The Short Version
- Features are a commodity. What separates these suites is what the provider can still decrypt on its own servers.
- Apple end-to-end encrypts 15 data categories by default and 25 with Advanced Data Protection on, but iCloud Mail, Contacts and Calendars sit outside both tiers, and some metadata stays under Apple-held keys.
- Proton end-to-end encrypts mail between Proton accounts, but mail to non-Proton addresses uses SMTP TLS instead, and subject lines are never end-to-end encrypted, even Proton to Proton.
- Google documents client-side encryption only for named Workspace business and education editions; Gmail's own documentation lists TLS for all Gmail accounts.
- Microsoft documents OneDrive Personal Vault as an authentication step plus local BitLocker, not as a design that puts files beyond it.
What "encrypted" actually means
Every suite here calls itself encrypted, and every one is telling the truth. The word covers at least three arrangements that give the provider very different amounts of access. Encryption in transit (usually TLS) protects the connection between a device and a server; it stops interception on the wire but says nothing about what happens next, since the server receives readable content. Encryption at rest under provider-held keys protects stored data against disk theft or a leaked backup, but the provider keeps the keys and can produce plaintext when a court tells it to. End-to-end or client-side encryption keeps the keys on user devices, so the server holds ciphertext it cannot open.
Proton adds a fourth term for inbound mail re-encrypted to the account key on arrival: "All messages and attachments in your Proton Mail inbox are secured with zero-access encryption."[3] That sits above provider-held keys and below end-to-end.
What each suite places beyond the provider
| Suite | End-to-end encrypted | Requires an opt-in or a specific edition | Not documented as beyond the provider |
|---|---|---|---|
| Apple iCloud | 15 categories by default, including Passwords and Keychain, Health, Messages in iCloud and Safari history | 25 categories with Advanced Data Protection on, adding iCloud Backup, iCloud Drive, Photos and Notes | iCloud Mail, Contacts and Calendars at both tiers, plus metadata under Apple-held keys |
| Proton | Mail between Proton accounts; Drive files, folders and file names | Nothing cited here sits behind a setting the user must find | Subject lines on every message; mail to non-Proton addresses, which uses SMTP TLS |
| Client-side encryption, described as encryption "that Google servers and third parties can't decrypt" | Named editions only: Frontline Plus, Enterprise Plus, Education Standard, Education Plus | Consumer Gmail, where the documented option is TLS; S/MIME and CSE are listed for work or school accounts | |
| Microsoft | Not documented on the pages cited | Customer Key, enterprise-scoped, keys held in Azure Key Vault | OneDrive Personal Vault, documented as authentication plus local BitLocker |
One clarification the table cannot carry: customer-managed keys are not end-to-end encryption, because the service still decrypts data to index and render it.
Apple: two tiers, and the categories outside both
Apple runs iCloud in two modes. "Standard data protection is the default setting for your account", under which only some data is end-to-end encrypted.[1] With the optional Advanced Data Protection, trusted devices retain sole access to the keys for most iCloud data, taking the count from 15 end-to-end encrypted data categories to 25 and pulling in iCloud Backup, Photos and Notes.[1]
Two details deserve more attention. Three everyday categories are excluded at both tiers: "iCloud Mail does not use end-to-end encryption because of the need to interoperate with the global email system", while contacts and calendars "are built on industry standards (CalDAV and CardDAV) that do not provide built-in support for end-to-end encryption".[1] The strongest setting Apple offers changes none of that.
Then the metadata caveat. "Some metadata and usage information stored in iCloud remains under standard data protection, even when Advanced Data Protection is enabled", and Apple is explicit about the consequence: "This metadata is always encrypted, but the encryption keys are still stored by Apple."[1] The examples are the useful part: a backup's device name, model and serial number, the apps it contains, and for iCloud Drive the file name, type and dates. Names and timestamps describe a life well without a byte of content.
The default tier has a bright spot: Passwords and Keychain are end-to-end encrypted before any opt-in, which puts Apple's credential store alongside the tools in the password manager comparison.
Proton: strong defaults with two documented edges
Proton's claim for mail is direct: "With Proton Mail, emails are encrypted at all times, so we can never access your messages."[2] For Drive, the claim covers names as well as contents: "no one, not even Proton, can access your files and folders or see their names without your permission".[4] That closes the gap Apple's metadata note leaves open, and it is why Proton Drive does well in the encrypted cloud storage comparison.
Two limits are documented by Proton and easy to miss, because the marketing does not lead with them. The first is the recipient boundary. Mail between Proton accounts is end-to-end encrypted by default, but "emails to non-Proton Mail accounts are protected with a different kind of encryption called SMTP TLS".[2] That is transport encryption to another company's server, whose access model then applies. A message to a Gmail address is a Gmail message, so a private mailbox secures half the conversation, the recurring finding of the encrypted email comparison.
The second is the subject line. "Subject lines in Proton Mail messages are not end-to-end encrypted to remain compliant with standards and ensure interoperability", and the reason is structural: "In PGP, the subject line is part of the header packet, which is not end-to-end encrypted."[3] This applies to every message, including Proton to Proton. The same page gives the mitigation in both directions: reaching a subject line is "exceptionally difficult for a third party" and "would require a court order that is approved by a Swiss judge", and readers can "use generic subject lines that disclose minimal information".[3] Where the subject itself would be sensitive, the tools in the secure messaging comparison are a better container.
Google and Microsoft: the strong option is somewhere else
Google does offer client-side encryption, described in the terms a privacy-focused reader wants: it "helps to keep your organization's data private with end-to-end encryption that Google servers and third parties can't decrypt". The same page lists who can have it: "Supported editions for this feature: Frontline Plus; Enterprise Plus; Education Standard and Education Plus."[8] For an individual account, Gmail's documentation sets the tier by section. One is headed "Transport Layer Security (TLS): Standard protection for your emails" and labelled "Available for: All Gmail accounts", while the S/MIME section, which lists client-side encryption among its key-management options, is labelled "Available for: Work or school Gmail accounts".[9] No consumer end-to-end option appears on the pages cited here.
Microsoft's consumer story runs the same way. Personal Vault is "a protected area in OneDrive that you can only access with a strong authentication method or a second step of identity verification", with files "encrypted using BitLocker when in use locally on a Windows 10 PC".[10] That is access control plus local disk encryption; neither statement describes a key Microsoft does not hold, and the page does not document the vault as provider-blind. Stronger key control sits elsewhere: Customer Key "is available for Exchange, SharePoint, OneDrive, Teams files, and Windows 365 Cloud PCs".[11] That document scopes itself to "Customer data within Microsoft's enterprise cloud services", so it covers the enterprise offering.
Who can be compelled
Encryption models matter most when a legal order arrives, and the useful question is not how many orders a provider receives but what an order can reach. It reaches whatever the provider holds keys to, which for Apple includes iCloud Mail, Contacts and Calendars, and for a personal Google account includes mail content. Proton's stated limit is jurisdictional as well as technical: "Proton Mail does not give data to foreign governments; that's illegal under Article 271 of the Swiss Criminal code."[6] Those are two different protections that fail in different ways, and a reader should know which one they are relying on. Proton publishes a transparency report with its own annual figures.[5] Its contents load in the browser rather than in the page source, so read it directly rather than through any summary, including this one.
The Proton questions readers keep asking
The 2021 French activist case. After a Swiss order routed through Europol from French police, Proton logged and disclosed a user's IP address, and the person was arrested. Proton's account, published on 6 September 2021, was that "Proton received a legally binding order from Swiss authorities which we are obligated to comply with. There was no possibility to appeal this particular request." It also drew a boundary: "Under no circumstances can our encryption be bypassed, meaning emails, attachments, calendars, files, etc. cannot be compromised by legal orders."[6]
The follow-up matters as much as the incident. The same page carries an update: "In October 2021, Proton won a Swiss court ruling that email services are not telecommunications providers. Consequently, email services are not subject to the data retention requirements imposed on telecommunications providers and are exempted from handing over certain user data in response to Swiss legal orders."[6] The case shows that connection metadata is a separate surface from message content, and the retention position changed after it.
The January 2025 political comments. Reported by The Intercept on 28 January 2025, Proton's chief executive Andy Yen posted on X praising the Republican Party's stance on antitrust relative to Democrats. Proton's official Reddit account then briefly posted, and deleted, a comment reading: "Until corporate Dems are thrown out, the reality is that Republicans remain more likely to tackle Big Tech abuses." Proton told the outlet that "Our policy is that official accounts cannot be used to express personal political opinions. If it happens by mistake, we correct it as soon as we notice it", and Yen said the policy going forward would be to "share no opinions of a political nature".[7] This was a communications episode, not a change to a documented encryption model.
How to run this comparison on any suite
The method generalises. Open the provider's own security page and answer four questions from it rather than from the marketing site: which categories are named as end-to-end encrypted, and are any off by default; which are named as excluded; what it says about metadata, file names and headers as distinct from content; and which tier or edition each claim is attached to, since a claim written for administrators often does not apply to an individual account.
Answer those and the suites separate cleanly. Apple's end-to-end coverage is genuine, has to be switched on, and still stops short of mail, contacts and calendars. Proton's is on by default, with two boundaries it documents openly. Google's strongest option is edition-gated, and Microsoft's consumer vault is an authentication feature. Category-level detail sits in the privacy tool comparison hub; the suite decision is which access model a person will live inside.
Sources
- Apple Support, iCloud data security overview. Published 5 January 2026.
- Proton, Proton Mail security. No date stated.
- Proton Support, Proton Mail encryption explained. No date stated.
- Proton, Proton Drive security. No date stated.
- Proton, transparency report. Updated 6 January 2026.
- Proton, climate activist arrest and October 2021 update. Published 6 September 2021.
- The Intercept, on Proton chief executive Andy Yen's political comments. Published 28 January 2025.
- Google Workspace Admin Help, client-side encryption. No date stated.
- Gmail Help, email encryption options. No date stated.
- Microsoft Support, OneDrive Personal Vault. No date stated.
- Microsoft Learn, encryption in the Microsoft cloud. Last updated 26 September 2025.