Online Meetings and Calls: Zoom, Google Meet, Teams, and End-to-End Encryption
“Encrypted meeting” can mean several different things. A meeting may be protected while it travels across the internet, encrypted on the provider’s servers, or protected so that the provider cannot ordinarily decrypt the content at all.
The question readers are really asking
If Zoom, Google Meet, or Teams says a meeting is encrypted, who can actually read or hear it?
It depends on the encryption model and on the features in use.
A normal cloud meeting is usually encrypted in transit and often encrypted at rest. But the provider may still decrypt content to deliver cloud recording, captions, transcription, AI summaries, search, and cross-device access.
End-to-end encryption, or E2EE, offers a different model. It is designed so that only authorized participants’ devices hold the ordinary ability to decrypt the call.
The practical question is:
Do I need ordinary secure cloud collaboration, or do I need a meeting in which the provider itself cannot ordinarily decrypt the content?
The short answer
Most routine meetings are adequately served by standard encrypted cloud meetings when participants use supported apps, strong accounts, and careful recording policies.
For highly sensitive discussions—legal strategy, confidential research, health information, security incidents, protected personnel matters, or high-risk communications—consider whether an E2EE or client-side-encrypted mode is available and appropriate.
But E2EE has trade-offs. It often disables cloud recording, live captions, transcription, AI summaries, and other convenient features. That is not an accident: a service cannot easily provide those features without processing the meeting content.
Four levels of meeting protection
1. Transport encryption
Transport encryption protects audio, video, chat, and shared content while it travels between participants and the meeting service. Services commonly use TLS for signaling and secure real-time transport protocols for media.
It helps protect against ordinary network eavesdropping, including on public Wi-Fi. It does not necessarily mean that the provider cannot decrypt or process content after it reaches the provider’s systems.
2. Ordinary cloud-encrypted meetings
In an ordinary cloud meeting, the service encrypts traffic in transit and typically protects stored data at rest. The provider may decrypt media or related data within its infrastructure to support recording, captions, transcription, search, interoperability, or AI-assisted features.
This can be appropriate for routine teaching and collaboration. It is real security, but not usually provider-blind security.
3. End-to-end encryption
With end-to-end encryption, meeting content is encrypted on participating devices and decrypted only on authorized participants’ devices. The provider does not ordinarily have the keys needed to read the call content.
E2EE can be valuable for highly sensitive meetings. It does not make a meeting risk-free: participants can still record screens, photograph a display, or share information afterward.
4. Post-quantum end-to-end encryption
Post-quantum E2EE adds a post-quantum cryptographic component to the protections used for an end-to-end encrypted meeting. Its purpose is to reduce the future risk that an adversary records encrypted traffic today and later acquires a quantum computer capable of attacking classical public-key methods.
Do not assume this from ordinary E2EE alone. Zoom currently documents post-quantum E2EE for Zoom Workplace meetings. Verify equivalent claims for other services against official documentation.
Why recordings, captions, transcripts, and AI summaries matter
A live conversation is one kind of risk. A retained record is another.
Recording, transcription, AI-generated notes, and automatic summaries can create multiple new copies:
- a video or audio recording;
- a transcript;
- meeting notes or action items;
- chat logs and shared files;
- cloud backups; and
- copies sent to participants or other systems.
These materials may remain valuable long after the meeting ends. Even when the live call used strong encryption, the resulting records need access controls, retention rules, encryption, and backups.
Ask:
Would the recording, transcript, or AI summary still be harmful if disclosed ten or twenty years from now?
If yes, minimize unnecessary retention and choose the meeting mode deliberately.
Why E2EE modes often remove useful features
The feature limits in E2EE follow from its security design. Recording, transcription, captions, search, AI notes, and some interoperability features require the service to process readable content. If only participant devices can decrypt, the provider cannot easily create those features.
Current documentation illustrates the pattern:
- Zoom states that E2EE disables cloud recording, live transcription, AI Companion, and several collaboration features.
- Google Meet’s client-side encryption mode excludes recordings, captions, transcripts, and Gemini features.
- Microsoft Teams documents that E2EE meetings and calls can limit or disable recording, captions, transcription, and related functions.
These details change frequently. Recheck official platform documentation before publishing a comparison or setting an institutional policy.
Zoom, Google Meet, and Teams: what to ask
It is more useful to ask the same questions of every platform than to rely on a broad label such as “encrypted.”
| Question | Why it matters |
|---|---|
| Is the meeting merely encrypted in transit, or can the provider decrypt content? | This distinguishes ordinary cloud security from provider-blind protection. |
| Is an E2EE or client-side-encryption mode available? | Availability may depend on account type, administrator settings, client, and meeting size. |
| Which features are disabled in the high-confidentiality mode? | Recording, captions, transcription, AI notes, browser access, or dial-in may be unavailable. |
| Where do recordings and transcripts go? | They may be retained in a cloud drive, shared with participants, or included in other workflows. |
| Is a post-quantum E2EE claim specifically documented? | Do not infer PQ protection from ordinary encryption or an E2EE label alone. |
| Can administrators set retention, recording, and access policies? | Institutional configuration is often as important as the encryption mode. |
For sensitive meetings, decide before the meeting begins whether recording, transcription, AI notes, and cloud storage are acceptable.
Endpoint compromise and participant behavior remain outside PQC
Neither conventional nor post-quantum E2EE protects information after it reaches an authorized endpoint. Encryption does not stop malware, a compromised account, screenshots, recordings, copied notes, forwarded files, or intentional disclosure. PQC does not eliminate human error or endpoint compromise.
What readers should do now
- Choose the meeting mode based on the sensitivity of the discussion.
- Decide in advance whether recording, transcription, captions, and AI summaries are appropriate.
- Treat recordings and transcripts as separate long-lived records. Apply access controls, retention rules, encrypted storage, and protected backups.
- Use supported, updated meeting apps and operating systems.
- Protect meeting accounts with a password manager and strong multi-factor authentication.
- For highly sensitive meetings, confirm the actual E2EE or client-side-encryption setting before joining.
- Recheck platform documentation periodically. Features, limitations, and PQ claims change faster than the underlying principles.
What readers do not need to do
Most people do not need to assume that ordinary Zoom, Google Meet, or Teams meetings are unprotected, avoid all cloud collaboration, or rely on an E2EE label without considering recordings and endpoint risks.
Match the meeting configuration to the information being discussed. Use ordinary encrypted cloud meetings for ordinary collaboration. Use stronger provider-blind modes when the sensitivity justifies lost features. And remember that a recording, transcript, or AI summary can outlive the conversation by many years.
Takeaway: “Encrypted meeting” does not necessarily mean that the provider cannot access the content. For sensitive calls, decide deliberately whether you need end-to-end encryption, whether recordings and AI features are acceptable, and how any resulting records will be protected over time.
Key terms
Transport encryption
Encryption that protects meeting traffic while it travels between a participant’s device and a service.
Cloud-encrypted meeting
A meeting in which traffic and stored data are encrypted, but the provider may be able to decrypt content to provide service features.
End-to-end encryption (E2EE)
A design in which only authorized participant devices ordinarily hold the keys needed to decrypt meeting content.
Post-quantum E2EE
End-to-end encryption that also uses post-quantum cryptography to reduce the future risk from quantum attacks on recorded traffic.
Provider-blind
A property in which the service provider does not ordinarily hold the ability to decrypt the content.
Transcript
A text record of what was said during a meeting, often stored separately from the audio or video recording.
0 comments