whats-best.ai
Search Sign in

Video Conferencing

Zoom

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Zoom Communications, Inc. · zoom.us

Compare with Microsoft Teams → Compare with Google Meet → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Skeptic

Weighted verdict

Has read many pages claiming end-to-end encryption and wants the sentence that says which meetings, on which plan, with what turned off. Also reads for the participant cap, the dial-in minutes, and where recording storage stops being free.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Skeptic

The meeting itself

How this is scored

Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.

0 — Small meetings only, no screen sharing worth the name, no moderation controls, and the call degrades without telling anyone.

3 — Standard meetings with screen sharing and mute-all, but low participant limits, no breakout rooms and no bandwidth adaptation stated.

5 — Meetings at the scale most teams need with screen sharing, breakout rooms, host moderation, and documented behaviour on constrained connections.

8 — Large meetings and webinars with published capacity limits, per-participant moderation and waiting rooms, layout control, simulcast or adaptive bitrate stated, and reliable behaviour on mobile networks.

10 — Scale and control are engineering claims the vendor stands behind: capacity published per plan and per region, selective forwarding with adaptive quality documented, live streaming, hardware-room support, and diagnostics an admin can read after a bad call.

Report an error

The Skeptic

Capacity is published per plan — 100 participants on Basic and Pro, 300 on Business, a paid add-on reaching 5,000, webinars at 500 — and breakout rooms are documented down to five roles, timers, preassignment and help requests, with waiting rooms, passcodes and authenticated-only joining enforced at the API level. What keeps this out of the top band: I found no public information on per-participant moderation detail, simulcast or adaptive bitrate under load, or what happens to the call on a constrained connection. 2 6 7 12

Report an error

Encryption & meeting access

How this is scored

What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".

0 — Transport encryption only, undocumented; meetings joinable by anyone with a link and no lobby.

3 — TLS in transit and encryption at rest, with the vendor holding all keys; access control is a passcode.

5 — The above plus a lobby or waiting room, host-controlled admission, per-meeting passcodes, and a clear statement that the vendor can technically access media.

8 — Optional end-to-end encryption for meetings with the trade-offs named (which features stop working), documented key handling, SSO-gated joining, and per-meeting access policies.

10 — End-to-end encryption available without surrendering the product — its cryptography documented or open source, key management explained, identity verification for participants, and the vendor stating plainly what it can and cannot see.

Report an error

The Skeptic

The sentence I always look for — which meetings, on which plan, get end-to-end encryption, with what turned off — does not exist in the captured pages; the browser support tables mark end-to-end encryption with a cross in every browser listed, and the only mechanism stated is TLS 1.2 with 256-bit AES-GCM. Access control is genuinely strong: per-meeting passcode, waiting room, authenticated-only joining, and the API overwrites any request that tries to disable all three. But the privacy statement only admits operator-side visibility for chat and email content, and I found no public information on at-rest encryption for meeting media or on key handling. 3 7 9 10

Report an error

Reach & accessibility

How this is scored

Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.

0 — A desktop client is the only way in; guests must create an account.

3 — Browser joining exists but is degraded, guests can join by link, and there is no dial-in and no accessibility statement.

5 — Full-feature browser joining without an install, guest access by link, mobile apps, and a stated accessibility posture.

8 — Telephone dial-in with numbers listed, live captions, keyboard-navigable and screen-reader-tested interface, and documented low-bandwidth behaviour.

10 — Reach is designed for: browser parity with the client, dial-in across the regions the customer operates in, live captions and translation, a published accessibility conformance report, and a usable experience on a poor mobile connection.

Report an error

The Skeptic

Browser joining is documented as feature-equivalent to the web client across Chrome, Edge and Safari with a stated two-version support window, and live transcription, live translation and RTMP streaming are marked available on every browser, mobile browsers included from iOS 16.4 and Android Chrome 112. I found no public information on telephone dial-in, on guests joining without an account, on keyboard and screen-reader testing, or on an accessibility conformance report — half of what this criterion asks for is simply absent from the captured pages. 9 10

Report an error

Recordings, retention & admin control

How this is scored

A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.

0 — Anyone can record, storage location unstated, no retention rule, no admin policy.

3 — Host-only recording with a notification, but storage region unstated, retention manual, and no organisation-wide policy control.

5 — Admin policy over who may record, participant notification and consent prompt, stated storage region, and manual deletion that works.

8 — Automatic retention and deletion per policy, recordings encrypted at rest with access logged, transcription handled with its own retention rule, and attendance or analytics features that can be switched off for co-determination.

10 — Built for a works agreement: every recording, transcript and analytics feature independently switchable and documented, retention executed and evidenced, an audit trail of who accessed which recording, and no participant-level behavioural scoring at all.

Report an error

The Skeptic

Recording comes with a stated visual-or-otherwise notification, a delete-after-a-specified-number-of-days retention setting, and a bring-your-own-storage option that puts the files in the customer's own S3 bucket — the one real governance lever here, alongside a 30-day retrieval window after contract termination before deletion. We found no public information on the default storage region, on access logging or an audit trail for recordings, or on admin switches to disable transcription and analytics features for a works council; individual recording at least requires the host to enable it and the user to elect it. 2 4 11 12

Report an error

Integrations & deployment

How this is scored

Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.

0 — No calendar integration, no SSO, no API; cloud-only with no alternative.

3 — One calendar integration and basic SSO, no API worth building on, cloud-only.

5 — Calendar integration for the major suites, SAML or OIDC SSO, a documented API for scheduling, and room-system support.

8 — The above plus SCIM provisioning, embedding via SDK, webhooks for meeting events, and either a self-hosted option or a documented private-cloud deployment.

10 — Deployment is the customer's choice: a genuine on-premises or private-cloud option with the same features, open protocols or open source, embeddable SDKs, and identity integration that does not require the vendor's directory.

Report an error

The Skeptic

The developer surface is deep and public: meeting create/update APIs, cloud-recording REST APIs with webhooks for completed recordings and transcripts, a documented Calendar API shipped with OpenAPI and Postman artifacts, embeddable web and mobile SDKs, and AI Services APIs. SSO with managed domains arrives at the Business tier. I found no public information on SCIM provisioning, room-system support, or any self-hosted or private-cloud deployment option, which caps this mid-band for a buyer who wants the stack on their own terms. 2 11 12 13 14

Report an error

European sovereignty

How this is scored

Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.

0 — Non-EU vendor and contracting entity, media routed through unstated regions, subprocessors unnamed.

3 — EU data residency for storage while media relays or metadata remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting and an EU contracting entity, but parts of the chain — relays, analytics, support tooling, transcription — are non-EU without an explained safeguard.

8 — Media and metadata processed in the EU on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: media never leaves the EU, every subprocessor European, certification published, and an on-premises option that removes the question entirely.

Report an error

The Skeptic

The contract is with Zoom Communications, Inc. of San Jose, the enforcer named is the Federal Trade Commission, and the DPO address is in California — a US contracting entity end to end. We found no public information on media routing regions, data residency, or any named subprocessor list beyond a generic mention of third-party service providers for payments and infrastructure; the Data Privacy Framework certification, standard contractual clauses and an Irish EU representative are mitigations, not EU processing. 3 4

Report an error

Pricing transparency

How this is scored

Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-host headline exists, but participant caps, dial-in minutes or recording storage are unpriced or unmentioned.

5 — Per-host prices public with billing period stated and capacity limits given, but at least one commonly needed piece (webinar capacity, dial-in, storage) sits in an unpriced add-on.

8 — Every tier and add-on priced publicly with per-host maths, capacity limits, dial-in rates, storage allowances, minimum term and VAT treatment stated.

10 — Complete price computability: a calculator producing the annual invoice for a given host count, meeting size and recording volume, including overage and per-region dial-in.

Report an error

The Skeptic

Per-host prices are public with billing period and VAT exclusion stated — €13.33 /user per month billed annually for Pro and €17.49 for Business, excluding VAT — with capacity limits of 100 and 300 participants, 10 GB cloud storage per user, and a large-meeting add-on from €46.50 for 500 participants per month. But I found no public information on telephone dial-in or its rates, I found no public price for the Enterprise tier, the AI summary is described only as 'a separate charge' with each feature billed separately, and no minimum term length is stated — so the annual invoice for a given host count is not computable from these pages alone. 2 4 12

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage zoom.us Checked 15 Sep 2026 Details →
  2. 2 Pricing zoom.us Checked 15 Sep 2026 Details →
  3. 3 Privacy policy explore.zoom.us Checked 15 Sep 2026 Details →
  4. 4 Terms of service www.zoom.com Checked 30 Sep 2026 Details →
  5. 5 The meeting itself — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  6. 6 The meeting itself — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  7. 7 Encryption & meeting access — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  8. 8 Encryption & meeting access — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  9. 9 Reach & accessibility — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  10. 10 Reach & accessibility — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  11. 11 Recordings, retention & admin control — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  12. 12 Recordings, retention & admin control — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  13. 13 Integrations & deployment — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →
  14. 14 Integrations & deployment — found from sitemap developers.zoom.us Checked 1 Oct 2026 Details →