Policies - Zoom

Security and Privacy Risks of Zoom: Technical Rationale for Restricted Use

This document outlines technical security and privacy concerns specific to Zoom as a third-party cloud service. These concerns support restricting its use for communications involving sensitive information or proprietary business matters. AfterNorth prefers self-hosted platforms under direct organizational control.

External Provider Control of Infrastructure and Keys

Zoom operates as a third-party cloud service. Under default configurations, encryption keys are managed by Zoom’s servers. This gives the external service provider the technical ability to access meeting content—including audio, video, chat, shared screens, and files—when required for legal process, support, or other operational reasons.

Because the infrastructure and key management sit outside the control of the organizations using the service, content access and data handling decisions remain with Zoom rather than the customer.

Third-Party Marketplace and Expanded Data Access

The Zoom Marketplace permits third-party applications to request extensive access to meeting content, user data, contacts, and audio-visual streams. Documented issues with these apps include:

This marketplace model introduces additional external parties into the data flow that are not present in a self-hosted environment with tightly controlled integrations.

External Legal Compulsion and Data Handling

As a third-party service provider, Zoom is subject to legal process directed at the company itself. Non-content user data could be disclosed through subpoenas; content generally requires a warrant. National-security and delayed-notice processes can further limit user notification.

Data retention, secondary use terms, and responses to legal requests are governed by Zoom's policies and legal obligations rather than by the customer organization.

Client and Link-Based Attack Surface

Zoom's public client software and meeting-link infrastructure have been the target of specific technical attacks, including:

These vectors are tied to the public, widely distributed nature of the Zoom client and its meeting-join workflow.

Preferred Architecture: Self-Hosted Mattermost

AfterNorth uses self-hosted Mattermost servers under direct company control. The primary technical advantages of this approach relative to a third-party cloud service such as Zoom are:

These differences center on control of infrastructure and the elimination of an external service provider from the data path. They form the basis for AfterNorth's preference for self-hosted Mattermost over Zoom for business communications.