Accountability & trust

E2E encryption

End-to-end encryption means only the sender and receiver can read a message. Not even the company running the service can access it.

End-to-end encryption, or E2E encryption, scrambles your data so only the people communicating can unscramble it. The company providing the service, whether it is email, messaging, or file storage, cannot read the content itself, even if a government asks them to. This is different from encryption that only protects data in transit or on a server, which the company can still access. E2E encryption is one of the strongest practical protections against outside access, including from the company’s own government.

Frequently asked questions

What is end-to-end encryption?

End-to-end encryption means only the sender and the receiver can read a message. The message is scrambled before it leaves your device. It only unscrambles on the receiver's device.

The company running the service cannot read the message in between. This is true even if the company wanted to help a government read it. The company simply doesn't hold the key.

Is end-to-end encryption actually unbreakable?

The encryption itself is extremely strong. With current technology, breaking it directly would take an unrealistic amount of time and computing power.

But attackers don't always need to break the encryption. They can target a weak password, a stolen device, or a bug in the app itself. Good encryption protects the message in transit, not every possible weak point around it.

Which everyday apps use end-to-end encryption?

Signal is a well-known example. It uses end-to-end encryption by default for all chats. WhatsApp also uses it by default for messages.

Some apps only turn it on if you choose it. Regular email, for example, is usually not end-to-end encrypted unless you add extra tools. Always check a specific app's settings if this matters to you.

Can police or governments access end-to-end encrypted messages?

Not directly through the company, in most cases. Since the company doesn't hold the key, it usually cannot hand over readable message content, even with a valid legal order.

But there are other ways in. Police can access a phone directly, with the right legal authority. They can also use spyware, or get access to an unencrypted backup. Encryption protects the message itself, not every device it passes through.