing: no browser-joining evidence, no dial-in numbers, no live captions, no keyboard or screen-reader testing, not even an accessibility statement to dismiss as marketing. A sheet with no accessibility page at all cannot evidence that a deaf colleague or a screen-reader user can so much as enter the room, let alone run the meeting. 1
The Skeptic
Nothing on browser joining, guest access, mobile apps, dial-in, captions, keyboard operation or any accessibility posture appears in the evidence. With no evidence anyone can get in any way, I score the floor. 1
Recordings, retention & admin control
Show reasoningHide reasoning
How this is scored
A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.
0 — Anyone can record, storage location unstated, no retention rule, no admin policy.
3 — Host-only recording with a notification, but storage region unstated, retention manual, and no organisation-wide policy control.
5 — Admin policy over who may record, participant notification and consent prompt, stated storage region, and manual deletion that works.
8 — Automatic retention and deletion per policy, recordings encrypted at rest with access logged, transcription handled with its own retention rule, and attendance or analytics features that can be switched off for co-determination.
10 — Built for a works agreement: every recording, transcript and analytics feature independently switchable and documented, retention executed and evidenced, an audit trail of who accessed which recording, and no participant-level behavioural scoring at all.
The IT Administrator
Storage location is explicitly 'unknown' in the sovereignty attributes, and there is no evidenced retention rule, admin policy, notification or consent mechanism. That is the zero anchor almost word for word, and recordings are personal data I would have to answer for to a works council. 1
The Security Officer
Recording rights, notification, storage region, retention and admin policy are all unstated; the only confirmed facts are CCPA statements about not selling personal data, which say nothing about what a recording is or who touches it. Storage unstated, retention unstated, policy unstated — the zero anchor. 1
The Works Council Advocate
The criterion I weigh most heavily, and the evidence is silent on every element: no rule on who may record, no notification or consent, no storage region, no retention, and no off-switch for attendance or attention analytics. The one confirmed fact — Cisco does not sell California consumers' personal data — is no substitute for a recording regime; an unevidenced recording pipeline is, from a co-determination standpoint, a surveillance risk, not a neutral unknown. 1
The Educator
Who may record, who is told, where it is stored, how long it lives, what an admin can switch off — none of it appears in the evidence. The single privacy fact about not selling data governs nothing about the room being recorded, so I score it at the no-policy anchor. 1
The Accessibility Advocate
Who may record, who is told, where recordings are stored and how long they live are all silent, and there is no admin-policy evidence of any kind. The only data-governance fact captured is that Cisco does not sell Californians' personal data, which says nothing about the room being recorded. 1
The Skeptic
The only confirmed facts are two CCPA statements; there is nothing on who may record, participant notification, storage region, retention, or admin policy. Storage location unstated and no retention rule is the 0 anchor by the letter. 1
Integrations & deployment
Show reasoningHide reasoning
How this is scored
Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.
0 — No calendar integration, no SSO, no API; cloud-only with no alternative.
3 — One calendar integration and basic SSO, no API worth building on, cloud-only.
5 — Calendar integration for the major suites, SAML or OIDC SSO, a documented API for scheduling, and room-system support.
8 — The above plus SCIM provisioning, embedding via SDK, webhooks for meeting events, and either a self-hosted option or a documented private-cloud deployment.
10 — Deployment is the customer's choice: a genuine on-premises or private-cloud option with the same features, open protocols or open source, embeddable SDKs, and identity integration that does not require the vendor's directory.
The IT Administrator
No calendar integration, no SSO, no API, no room systems and no on-premises or private-cloud option appear anywhere. I run an SSO-gated estate; a product with no evidenced identity integration cannot be deployed in it. 1
The Security Officer
No calendar integration, no SSO, no API and no deployment model appear anywhere in the captured evidence — the evidence does not even establish whether the product is cloud-only or can be self-hosted. Nothing to score above zero. 1
The Works Council Advocate
No calendar integration, no SSO, no API, and no self-hosted or private-cloud alternative is evidenced anywhere. The privacy policy that makes up the entire registry says nothing about the wider stack or about running anything on our own infrastructure. 1
The Educator
No calendar integration, SSO, API, room-system support, or self-hosted option is evidenced — cloud-only with no alternative stated is all I can conclude. The zero anchor is exactly this. 1
The Accessibility Advocate
No calendar integration, no SSO, no API, no room systems and no self-hosted or private-cloud option appears anywhere in the capture [E1 is a privacy policy only]. As evidenced, this product connects to nothing. 1
The Skeptic
No calendar integration, no SSO, no API, no room systems, and no self-hosted or private-cloud option appears anywhere in the evidence. Cloud-only with no documented alternative is the anchor-0 description. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.
0 — Non-EU vendor and contracting entity, media routed through unstated regions, subprocessors unnamed.
3 — EU data residency for storage while media relays or metadata remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting and an EU contracting entity, but parts of the chain — relays, analytics, support tooling, transcription — are non-EU without an explained safeguard.
8 — Media and metadata processed in the EU on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: media never leaves the EU, every subprocessor European, certification published, and an on-premises option that removes the question entirely.
The IT Administrator
The contracting entity is Cisco Systems of San Jose, data residency is 'unknown', subprocessors are unnamed and media routing is unstated — the exact bottom anchor, and the computed score agrees at 0/10. I weigh this category heavily, and an American vendor that cannot even confirm where media is processed is disqualifying for a European buyer. 1
The Security Officer
The contracting entity is Cisco Systems, San Jose — outside the EU — while data residency and subprocessor exposure are both marked unknown with no vendor confirmation. A US vendor, unstated media routing and unnamed subprocessors is the exact zero anchor, and I weigh this category heavily. 1
The Works Council Advocate
The pipeline 0 of 10 and I weigh this heavily: Cisco Systems of San Jose is a non-EU vendor, and legal-entity jurisdiction, ownership, data residency and subprocessors are all marked unknown. Media routed through unstated regions with unnamed subprocessors under a US contracting entity is exactly the anchor-zero picture. 1
The Educator
The vendor is Cisco Systems, Inc. of San Jose, California — a non-EU contracting entity — and the pipeline marks legal jurisdiction, ownership, data residency, and subprocessors all unknown, with the one captured page a path guess. For a buyer who weighs sovereignty heavily, this is the worst anchor matched fact for fact: US entity, unstated routing, unnamed subprocessors. 1
The Accessibility Advocate
I concur with the pipeline's 0/10: the vendor is San Jose-based Cisco per provenance, data residency is unknown, and the subprocessor list was not confirmed on any captured page, including the privacy policy. Non-EU vendor, unstated media routing, unnamed subprocessors is rubric level 0 verbatim. 1
The Skeptic
The sovereignty pipeline 0 of 10 with legal entity, ownership, data residency and subprocessors all unknown, and the provenance puts the contracting entity in San Jose, California — non-EU vendor with media routing and subprocessors unnamed is precisely the 0 anchor. The one captured document is a US-facing privacy policy; it names no EU region and not a single subprocessor. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-host headline exists, but participant caps, dial-in minutes or recording storage are unpriced or unmentioned.
5 — Per-host prices public with billing period stated and capacity limits given, but at least one commonly needed piece (webinar capacity, dial-in, storage) sits in an unpriced add-on.
8 — Every tier and add-on priced publicly with per-host maths, capacity limits, dial-in rates, storage allowances, minimum term and VAT treatment stated.
10 — Complete price computability: a calculator producing the annual invoice for a given host count, meeting size and recording volume, including overage and per-region dial-in.
The IT Administrator
Not one public price, tier, capacity limit, term or VAT statement appears in the evidence. Every invoice would be a sales conversation, which is the zero anchor by definition. 1
The Security Officer
No public price, tier, capacity limit or billing term appears anywhere in the evidence. Per the anchor, no public pricing means the invoice is a sales conversation — zero. 1
The Works Council Advocate
No tier, per-host price, capacity limit, dial-in rate or storage allowance appears in the captured material — the single entry is a legal policy page. Nobody, works council or buyer, can compute an annual invoice from this. 1
The Educator
No public prices, per-host maths, capacity limits, dial-in rates, or storage allowances appear anywhere in the evidence. A school office could not compute so much as a rough invoice, so the no-public-prices anchor applies. 1
The Accessibility Advocate
Not a single price, tier, capacity limit, dial-in rate or storage allowance was captured — the only document is a privacy policy. A buyer cannot compute an annual invoice from silence; if pricing exists publicly, this capture never found it. 1
The Skeptic
There is no per-host price, no tier, no billing period, no capacity limit, no dial-in rate, no storage allowance anywhere in the evidence. On this sheet every tier is a sales conversation, which is the definition of the bottom anchor. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in US ⚠ unverified | 0/3 pts | 1 Report an error |
|---|---|---|---|
| Ownership | Not determined ⚠ unverified | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Ownership, Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Legal entity. Derived from the Privacy Office mailing address in the privacy statement, not from a legal imprint or company register, so the incorporation jurisdiction is inferred from the USA address.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (cisco.com/c/en/us/about/legal/privacy-full.html, help.webex.com/en-us/article/iv300cb/Allow-participants-to-share-in-your-Webex-Meeting, help.webex.com/en-us/article/ntwtdhl/Set-your-Webex-Meetings-audio-and-video-preferences, help.webex.com/en-us/article/hf0owp/What-does-end-to-end-encryption-with-identity-verification-do, help.webex.com/en-us/article/vf2yaz/Webex-App-Security, help.webex.com/en-us/article/0ix72j/Webex-App-Accessibility-Support and 5 more). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 7 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Privacy policy www.cisco.com Checked 15 Sep 2026 Details →
- 2 The meeting itself — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 3 The meeting itself — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 4 Encryption & meeting access — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 5 Encryption & meeting access — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 6 Reach & accessibility — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 7 Reach & accessibility — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 8 Recordings, retention & admin control — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 9 Recordings, retention & admin control — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 10 Integrations & deployment — found from sitemap help.webex.com Checked 1 Oct 2026 Details →
- 11 Integrations & deployment — found from sitemap developer.webex.com Checked 1 Oct 2026 Details →