Your Employees May Already Use Secure Messaging. But Who Controls the Business Information?
- 2 days ago
- 4 min read
Updated: 2 days ago

Encrypted messaging has become part of everyday life.
Applications such as WhatsApp have brought strong end-to-end encryption to billions of users. Personal messages, calls, photos and documents are protected so that the conversation remains between the people communicating. That is an important security achievement.
But organizations have a different problem to solve.
For a CISO, IT security manager, hospital, laboratory, law firm, engineering company or financial organization, the question is not only:
Is the message encrypted?
There is another question:
Who controls the business information before, during and after the communication?
1 Personal Privacy vs. Organizational Control
A private encrypted messaging application is principally designed to protect communications between its users.
An enterprise communication environment must address additional requirements.
The organization may need to determine:
Who is authorized to participate.
Which communication Groups they belong to.
Who is permitted to exchange particular messages and files.
What happens to confidential files delivered to a mobile device.
Whether mobile access can be withdrawn by an administrator.
What records are available for message tracking, protected-file activity and security oversight.
How authorized business communications and files can be retrieved later.
This is an important distinction:
Personal privacy and organizational information control are not the same security objective.
2 Consider One Confidential File
Suppose an executive receives a confidential financial report on a smartphone.
Encryption protects the report while it is being transmitted.
But what happens next?
Does the decrypted document become another permanent file stored on the employee's phone?
What happens if the employee leaves the organization?
What happens if access to the information must be withdrawn?
And if the executive legitimately needs that report again three months later, must another decrypted copy be stored on the phone simply to make that possible?
These questions led us to a different approach when developing TeraMessage Mobile.
3 Protected File → Verify Authorization → Temporary Decryption → Authorized Viewing → Temporary File Destruction.
The authorized user can view the protected information without needing to accumulate permanently decrypted copies of confidential business files on the mobile device.
If the user remains authorized and the protected information remains available through the communication, it can be requested again when needed.
This separates two concepts that are often treated as though they were the same:
Continuing access to business information does not have to mean permanent possession of a decrypted mobile copy.
4 The Organization Establishes the Secure Messaging Environment
TeraMessage Mobile was designed around organizational control.
The organization creates the users.
The organization creates the communication Groups.
The organization determines the communication environment.
The organization can withdraw mobile access.
The organization maintains records of communication and protected-file activity for security oversight.
Protected business files do not have to accumulate as permanently decrypted copies on employees' phones.
And when TeraMessage is used with TeraMail, the controlled business conversation can remain available for authorized retrieval from the computer.
That last point is particularly important.
TeraMessage Mobile and TeraMail are not simply two unrelated messaging applications.
They provide mobile and computer access to the organization's controlled communication environment.
An executive can receive information while traveling on a smartphone and later return to the corresponding communication from TeraMail at a computer.
Authorized retained communications can be searched and protected attachment links can be accessed again without depending upon a collection of decrypted documents stored on the smartphone.
5 What Happens When an Employee Leaves?
This is another way to understand the difference.
Imagine that an employee leaves the company on Friday. The security question is no longer simply:
Were the employee's communications securely protected?
They may have been very well protected.
The organization's question becomes:
What control does the company retain over its communication environment and the business information accessed through it?
TeraMessage provides administrators with the ability to withdraw the mobile endpoint from the TeraCryption communication environment.
That is an organizational security function, not simply a message-encryption function.
6 Security Records Have a Different Purpose
Personal encrypted messaging appropriately places considerable emphasis on the privacy of the individual conversation.
WhatsApp, for example, states that it does not retain logs identifying who everyone is messaging or calling.
That makes sense for a service designed around private communications.
An enterprise may have a different requirement.
It may need records supporting security oversight, message tracking, protected-file activity and organizational accountability.
Neither approach makes the other inherently insecure.
They are solving different problems.
7 Encryption Is Only One Part of Enterprise Information Control
Encryption is essential. But encryption alone does not determine who should be a company user.
Encryption does not establish organizational Groups.
Encryption alone does not determine whether a former employee should continue to have access.
Encryption does not determine what should remain on a mobile device after confidential information has been viewed.
And encryption alone does not provide the organization with the records it may require for security oversight and accountability.
Those are questions of authentication, authorization, access control, information lifecycle, revocation and accountability.
This is why we describe TeraMessage Mobile as:
8 Controlled Enterprise Mobile Communications
The objective is not to replace personal encrypted messaging.
The objective is to give organizations a communication environment designed around the additional controls required for business information.
Because there is an important difference between:
protecting a private conversation.
and
giving an organization control over its business communications and protected information.
______________________________________________________________________________________
Jorge D. Fernandez is President and CEO of Canamex Communications Corporation and President of TeraCryption, the Enterprise File Security Division of Canamex.
For more than 35 years, he has developed enterprise technologies for secure communications and enterprise file security. His articles explore the evolution of mission-critical communications, transparent enterprise file encryption, and the practical challenges organizations face in protecting confidential information without disrupting the way people work.




