How end-to-end encryption works
End-to-end encryption uses public-key cryptography. Each person has a pair of keys: a public key they can share with anyone, and a private key that never leaves their device.1
- Keys are made on your device. Your private key is created where you are and stays under your control.
- The sender locks the message. Their app fetches your public key and uses it to encrypt the message before it leaves their device.
- The service only relays. Servers pass along and store only ciphertext, without the keys to open it.
- You unlock it. Only your private key can decrypt the message, on your device.
In practice, the public key protects a fresh random key, and that key encrypts the message with a fast cipher. That combination is called hybrid encryption. Good systems also let you check that a public key really belongs to the person you think, so nobody can quietly swap in their own.2
End-to-end encryption vs other kinds
| Approach | Protected on the network? | Can the service read it? |
|---|---|---|
| Encryption in transit (TLS) | Yes | Yes, once it arrives |
| Encryption at rest, provider keys | Depends | Yes |
| End-to-end encryption | Yes | No |
Why it matters
If a service can read your messages, so can anyone who hacks it, any employee with the right access, and anyone who sends it a legal demand. End-to-end encryption removes the service from that list. A data breach exposes only ciphertext.
It is worth knowing what it covers. End-to-end encryption protects the content of a message. Depending on the system, details like who you talked to and when may still be visible to the service. And it protects messages in transit and in storage, not on a device that is already compromised.
Where you’ll see it
- Messaging apps, many of which now use it by default. Signal’s protocol, for example, now adds a post-quantum key exchange to its end-to-end encryption.3
- Email, through standards like OpenPGP and S/MIME,45 and through encrypted email services that handle the keys for you.
- Cloud storage and backups, where some services offer it as an option.
A newer concern is the quantum computer. Most end-to-end systems still rely on elliptic-curve keys that Shor’s algorithm could one day break, so messages recorded today could be read later. Post-quantum key exchange, such as ML-KEM, closes that gap.
End-to-end encryption in Secria
In Secria Mail, end-to-end encryption is on by default, on every plan, free included. Your keys are created on your device and only reach our servers encrypted, and every message in your mailbox is protected with ML-KEM-1024 and X25519, so it is post-quantum from the start. Stored mail sits under zero-access encryption.
Related terms
Sources
- Knodel, Celi, Kolkman and Grover, IETF, Definition of End-to-end Encryption (Internet-Draft).
- Signal, The X3DH Key Agreement Protocol, section on authentication.
- Signal, The PQXDH Key Agreement Protocol.
- IETF, RFC 9580: OpenPGP (July 2024).
- IETF, RFC 8551: S/MIME Version 4.0 Message Specification (April 2019).
Checked October 2026. Secria facts are from our Mail and VPN pages and the whitepaper.
Questions about end-to-end encryption
What does end-to-end encryption mean?
That a message is encrypted on the sender’s device and can only be decrypted on the recipient’s. Nobody in between, including the service, can read it.
Is end-to-end encryption safe?
It is the strongest protection widely available for messages. Its main limits are outside the encryption itself: a hacked phone, or details like who you contacted, which some services can still see.
Can the police read end-to-end encrypted messages?
Not by asking the service, because the service doesn’t have the keys. They would need access to a device at one end of the conversation.
What is the difference between end-to-end encryption and TLS?
TLS protects data between your device and a server, which then decrypts it. End-to-end encryption keeps data locked all the way to the recipient, so the server never sees it in readable form.