Encryption can protect data in transit or at rest, depending on how a system is designed. The endpoints, key management, and access controls determine where that protection begins and ends.

Transport encryption protects a connection. It does not, by itself, prevent the receiving service from reading or storing the data. End-to-end designs have a different model and still depend on their endpoints.

Ask the precise question: who can access the information in this particular system? That answer is more useful than treating the word “encrypted” as a complete description.

Try the idea in context.

Consider an encrypted document opened on a shared display. Protecting the stored file does not decide who can read the visible contents after it opens.

A thought for the next read.

A reassuring appearance does not explain every boundary. Ask what a particular safeguard covers, and which decisions still belong to the person using it.
A few starting points
  1. Identify the endpoints.
  2. Check which parties hold access or keys.
  3. Distinguish transport protection from stored-data handling.

Follow a related question

Keep labels visible during entry.

A form explains why it asks

Name the destination or action.

Links that explain the next step

Keep learning

Related background to continue exploring this subject.

MDN: privacy on the web MDN: web security
Take a reading break