Email or messenger – in the end that is secondary. What matters is something else: the text must be encrypted before it leaves your own device.
If the content is already ciphertext, it does not help an attacker to intercept it along the way. This overview compares the common ways to get there.
If only the transmission channel itself encrypts – such as a messenger's built-in encryption – security depends on one thing: the correct implementation by the provider. If the text is encrypted beforehand, locally, the channel no longer matters afterwards.
Four independent stages. Each one is an obstacle on its own, together they form a system:
The program itself is protected as well. At least 12 characters, hardened with Argon2id – a method that deliberately consumes a lot of memory and computing time. A brute-force attack on this password? Simply not practical within a reasonable time.
Before the first secured communication with a contact, there is a handshake. After that, the session key is renewed automatically after every single message – forward secrecy. And every message can be decrypted only once, never a second time, nowhere – replay protection.
The same goal, five different ways to get there.
| Method | End-to-end encryption | Forward Secrecy | Runs via the provider's servers |
|---|---|---|---|
| PGP / GPG | ✔ Yes (static key) | ✘ No, unless an additional protocol is used | ✘ No (offline) |
| Online PGP tools | ✔ Yes | ● Depends on the provider | ✔ Yes |
| Signal / WhatsApp | ✔ Yes, by default | ✔ Yes | ✔ Yes |
| Telegram (standard chat) | ✘ No | ✘ No | ✔ Yes |
| Telegram (Secret Chat) | ✔ Yes, optional | ✔ Yes | ● Yes (relay) |
| RotorCrypt X | ✔ Yes, before every send | ✔ Yes | ✘ No (offline) |
With PGP/GPG and RotorCrypt X: no one. Encryption runs offline, on your own computer. In addition, the source code of PGP/GPG is publicly viewable.
With Signal, WhatsApp and Telegram it looks different. You trust the provider – that the method is sound and that no backdoor exists. Signal Foundation and Meta are US companies. And are therefore subject to the US CLOUD Act, which can give US authorities access to stored data. Regardless of where the server is actually located.
Signal, WhatsApp, Telegram: encrypt automatically, in the background, without any effort. PGP/GPG and RotorCrypt X require an intermediate step – encrypt the text, copy the ciphertext, only then send it. More effort. In return, independent of the channel.
For most everyday messages, a normal messenger is enough. But there are situations in which additional encryption, independent of the provider, is more than just a precaution:
RotorCrypt X specializes in text – only text. For files and folders there is RotorCrypt X-Files: compatible, with its own file vault, export as a self-extracting EXE and a password vault including a generator.
Locally, with a standalone program – PGP/GPG or RotorCrypt X, for example. Only then does the already encrypted text go on its journey, no matter through which channel.
Yes. Signal protocol, double ratchet – the session key is renewed after every message.
Only the optional Secret Chat. The normal cloud chat is stored on Telegram servers without end-to-end encryption.
Yes. GPG4Win with Kleopatra, for example – free and open source.
No, RotorCrypt X cannot. For that there is the compatible extension RotorCrypt X-Files, with a file vault.
Yes. US encryption software is subject to US export controls (EAR). Cuba, Iran, North Korea, Sudan, Syria – exporting there is restricted or requires a license.
No. China blocks WhatsApp, Telegram and Signal completely. Iran has blocked Telegram since 2018, Russia again since 2026. Pakistan and Thailand: temporarily. The situation changes, depending on the country and the political climate.