Security help
A practical guide for using E2EE without confusing users or leaking encrypted content into normal screens.
If all passphrases, trusted devices, and recovery keys are lost, encrypted content cannot be decrypted by the server. Admins should register recovery keys, verify trusted devices, and keep at least two authorized admins able to unlock required scopes.
Set company E2EE to Recommended so teams can unlock scoped keys and migrate active work.
Run the plaintext scanner from Company Security and migrate sensitive findings in batches.
Invite members, register trusted devices, and distribute scoped key wraps before requiring E2EE.
Verify browser-side decrypted exports, encrypted backup artifacts, and secure deletion reporting.
Turn on Required mode for the company or project once active users can unlock their devices.
Use the security coverage report to confirm plaintext sensitive records are falling toward zero before Required mode is enabled.
Use browser-side exports for decrypted PDFs, PNGs, JPGs, and task backups. Server exports intentionally show locked labels.
Use the secure deletion report after deleting files to confirm object storage removal was verified and retained metadata is audit-only.