Encryption at rest, end-to-end encryption and "zero knowledge" mean very different things. A practical guide for UK and EU teams evaluating a document collaboration tool under the GDPR — including the questions we think you should ask us.
If you are replacing Google Docs for security or compliance reasons, you will quickly notice that every vendor’s marketing page says roughly the same thing. Bank-grade encryption. Enterprise security. GDPR compliant. The words are cheap, and — as we will show with our own product below — they are frequently used loosely.
This is a guide to the questions that actually separate vendors, written by a team that had to answer them. We have deliberately included the answers where CollaboPoint does not come out ahead, because a security evaluation built on marketing copy is worse than no evaluation at all.
This is the question where most confusion lives, and the distinction matters enormously for your threat model.
Encryption in transit (TLS/HTTPS) protects data moving between your browser and the server. Every credible vendor has this. It is table stakes, not a differentiator, and a vendor leading with it is telling you something.
Encryption at rest means your data is stored encrypted on the provider’s disks. It protects against a stolen drive or an improperly disposed server. Crucially, in most implementations the provider holds the keys — which means the provider can decrypt your content, and so can anyone who legally compels the provider.
End-to-end encryption (E2EE) means content is encrypted on your device with keys only you and your collaborators hold. The provider stores ciphertext it cannot read. This is a genuinely different security property — and it is rare in collaborative document tools, because real-time multi-user editing, server-side search and link previews are all hard or impossible when the server cannot read the content.
Where CollaboPoint stands: chat messages are encrypted at rest with AES-256-GCM, and the workspace keys are held and managed by us. That means this is encryption at rest, not end-to-end encryption — we can technically decrypt workspace content, and we would be obliged to comply with a valid legal order. If your threat model requires that your provider mathematically cannot read your data, you need a true E2EE product, and you should not choose us on that basis.
Ask every vendor the same question in this exact form: “Can you, the provider, technically decrypt my content? If served a lawful order, could you produce it in readable form?” A straight answer tells you more than any certification badge. Be wary of “zero knowledge” used as a synonym for “we take privacy seriously” — it has a specific technical meaning.
Under the UK GDPR, transferring personal data outside the UK requires a valid transfer mechanism — usually the UK International Data Transfer Addendum alongside the EU Standard Contractual Clauses. This is not a blocker; it is paperwork you need to have actually done.
Where CollaboPoint stands: our primary datastore currently runs in Google Cloud’s us-central1 region — that is, the United States, not the UK or EU. Transfers are covered by SCCs plus the UK addendum with our sub-processors. If your procurement policy or sector regulator requires UK or EU data residency, that is a genuine reason to rule us out today, and we would rather you learn it here than three weeks into a pilot.
For many UK small businesses, US hosting under SCCs is entirely acceptable — it is what most of the SaaS they already run does. For a public-sector body, a healthcare provider handling patient records, or a firm with a contractual residency clause, it is not. Know which you are before you shortlist.
Your document tool is never one company. It is a hosting provider, an email relay, a video infrastructure provider, a payment processor, and increasingly one or more AI providers. Under Article 28 of the GDPR you need to know who they are, and you are entitled to a list.
Ask for the sub-processor register. If a vendor cannot produce one quickly, they have not done the compliance work, whatever the website claims. Ask specifically about AI: if the product has an AI assistant, which provider processes the prompts, and are the prompts used for model training? For most business use the answer needs to be no.
Export is a security question, not just a convenience one. A tool you cannot leave is a tool that can raise its price indefinitely, and a dataset you cannot retrieve is a continuity risk.
Test this during the trial, not at renewal. Export a document with real formatting — tables, images, comments — and open it elsewhere. Ask how long data is retained after account deletion, and whether backups are purged on the same schedule. Many vendors delete your live data promptly and keep backups for another thirty days; that is usually fine, but you should know it rather than assume it.
Almost every tool supports MFA. The question is whether an administrator can require it for everyone, because optional MFA protects only the people who were already careful. Ask whether enforcement is available on the tier you are buying, or only on an enterprise plan several times the price.
The same applies to offboarding. When someone leaves, how many places must an admin visit to revoke access? Every additional console is a chance for a forgotten account — which is, in practice, how a great many small-business breaches actually begin.
ISO 27001 and SOC 2 tell you an organisation has documented processes and had them audited. They are meaningful, and they are also expensive enough that early-stage vendors often lack them while still being competently run.
Read what the certificate actually covers — scope statements are often narrower than the badge implies. And treat an unaudited security page as what it is: a set of claims. Ask for evidence.
Where CollaboPoint stands: we are not ISO 27001 or SOC 2 certified today. We maintain an ISMS documentation set, a sub-processor register, a risk register and an incident response plan, and we publish a security policy and GDPR page. If your procurement requires a certificate, we will not pass that gate yet.
Send this to every vendor on your shortlist, including us. The replies are more informative than any comparison table:
If you need true end-to-end encryption or guaranteed UK data residency, CollaboPoint is not the right tool for you today, and we have said so plainly above rather than burying it. If what you need is a single workspace where documents, chat and calls live together, with encryption at rest, enforceable MFA and documented GDPR processes, that is what we have built — and you can test every claim on this page in the free tier before speaking to anyone.
Whatever you choose, choose it on answers rather than adjectives. The vendor that tells you where it falls short is usually the one telling you the truth about everything else.
Read our security policy
Every claim in this article is documented on our security and GDPR pages — including the limitations.
View security policy© 2026 TranSecure Consulting Limited · CollaboPoint. Back to home