End-to-End Encryption
Every read is encrypted in transit (TLS) and at rest. End-to-end encryption adds two things: the drawing is stored encrypted to a key made for that one request, and the files a read returns are encrypted to your key, so only you can open them.
What is encrypted
| Without end-to-end encryption | With end-to-end encryption | |
|---|---|---|
| The drawing, while it waits to be read | Encrypted at rest | Also encrypted to a key pair made for this request alone |
Result files behind a payload_url (sheet and view images, a redacted drawing) | Encrypted at rest | Encrypted to your public key, when you send one: only your private key opens them |
Structured results (payload_dict) | Sent over TLS | Sent over TLS, not encrypted to your key |
| Replaying the result of an identical earlier request | Possible | Never: a request with end-to-end encryption is not kept for replay |
To read the drawing, Werk24 decrypts it for the duration of the read.
Switching it on
End-to-end encryption has to be switched on for your account; until it is, the server does not make a key pair for your requests. It is an add-on on the plans that take add-ons, or part of a contract; werk24.io/pricing lists them.
With the Python client
Make a key pair once and keep the private key and its passphrase to yourself. Then pass both halves to every read:
With end-to-end encryption on the account, the client also encrypts the drawing to the key the server made for the request before uploading it. The client sends your public key whenever you pass encryption_keys, so result files are encrypted to it either way.
Always pass encryption_keys once it is switched on
With end-to-end encryption on the account, a read without encryption_keys fails: the client still encrypts the drawing to the server's key, but the server can only use that key when your public key comes with the read.
With the HTTP API
Send your PEM public key in the public_key form field of the HTTP API submit. On this route it is used only when end-to-end encryption is switched on for your account; otherwise it is ignored and result files are not encrypted to it. With it switched on but no public_key sent, result files are not encrypted to a key of yours either. Werk24 encrypts the drawing it received on arrival, before storing it.
Decrypt a downloaded file with your private key, for example with werk24.utils.crypt.decrypt_with_private_key(private_key_pem, passphrase, data).