Collaborate securely
An encrypted online whiteboard, explained clearly
Skedra Cloud offers two protection models: an end-to-end encrypted mode for confidential canvas content and server-managed AES-256-GCM encryption for compatible team and automation workflows.
Last updated: July 14, 2026
What does end-to-end encryption protect?
In E2EE mode, canvas content, Y.js updates, image content and live presence data are encrypted in the browser. The server stores and transports encrypted payloads but does not hold the board's plaintext key.
A share link or authorized user account needs access to the required key. Lost keys cannot simply be reconstructed by the operator; that limitation is part of the security model.
Which information remains visible?
End-to-end encryption does not hide every technical detail. Authentication, permissions, synchronization and billing require operational metadata. This can include user and board IDs, roles, timestamps, data volume or technical events.
A useful security assessment therefore separates content encryption from unavoidable operational data. The current privacy policy documents that boundary in more detail.
When is server-managed encryption useful?
Some workflows require server-side processing, integrations or recovery options. Skedra therefore provides a server-managed AES-256-GCM mode. It protects stored content while allowing controlled server-side features.
The choice is not a simplistic secure-versus-insecure switch. It is a trade-off between maximum content confidentiality and the functionality a workflow needs.
Frequently asked questions
Can Skedra read E2EE boards in plaintext?
In end-to-end encrypted mode, protected canvas payloads are encrypted in the browser and the server does not hold the plaintext board key.
Does E2EE hide all metadata?
No. Some technical and operational metadata for accounts, permissions, synchronization and service operation remains server-readable.
Can I choose the encryption mode?
Yes. When creating a cloud board you can choose between end-to-end and server-managed encryption.