Data Rooms Providers Find a data room
VDR glossary · Security

What is end-to-end encryption?

Definition

End-to-end encryption (E2EE): Encryption in which only the sender and intended recipients hold the keys, so the service provider in between stores and relays data it cannot read itself.

How it works in a data room

Most data rooms encrypt files in transit and at rest, but the provider’s systems can still decrypt them to render previews, run search, apply watermarks or power AI features. A truly end-to-end design encrypts files on the uploader’s device and decrypts them only on an authorized viewer’s device, so the provider never sees plaintext. Some products offer this for specific folders or messages rather than the whole room. Others use customer-managed keys as a middle ground, where the provider can process content only while the customer allows it.

Why it matters in a deal

End-to-end encryption gives the strongest protection against a compromised provider, but it has costs. Server-side full-text search, OCR, automatic indexing, redaction tools and AI summaries generally need access to the content, so they become limited or unavailable. Buyers should be wary of marketing that uses the phrase loosely for ordinary transit encryption. Ask exactly who can decrypt what, and which features stop working when the strictest mode is switched on.

Example

A defense supplier sharing design files with one strategic partner chooses an end-to-end encrypted folder for the drawings and keeps the commercial documents in the normal room. The partner can open the drawings only on enrolled laptops. The trade-off is that the drawings are not searchable inside the room, which the engineers accept for that small, sensitive set.

Related terms