Somewhere in your inbox sits a note from a bank or a payroll provider. A secure message is waiting for you, and here’s a link to go and read it. Your mailbox holds the notice. The message itself lives somewhere else, and everything you’ve ever connected to your mail sits on the far side of that gap.
- Five arrangements get called encrypted email, and only two of them put a message past the reach of the company running your mail. One question sorts all five, and it’s who holds the key, not how strong the encryption is.
- The kind a small firm meets most often has a provider holding the content and releasing it to whoever authenticates. Your mailbox gets a link. So does your archive, your own search, and any assistant you’ve connected.
- An assistant reaches exactly as far as your mailbox reaches. Google and Microsoft both write that limit into the documentation for their own AI products. So this is one of the few questions in the subject with a published answer rather than an assurance.
- That limit is also the price. Whatever keeps a vendor out of a message keeps your own software out too. So you decide message by message, and this page is about how.
Five arrangements and one sorting question
Ask who holds the key. The answer tells you what your software can do with a message. It also tells you what a subpoena or a breach would reach.
Encrypted on the way there. Transport encryption protects a message while it moves between mail servers. Google says it in one sentence: “All Gmail messages use TLS automatically. Think of TLS as a secure mail carrier for your messages.” (Google, checked September 7, 2026.) You already have this, and you got it for free. It covers the journey. Once the message lands it sits in your mailbox in readable form, which is exactly what makes it useful, and exactly why it leaves the question of who reads it later wide open.
Encrypted on the provider’s disks. Your mail sits encrypted at rest. The provider holds the key, because the provider has to hand you your mail when you sign in. Google describes client-side encryption as a further layer “in addition to the default encryption that Google Workspace provides” (Google, checked September 7, 2026), which tells you what the default layer is worth. It covers somebody walking out of a data center with a disk. Anyone who can sign in as you reads the mail the way you read it.
Held by a provider and released to whoever authenticates. Gmail confidential mode, Microsoft Purview Message Encryption, and every bank portal that sends you a notification instead of a message. The content is real, and it’s genuinely protected in transit and at rest. A company you didn’t choose holds it and decides who gets to see it. This is the category almost everybody means by encrypted email, and it’s the one that changes what arrives in your mailbox.
Encrypted with a key the provider does not have. Client-side encryption, S/MIME where the keys stay with you, PGP, and a per-message lock inside a mail app. Google draws the line itself, in the plainest language on any of its help pages. With hosted S/MIME, “Google securely manages a copy of your key,” and those messages carry a green lock. With client-side encryption, “Your organization holds the only copy of the key. Not even Google can open your briefcase,” and those carry a blue shield. Two features both called encryption, and one sentence tells them apart.
A locked file inside an ordinary message. A password-protected PDF or spreadsheet attached to a plain email, with the password sent some other way. Plain, free, and for most small firms the one piece of end-to-end encryption they’ll ever actually use. It’s also the arrangement the IRS recommends to tax preparers, which gets its own section further down.
The third arrangement is where the confusion lives, because from the outside it looks like the fourth. A sender who ticks a box marked encrypt has done something real. Usually they’ve handed the content to a provider, which is a different piece of work from taking it out of every provider’s hands.
Telling them apart without asking anyone
You can tell all five apart from your own screen. It takes seconds once you know what you’re looking at.
In Gmail, the icon beside the sender does it. A gray lock means standard transport encryption. A green lock means hosted S/MIME, where Google keeps a copy of the key. A blue shield means client-side encryption, where your organization holds the only copy. A red open lock means the message traveled in the open, and Google says so directly: “If you get a message with a red open lock icon, it means the message is unencrypted.”
In Outlook, a protected message announces itself with a banner naming the restriction. Usually that’s encrypt only or do not forward. The banner is a rights label, so it’s a statement about permissions rather than keys, and the section below is about what that means for anything reading on your behalf.
Then there’s the tell that works everywhere, with no icon involved. If reading the message meant going somewhere else, signing in again, or entering a code, the content was never in your mailbox. That’s the distinction with consequences you can feel.
When the message is not in the message
This is the part people discover by accident, usually while searching for something they’re certain they received.
Google is clear about what confidential mode delivers. “Gmail removes the message body and any attachments from the recipient copy of a confidential mode message. Gmail replaces message content and attachments with a link to the content,” and “Only the subject and link are sent, using SMTP.” Outside Gmail’s own interface, the documentation adds the consequence: “Third-party email clients display a link in place of the message content.” (Google, checked September 7, 2026.)
Microsoft’s version behaves the same way across a provider boundary. “Recipients of encrypted messages who receive encrypted or rights-protected mail sent to their Gmail and Yahoo accounts receive a wrapper mail that directs them to the encrypted message portal where they can easily authenticate using a Microsoft account, Gmail, or Yahoo credentials.” (Microsoft, checked September 7, 2026.) A wrapper mail is a message about a message.
Four things follow, and all four are about your own mailbox rather than artificial intelligence.
Your own search comes back empty, because the words were never in your mailbox to index. You can remember the message perfectly and still come up dry on every term in it.
Your backup or archive holds the wrapper. So a firm that believes it’s retaining its correspondence may be retaining a folder of expired links, and a professional inquiry is a bad moment to learn that.
The content can be withdrawn, or expire, while you still need it. That’s the feature working as designed for the sender. The copy you were relying on runs on a schedule somebody else set.
The protection is narrower than it sounds for the sender too. A camera gets around it, and Google says so: “While confidential mode can help prevent recipients from accidentally sharing emails, they can still take screenshots or photos of your emails.” (Google, checked September 7, 2026.)
The habit that covers all four is small. When something genuinely matters, open the portal message on the day it arrives and save the document into your own files. The link is a pointer, and your copy is the record.
What an assistant can reach
Here’s the useful part, and it’s documented rather than promised, which is rare in this subject.
An AI email tool reads through the connection you authorized at Google or Microsoft. What your mailbox holds is what the tool gets. That connection is the only route in, and it carries no key of its own. The tool opens what your own mail app opens, and stops where your mail app stops. So an assistant reaches as far as your mailbox reaches, and encryption that puts a message outside your mailbox puts it outside the assistant too.
Microsoft states the results for its own product plainly. “S/MIME protected emails won’t be returned by Copilot, and Copilot isn’t available in Outlook when an S/MIME protected email is open.” And for the locked-file case: “Password-protected documents can’t be accessed by AI apps unless they’re already opened by the user in the same app (data in use). Passwords aren’t inherited by a destination item.”
Then the sentence that proves the whole who-holds-the-key test, in the same document. Content encrypted under a key Microsoft manages on the customer’s behalf stays readable: “items encrypted with Microsoft Purview Customer Key or your own root key (BYOK) are supported and eligible to be returned by Copilot.” Strong encryption, enterprise key management, and the AI reads it anyway. The service can still get the key. Where a rights label is involved, a specific permission is the gate rather than the encryption, and Microsoft names it. “When the sensitivity label applies encryption, users must have the EXTRACT usage right, as well as VIEW, for the AI apps to return the data.” (Microsoft, checked September 7, 2026.) Microsoft’s privacy documentation puts the same lever in one line: “For content accessed through agents in Microsoft 365, encryption can exclude programmatic access, thus limiting the agent from accessing the content.” (Microsoft, checked September 7, 2026.)
Google publishes the same trade as a list of what stops working. With client-side encryption on, the body of the message and its attachments are sealed, and the features Google names as unavailable include “Google AI products” and “Smart features for Gmail” (Google, checked September 7, 2026). That’s the whole list, with a partial mode nowhere in it. The company that built both the encryption and the assistant keeps them off the same message.
Both companies are describing arithmetic rather than a shortcoming. Every vendor’s assistant sits in the same position. One that offered to summarize a message it can’t decrypt would be telling you something alarming about where the key went.
The one control here that is not a promise
Step back and look at what the rest of this subject is made of.
A retention schedule is a policy. A list of subprocessors is a disclosure. A commitment not to train on your mail is a contractual undertaking, and where your mail goes when AI reads it is a whole page about reading those documents carefully. A permission list is stronger, because your provider enforces it, and what to check before connecting your inbox is how to read one. Every item on that list rests on a company continuing to behave as it said it would, and on that company still being there next year.
Encryption where you hold the key is different in kind. It holds regardless of whether the vendor is honest, well run, solvent, or in business next year. It survives a change of ownership, a change of terms, a subpoena served on the wrong party, and a breach of the vendor’s own systems. It’s the one control in this entire subject that keeps working after trust fails. That’s why it earns this much space, even though most firms will use it on a small minority of their mail.
The cost is the same property, seen from the other side. A sealed message arrives as a lock and stays one. There’s no summary, no ranking against everything else that landed, no date lifted out into a task, and no finding it by searching your inbox for what you remember rather than the exact words. If your working method depends on a deadline getting noticed inside a long thread, sealing that thread takes the mechanism away, and catching the deadline hidden in a thread is the habit that stops working.
So the useful instruction is decide per message. Seal the handful where a stranger reading it would really cost you. Leave the rest where your tools can help. The sealed ones are yours to track, and that’s the trade you’re taking on.
What the envelope still gives away
Encryption covers the body of a message. The envelope travels in the open, and that’s the part small firms consistently miss.
Google states the boundary exactly: “The body of the email, including inline images and attachments, will have additional encryption. The header of the email, including subject, timestamps, and recipients, will not have additional encryption.”
So even on the strongest arrangement available, anyone with access to the mailbox learns who you corresponded with, when, how often, and what you called it. For a professional firm, that’s most of the sensitive fact. Say your firm exchanged eleven messages with a named company and its outside counsel over four days in March, under a subject line reading “restatement,” and that discloses the engagement whatever the bodies say.
The fix is free and it takes no software. Write dull subject lines. “Documents for your review” and “Following up on our call” carry the same information to the recipient and none to anybody else. It’s the cheapest privacy habit available, and it works on every message you send, sealed or plain.
What encryption is worth on paper
Two obligations and one relief. All three change what encryption is for. It becomes part of your file rather than a preference you hold.
The Safeguards Rule sets the standard, and names its own escape. A financial institution inside the rule must “Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest.” That definition reaches tax preparation firms and many bookkeeping and advisory practices. The same paragraph allows for reality. Where you determine encryption is infeasible, you may instead secure the information “using effective alternative compensating controls reviewed and approved by your Qualified Individual” (16 CFR 314.4(c)(3)). Notice the shape of that. The alternative is there, and it takes a named person to review and approve it, so somebody has to write the decision down. What the same rule does to your choice of supplier rather than your own controls is whether it is safe to use AI with client financial data.
The IRS is more specific, and more awkward. Publication 4557, Safeguarding Taxpayer Data, was revised June 2024. It tells tax professionals to “Send only password-protected and encrypted documents if you must share files with clients via email or use Secure File Transfer Protocol (SFTP) to transmit files instead of email,” and elsewhere that “If you must transmit sensitive data by email over the Internet, be sure to encrypt the data” (IRS).
Read those two passages beside Microsoft’s line about password-protected documents and the tension is complete. The guidance your own regulator gives you produces, by design, exactly the material your software can’t read. Follow it anyway, and plan for the blind spot now rather than meeting it in April.
Encryption is also what keeps a bad day from becoming a notification. California requires a business to disclose a breach to a resident “whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person,” and the word doing the work there is unencrypted. The duty extends to encrypted information only where the key or credential was taken too and could render the data readable (California Civil Code 1798.82). Breach notification is state law, so the exact wording that governs you follows where the people whose data it is live, rather than where your office is. The general shape is worth carrying anyway. Properly encrypted data with the key kept elsewhere is treated very differently from the same data in the clear, and the difference shows up as client letters you get to skip.
A rule a seven-person firm can actually keep
A policy that asks everyone to think about cryptography before every message gives way in a busy week. This one has four parts, and it holds through one.
Seal documents, not conversations. The client’s completed return, the payroll register, the bank statements, the settlement figures. Those go as a locked file, or through the portal your practice already runs. The message that says the file is coming stays ordinary, so your tools can still see the commitment, the date and the follow-up.
Send the passphrase down a different wire. A password in the same thread as the file it opens travels with the file, so whoever has the one has the other. Say it on a call, to a number you already had from a record that predates the message. That last clause defeats a whole family of fraud, and keeping suspicious mail away from AI is where it’s laid out.
Leave yourself a plain-text handle. This is the part almost everyone skips, and it’s worth the most. When you seal something, send or keep one plain line naming what it was and when it’s due. Your inbox can rank that line, remind you about it, and turn it into a task. It’s also the difference between choosing a blind spot and acquiring one.
Save portal messages into your own records on arrival. They expire, they get revoked, and your archive holds only the wrapper. Ten seconds now buys back an afternoon of reconstruction later. If chasing documents in and out of portals is most of your season, how to stop chasing client documents is the wider version of that problem.
One thing worth checking before you build any of this on a platform feature: the tiers. Google publishes the editions that support client-side encryption as Enterprise Plus, Education Plus, Education Standard and Frontline Plus, and hosted S/MIME on a similar list. On a standard business plan either one is a purchasing conversation rather than a setting. The locked-file method works on any edition, which is a large part of why it’s the one small firms actually use.
What Point can read, and cannot
Point is an AI email client, so all of this applies to a mailbox with Point connected. Two halves, and they land in different places.
- Point sees exactly what your mailbox holds. Point reads through the connection you authorized at Google or Microsoft. So a confidential mode message or an encrypted-portal wrapper arrives as what your mailbox holds: a subject and a link. Point files it, ranks it and reminds you about it. Point can’t summarize a body that never arrived. A password-protected attachment stays closed to Point for the same reason it stays closed to you until you type the password, and asking questions of your attachments and PDFs is where that boundary is drawn properly.
- There’s a lock in the composer, and it works per message. Point’s own inventory puts it in one line: “Lock a message end to end and it stays between you and the recipient. Not even Point can read it.” The message is sealed on your device before it leaves. Point’s servers carry it sealed. It opens on the recipient’s device, because that device holds the key. You make that call on the message in front of you rather than as a mode for the whole mailbox, which is the same shape this page has been arguing for throughout.
- The cost is stated rather than hidden, and it’s the cost this whole subject carries. A locked message shows a lock where the other rows show summaries. No summary, no fresh judgment about it, no task lifted out of it. Sealed means sealed. A product that offered you a summary of a message it couldn’t read would be describing a key it shouldn’t have.
- Everything else Point holds is protected the ordinary way, which is a different claim. The privacy policy lists “encryption in transit and at rest where supported” among the measures. Access controls, least privilege, token handling controls and human-access limits sit alongside it, and the terms carry the same list in the security annex. That’s the layer protecting the copy Point holds, and it’s the second and third arrangement from the top of this page. The fourth one is the composer lock, message by message. The same documents say plainly that “No method of transmission, storage, or processing is completely secure.”
- Held at the door and unreadable are two different states. A message from a sender with no history is set aside before anything reads it, and that’s a decision about trust. A sealed message is one the keys keep closed, and that’s a fact about cryptography. They sit next to each other in a list and they run on different mechanisms.
- How far Point goes on anything it can read is a separate setting. Point holds that per kind of action, and each kind arrives on review, so Point works the message up and leaves the decision with you. Setting how much your inbox does on its own is where the positions are argued out.
If your firm needs a written commitment about any of this before it proceeds, ask while you’re still a prospect, ask in writing, and the questions that get real answers out of a vendor is the list to send. The full inventory of what Point does with a connected mailbox sits on the benefits page.
Common questions
Can an AI email assistant read my encrypted emails?
It comes down to where the key is, and the answer is the same for every vendor. Transport encryption, storage encryption your provider can undo, or a rights label under a key the platform manages: in all three the assistant reads the message, because your mailbox reads it. If the message was encrypted with a key your provider never held, the assistant is shut out, and so is every other product. Microsoft documents both outcomes for its own assistant. S/MIME protected emails will not be returned by Copilot, while items encrypted under Customer Key or the customer’s own root key are eligible to be returned. That single contrast is the whole rule.
Is Gmail confidential mode end-to-end encrypted?
No. It’s a delivery arrangement. Google states that the message body and attachments are removed from the recipient’s copy and replaced with a link, that only the subject and link travel by SMTP, and that third-party clients show a link in place of the content. The content stays on Google’s servers, and that’s what makes expiry and revocation possible in the first place. It’s genuinely useful for keeping a message from being forwarded around casually, and Google notes that recipients can still take screenshots or photos regardless.
Why can my assistant not summarize the secure message from my bank?
Because your mailbox holds a notification with a link, and the content sits in the bank’s portal behind a sign-in. There’s no message there to summarize. This is the most common form of encrypted mail a small firm meets, and the one that quietly breaks the most. Your own search misses those messages too, and your archive holds the wrapper rather than the document. The fix is a habit: save anything you’ll need again into your own records on the day it arrives, while the link still works.
Should a small accounting firm encrypt client email?
Encrypt the documents, not the correspondence. IRS Publication 4557 tells tax professionals to send only password-protected and encrypted documents if files must go by email, or to use SFTP instead. The FTC Safeguards Rule requires encryption of customer information in transit over external networks and at rest, with alternative compensating controls only where a Qualified Individual reviews and approves them. Both rules are aimed at client documents, and both leave a message about a meeting time alone. Sealing everything is also the fastest way to lose the value of any tool that reads your inbox. So the workable line is documents sealed, cover notes plain, and passphrases sent by phone.
Does encrypting email mean I would not have to report a breach?
Sometimes, and it’s one of the strongest practical arguments for doing it. Breach notification is state law, so what governs you follows where the affected people live. The common structure exempts properly encrypted data, as long as the key stayed out of the same hands. California’s statute is written that way. The duty attaches to unencrypted personal information, and reaches encrypted information only where the encryption key or security credential was also acquired and could render the data readable. So keeping the key somewhere other than beside the data earns its keep.
The short version
- Ask who holds the key. Transport encryption, storage encryption and provider-held message protection all leave a company able to read your mail. A key your provider never held is what changes that.
- In Gmail the icon tells you which one you have. Gray is transport. Green is hosted S/MIME, where Google keeps a copy of the key. A blue shield means your organization holds the only copy. Red means the message traveled in the open.
- If reading a message meant going somewhere else and signing in, the content was never in your mailbox. Your search misses it, your archive holds a wrapper, and it can expire while you still need it.
- An assistant reaches exactly as far as your mailbox reaches. Microsoft says S/MIME mail will not be returned by Copilot and that password-protected documents are closed to AI apps, while content under a key the platform manages stays readable. Google lists its own AI products among the features that stop working under client-side encryption.
- Encryption is the only control in this subject that survives a vendor failing you, and the price of that is the same property: no summary, no ranking, no date lifted into a task. So decide per message rather than per mailbox.
- Bodies get encrypted and headers stay as they are. Subject lines, recipients and timestamps travel in the open, so write dull subject lines and you’ve done most of the work for free.
- For a US firm the paperwork points the same way. The Safeguards Rule requires encryption or a documented alternative approved by your Qualified Individual, IRS Publication 4557 asks tax preparers for password-protected and encrypted documents, and state breach notification generally spares properly encrypted data where the key was not taken.
If your real question is whether to hand a mailbox full of client business to any AI tool, why you are right to be careful with AI starts where the hesitation does. And what Point can see, and what it cannot draws the same boundary around one product.