Security help

End-to-end encryption guide

A practical guide for using E2EE without confusing users or leaking encrypted content into normal screens.

Help

What E2EE Protects

  • Chat message bodies
  • Project page bodies and comments
  • Task descriptions, comments, work-log notes, and custom field values
  • Task and page file bytes when uploaded with file E2EE
  • Company goals, discovery text, portal approval notes, invoice notes, and support/contact message bodies where E2EE is enabled

Metadata Still Visible

  • Project, task, page, invoice, and file titles
  • Assignees, reporters, owners, dates, status, priority, estimates, and billing amounts
  • File size, source, storage quota usage, and generic encrypted filename labels
  • Audit logs, access events, E2EE policy state, and security coverage counts

Lost Keys

If all passphrases, trusted devices, and recovery keys are lost, encrypted content cannot be decrypted by the server. Admins should register recovery keys, verify trusted devices, and keep at least two authorized admins able to unlock required scopes.

Rotate keys after membership changes or suspected exposure, then re-wrap keys for the remaining authorized devices.

Admin Rollout Checklist

1

Set company E2EE to Recommended so teams can unlock scoped keys and migrate active work.

2

Run the plaintext scanner from Company Security and migrate sensitive findings in batches.

3

Invite members, register trusted devices, and distribute scoped key wraps before requiring E2EE.

4

Verify browser-side decrypted exports, encrypted backup artifacts, and secure deletion reporting.

5

Turn on Required mode for the company or project once active users can unlock their devices.

Verification Points

Use the security coverage report to confirm plaintext sensitive records are falling toward zero before Required mode is enabled.

Use browser-side exports for decrypted PDFs, PNGs, JPGs, and task backups. Server exports intentionally show locked labels.

Use the secure deletion report after deleting files to confirm object storage removal was verified and retained metadata is audit-only.