E2EE definition
End-to-end encryption (E2EE) is a communication method in which data is encrypted on the sender's device and can only be decrypted on the recipient's device. The service provider and any intermediaries see only ciphertext, so they cannot read messages or files even if their servers are compromised. Signal and WhatsApp use E2EE for messaging.
How does end-to-end encryption work?
Each user has a key pair generated on their own device. The private key never leaves the device, while the public key is shared through the service. When Alice messages Bob, her app uses Bob's public key, often combined with her own keys through a key agreement protocol, to derive encryption keys. The message is encrypted before leaving her phone, travels through the provider's servers as unreadable ciphertext, and is decrypted only on Bob's device.
Modern protocols such as the Signal Protocol add forward secrecy, generating new keys for each message so that a key compromised today cannot decrypt past conversations. Group messaging and multi-device support add further complexity, handled with protocols like Sender Keys or the IETF Messaging Layer Security (MLS) standard. Implementing these protocols correctly is difficult, which is why most apps rely on audited libraries.
E2EE vs encryption in transit
Standard HTTPS or TLS encrypts data between your device and the server, but the server decrypts it to process and store it. The provider, anyone who compromises its servers, or anyone with legal access can read the content. With E2EE, the server only relays and stores ciphertext. Both are valuable, but they protect against different threats, and E2EE is the only one that keeps the provider itself from reading user content. Many products use TLS everywhere and add E2EE only for the most sensitive content.
Examples of end-to-end encryption
End-to-end encryption has moved from niche security tools to mainstream consumer products. It appears in messaging, calling, file storage and backup services, and some providers apply it by default while others offer it as an option users must enable. Common examples are listed below.
- Messaging apps such as Signal, WhatsApp and iMessage.
- Encrypted email services such as Proton Mail between their users.
- Video calling with E2EE options in tools like FaceTime and some Zoom meetings.
- Password managers that encrypt vaults with keys derived from the user's master password.
- Cloud storage with client-side encryption options.
Limitations and trade-offs
E2EE protects content, not everything. Metadata, such as who talked to whom and when, may still be visible to the provider. Endpoints remain vulnerable: malware on a phone can read messages after decryption. Because the provider cannot read data, server-side features such as search, content moderation, spam filtering and AI summaries become harder to build. Key recovery is another challenge, since losing all devices and backups can mean losing access to data permanently. Users should understand these limits.
When should an application use E2EE?
E2EE fits products where users expect the provider never to see content: private messaging, health or legal communications, sensitive document sharing and personal vaults. It requires careful design of key management, device verification, backups and multi-device support, preferably using established libraries rather than custom cryptography. Nexzem advises clients on whether E2EE fits their product and implements it with proven protocols when it does.