Skip to content

End-to-end encrypted calls, explained

The QuiC team · · 3 min read

What "end-to-end encrypted" actually means for a voice or video call, how QuiC does it with a media server in the middle, and what it does not cover.

"Encrypted" appears on almost every calling product's website. It can mean very different things. This post explains the difference, and exactly what QuiC does.

Encrypted in transit is not end-to-end

Almost every modern call is encrypted in transit: the audio and video are encrypted between your device and the provider's server, and again between the server and the other people on the call. That stops someone on the same Wi-Fi from listening in. But the server in the middle decrypts the media to route it, so the provider can technically see and hear the call.

A call is end-to-end encrypted when only the people on the call hold the key. The provider's servers still carry the media, but they can't decrypt it.

The problem with group calls

In principle a one-to-one call can go straight from device to device. Group calls can't really: sending your video separately to each of ten people would melt your phone's upload. So group calls go through a media server (an SFU, selective forwarding unit) that receives one copy of your video and forwards it to everyone else.

Traditionally that server decrypts the media. End-to-end encryption for group calls means encrypting each audio and video frame on your device before it leaves, so the server forwards frames it can't read.

How QuiC does it

QuiC's one-to-one and group calls are end-to-end encrypted on current apps:

  1. A fresh key for every call. When a call starts, a random 32-byte key is created for that call only.
  2. Delivered over Signal. The key is sent to each participant's devices inside a message encrypted with the Signal Protocol, the same end-to-end encryption that protects QuiC messages. QuiC's servers relay that envelope but can't open it.
  3. Every frame encrypted. Each audio and video frame is encrypted with AES-GCM on the sending device, using that key. The media server forwards the encrypted frames; it can't decrypt them.

The in-call badge says End-to-end encrypted only when your own connection has end-to-end encryption on and every other participant's audio and video is arriving encrypted. If not, it says Encrypted in transit, so you are never told a call is end-to-end encrypted when it isn't.

End-to-end encrypted calls need a current app: iOS and Android 1.0.90 or later, the current web app, or the Mac app 0.2.3 or later. Older versions are asked to update before they can join an encrypted call.

Meetings: a choice, made visibly

Meetings are different, because many teams want recordings, transcripts and AI notes, and those need someone other than the participants to process the media.

So each QuiC meeting is one of two kinds:

  • End-to-end encrypted. Same protection as calls. Guests joining by link get the key from the part of the invite link after the #, which browsers never send to the server. These meetings can't be recorded, transcribed or summarised; the server couldn't do it even if asked.
  • Recording & AI notes. Encrypted in transit and at rest, but not end-to-end: the media server can see the media, which is what makes recording and notes possible.

Admins set which kind is the default, or require end-to-end encryption for every meeting.

What end-to-end encryption doesn't cover

Being precise matters more than sounding impressive:

  • Call details. QuiC keeps who took part, when and for how long, so your call history works. That metadata is not end-to-end encrypted.
  • In-call chat and reactions sent over the meeting's data channel are encrypted in transit, not end-to-end.
  • AI features. Text you send to the AI assistant goes to our AI provider to be processed.
  • Organisation-controlled keys. On Enterprise, an organisation can keep a copy of its members' messages under its own key for regulatory reasons. That setting covers messages and files only, not calls or meetings.

The Privacy Policy sets out all of this in full.

Why this matters for your team

If your calls include customer data, deal terms, patient details or board discussions, "encrypted" should mean the provider can't listen. With QuiC, one-to-one and group calls are end-to-end encrypted by default, and every meeting tells you which kind it is.

See how this compares with other tools in QuiC vs Microsoft Teams and QuiC vs Slack, or see pricing.

More from the blog

Secure messaging, calls and AI for your team

Messages and one-to-one and group calls are end-to-end encrypted. Start a free trial or see pricing.