Skip to content
Knowledge

Encryption and privacy

Traffic is encrypted in transit. Content is encrypted at rest with server-managed keys, which means the relay operator can read it and eDiscovery reaches everything. Direct messages use gift-wrapped events at the protocol level but are not end-to-end encrypted in Buzz's operational model — the operator can read those too. End-to-end encryption is described as a future consideration.

Deletion soft-deletes: the message leaves the view, the event stays in the audit log.

Separately, prompts sent through shared compute are processed on other members' machines rather than by a vendor. See Buzz Mesh and where prompts go.

Why it matters to you

Buzz's vocabulary — signed, cryptographic, sovereign — makes it easy to conclude that messages are secret. They are not. What the cryptography establishes is who said something and that it has not been altered, which is a genuinely valuable and completely different property.

Conflating authenticity with confidentiality is the single mistake most likely to produce a real problem in professional work.

How to apply it

Assume the relay operator can read every channel and every DM, and design what you say accordingly.

Do not move a sensitive conversation into a DM believing that solves it — see Who can read my DMs?

If you operate the relay, be explicit with your members about what you can see, before they assume otherwise.

Never describe Buzz to a client or stakeholder as an encrypted or private channel without the qualification. Getting this wrong in a sales conversation is worse than getting it wrong in a technical one.

Remember that huddle speech is transcribed into the workspace, and that media uploads are readable by every channel member including agents.

If you ignore this

Where this understanding is absent, people put things in Buzz that they would never put in an unencrypted email — because the tool feels secure. The exposure begins at the first message and is discovered, if at all, much later.

Where it is present, the tool is entirely usable for professional work; you simply know which conversations belong elsewhere.

Examples

A signed letter on unsealed paper. Everyone can confirm you wrote it and that nobody edited it. The postman can also read it.

Someone moves a discussion of a client's contract terms from a channel into a DM "to be safe". The audience narrowed by two colleagues; the operator's access did not change at all.

Telling a client their material is "encrypted end to end in our workspace" because the product literature emphasises cryptography.

Verified against Buzz v0.5.20 · Updated 2 Sep 2026