What Microsoft Teams encrypts, what it can still read, and what changes when messages and files are sealed on the device before they ever reach a server.
Three private surfaces. Same zero-knowledge architecture.
Encrypted alternatives target a different threat: the platform itself, and anyone who can compel or compromise it. Both models are legitimate. They answer different questions.
This is not a criticism — it is a design requirement. Compliance search, retention, legal hold, DLP and Copilot-style features all require the service to read content. You cannot have server-side eDiscovery of message bodies and a server that cannot read message bodies.
That split is easier to defend to a compliance officer than an all-or-nothing swap, and it puts encryption where the risk actually lives.
Three private surfaces. Same zero-knowledge architecture.