Why is my workspace encrypted?
Patient, exam, file, and template data is end-to-end encrypted — not even diagnos can read it — and stays unreadable until a member unlocks the workspace on that device. Settings stays reachable either way, because it never holds that encrypted content.
- Updated on
- 2 min read
On this page
Patient, exam, file, and document template data is end-to-end encrypted by the members of the workspace. While the vault is locked on this device, that content stays unreadable — not even diagnos can open it — until a member unlocks it.
What you'll see while it's locked#
Patients, Exams, Drives, and Templates each show their own title with an unlock prompt in place of the real content — the page never loads the encrypted data in the first place, so there's nothing to accidentally expose. The report editor is the one exception: because it fills the whole screen with no navigation around it, it shows a full-page "Encrypted workspace" screen instead.
What stays reachable without unlocking#
Settings stays reachable either way. That's not a metadata exception — it's because none of what Settings shows is part of the encrypted vault in the first place: workspace configuration, plan, and team membership are encrypted in transit and at rest like everything else, but they were never sealed behind your security password. Opening Settings never exposes patient, exam, file, or template content — that content simply isn't there.
How to unlock the content#
A member unlocks the workspace with the security password or the recovery phrase. See How do I unlock a workspace for the steps. From then on, patients, exams, files, and templates are readable again on that device, until you lock it again or the session ends.
The demo environment#
The demo workspace also opens encrypted, so the gesture looks exactly like it does in a real workspace. Only the price of the key differs: instead of the security password, a confirmed email address is enough.