Zulu transmitting passwords in clear text?

A local customer running Zulu had a compliance audit done and they found that the Zulu desktop client was transmitting passwords in cleartext. I thought all Zulu traffic was encrypted so I"m a bit confused. Do we assume the audit is incorrect?

It’s a serious claim. Can they prove it out with a network capture?

I’ll see if I can obtain it.

After looking at the network capture they were actually seeing the admin username and password of an IP phone and not Zulu.

