
What the order found
On 9 November 2020 the Federal Trade Commission announced a settlement with Zoom Video Communications. The FTC's press release states that Zoom had claimed to offer end-to-end, 256-bit encryption for meetings since at least 2016, while in fact Zoom itself held the cryptographic keys that could unlock the content. That is a specific, checkable distinction: end-to-end encryption normally means the provider cannot read the traffic it carries; transport encryption to a provider-controlled server means it can. The release also records that some cloud recordings were left unencrypted on Zoom's servers for up to 60 days, and that Zoom had installed software that bypassed a Safari safeguard without adequate disclosure. The case record shows the complaint and proposed order were filed the same day, a Federal Register comment period followed on 13 November 2020, and the Commission gave final approval on 1 February 2021.
Reading a vendor's security claim
The order is a useful checklist for any team evaluating a collaboration tool's own trust page. A claim of encryption is only as strong as who holds the keys and at what stage the data is decrypted; a claim about recordings should specify at rest, in transit, and for how long. Zoom's own trust centre, as retrieved on 16 September 2026, still summarises its posture as encryption and multi-factor authentication working together to keep customers safe, which is the kind of general assurance language the 2020 order exists precisely to test. A reader cannot verify a security claim from a marketing paragraph alone; the specific mechanism, and who controls it, has to be stated.
What the settlement required, and what it does not prove
The order requires Zoom to run a documented information-security programme, including annual internal and external risk assessments, a vulnerability-management process, multi-factor authentication and credential controls, a ban on further misrepresentation, and biennial assessments by an FTC-approved independent third party, with breach notification to the agency. It does not function as an ongoing public scorecard: compliance is monitored by the FTC and the assessor, not published as a live rating, and the order addresses the specific 2016 to 2020 conduct rather than certifying every current Zoom feature. A settlement also is not an admission of guilt in the way a court judgment is; it resolves the matter without further litigation.
- Does the vendor specify who holds the encryption keys, not just that encryption exists?
- Is there an independent assessment behind the claim, and can your organisation see any part of it?
- Has a regulator or court record ever addressed this vendor's security representations?
The order is several years old and describes a specific period of Zoom's history, not a verdict on the product today. Its lasting value is procedural: it shows what a checkable encryption claim looks like, and what a written security programme has to include once a regulator has looked closely.
Sources & reading trail
States the FTC's finding that Zoom misrepresented end-to-end encryption and left some recordings unencrypted, and lists the settlement's security-programme requirements.
Source published: 9 November 2020 · Retrieved: 16 September 2026
Confirms the case timeline: complaint and consent order filed 9 November 2020, a public comment period, and final Commission approval on 1 February 2021.
Source published: Not established · Retrieved: 16 September 2026
Shows the general security assurances on Zoom's current marketing page, useful for comparison against the specific findings in the order.
Source published: Not established · Retrieved: 16 September 2026
Announcements and papers establish the record; the friction reading and the adoption questions are Productivity Atlas editorial analysis. This retrospective draft does not imply the site published on the event date.