SOC2C

Zoom Communications security & compliance

An overview of Zoom Communications's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).

SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II, ISO 27001, PCI DSS, FedRAMP, HITRUST, CSA STAR
Penetration testNot listed
SubprocessorsNot listed
HostingAWS, Oracle Cloud
Trust centerView

Security questions about Zoom Communications

Is Zoom Communications secure?
Security isn't a single yes/no, but Zoom Communications is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, PCI DSS, FedRAMP, HITRUST, CSA STAR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Zoom Communications have a bug bounty or vulnerability disclosure program?
Zoom Communications hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@zoom.com or via a /security page.
Who are Zoom Communications's subprocessors?
Zoom Communications's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Zoom Communications host or store data?
Zoom Communications hosts on AWS, Oracle Cloud. Data residency details are on its trust center.
Where is Zoom Communications's trust center or security page?
Zoom Communications's trust center is at https://trust.zoom.com/. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.

See Zoom Communications's full SOC 2 profile →