Montro

Zoom Governance & Compliance Discovery

Zoom accounts grow quietly - provisioned outside your identity provider, renewed without IT review, and rarely audited. Montro discovers every user and licence in your Zoom environment and maps it against your EU compliance obligations.

01GDPR

GDPR

Zoom and GDPR - what your organisation needs to know

Zoom processes personal data on your behalf - including user identities, email addresses, and account metadata. Under GDPR, your organisation is the data controller and Zoom acts as a processor. A Data Processing Agreement must be in place. When Montro connects to Zoom, that data flows into Montro's EU-hosted infrastructure under a separate DPA. All Zoom data imported into Montro remains within the EU.

Learn more →
02EU AI Act

EU AI Act

Zoom AI Companion and the EU AI Act - know your obligations

Zoom AI Companion - meeting summaries, transcription, in-meeting assistance - is an AI system under the EU AI Act. If your organisation has it enabled, deployer obligations apply: documenting its use, confirming the risk tier, and ensuring oversight is in place. Usage in recruitment, performance reviews, or employee-facing workflows warrants closer review under Annex III. Montro surfaces Zoom in your governed inventory so AI feature usage does not slip through undocumented.

Learn more →
03DORA

DORA

Zoom under DORA - for regulated financial entities only

Under DORA, every ICT tool supporting your operations must be registered and assessed. Zoom, as a communication platform, is an ICT service that belongs in your ICT Third-Party Register under Article 28.3. Connecting Zoom to Montro supports register completeness and gives you the visibility needed to meet DORA third-party risk obligations.

Learn more →
04NIS2

NIS2

Zoom as a supply chain tool under NIS2

NIS2 Article 21(3)(d) requires organisations to document and assess the cybersecurity of their direct ICT suppliers and service providers. Zoom is a communication and collaboration tool that qualifies as an ICT service under NIS2. Connecting Zoom to Montro brings it into your governed application inventory, supporting your supply chain security obligations and ensuring Zoom is visible in any NIS2 compliance review.

Learn more →

Discovery

What Montro discovers from Zoom

When you connect Zoom to Montro, the platform pulls user account data and subscription information into your governed application inventory. IT and security teams get a clear view of who has access to your conferencing environment, how licences are allocated, and whether Zoom is mapped against your EU compliance obligations.

User access visibility

See every Zoom account tied to your organisation, including users added outside standard provisioning flows. Montro surfaces accounts created with personal email addresses, users provisioned directly rather than through your identity provider, and any access that exists outside your governed onboarding process.

Licence allocation

Understand how Zoom licences are distributed across teams and identify seats that are provisioned but unused. Montro gives you the data to right-size your Zoom subscription, reclaim inactive licences, and ensure your conferencing spend reflects actual usage rather than historical allocation.

Subscription tracking

Zoom subscription records are imported into Montro's Subscriptions module for renewal and cost visibility. Track your plan details, licence counts, and renewal dates alongside every other SaaS and AI tool in your estate - so nothing renews unreviewed.

Single governed view

Zoom sits alongside every other SaaS and AI tool Montro has discovered - mapped to your EU compliance and regulatory obligations in one place. No spreadsheets. No separate audit trail. One governed view of your entire application estate.

Technical details

Authentication Method


Zoom authenticates via OAuth. Users can sign in with Zoom credentials or a supported identity provider (currently Google).


How to connect:


  1. Navigate to Integrations in your Montro dashboard.
  2. Select Zoom from the integrations catalogue and click Connect.
  3. On the Zoom integration screen, click Connect to initiate authentication.
  4. Sign in to Zoom using your email and password, or select an available sign-in provider.
  5. If using Google, select the account you want to use for Zoom authentication.
  6. Review the requested permissions and click Continue.
  7. Complete the Zoom account authorisation process.
  8. Montro validates the connection and begins synchronising Zoom data.
  9. Review imported Zoom records within Montro.


Data Synced

Users module

Zoom user identities, including email addresses and account ownership.

Subscriptions module

Zoom subscription records, license counts, and plan information.

Data Residency


Zoom data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. No customer data is transferred outside the EU. Data residency terms are specified in Montro's Data Processing Agreement.


Sync Frequency


Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.


Permission Scope


Montro requests read-only OAuth permissions from Zoom. Scopes are limited to user account information and subscription data. Montro does not request access to meeting content, recordings, chat messages, or administrative controls. All scopes requested are the minimum required for discovery. You can review the exact scopes presented during the OAuth authorization flow before approving the connection.


EU Data Storage



Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option - it is the architecture.

Related

Apps commonly used with ZOOM

Discover compliance profiles for tools in your stack.

Project & Knowledge Management

Jira External User Discovery & Governance

Jira accounts are where contractors, agencies, and external collaborators often live - outside your identity provider, outside your offboarding process, and outside your compliance picture. Connect Jira to Montro to bring them in.

Learn more →

OpenAI Governance & Compliance Discovery

Most organisations using OpenAI have no visibility into who holds access, how many seats are active, or whether usage is documented against EU AI Act obligations. Montro surfaces all of it.

Learn more →

Slack Workspace Access & AI Governance

Slack is where work happens, and where ungoverned access accumulates. Guest accounts, inactive seats, and users added outside your identity provider all show up when Montro connects to your workspace.

Learn more →

Identity & Access Management

Okta Identity Governance & Compliance

Okta controls who gets into everything else. Without it in your governed inventory, your compliance picture has a gap at the foundation. Montro connects Okta identity data to your full application estate.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.