What Is End-to-End Encryption (E2EE)? Definition and How to Check It

End-to-end encryption (E2EE) is a method of protecting data in which content is encrypted on the sender's device and can be decrypted only on the devices of the intended recipients. The decryption keys exist only on those devices. Every server in between — the one that relays messages, stores files or syncs devices — handles ciphertext it has no key for, so it cannot read the content.

The "ends" in the name are the people, or more precisely their devices. The provider is in the middle, and that is the whole point: end-to-end encryption is the one kind of encryption that protects your data from the service that carries it, not only from outsiders.

How end-to-end encryption works

Most E2EE systems combine two ideas. Each device has a key pair: a public key that others use to encrypt data for it, and a private key that never leaves the device. The parties then use those keys to agree on shared keys that encrypt the actual content, often rotated per message or per session so that one leaked key does not expose everything.

Well-known implementations:

What end-to-end encryption is not

The word "encrypted" appears on almost every security page, and most of the time it means something narrower.

Term Who holds the key Can the provider read the content?
Encryption in transit (TLS) The provider's servers Yes, once it arrives
Encryption at rest The provider Yes, whenever its systems need it
End-to-end encryption Only the participants' devices No

Encryption in transit protects data on the way between your device and the server. Encryption at rest protects it on the server's disks from someone who steals the hardware. Both are useful, and both leave the provider able to read everything, because the provider decrypts the data to show it, search it or process it. For meeting notes specifically, we walk through what that means in are AI meeting notes encrypted.

Four ways to check a vendor's E2EE claim

A real end-to-end design has visible consequences. You can test for them without reading any cryptography:

  1. Password recovery. If support can restore your content after you forget your password, the provider has a key. WhatsApp states plainly that if you lose the password or 64-digit key of an encrypted backup, it cannot restore the chats for you — that is what the real thing looks like.
  2. Server-side search and web access. Full-text search across your content on the server, or reading it in a browser with no key on the device, both require the server to see plaintext.
  3. Key verification. Mature E2EE products let you compare keys with the other party. Signal shows a safety number for each one-to-one chat that you can compare in person or scan as a QR code.
  4. Removing a member. In a shared space, "access revoked" is an access-control answer. "Keys rotated" is a cryptographic one: new content is encrypted with keys the removed member never received.

What end-to-end encryption does not protect

E2EE also depends on law and policy around it. Since February 2025, Apple has not offered Advanced Data Protection to new users in the United Kingdom after a government demand under the Investigatory Powers Act, and Apple's legal challenge was still pending when this entry was written on 28 September 2026.

E2EE in Speak-Y

In Speak-Y, audio is deleted after processing, transcripts stay on your device by default, and sync between your own devices is end-to-end encrypted. Sharing into a team knowledge base uses the same model: channel keys exist only on the team's devices, and removing a member rotates them. The full data handling is described in the privacy policy.

For how this plays out when a team shares meeting notes — who can read what, and what changes when someone leaves — see the team knowledge base guide.

FAQ

What is end-to-end encryption in simple terms?

End-to-end encryption (E2EE) is a way of protecting data so that it is encrypted on the sender's device and can only be decrypted on the devices of the intended recipients. The keys never leave those devices, so the service that stores or relays the data sees only ciphertext and cannot read the content, even if it wants to.

Is encryption at rest the same as end-to-end encryption?

No. Encryption at rest protects data on the provider's disks with a key the provider holds, so the provider can decrypt the data whenever its systems need it. End-to-end encryption means the provider never has the key at all. A service can truthfully say "encrypted" about both, which is why the word alone tells you little.

How can I tell if a service is really end-to-end encrypted?

Ask whether support can restore your data if you forget your password. If it can, the provider holds a key and the content is not end-to-end encrypted. Other signs of a real E2EE design: no server-side search over your content, no way to read it in a browser without key material, and a way to compare keys with the other party, like Signal's safety numbers.

What does end-to-end encryption not protect?

It does not hide metadata such as who communicated with whom, when and how much. It does not protect content on a compromised or unlocked device, where the plaintext is available. And it does not stop a legitimate recipient from copying, forwarding or screenshotting what they received.

Why do AI features stop working when end-to-end encryption is on?

Because the machine that transcribes or summarizes content has to read it in plaintext. Zoom's end-to-end encrypted meetings, for example, disable Zoom's AI features, cloud recording and live transcription, since the meeting keys are generated by participants' machines rather than Zoom's servers. AI and E2EE can coexist only when the AI runs on a device that already holds the key.