01 · Glossary
What E2EE actually protects
The guarantee is precise.
- Messages, calls, and media between the two devices
- No one in the middle can read the content
- WhatsApp cannot read messages to serve ads or profiles
- Keys are stored on devices, not on Meta's servers
02 · Glossary
What E2EE does not protect
The limits matter for business trust.
- Backups are encrypted but not always end-to-end, depending on your settings
- Anyone with the unlocked phone can read the chat
- Screenshots and forwarding are outside encryption's scope
- The recipient's own tooling can store what it receives
03 · Glossary
Business tools and encryption
A shared inbox means the business holds the keys.
- API conversations are E2EE between the customer and the business's systems
- Agents with access see the conversation — that is the point of a team inbox
- Access control, roles, and audit logs are the security layer on top
- Opt-in records and compliance data should sit in controlled storage
04 · Glossary
What merchants should do
Encryption is baseline, not the whole security story.
- Control who holds agent access to the shared inbox
- Use roles so only needed staff see conversations
- Keep backups and exports protected
- Wutt runs role-based access, secure connections, and controlled data handling; see the security page for details
Last updated 5 August 2026
Common questions
Yes. Conversations are end-to-end encrypted between the customer's device and the business's systems.
Agents with access to the inbox see the conversation — that is how a team inbox works. Encryption protects the channel, not the people you authorize.
No. Encryption and compliance are separate: Meta can still act on reports and spam signals.
WhatsApp offers encrypted backups; settings decide the level. Keep business records in controlled storage regardless.