Which messaging apps are end-to-end encrypted? As of mid-2026, Signal, WhatsApp and Apple's iMessage encrypt conversations end to end by default, and Meta has rolled out default end-to-end encryption for personal chats on Messenger. Ordinary text messages (SMS) are not encrypted at all. The US Cybersecurity and Infrastructure Security Agency (CISA) puts it bluntly in its mobile communications best practice guidance: "SMS messages are not encrypted."

For a business in Canada or the US, the question matters because staff already use these apps to talk to clients, share photos of job sites and pass along account details. End-to-end encryption (E2EE) means only the people in the conversation can read the messages, not the app provider or anyone intercepting them in transit. This check covers where the common apps stand and what encryption does not protect.

Which messaging apps are end-to-end encrypted by default?

Four widely used apps encrypt one-to-one chats end to end by default, based on each company's own documentation. Signal says its conversations are always end-to-end encrypted. WhatsApp announced in 2016 that every message, photo, video, file and voice message is end-to-end encrypted by default, including group chats. Apple says iMessage "has always been end-to-end encrypted."

  • Signal: always end-to-end encrypted, for every message and call.
  • WhatsApp: end-to-end encrypted by default, including groups.
  • iMessage: end-to-end encrypted between Apple devices. Green-bubble messages to non-Apple phones are a different story (see below).
  • Messenger: in December 2023, Meta announced it was rolling out default end-to-end encryption for personal messages and calls on Messenger and Facebook.

Is texting between iPhone and Android encrypted now?

Increasingly, but not everywhere yet. On May 11, 2026, Apple announced that end-to-end encrypted RCS messaging was rolling out in beta for iPhone users on iOS 26.5 with supported carriers and Android users on the latest Google Messages. Encryption is on by default, a lock icon shows when a chat is protected, and Apple says it will be enabled over time for new and existing conversations.

RCS (Rich Communication Services) is the modern replacement for SMS. Google's help page on end-to-end encryption in Google Messages says RCS chats between Google Messages users are encrypted when both people have RCS turned on, and that end-to-end encryption "isn't available for SMS/MMS messages." In practice, if you do not see the lock icon, assume the message is not end-to-end encrypted.

Which popular apps are not end-to-end encrypted by default?

Plain SMS, Telegram's regular chats and Snapchat text chats are the common gaps. Telegram's FAQ says its Secret Chats use end-to-end encryption, while regular cloud chats are stored in Telegram's data centres so they can sync across devices. You have to start a Secret Chat on purpose to get E2EE.

Snapchat is partial. A 2019 Real World Crypto conference presentation by the team that built it described end-to-end encryption for one-to-one Snaps, and Snap's privacy pages describe password-protected encryption for Snaps saved to My Eyes Only. Those pages do not describe text chats as end-to-end encrypted. Our post on how secure Snapchat is covers its other privacy settings, including location sharing on Snap Map.

SMS is the weakest option. Our article on why SMS security codes are not as safe as you think explains why that matters for two-factor authentication, and CISA's guidance tells highly targeted individuals not to use SMS as a second factor at all.

What does end-to-end encryption not protect?

Encryption protects messages in transit. It does not protect a phone that is unlocked, lost or compromised, and it does not stop a scammer you are chatting with. Our post on mobile devices as a business security blind spot notes that a phone with access to email, business apps and authentication tokens is significant exposure if it falls into the wrong hands.

Three limits are worth explaining to staff:

  1. The endpoints: anyone holding an unlocked phone can read its chats. Screen locks and device encryption still matter.
  2. The person on the other end: E2EE does not verify intent. A message from an impersonated executive is still encrypted. Our guide to verifying requests against deepfake voice scams recommends confirming unusual requests through a different communication channel.
  3. Your records: conversations in personal messaging apps may sit outside the systems your business uses to keep and search records, which can matter for client disputes, regulated industries and departing employees.

What should a business decide about work chats?

Pick the channels on purpose instead of letting each employee decide. CISA's guidance, written for highly targeted officials but useful for anyone handling sensitive data, says to "use only end-to-end encrypted communications" and to look for apps with features like disappearing messages. For most businesses, the practical decision is narrower: which approved channels are used for client data and payment details, and which are off-limits.

  • Write down which apps staff may use for client conversations, and which they may not.
  • Never send passwords, banking details or ID documents by plain SMS.
  • Confirm payment changes by calling a number you already have, not one in the message.
  • Keep work conversations somewhere the business can retain them when an employee leaves.

What should US and Canadian business owners ask next?

The encryption facts are the same on both sides of the border, and so is the risk of client data scattered across personal chat apps. The question to ask your IT lead or provider is: "Which apps are our people actually using to talk to clients, and do we know what happens to those messages when someone leaves?" To see how your mobile and messaging practices compare with the rest of your security, take our free cybersecurity assessment. It covers 20 security areas in under five minutes.


This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Encryption features described are based on vendor documentation and public guidance available as of the date of publication, change frequently and may vary by app version, device, carrier and settings. Organizations should consult qualified cybersecurity professionals before setting communication policies based on this article.