In the event your company needs assistance completing a security or compliance assessment or questionnaire, the Zoom Trust Center provides you with self-service access to the resources you need to complete your assessment, including responses to the most common industry standard questionnaires, third-party certifications and attestations, and other artifacts and validated assessments. The resources most frequently used by our customers to complete the security and compliance assessments include:
Safebase is a third-party tool Zoom uses to distribute our security and compliance documentation to customers. Customers do not need to create an account to access Zoom's security and privacy documents. Instead, customers will be asked to provide their name and corporate email address for verification. Access will be granted via a magic link sent to their provided email address which will enable them to access and/or download Zoom’s latest security and compliance documentation.
Zoom maintains a robust set of security certifications and attestations to help meet the collective needs of our customers in various geographies and industries. For the current list of certifications and attestations maintained by Zoom, please visit the Compliance page on the Zoom Trust Center.
Zoom makes certain third-party audit and attestation reports available to customers through the Zoom Trust Center; these reports can be accessed through the Compliance page.
The SOC 2 Type 2 bridge letter can be accessed on Zoom’s Trust Center via the SOC 2 Type 2 page.
This document can be accessed through Zoom’s security profile maintained on Zoom’s third-party service provider’s platform, SafeBase. Zoom customers can access Zoom’s security profile via the Zoom Trust Center. Customers will be asked to provide their corporate email address for verification. Access will be granted via a magic link sent to their provided email address which will enable them to access and/or download Zoom’s security and compliance documentations.
Zoom’s Privacy Statement is available on Zoom’s Trust Center via the Privacy at Zoom page. Additional privacy resources can be found here.
Zoom’s Global Data Processing Addendum (DPA) can be accessed here.
Zoom makes information available about its data processing in the privacy data sheets and Global Data Processing Addendum located here.
A list of Zoom-authorized subprocessors and affiliates — including the names, type(s) of data shared, and location of each subprocessor — is located on the Zoom Third-Party Subprocessors & Zoom Affiliates page. Please note customers can sign up to receive notifications of any new subprocessors on this page.
If you think you have found a security vulnerability in a Zoom product or service, please visit our Vulnerability Disclosure Policy for details on how to report the potential vulnerability to Zoom’s Security team.
The Zoom Security Bulletin page provides information related to Zoom’s Security Bulletins.We recommend that users update to the latest version of Zoom software to get the latest fixes and security improvements. Please note that customers can sign up to receive notifications of future Zoom Security Bulletins on this page.
There is currently no regulatory-backed certification available for HIPAA compliance; however, Zoom helps customers enable HIPAA compliant programs by executing a Business Associate Agreement (BAA) and safeguarding protected health information (PHI). Zoom aligns its controls to the Healthcare Industry Trust Alliance Common Security Framework (HITRUST CSF). To provide our healthcare customers assurance over the controls we have in place to support HIPAA requirements, Zoom makes available a SOC 2 + HITRUST report, which aligns with AICPA Trust Services Principles and Criteria and the HITRUST CSF.
Yes, Zoom has a standard BAA that can be entered into when required by our customers. Please see the Zoom for Healthcare page for more information.