Encryption can protect data in transit or at rest, depending on how a system is designed. The endpoints, key management, and access controls determine where that protection begins and ends.

Transport encryption protects a connection. It does not, by itself, prevent the receiving service from reading or storing the data. End-to-end designs have a different model and still depend on their endpoints.

Ask the precise question: who can access the information in this particular system? That answer is more useful than treating the word “encrypted” as a complete description.

A few starting points
  1. Identify the endpoints.
  2. Check which parties hold access or keys.
  3. Distinguish transport protection from stored-data handling.

Picture this situation.

Imagine sending a protected attachment to the wrong intended recipient. The protection and the recipient choice address different parts of the sharing decision.

A second way to look.

Information can travel further than its original purpose. Review the copies, attachments, and exports that may remain after the immediate task is finished.

Follow a related question

Write the next action before leaving.

Leave a note for your return

State the job and relevant input.

A prompt that states the work

Keep learning

Related background to continue exploring this subject.

MDN: privacy on the web MDN: web security
Look a little closer