RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 100 retrospective records ↗
productivityatlas.

The archive / Platform change

Platform change / From the archive · 9 November 2020 event · prepared 16 September 2026

An FTC order found Zoom overstated its meeting encryption

The 2020 settlement records what Zoom claimed about encryption and what a security programme now requires.

Visual for this record: zoom-ftc-settlement-2020
Visual published by media.zoom.com, shown for identification of the record. Credit: media.zoom.com · source page ↗ Rights: owner-review-pending.

What the order found

On 9 November 2020 the Federal Trade Commission announced a settlement with Zoom Video Communications. The FTC's press release states that Zoom had claimed to offer end-to-end, 256-bit encryption for meetings since at least 2016, while in fact Zoom itself held the cryptographic keys that could unlock the content. That is a specific, checkable distinction: end-to-end encryption normally means the provider cannot read the traffic it carries; transport encryption to a provider-controlled server means it can. The release also records that some cloud recordings were left unencrypted on Zoom's servers for up to 60 days, and that Zoom had installed software that bypassed a Safari safeguard without adequate disclosure. The case record shows the complaint and proposed order were filed the same day, a Federal Register comment period followed on 13 November 2020, and the Commission gave final approval on 1 February 2021.

Reading a vendor's security claim

The order is a useful checklist for any team evaluating a collaboration tool's own trust page. A claim of encryption is only as strong as who holds the keys and at what stage the data is decrypted; a claim about recordings should specify at rest, in transit, and for how long. Zoom's own trust centre, as retrieved on 16 September 2026, still summarises its posture as encryption and multi-factor authentication working together to keep customers safe, which is the kind of general assurance language the 2020 order exists precisely to test. A reader cannot verify a security claim from a marketing paragraph alone; the specific mechanism, and who controls it, has to be stated.

What the settlement required, and what it does not prove

The order requires Zoom to run a documented information-security programme, including annual internal and external risk assessments, a vulnerability-management process, multi-factor authentication and credential controls, a ban on further misrepresentation, and biennial assessments by an FTC-approved independent third party, with breach notification to the agency. It does not function as an ongoing public scorecard: compliance is monitored by the FTC and the assessor, not published as a live rating, and the order addresses the specific 2016 to 2020 conduct rather than certifying every current Zoom feature. A settlement also is not an admission of guilt in the way a court judgment is; it resolves the matter without further litigation.

  • Does the vendor specify who holds the encryption keys, not just that encryption exists?
  • Is there an independent assessment behind the claim, and can your organisation see any part of it?
  • Has a regulator or court record ever addressed this vendor's security representations?

The order is several years old and describes a specific period of Zoom's history, not a verdict on the product today. Its lasting value is procedural: it shows what a checkable encryption claim looks like, and what a written security programme has to include once a regulator has looked closely.

Sources & reading trail

FTC Requires Zoom to Enhance its Security Practices as Part of Settlement ↗

States the FTC's finding that Zoom misrepresented end-to-end encryption and left some recordings unencrypted, and lists the settlement's security-programme requirements.

Source published: 9 November 2020 · Retrieved: 16 September 2026

Zoom Video Communications, Inc., In the Matter of ↗

Confirms the case timeline: complaint and consent order filed 9 November 2020, a public comment period, and final Commission approval on 1 February 2021.

Source published: Not established · Retrieved: 16 September 2026

Zoom Trust Center ↗

Shows the general security assurances on Zoom's current marketing page, useful for comparison against the specific findings in the order.

Source published: Not established · Retrieved: 16 September 2026

Announcements and papers establish the record; the friction reading and the adoption questions are Productivity Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.