Zight for enterprise

The app your teams already want, with the answers your security review needs.

Five million people use Zight to show each other what they mean. This page is for the people who have to approve that: SOC 2 Type II, SSO and SCIM, retention you set, and a BAA where PHI is in scope.

  • SOC 2 Type II SOC 2 Type II Independently audited
  • GDPR Compliant GDPR EU compliant
  • HIPAA compliant HIPAA Scale plan, BAA available
  • AWS S3 AWS S3 Custom Bring your own bucket

Trusted by 5m+ people who would rather show than tell

Is Zight suitable for enterprise use?

Yes. Zight is SOC 2 Type II certified and its Scale plan adds SSO and SCIM with group-based permissions, custom data retention with optional S3 storage, HIPAA compliance with a signed BAA, premium integrations, unlimited users and view-only licences. Recipients never need an account, so there is no external directory to administer.

What enterprise adds

The same product, with the controls around it

Nothing here changes what the people recording their screens have to learn. It changes what you can prove about it afterwards.

Identity and access

SSO and SCIM with group-based permissions, so joiners and leavers are handled by your directory rather than by somebody remembering. Access to content is controlled at the organisation level, not left to whoever created it.

Retention on your terms

Custom data retention, and storage in your own S3 bucket if your policy requires the data to live somewhere you control. Retention that matches the policy you already wrote beats retention you have to explain away.

Admin controls and policy

Organisation-wide defaults for sharing, expiry and visibility, applied to employees and contractors alike, so the safe setting is the default rather than a training slide.

The integrations IT actually gets asked for

Zendesk, Intercom, Fin, Salesforce Service Cloud, Jira, Confluence, Notion and Lucid are included at the Scale tier rather than sold as an add-on, which is usually the difference between a rollout and a pilot that stalls in one department.

Your brand on the share page

A custom domain, your logo, and control over the calls to action, comments and reactions on the pages your customers open. Available from Collaborate up.

Volume that fits an org

Up to 250 video requests a month, unlimited users, and view-only licences for the people who need to watch rather than record — so you are not buying seats for an audience.

The premium set, page by page: Zendesk , Intercom , Fin , Salesforce Service Cloud , Jira , Confluence , Notion , Lucid .

Plan scope is on pricing; the security controls themselves are on trust & security.

Rolling it out

Pilot, review, provision, expand

  1. 1

    Pilot in one department

    Usually support or IT, because both have a measurable loop: how long it takes to understand what a person is reporting. That number is the business case for everything after.

  2. 2

    Security review

    SOC 2 Type II report, the retention and encryption picture on /trust-security, and a BAA if you are on Scale and handling PHI. Bring us the questionnaire.

  3. 3

    Connect the directory

    SSO and SCIM, group-based permissions mapped to the groups you already have, and organisation-level defaults for sharing and expiry set before anyone else is invited.

  4. 4

    Roll out by workflow, not by headcount

    Give each department the workflow it will actually use — request links for support, walkthroughs for enablement, async updates for leadership — rather than a licence and a login.

Proof

What it did somewhere else

50% less debugging time Thinkific
40% lower video tooling costs Qualtrics
90% fewer fraudulent claims SeatGeek
“Leveraging Zight in our GitHub pull requests and during conversations with our Engineering team saves us about 50 minutes every day!”
Josh Wyse Sr. Software Developer, Cloud Elements

FAQ

Questions a review asks first

Yes. Zight is SOC 2 Type II certified, which is the audited-over-time version rather than a point-in-time attestation. The controls, encryption and retention detail are on /trust-security, and we can walk a security team through a questionnaire.

Yes, on the Scale plan. That is the tier where HIPAA compliance and a signed Business Associate Agreement are available, which matters if recordings or screenshots could contain protected health information.

Yes. SSO and SCIM with group-based permissions come with the Scale plan, so accounts are created and removed by your identity provider and permissions follow the groups you already maintain.

Retention is configurable at the organisation level, and Scale supports storage in your own S3 bucket. If your policy sets a retention window, the platform can be set to match it rather than being an exception you have to document.

No, and this is usually the part that surprises a security review in a good way. A Zight link opens in a browser with no account, and a request link lets a customer send you their screen and console logs without installing anything — so there is no external user directory to manage.

The Mac and Windows installers are the standard packages your endpoint management already knows how to push, and the Chrome extension covers machines where installing software is not an option. All of them share one library.

Scale is custom-priced, and includes unlimited users and view-only licences, so the shape of the agreement depends on how many people record versus how many only watch. The plan comparison is on /pricing; the conversation starts at /contact-sales.

Bring us the questionnaire.

A pilot in one department, a security review, and a rollout that follows the workflows rather than the org chart.