What is encryption in transit?

Encryption in transit
Encryption in transit means data is encrypted while moving between systems, so anyone intercepting the connection sees scrambled traffic rather than the content.

What encryption in transit means in practice

For web traffic this is settled. Browsers refuse plain connections and nobody argues about it any more.

Telephony is messier. A call crossing the traditional phone network is not encrypted, because that network was built long before anybody was worried about it.

Internet-based calling can encrypt the leg it controls, and the leg that touches the old network usually cannot be.

Data about the call, as opposed to the audio, is easier. Transcripts and records move over ordinary encrypted connections.

What people get wrong

Following one call across four hops

Say a customer in Ohio calls your office from her cell phone. Hop one runs from her handset to the cell tower, and modern mobile networks encrypt that radio link. Next, hop two crosses the carrier's network and the traditional phone system, where her voice generally travels as ordinary unencrypted traffic.

The third hop starts where the call is handed to an internet calling provider. From there it can travel as SIP over TLS with the audio in SRTP, if both ends have switched them on. Those are the encrypted versions of the standard calling protocols. The last hop is you, opening the transcript in a browser over HTTPS.

So your path reads encrypted, open, maybe encrypted, encrypted. Nobody selling you a phone product controls hop two, and you'll find that's true of every vendor you compare.

Testing the parts you can see

Your browser shows you the last hop for free. Click the padlock on any dashboard and you'll see the certificate. For a closer look, a free scanner such as Qualys SSL Labs grades a site's setup in about two minutes. You want to see TLS 1.2 or 1.3 accepted and the older versions refused.

Email is the leak people forget. A call summary sent to your inbox travels between mail servers, and that link is encrypted only when both servers agree to it. If your summaries carry sensitive detail, read them in the dashboard and keep the emails brief.

How much this matters depends on what your callers say. For a bakery taking cake orders, the open hop is a curiosity. A law office should care a great deal, so ask each vendor about SRTP by name and listen for a straight answer.

How GreetKeeper handles it

Calls reach GreetKeeper over your carrier's network, and that leg works the way ordinary telephone calls work rather than the way a web request does.

Transcripts, summaries and anything you read in a browser travel over ordinary encrypted connections.

GreetKeeper carries no certifications attesting to any of this, and that is worth knowing before a formal security review rather than during one.

Encryption in transit questions

Are phone calls encrypted?

Not end to end, in general. Parts of the path can be, and the traditional network legs typically are not, which is true of every phone service you have used.

Is a transcript safer than the audio?

In transit, usually, because it moves over web protocols that are encrypted by default. At rest they carry the same sensitivity.

What should I ask a vendor?

Which legs of the path are encrypted and which are not. A vendor who answers precisely is telling you they have thought about it.

Hear it take one of your calls

Two minutes, your own scenario, no card.