โ† Back to blog

Zscaler ยท Cybersecurity

Zscaler's Terms Shift Without Warning, Third-Party Access Poorly Defined

September 18, 2026

C
Moderate

Zscaler is a cybersecurity platform that handles network traffic and security services. Their terms of service contain some structural gaps and consent mechanisms that deserve scrutiny.

๐Ÿ”ด Terms change silently. The company reserves the right to update these terms automatically. You accept new terms simply by continuing to use the service, with no notification requirement beforehand.

๐Ÿ”ด Third-party access is loosely defined. "Authorized Users" includes contractors and third parties, but the terms don't specify who qualifies, under what conditions, or what access limits apply to them.

๐ŸŸก Customer data handling is incomplete here. The terms acknowledge that customer data gets collected and processed but punt the actual privacy details to a separate policy. You're asked to trust a document that isn't in front of you.

๐ŸŸก This analysis is incomplete. The document cuts off abruptly mid-terms, so we can't see the full agreement or catch what else might be buried in later sections.

๐ŸŸข One thing is clear. The agreement does explicitly lay out that these are the governing terms for all product access and useโ€”no ambiguity on that point.

Zscaler scores a C. The auto-update mechanism and vague third-party language are the real issues here.

This breakdown is based on Zscaler's publicly available Terms of Service and/or Privacy Policy. It may contain mistakes. Spot one? Let us know.