Policies - Zoom
Security and Privacy Risks of Zoom: Technical Rationale for Restricted Use
This document outlines technical security and privacy concerns specific to Zoom as a third-party cloud service. These concerns support restricting its use for communications involving sensitive information or proprietary business matters. AfterNorth prefers self-hosted platforms under direct organizational control.
External Provider Control of Infrastructure and Keys
Zoom operates as a third-party cloud service. Under default configurations, encryption keys are managed by Zoom’s servers. This gives the external service provider the technical ability to access meeting content—including audio, video, chat, shared screens, and files—when required for legal process, support, or other operational reasons.
Because the infrastructure and key management sit outside the control of the organizations using the service, content access and data handling decisions remain with Zoom rather than the customer.
Third-Party Marketplace and Expanded Data Access
The Zoom Marketplace permits third-party applications to request extensive access to meeting content, user data, contacts, and audio-visual streams. Documented issues with these apps include:
- Over-collection of data beyond stated functionality.
- Incomplete or vague privacy policy disclosures.
- Limited transparency regarding further data sharing.
This marketplace model introduces additional external parties into the data flow that are not present in a self-hosted environment with tightly controlled integrations.
External Legal Compulsion and Data Handling
As a third-party service provider, Zoom is subject to legal process directed at the company itself. Non-content user data could be disclosed through subpoenas; content generally requires a warrant. National-security and delayed-notice processes can further limit user notification.
Data retention, secondary use terms, and responses to legal requests are governed by Zoom's policies and legal obligations rather than by the customer organization.
Client and Link-Based Attack Surface
Zoom's public client software and meeting-link infrastructure have been the target of specific technical attacks, including:
- Typo-squatted domains and forged meeting links delivering malware.
- Browser extensions designed to harvest Zoom meeting identifiers, topics, and credentials.
- Impersonation of client update or connection mechanisms.
These vectors are tied to the public, widely distributed nature of the Zoom client and its meeting-join workflow.
Preferred Architecture: Self-Hosted Mattermost
AfterNorth uses self-hosted Mattermost servers under direct company control. The primary technical advantages of this approach relative to a third-party cloud service such as Zoom are:
- Data residency and infrastructure control — Messages, files, and metadata remain on systems owned and operated by the organization. No external SaaS provider holds the data or the encryption keys used for transit and storage.
- No public third-party marketplace — Integrations are limited to those explicitly approved and managed internally, eliminating the broad permission model of Zoom's Marketplace.
- Organizational control over retention, logging, and access — Policies for data retention, audit logging, and administrative access are set and enforced by the organization rather than by an external vendor.
- Legal process directed at the organization — Because data is not held by a third-party cloud provider, legal requests must be directed to the organization that controls the infrastructure.
- Open-source core — The platform code can be reviewed, audited, and hardened according to internal requirements.
These differences center on control of infrastructure and the elimination of an external service provider from the data path. They form the basis for AfterNorth's preference for self-hosted Mattermost over Zoom for business communications.