Security

End-to-End Encryption

End-to-end encryption protects content between authorised endpoints so an intermediate service is not supposed to hold the keys needed to read it. Scope and recovery vary.

Protected messages cross a relay between keyed phones; the backup has separate protection.

What it means

This differs from transport encryption that protects only the connection to a server. The receiving device can display the content, so screenshots, exports and compromised endpoints remain possible exposure routes. Metadata protection and backup encryption depend on the service and feature; an encrypted message does not automatically make every related copy end-to-end encrypted.

How this affects everyday use

Missing history can result from an untransferred device key or an unavailable recovery method. A message may also reach the wrong person if account identities were not verified.

A practical example

A private chat passes through a relay as protected data. The recipient can still save a readable screenshot, while restoring its backup may require a separate recovery key.

What to check

  • Check which content and features actually use end-to-end protection.
  • Review device identity checks, linked devices and account recovery.
  • Confirm how backups and exports are encrypted and restored.

Practical next steps

  • Verify important recipient identities through the supported process.
  • Secure endpoint access and remove unknown linked devices.
  • Prepare the documented recovery method before replacing or resetting devices.

Keeping it reliable

Keep endpoint software supported and protect recovery material separately. Choose sharing and backup settings deliberately. End-to-end encryption protects a particular content path; it does not guarantee anonymity, prevent a recipient sharing content or replace a recoverable backup.

Technical sources

← All glossary terms