ComplyChat Start free

Guide · Work messaging

Encrypted messaging for business

Most people choosing a messaging app for work start with one question: is it encrypted? It is a good instinct and the wrong place to stop. Almost every serious messaging service now encrypts messages somewhere, and the kind that matters most to privacy, end-to-end encryption, is also the kind that makes it hardest for an organisation to keep and produce what was said. This guide explains what end-to-end encryption protects against and what it does not, what the National Cyber Security Centre asks an organisation to check before it chooses a messaging service, and how a school, charity or care provider can weigh confidentiality against the record it is required to keep.

By ComplyChatPublished 13 minute read

A school business manager and the school's IT technician talking in a secondary school corridor in the afternoon, lockers behind them, the technician holding a closed laptop under one arm
01

Three kinds of encryption, and the one that decides who can read

In short

Encryption in transit protects a message on its way between a device and a server. Encryption at rest protects it on the server's disks. End-to-end encryption means only the devices at each end hold the keys, so the service in the middle cannot read the content at all.

End-to-end encryption is a strong defence against interception and against the provider. It does nothing about a lost or unlocked phone, a hijacked account, a screenshot or a member of staff who leaves, and it makes it much harder for the organisation to hold a copy of its own. Which of those matters more is a decision about your risks and your duties, not about the app.

Encryption turns a message into data that cannot be read without a key. The question that separates one messaging service from another is not whether it encrypts but where the keys are, and so who can read the content. There are three arrangements, and most business systems use two of them together.

  • Encryption in transit. The connection between your device and the service is encrypted, usually with TLS, the same protection a banking website uses. Nobody on the network in between, such as a café's wi-fi, can read the message. The service itself receives it and can read it.
  • Encryption at rest. The message is stored encrypted on the service's disks, so a stolen disk or a copied backup file is unreadable. The service still holds the keys and can decrypt the message to show it to an authorised user, search it or keep it.
  • End-to-end encryption (E2EE). The message is encrypted on the sender's device and can only be decrypted on the recipients' devices. The provider carries data it cannot read. Consumer messengers built on the Signal Protocol work this way by default, and so do some messaging platforms sold to organisations.

The National Cyber Security Centre (NCSC) does not tell organisations which product to use. Its secure communications principles set out seven things a service should do, starting with "Protect data in transit" and including "Provision for secure audit of the service", "Allow administrators to securely manage users and systems" and "Use metadata only for its necessary purpose". Its guidance on choosing an enterprise instant messaging solution asks organisations to assess "security features provided by the IM service. This includes end-to-end encryption and enterprise single sign on", and in the same breath reminds them that "regulated industries and public sector organisations may have additional strictures to comply with, including the need to audit communications between staff, or respond to Freedom of Information requests." Both halves of that sentence are the subject of this guide.

02

What end-to-end encryption protects against, and what it does not

End-to-end encryption solves a specific problem very well: the message cannot be read by anyone between the two ends, including the company that runs the service, an attacker who breaks into its servers, or anyone intercepting the traffic. For a journalist protecting a source, or anyone whose main risk is the provider or a state reading their messages, that is the property that matters most.

It is worth being precise about what it leaves untouched, because most of the incidents an organisation actually deals with sit in this list:

  • The phone itself. The message is decrypted on the device so that someone can read it. A phone left unlocked on a desk, a shared family tablet signed in to a work account, or a lost handset without a strong passcode exposes everything on it, encrypted in transit or not. Device security matters as much as the app: a passcode, an up-to-date operating system, whether iOS or Android, and an up-to-date app, and for organisation-issued mobile devices the management the NCSC's device security guidance describes.
  • A hijacked account. In March 2026 the NCSC published a warning, NCSC warns of messaging app targeting, describing attackers who "trick you into sharing login or account recovery codes", "add their own device to your account without you noticing" and "join group chats without detection". None of that breaks the encryption; it adds the attacker as another end. Its advice is two-step verification, checking the linked devices on the account and caution with codes and QR codes.
  • The people at the ends. A recipient can screenshot, forward or copy a message, and nothing in the cryptography prevents it. A group chat that has quietly grown to include someone who should not be in it is end-to-end encrypted to that person too.
  • Metadata. End-to-end encryption protects the content of a message. It does not in itself hide who messaged whom, when, from where and how often, which the service may still see and keep, which is why the NCSC's sixth principle is about metadata and why its enterprise guidance asks whether information about your use of a service is exposed "for monetisation or advertising purposes".
  • Backups. Messages backed up from a phone to a personal cloud account may be protected differently from the conversation itself, depending on the app and the settings the user chose. The NCSC lists "How does backup and recovery of messages work, if devices are lost or stolen?" as a question to ask of any service.
  • Leavers. When a member of staff or a volunteer leaves, the conversation leaves with their phone. The organisation has no account to close and no copy to keep.

None of this is an argument against end-to-end encryption. It is an argument against treating the word "encrypted" as the end of a security assessment. Open source code, independent audits by security researchers and a well-reviewed protocol tell you the encryption is sound; they tell you nothing about who is in the group, what happens on a lost phone or where the record is.

03

The trade-off: confidentiality from the provider, or a record the organisation holds

End-to-end encryption and a record held by the organisation pull in opposite directions, by design rather than through any one product. If the only keys are on the participants' phones, the only copies are there too, and a service that cannot read a message cannot file, search, keep or produce it. A service that can do those things holds a key, or the organisation's archive is itself one of the ends, so the useful question is who else can read the conversation, under what controls, and whether the people in it know. Our guide to choosing a messaging app with an audit trail works through that trade-off from the record's side.

For a school, a charity or a care service the record is rarely optional. A message that decides something about a person may have to be produced for a subject access request, a Freedom of Information request if the organisation is a public authority such as a maintained school or academy, a safeguarding review, an inspection or a tribunal. UK GDPR Article 32 also asks for the ability to restore access to personal data after an incident, not only to keep it confidential; our GDPR compliant messaging app guide works through that article and why end-to-end encryption answers only part of it.

That is also why the ICO's guidance on non-corporate communications channels says that where staff use instant messaging, "auto-delete options should be in line with the retention policies of your official systems": disappearing messages are sensible advice for a private individual, and a retention decision taken by default when they are used for work.

04

The questions to put to a supplier

The NCSC's enterprise messaging guidance recommends a simple sequence: identify the features your people need, draw up a shortlist that meets your business and regulatory requirements, and "conduct a security assessment of your potential Instant Messaging services, to ensure they comply with your requirements". Then write an acceptable use policy, so that staff are not left to pick their own. Evaluate usability as seriously as security: a secure messaging app that a volunteer on an old phone finds awkward will lose to the one already installed. The questions below turn its principles into things a school business manager, a charity's operations lead or a registered manager can ask and understand the answers to.

  1. Who can read a message once it has been delivered? The participants only, the provider, the organisation's administrators, or some combination. Ask for the answer in a sentence, not a list of ciphers.
  2. Where is it stored, and for how long? Which country the messages are stored and processed in, which sub-processors touch them, and whether the organisation sets the retention period or the product does.
  3. Who is in the conversation, and how is that controlled? How people are identified, who can add them, and how a leaver is removed. The NCSC's fifth principle, administrators securely managing users, is the one a consumer app cannot meet because there is no administrator.
  4. What happens when a phone is lost or stolen? Whether the account can be locked remotely, whether messages can be recovered, and whether anything useful is left on the device.
  5. Can the organisation produce a conversation? For a subject access request, a Freedom of Information request, a safeguarding review or a legal hold, without borrowing a member of staff's phone.
  6. Is there an audit trail of access? If administrators can read content, whether their reading is itself recorded, and who can see that record.
  7. What is the provider's business model? Whether information about your use of the service is used for advertising, and what the data processing agreement under UK GDPR Article 28 says the provider may do with your data.
  8. Are voice and video calls, file sharing and group chats covered by the same answers? They are often handled differently from text messages, and a third-party integration or bot added to a channel may see content the core service protects.

A supplier that answers the first question with "it's end-to-end encrypted" and the fifth with "yes, we archive everything" owes you an explanation of how both are true. Sometimes there is a good one, usually that the organisation's own archive is added as a participant, and sometimes the two claims are about different parts of the product.

A charity volunteer coordinator sits on a bench on a breezy seaside promenade, phone face down on her knee, talking with a colleague beside her
05

The realistic options for a school, charity or care service

Most organisations in these sectors are choosing between four arrangements, and each is right for someone.

  • The work accounts you already have. If every person who needs to be in the conversation already has a Microsoft 365 or Google Workspace account, the chat that came with it is encrypted in transit and at rest, managed by your own administrators and within reach of the organisation's own retention and search tools. For staff with work accounts talking to each other, this is usually the right answer and costs nothing more.
  • An end-to-end encrypted messenger for organisations. Several are sold to businesses, some with administration, single sign-on and optional archiving added. They suit an organisation whose main risk is the confidentiality of content from the provider, and they are worth assessing against the questions in section 04, especially how any archive works.
  • Consumer messaging apps on personal phones. Well encrypted, free and already installed, which is why staff groups form on them. The organisation controls nothing: not membership, not retention, not the copy. Ordinary SMS text messaging is not end-to-end encrypted either, and the NCSC's guidance observes that without formal guidance people may turn to "insecure methods of communication, such as SMS"; banning the consumer app without offering something better tends to move the conversation rather than end it.
  • A messaging service built to keep a record. Encrypted in transit and at rest rather than end to end, run so that the organisation, not each phone, holds the lasting copy, and honest with its users that the conversation is kept. This suits conversations the organisation must be able to produce, including those with people who have no work account.

Whichever you choose, the encryption is the easy part to verify and the least likely to fail. The parts that fail are the ones the NCSC keeps returning to: who is in the conversation, what happens when a device or a person leaves, and whether the organisation can find what was said when it needs to.

06

"Use Signal for anything sensitive" – the advice that loses the record

In many organisations the most sensitive conversations are moved to the most private app, with the best of intentions. A designated safeguarding lead tells colleagues to use an encrypted app for anything about a child. A care manager and her deputy discuss a staff allegation on their personal phones because it feels safer than email. A charity's trustees settle a difficult decision in a private group because nobody wants it in the shared inbox.

Each of those conversations is confidential in exactly the way end-to-end encryption promises. Each is also a record: of a concern, a decision, a judgement about a person. When a parent's subject access request, a Freedom of Information request, an inspection or a tribunal asks what was known and when, the organisation's copy of its most important conversations is on the phones of the people who had them, including any who have since left.

ComplyChat is built for the other side of that trade-off, and it is not end-to-end encrypted. Messages travel over an encrypted connection and are written into the record on the server as they are sent, and the working copy is encrypted at rest; messages are stored and processed in the UK. Everyone added to a channel is told it is on the record and can object or leave, and a mobile number verified by SMS is an identity, so a volunteer, a bank carer or a parent can be in a channel without a work account. On paid plans the lasting record files into the organisation's own Microsoft 365 once its tenant is connected, under its own retention rules and access controls. We do not claim that nobody can read the record: a usable record and one nobody can read are not the same thing. If your first risk is the provider or a hostile state reading your messages, an end-to-end encrypted messenger is the better tool, and ComplyChat is not it. ComplyChat Free is one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive; it is a way to try the experience, not to meet a retention duty.

A question for the next leadership meeting: of the conversations in which your organisation decided something about a child, a resident or a member of staff in the last term, how many could you produce tomorrow, and which app was each one in?

07

Official guidance and your next step

The NCSC's secure communications principles and its guidance on choosing an enterprise instant messaging solution are the starting points for the security assessment, and its messaging app advisory covers account takeover. The ICO's encryption guidance sets encryption within UK GDPR, and its guidance on non-corporate communications channels applies to schools and other public authorities. The Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018, and its last data protection provisions came into force on 19 June 2026, so check the date on any ICO page you rely on. Quotations here are from those pages as published on 25 September 2026.

This guide is general information for UK organisations, not legal or security advice for your circumstances. Your data protection officer, or whoever leads on data protection, should own the assessment.

One step to take this week: list the messaging apps your staff and volunteers actually use for work, not the ones the policy names, and for each write down who holds the copy of a conversation after it is sent. That list is the start of your NCSC assessment and of your retention schedule.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep, and we chose not to make it end-to-end encrypted because a record the organisation cannot read is not a record. We would rather you understood that trade-off and chose deliberately than bought the word "encrypted" and found the gap later.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Secure communications principles ncsc.gov.uk
  2. Choosing an enterprise instant messaging solution ncsc.gov.uk
  3. Device security guidance ncsc.gov.uk
  4. NCSC warns of messaging app targeting ncsc.gov.uk
  5. Non-corporate communications channels ico.org.uk
  6. Encryption guidance ico.org.uk