Security at ZengoMeet
Last Updated: September 29, 2026
ZengoMeet is designed to hold as little about you as possible. This page describes how we protect what we do handle, and how to report a problem.
How the service is built
- Self-hosted. Calls run on infrastructure Zengo Hosting LLC controls, not through a third-party meeting platform.
- Minimal data. Guests join without an account. We set no cookies and run no analytics or advertising trackers on our pages.
- No server-side recording. We do not record meetings on our servers. The built-in local recording feature saves only to the recorder's own device.
- Service providers. We use a small set of providers for hosting, DNS, email routing and source-code hosting. Contact us for the current list.
Encryption
- Connections to our site and meeting servers use TLS, and calls are encrypted in transit.
- A moderator can turn on optional end-to-end encryption for a meeting under Security Options. It needs a recent Chrome, Firefox or Edge, and starting a local recording turns it off for that meeting.
Access control
- Hosting a room requires a one-time moderator code; guests need only the room link.
- Meeting hosts can use the lobby, mute or remove participants, and end the meeting.
- Our sign-in and moderator-code endpoints are rate limited, and an abandoned session is disconnected automatically.
How we work
- Changes to our code are reviewed and pass automated checks, including secret scanning, before release.
- Our web pages are served with security headers, and dependency versions are pinned to audited lockfiles.
- Access to our servers and code hosting is limited to the people who operate the service.
Compliance status
ZengoMeet is not currently certified or attested against HIPAA, SOC 2, ISO/IEC 27001 or ISO/IEC 27701, and we do not sign business associate agreements today. We are building our security program with independent attestation in mind. If your organization has specific requirements, contact privacy@zengomeet.com.
Reporting a vulnerability
If you believe you have found a security problem, email security@zengomeet.com with the subject "Security report". Please include what you found, how to reproduce it, and how to reach you.
- We aim to acknowledge reports within three business days and to keep you updated until it is resolved.
- Please give us reasonable time to fix an issue before disclosing it publicly.
- Test only against your own meetings and accounts. Do not access other people's data, degrade the service, or use social engineering or physical attacks.
- We do not currently run a paid bounty program.
Our machine-readable contact details are at /.well-known/security.txt.