whats-best.ai
Search Sign in

Video Conferencing

Zoom

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Zoom Communications, Inc. · zoom.us

Compare with Microsoft Teams → Compare with Google Meet → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Zoom is a video conferencing platform from Zoom Communications, Inc. of San Jose, strongest on the meeting core and integrations, where scores cluster at 6-7: per-plan capacities are published (100 participants on Basic and Pro, 300 on Business, a paid add-on reaching 5,000, webinars at 500), breakout rooms are documented across five roles, and the developer surface runs from meeting and calendar APIs to recording webhooks and embeddable SDKs, with SSO and managed domains from the Business plan. Weakest is sovereignty at 0-1: the contract sits with the San Jose entity, the Federal Trade Commission is the named enforcer, and the pages give no information on media residency or named subprocessors. The widest spreads are in recording governance and reach and accessibility: some judges credited retention settings and bring-your-own S3 storage or browser feature parity, while others weighed missing public information on consent prompts, access logs, telephone dial-in and screen-reader testing. Encryption and access holds at 4-5, with end-to-end encryption marked unsupported in every browser listed.

Report an error

Speaks for it

  • Per-plan capacities are published — 100 participants on Basic and Pro, 300 on Business, a paid add-on reaching 5,000, and webinars at 500.
  • Breakout rooms are documented in depth, with five distinct roles, preassignment, timers and help requests.
  • A forced minimum of meeting security — a passcode, the waiting room or authenticated-only joining — is enforced even when meetings are created through the API.
  • The developer surface is broad and public — meeting and calendar APIs, recording and transcript webhooks, OpenAPI and Postman downloads, embeddable SDKs — with SSO and managed domains from the Business plan.
  • Recording levers are present: a delete-after-a-specified-number-of-days setting, bring-your-own storage in the customer's own S3 bucket, and a 30-day retrieval window after contract termination.

Report an error

Held against it

  • Sovereignty scores sit at 0-1 — a US contracting entity, Federal Trade Commission enforcement, and no public information on media residency or named subprocessors.
  • End-to-end encryption is marked unsupported in every browser in the captured support tables, with no public information on encryption at rest or key handling beyond TLS 1.2 with 256-bit AES-GCM.
  • No public information exists on telephone dial-in, guests joining without an account, keyboard and screen-reader testing, or an accessibility conformance report.
  • No public information exists on SCIM provisioning, hardware room-system support, or self-hosted or private-cloud deployment.
  • A full annual invoice is not computable from the pages — the add-on is quoted only 'From €46.50 for 500 participants per month', AI summary and cloud recording each incur a separate charge, and the captured pages give different figures for AI cost.

Report an error

Best for

  • You run browser-first meetings and need live transcription and live translation, marked supported in every browser in the support tables.
  • Your participants join from Chromebooks or shared machines — browser joining is documented with the same features as the web client.
  • Your developers build against documented APIs and you can land on the Business plan for SSO and managed domains.
  • Your recordings must live in your own S3 bucket, with deletion after a set number of days.

Report an error

Avoid if

  • You need a European contracting and processing chain — the contract is with Zoom Communications, Inc. of San Jose, the named enforcer is the Federal Trade Commission, and the only European foothold on the pages is a representative in Cork.
  • You require end-to-end encrypted meetings from the browser — the captured support tables mark it unsupported in every browser listed.
  • Your deployment must be self-hosted or in a private cloud — every captured endpoint runs on the vendor's cloud.
  • Your works agreement cannot accommodate employer-side visibility into communications — the privacy statement records that account owners can see message content unless Advanced Chat Encryption is enabled, and email and calendar content even when encrypted.

Report an error

The scores

The meeting itself

Show reasoning
How this is scored

Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.

0 — Small meetings only, no screen sharing worth the name, no moderation controls, and the call degrades without telling anyone.

3 — Standard meetings with screen sharing and mute-all, but low participant limits, no breakout rooms and no bandwidth adaptation stated.

5 — Meetings at the scale most teams need with screen sharing, breakout rooms, host moderation, and documented behaviour on constrained connections.

8 — Large meetings and webinars with published capacity limits, per-participant moderation and waiting rooms, layout control, simulcast or adaptive bitrate stated, and reliable behaviour on mobile networks.

10 — Scale and control are engineering claims the vendor stands behind: capacity published per plan and per region, selective forwarding with adaptive quality documented, live streaming, hardware-room support, and diagnostics an admin can read after a bad call.

Report an error

The IT Administrator

Capacity is published per plan — 100, 100 and 300 participants, webinars at 500, and an add-on path to 5,000 — and breakout rooms are documented down to roles, preassignment and help requests, which is what I want to see rather than promises. Waiting rooms and a mandatory minimum security option are enforced even at the API level, and live streaming is stated. What I found no public information on is adaptive quality under load, hardware room-system support, or diagnostics an admin can read after a bad call. 2 6 7 10 3

Report an error

The Security Officer

Capacity is published per plan — 100 participants on Basic and Pro, 300 on Business, a large-meeting add-on reaching 5,000 and a 500-attendee webinar — and breakout rooms are documented down to roles, timers and per-room user limits, with meetings required to carry a passcode, waiting room or authenticated-only join. What the pages do not show is behaviour under strain: no adaptive bitrate or simulcast claim, no documented mobile-network reliability, and no diagnostics an admin can read after a bad call. Quality appears only as hardware gates — 1080p send demands an eight-core machine, GPU and "quality network connections". 2 6 7 10

Report an error

The Works Council Advocate

Capacity is published per plan — 100 participants on Basic and Pro, 300 on Business, a paid add-on up to 5,000, webinars at 500 — and breakout rooms carry five roles with timers, preassignment and help requests, which is real host control. Waiting rooms, passcodes and authenticated-only joining are enforced even when meetings are created through the API. We found no public information on adaptive quality or behaviour on constrained and mobile networks, or on diagnostics an administrator could read after a bad call. 2 6 7 9 10

Report an error

The Educator

Breakout rooms are documented in real depth — five distinct roles, pre-assignment, broadcast into rooms, help requests, timed close — and capacity is published per plan, from 100 participants up to a 5,000-participant add-on, with webinars at 500 and RTMP live streaming and live transcription in the browser. What holds it back for a class where half the room is on a phone: I found no public information on adaptive quality or behaviour on a weak connection, and none on per-participant moderation, layout control, or diagnostics after a bad call. 2 6 10

Report an error

The Accessibility Advocate

Breakout rooms are documented in real depth — five distinct roles, preassignment, timers, broadcast, help requests — and capacities are published per tier, from 100 and 300 participants up to an add-on reaching 5,000, with webinars at 500. Waiting rooms, passcodes and authenticated-only joining are enforced, with a waiting room switched on automatically when nothing else is set. We found no public information on adaptive bitrate, on what the call does on a constrained connection beyond a stated requirement of quality network connections for 1080p, or on diagnostics an admin could read after a bad call. 2 6 7 9 10

Report an error

The Skeptic

Capacity is published per plan — 100 participants on Basic and Pro, 300 on Business, a paid add-on reaching 5,000, webinars at 500 — and breakout rooms are documented down to five roles, timers, preassignment and help requests, with waiting rooms, passcodes and authenticated-only joining enforced at the API level. What keeps this out of the top band: I found no public information on per-participant moderation detail, simulcast or adaptive bitrate under load, or what happens to the call on a constrained connection. 2 6 7 12

Report an error

Encryption & meeting access

Show reasoning
How this is scored

What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".

0 — Transport encryption only, undocumented; meetings joinable by anyone with a link and no lobby.

3 — TLS in transit and encryption at rest, with the vendor holding all keys; access control is a passcode.

5 — The above plus a lobby or waiting room, host-controlled admission, per-meeting passcodes, and a clear statement that the vendor can technically access media.

8 — Optional end-to-end encryption for meetings with the trade-offs named (which features stop working), documented key handling, SSO-gated joining, and per-meeting access policies.

10 — End-to-end encryption available without surrendering the product — its cryptography documented or open source, key management explained, identity verification for participants, and the vendor stating plainly what it can and cannot see.

Report an error

The IT Administrator

The documented mechanism is TLS 1.2 with 256-bit AES-GCM, per-meeting passcodes, waiting rooms and authenticated-only join, and the API overwrites requests that try to strip every security option — a forced minimum is good engineering. But the captured browser matrix marks end-to-end encryption as not supported across all browsers, and I found no public information on an end-to-end option for meetings, key handling, or a plain statement of what Zoom can see of meeting media; the privacy pages do show account owners and Zoom accessing chat and email content. 9 10 7 3

Report an error

The Security Officer

The captured pages mark end-to-end encryption unsupported on every browser for the web client, and the only mechanism documented is "TLS 1.2 and 256-bit AES-GCM Encryption" — with nothing on key handling or encryption at rest for recordings. Access control is the stronger story: at least one of a passcode, waiting room or authenticated-only join is required, the meeting API overwrites any request that tries to switch all three off, and on most account sizes that requirement is locked. But the privacy pages themselves record that account owners can read chat and even encrypted email content and that Zoom automatically scans shared files — so what the vendor can see is documented only in fragments, never as a plain statement about meeting media. 3 7 9 10

Report an error

The Works Council Advocate

Transport encryption is concrete — TLS 1.2 with 256-bit AES-GCM — and meeting access is defended by per-meeting passcode, waiting room and an authenticated-users-only setting the API will not let you remove entirely. But the captured browser support pages mark end-to-end encryption unavailable in every browser listed, and we found no public information on encryption at rest for meetings or recordings, key handling, or a plain statement of what the vendor can technically see in meeting media. Account owners can read users' message content unless advanced chat encryption is enabled — employer-side surveillance a works agreement would have to govern. 3 7 9 10

Report an error

The Educator

Transport security is concrete — TLS 1.2 with 256-bit AES-GCM — and admission is thought through: passcode, waiting room and authenticated-only joining, with the waiting room auto-enabled when no other security option is set and the requirement locked for smaller account types. The captured browser pages show end-to-end encryption as not supported in any listed browser, and I found no public information on encryption at rest, key handling, or a plain statement of what the vendor can see in meeting media. 3 7 9 10

Report an error

The Accessibility Advocate

Transport security is documented as TLS 1.2 with 256-bit AES-GCM, and meeting entry is gated by a passcode, the waiting room, or authenticated-only joining, with the waiting room enabled automatically when no security option is provided. The privacy statement is candid that account owners can read message content unless Advanced Chat Encryption is on, which is at least a plain statement about vendor-side visibility. We found no public information on end-to-end encryption for meetings beyond browser support tables that mark it with a cross in every browser listed, and no documentation of key handling. 3 7 9 10

Report an error

The Skeptic

The sentence I always look for — which meetings, on which plan, get end-to-end encryption, with what turned off — does not exist in the captured pages; the browser support tables mark end-to-end encryption with a cross in every browser listed, and the only mechanism stated is TLS 1.2 with 256-bit AES-GCM. Access control is genuinely strong: per-meeting passcode, waiting room, authenticated-only joining, and the API overwrites any request that tries to disable all three. But the privacy statement only admits operator-side visibility for chat and email content, and I found no public information on at-rest encryption for meeting media or on key handling. 3 7 9 10

Report an error

Reach & accessibility

Show reasoning
How this is scored

Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.

0 — A desktop client is the only way in; guests must create an account.

3 — Browser joining exists but is degraded, guests can join by link, and there is no dial-in and no accessibility statement.

5 — Full-feature browser joining without an install, guest access by link, mobile apps, and a stated accessibility posture.

8 — Telephone dial-in with numbers listed, live captions, keyboard-navigable and screen-reader-tested interface, and documented low-bandwidth behaviour.

10 — Reach is designed for: browser parity with the client, dial-in across the regions the customer operates in, live captions and translation, a published accessibility conformance report, and a usable experience on a poor mobile connection.

Report an error

The IT Administrator

Browser joining is the strongest thing here: the web client feature set is the baseline, live transcription and translation are listed across all captured browsers, and 720p send on mobile browsers is specified by OS version down to iOS 16.4 and Android Chrome 112. However, component view is not supported on mobile or tablet browsers at all, and I found no public information on telephone dial-in, keyboard or screen-reader testing, or documented behaviour on poor connections. 9 10

Report an error

The Security Officer

Browser joining is solid: the web client claims feature parity, WebRTC video is supported across Chrome, Edge, Safari and iOS WebKit, live transcription and live translation are marked supported on every browser, and mobile send is documented down to OS versions. We found no public information on telephone dial-in, on joining as a guest without an account, or on any accessibility conformance statement, keyboard operation or screen-reader testing. Constrained connections appear only as requirements for reaching higher resolutions, not as a documented degraded mode. 9 10

Report an error

The Works Council Advocate

Browser joining is documented across Chrome, Edge and Safari families via WebRTC, live transcription and translation are marked available in every supported browser, and Chromebooks are stated to match desktop-browser features. Android Firefox is documented as unsupported and the component view is unavailable on mobile browsers. We found no public information on telephone dial-in, a stated accessibility posture or conformance report, keyboard and screen-reader testing, or behaviour at low bandwidth. 9 10

Report an error

The Educator

The no-install story is the strong half: browser joining carries the same features as the web client, Chromebooks and Windows tablets behave like desktops, mobile browsers follow the supported OS versions, and live transcription and translation are ticked for every browser — nobody misses a caption. For the people on a phone in a dead spot, though, I found no public information on dial-in, on behaviour at low bandwidth, on guests joining without an account, or on any accessibility statement or screen-reader testing. 9 10

Report an error

The Accessibility Advocate

Live transcription and live translation are marked supported in every browser in the support tables, so a deaf colleague can genuinely follow the meeting, and browser joining is claimed at full feature parity with the web client, including Chromebooks. Remote control is marked with a cross in all browsers and component view is desktop-only, which narrows who can fully run a session from the browser. We found no public information on telephone dial-in, keyboard operation, screen-reader testing, or any published accessibility conformance report — and an accessibility posture without a report is marketing, not accessibility. 9 10

Report an error

The Skeptic

Browser joining is documented as feature-equivalent to the web client across Chrome, Edge and Safari with a stated two-version support window, and live transcription, live translation and RTMP streaming are marked available on every browser, mobile browsers included from iOS 16.4 and Android Chrome 112. I found no public information on telephone dial-in, on guests joining without an account, on keyboard and screen-reader testing, or on an accessibility conformance report — half of what this criterion asks for is simply absent from the captured pages. 9 10

Report an error

Recordings, retention & admin control

Show reasoning
How this is scored

A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.

0 — Anyone can record, storage location unstated, no retention rule, no admin policy.

3 — Host-only recording with a notification, but storage region unstated, retention manual, and no organisation-wide policy control.

5 — Admin policy over who may record, participant notification and consent prompt, stated storage region, and manual deletion that works.

8 — Automatic retention and deletion per policy, recordings encrypted at rest with access logged, transcription handled with its own retention rule, and attendance or analytics features that can be switched off for co-determination.

10 — Built for a works agreement: every recording, transcript and analytics feature independently switchable and documented, retention executed and evidenced, an audit trail of who accessed which recording, and no participant-level behavioural scoring at all.

Report an error

The IT Administrator

There is a recording notification in the terms, a delete-after-a-specified-number-of-days setting, host start/pause/stop control, and a bring-your-own-storage option that puts the files in the customer's own S3 bucket — that last one a works council can live with. I found no public information on the storage region for Zoom-held recordings, a consent prompt, an audit trail of recording access, or independent switches for transcription and analytics. 4 11 12

Report an error

The Security Officer

Recording is host-controlled in the SDK with a contractual notification when recording is enabled, participants can request recording or be permitted to start it, a delete-after-a-set-number-of-days policy exists, and a bring-your-own-storage mode keeps the files in the customer's own S3 bucket with Zoom holding only metadata. For the works council the gaps are real: we found no public information on the storage region of Zoom-held recordings, on encryption at rest or access logs for recordings, on a separate retention rule for transcripts and AI summaries, or on switching off attendance analytics. Termination is handled — thirty days to retrieve content before deletion — but that is the end of the relationship, not the life of a recording. 4 11 12

Report an error

The Works Council Advocate

Recording comes with a notification, deletion after a configured number of days, and Bring Your Own Storage that keeps the files in the customer's own bucket while the vendor retains only metadata — groundwork a works agreement could use. The rest of what a works council needs goes unanswered: we found no public information on a participant consent prompt, the storage region of cloud recordings, an audit trail of who accessed a recording, an organisation-wide policy over who may record, or any attention tracking and attendance analytics and whether they can be switched off. Transcripts and AI summaries generate automatically alongside recordings, each incurring a separate charge, with no separate retention rule evidenced. 4 11 12

Report an error

The Educator

Recording is host-controlled, a notification is promised when it starts, sessions can be set to delete automatically after a specified number of days, and Bring Your Own Storage can keep the files in your own bucket instead of the vendor's — the first two things a works council asks about are at least present. We found no public information on where vendor-stored recordings are kept, on encryption at rest for them, on who accessed them, or on a separate retention rule for transcripts. 4 11 12

Report an error

The Accessibility Advocate

Participants are notified when recording is enabled, hosts can start, pause and stop, retention can be set to delete cloud recordings after a stated number of days, and Bring Your Own Storage puts the files in the customer's own S3 bucket with Zoom holding only metadata — a real answer to where a recording lives. Transcripts and AI summaries arrive as their own files with their own endpoints. We found no public information on the storage region for Zoom-held cloud recordings, on encryption of recordings at rest, on access logging, or on organisation-wide switches for attendance and analytics features. 4 11 12

Report an error

The Skeptic

Recording comes with a stated visual-or-otherwise notification, a delete-after-a-specified-number-of-days retention setting, and a bring-your-own-storage option that puts the files in the customer's own S3 bucket — the one real governance lever here, alongside a 30-day retrieval window after contract termination before deletion. We found no public information on the default storage region, on access logging or an audit trail for recordings, or on admin switches to disable transcription and analytics features for a works council; individual recording at least requires the host to enable it and the user to elect it. 2 4 11 12

Report an error

Integrations & deployment

Show reasoning
How this is scored

Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.

0 — No calendar integration, no SSO, no API; cloud-only with no alternative.

3 — One calendar integration and basic SSO, no API worth building on, cloud-only.

5 — Calendar integration for the major suites, SAML or OIDC SSO, a documented API for scheduling, and room-system support.

8 — The above plus SCIM provisioning, embedding via SDK, webhooks for meeting events, and either a self-hosted option or a documented private-cloud deployment.

10 — Deployment is the customer's choice: a genuine on-premises or private-cloud option with the same features, open protocols or open source, embeddable SDKs, and identity integration that does not require the vendor's directory.

Report an error

The IT Administrator

The developer surface is broad: calendar APIs with ACL management, meeting create and update APIs, embeddable web SDKs, recording and transcript webhooks, OpenAPI downloads, client libraries, plus SSO and managed domains from the Business tier. I found no public information on SCIM provisioning, hardware room-system support, or any self-hosted or private-cloud deployment — everything captured runs in Zoom's cloud. 2 13 14 9

Report an error

The Security Officer

The developer surface is broad: meeting create-and-update APIs, a calendar API complete with access-control lists, webhooks for recording, transcript and summary events, OAuth with automatic token refresh, a downloadable OpenAPI spec with client libraries, and the Business tier carries SSO with managed domains. We found no public information on SCIM provisioning, room-system support, or any self-hosted or private-cloud deployment — every captured endpoint sits on the vendor's cloud — and the SSO mechanism is not named as SAML or OIDC. Embedding via SDK is well documented, but third-party app data rides under the app developers' own privacy policies rather than the meeting vendor's. 2 3 7 13 14

Report an error

The Works Council Advocate

The build stack is real — calendar APIs with access control, OAuth starter apps, OpenAPI downloads, recording webhooks and embeddable Meeting and Video SDKs — and SSO with managed domains is listed at the Business tier. We found no public information on SCIM provisioning, room-system support, or any self-hosted or private-cloud option, so deployment choice does not appear on the public pages. 2 11 13 14

Report an error

The Educator

The developer surface is real and well documented: meeting scheduling APIs, calendar APIs with an OpenAPI download and Postman collection, recording and transcript webhooks, and embeddable SDKs for web and mobile, with SSO and managed domains arriving on the Business plan. We found no public information on SCIM provisioning, hardware room-system support, or any self-hosted or private-cloud deployment, and the recording webhooks are noted as limited to universal credit accounts. 2 7 11 14

Report an error

The Accessibility Advocate

The API surface is serious: documented meeting create and update endpoints, calendar APIs with access-control roles, OpenAPI and Postman downloads, recording and transcript webhooks, OAuth sample tooling, and embeddable web SDKs, with SSO and managed domains arriving at the Business tier. We found no public information on SCIM provisioning, on room-system support, or on any self-hosted or private-cloud deployment, so the vendor's cloud is the only evidenced mode of running it. 2 7 13 14

Report an error

The Skeptic

The developer surface is deep and public: meeting create/update APIs, cloud-recording REST APIs with webhooks for completed recordings and transcripts, a documented Calendar API shipped with OpenAPI and Postman artifacts, embeddable web and mobile SDKs, and AI Services APIs. SSO with managed domains arrives at the Business tier. I found no public information on SCIM provisioning, room-system support, or any self-hosted or private-cloud deployment option, which caps this mid-band for a buyer who wants the stack on their own terms. 2 11 12 13 14

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.

0 — Non-EU vendor and contracting entity, media routed through unstated regions, subprocessors unnamed.

3 — EU data residency for storage while media relays or metadata remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting and an EU contracting entity, but parts of the chain — relays, analytics, support tooling, transcription — are non-EU without an explained safeguard.

8 — Media and metadata processed in the EU on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: media never leaves the EU, every subprocessor European, certification published, and an on-premises option that removes the question entirely.

Report an error

The IT Administrator

The contracting entity is Zoom Communications, Inc. of San Jose with the Data Protection Officer at the same address, enforcement sits with the Federal Trade Commission, and transfers to Europe rely on standard contractual clauses and the Data Privacy Framework — a US arrangement end to end. The captured pages leave media and metadata residency unstated and name no subprocessors beyond a generic mention of third-party providers, so we found no public information a European buyer could verify against. 4 3

Report an error

The Security Officer

The contracting entity is Zoom Communications, Inc., a US company with the Federal Trade Commission named as enforcer of its data-framework commitments; the EU-facing facts are a representative in Cork, standard contractual clauses and US Data Privacy Framework certifications — mechanisms for sending data out, not for keeping it in. We found no public information on where media and metadata are processed, and subprocessors appear only as unnamed third-party service providers for infrastructure and payment processing. Weighted heavily, as this buyer does, that is a US chain end to end with the geography of the traffic itself unpublished. 1 3 4

Report an error

The Works Council Advocate

The contracting entity is Zoom Communications, Inc. of San Jose, California, and the only European foothold in the captured facts is an EU representative in Cork; we found no public information on data residency or on where meeting media and metadata are processed. Subprocessors appear only as unnamed third-party service providers for payments and infrastructure. Standard contractual clauses, Data Privacy Framework certifications and FTC enforcement are published — legal mechanisms for a non-EU chain, not European processing. 3 4

Report an error

The Educator

The contracting entity is Zoom Communications, Inc. of San Jose, California, with the Federal Trade Commission named as the enforcer of its Data Privacy Framework commitments; nothing in the captured pages confirms EU residency for media or storage, and we found no public information naming the third-party service providers that carry the traffic. Standard contractual clauses, DPF certifications and an EU representative in Cork paper the transfers, but an EU representative is not EU hosting, and for a buyer who weighs this heavily that decides it. 3 4

Report an error

The Accessibility Advocate

The contracting entity is Zoom Communications, Inc. of San Jose, and the captured pages give no information on where media or metadata are processed; the only subprocessor statement is a generic reference to third-party service providers. Cross-border transfers are covered by the Data Privacy Framework and standard contractual clauses, which legitimise exports rather than establish EU processing. Weighted heavily as this buyer weighs it, a non-EU entity with unstated media routing and unnamed subprocessors sits at the bottom of the scale. 3 4

Report an error

The Skeptic

The contract is with Zoom Communications, Inc. of San Jose, the enforcer named is the Federal Trade Commission, and the DPO address is in California — a US contracting entity end to end. We found no public information on media routing regions, data residency, or any named subprocessor list beyond a generic mention of third-party service providers for payments and infrastructure; the Data Privacy Framework certification, standard contractual clauses and an Irish EU representative are mitigations, not EU processing. 3 4

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-host headline exists, but participant caps, dial-in minutes or recording storage are unpriced or unmentioned.

5 — Per-host prices public with billing period stated and capacity limits given, but at least one commonly needed piece (webinar capacity, dial-in, storage) sits in an unpriced add-on.

8 — Every tier and add-on priced publicly with per-host maths, capacity limits, dial-in rates, storage allowances, minimum term and VAT treatment stated.

10 — Complete price computability: a calculator producing the annual invoice for a given host count, meeting size and recording volume, including overage and per-region dial-in.

Report an error

The IT Administrator

Per-host prices are public with billing period and VAT treatment stated — €13.33 and €17.49 per user per month billed annually excluding VAT, a free tier with its 40-minute and 100-participant limits, 10 GB cloud storage per licence, and a large-meeting add-on from €46.50 for 500 participants. But that add-on is priced only from a floor, I found no public information on dial-in rates or the subscription term length, and the captured pages give different signals on AI cost — a no-extra-cost claim on the homepage beside per-feature charges in the developer documentation. 1 2 4 11

Report an error

The Security Officer

Headline per-host prices are public with billing period and VAT treatment stated — Pro at €13.33 /user per month billed annually excluding VAT, Business at €17.49 — alongside participant caps, 10 GB cloud storage per license, tier license counts, webinar capacity of 500, and terms that payments are non-refundable. Computing the real invoice still fails: we found no public information on dial-in rates, the large-meeting add-on is priced only "From €46.50 for 500 participants per month" with no figures up to 5,000, and cloud recording and the AI summary are each "a separate charge" whose rates sit behind a developer credit plan. 2 4 11 12

Report an error

The Works Council Advocate

Per-host prices are public with billing period and VAT treatment stated — €13.33 per user per month on Pro and €17.49 on Business, both billed annually and excluding VAT — alongside participant caps, licence-count ranges and per-user cloud storage. A buyer still cannot compute the invoice: the large-meeting add-on is quoted only from €46.50 for 500 participants per month, and we found no public information on dial-in rates, webinar add-on pricing or the cloud recording storage plan. The captured pages also give different figures for AI — the homepage claims AI at no extra cost while the developer documentation states cloud recording and AI summary each incur a separate charge. 1 2 4 11 12

Report an error

The Educator

Per-host prices are public with billing period and VAT treatment stated — "€13.33 /user per month · billed annually‡· excludes VAT" on Pro, €17.49 on Business — alongside capacity limits and 10 GB cloud storage per user, and a large-meeting add-on "From €46.50 for 500 participants per month". I still could not compute a full annual invoice: dial-in rates, the cloud-recording storage plan and the separate charges for AI summaries and extra recording file options are not quantified on the captured pages. 2 4 11

Report an error

The Accessibility Advocate

Headline prices are public with billing period and VAT treatment stated — "€13.33 /user per month" and "€17.49 /user per month", both "billed annually" and excluding VAT — alongside capacity limits and 10 GB cloud storage per user. But the large-meeting add-on is quoted only "From €46.50 for 500 participants per month", cloud recording and AI summary each incur a separate charge under a credit-plan subscription whose pricing sits on a separate page, and we found no public information on dial-in rates or storage overage. The annual invoice for a real host count is not computable from these pages alone. 2 4 12

Report an error

The Skeptic

Per-host prices are public with billing period and VAT exclusion stated — €13.33 /user per month billed annually for Pro and €17.49 for Business, excluding VAT — with capacity limits of 100 and 300 participants, 10 GB cloud storage per user, and a large-meeting add-on from €46.50 for 500 participants per month. But I found no public information on telephone dial-in or its rates, I found no public price for the Enterprise tier, the AI summary is described only as 'a separate charge' with each feature billed separately, and no minimum term length is stated — so the annual invoice for a given host count is not computable from these pages alone. 2 4 12

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage zoom.us Checked 15 Sep 2026 Details →
  2. 2 Pricing zoom.us Checked 15 Sep 2026 Details →
  3. 3 Privacy policy explore.zoom.us Checked 15 Sep 2026 Details →
  4. 4 Terms of service www.zoom.com Checked 30 Sep 2026 Details →
  5. 5 The meeting itself — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  6. 6 The meeting itself — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  7. 7 Encryption & meeting access — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  8. 8 Encryption & meeting access — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  9. 9 Reach & accessibility — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  10. 10 Reach & accessibility — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  11. 11 Recordings, retention & admin control — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  12. 12 Recordings, retention & admin control — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  13. 13 Integrations & deployment — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  14. 14 Integrations & deployment — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →