01 What "encrypted" usually means

When a service tells you your files are encrypted, they almost certainly mean two things: encryption in transit and encryption at rest. In transit means your files are scrambled while they travel over the network — standard HTTPS/TLS, the same thing protecting your online banking. At rest means the files are scrambled while they sit on the provider's disks. Both are real security, and both are genuinely worth having.
Here's the catch: the provider holds the keys. Google, Dropbox, Microsoft — they encrypt your files, but they also control the decryption. That means they can read your files to power search and previews, comply with a court order, respond to a data breach, or make decisions about your account. You're trusting their infrastructure and their intentions. For most people in most situations, that's a reasonable trade. But it isn't the same as only you being able to read your data.
02 What end-to-end encryption actually does
End-to-end encryption (E2E) moves the key out of the provider's hands entirely. Your device encrypts the file before it ever leaves — the service sees only ciphertext it cannot decode. When your recipient downloads it, their device decrypts it. The provider is a blind courier: it moves an envelope it cannot open.
This is what "zero-knowledge" means when cloud services use the term correctly. Proton Drive and Mega are two well-known examples that implement zero-knowledge storage: they store only encrypted data they have no means of reading, previewing, or handing over to a third party in readable form. If a government serves them a subpoena, all they can produce is scrambled bytes. Tresorit takes a similar approach for business file-sharing.
The practical difference is significant. With conventional cloud storage, a data breach at the provider can expose readable files. With genuine E2E, a breach exposes ciphertext — useless without keys the provider never had.
03 What E2E can't protect you from
End-to-end encryption is powerful, but it secures the pipe — not the endpoints. Three things can still go wrong.
A compromised device. Encryption protects data in motion and at rest on the server. On your own phone or laptop, files get decrypted for you to use them. If malware, spyware or an attacker has access to your device, they can read files at the moment you open them, before encryption applies. E2E didn't fail — it just can't help you there.
A leaked or weak password. Zero-knowledge services derive your encryption key from your password. Lose the password, lose the files — permanently, in many cases, because there's no backdoor. But a guessed or phished password hands an attacker the key just as surely. Strong, unique passwords and a second authentication factor are essential.
The other endpoint. End-to-end means you and your recipient. If your recipient's device is compromised, or they forward the file, or they use a weak password, the encryption did its job and the problem is still real. You secured your half of the conversation.
There's also a subtler issue: metadata. Even a perfectly encrypted file carries information around it — who sent it, when, to whom, how large it was. Most E2E services protect file contents; fewer protect metadata to the same degree. Worth knowing if the fact of communication is sensitive, not just the content.
E2E protects the file from everyone except you and the person you chose.
04 How to tell if a service is genuinely E2E
Look for "zero-knowledge" in the architecture documentation, not just the marketing page. Check whether the provider can reset your password without you — if they can, they hold a copy of your key, and the encryption isn't fully end-to-end. Proton publishes detailed technical whitepapers; Mega's architecture has been publicly audited. Scepticism is healthy: "encrypted" on its own tells you far less than you'd think.
For everyday file-sharing, standard cloud encryption is fine for most things. But for anything genuinely sensitive — legal documents, medical records, private communications — E2E isn't paranoia. It's the correct tool. The difference isn't whether your files are locked. It's who holds the key.
Named in this guide
Proton Drive
privacy-focused Swiss cloud storage with zero-knowledge E2E architecture
Mega
cloud storage service with client-side end-to-end encryption, founded in New Zealand
Tresorit
end-to-end encrypted file-sharing service aimed at businesses, based in Switzerland/Hungary
Dropbox
major US cloud storage provider; encrypted in transit and at rest, not zero-knowledge
Google Drive
Google's cloud storage; encrypted but Google holds decryption keys