Encryption can protect data in transit or at rest, depending on how a system is designed. The endpoints, key management, and access controls determine where that protection begins and ends.

Transport encryption protects a connection. It does not, by itself, prevent the receiving service from reading or storing the data. End-to-end designs have a different model and still depend on their endpoints.

Ask the precise question: who can access the information in this particular system? That answer is more useful than treating the word “encrypted” as a complete description.

A few starting points
  1. Identify the endpoints.
  2. Check which parties hold access or keys.
  3. Distinguish transport protection from stored-data handling.

An example to consider.

Consider an encrypted document opened on a shared display. Protecting the stored file does not decide who can read the visible contents after it opens.

Put it in perspective.

Look for a clear ending as well as a clear beginning. Removing a permission, leaving a session, and deleting a copy should be understandable actions.

Follow a related question

Review access for one application.

Review permissions after the task

Assign colors to clear roles.

A palette with a few clear roles

Keep learning

Related background to continue exploring this subject.

MDN: privacy on the web MDN: web security
Make room for ideas