Some security claims describe a property that can be checked. Others describe a feeling. Sorting the phrases in common marketing use into those that carry information and those that carry only reassurance, with the question that exposes each one.
Why the phrase is empty
The ciphers a defence ministry would use are public, standardised, free, and already running in the browser displaying this sentence. Calling them military-grade is true in the sense that a military would also use them, and uninformative for exactly that reason.
It also points at the wrong component. The cipher is close to never the thing that fails. Implementations fail at key management — where the key is derived, who holds a copy, what happens when somebody forgets a password — and the phrase says nothing about any of that. It describes the lock while the question was about who has a key cut.
The general rule
A claim carries information only if it could have been otherwise.
If every competitor could say the same sentence without lying, the sentence is describing the floor of the industry rather than the product. It is reassurance in the grammatical shape of a specification.
Phrases that carry nothing, and what to ask instead
"Military-grade encryption." Ask where the key is derived and who holds it. Strong ciphers with provider-held keys are the ordinary arrangement, not a distinguishing one.
"Bank-grade security." Ask what specifically. Banks are not a standards body and vary enormously; the phrase is a mood.
"We take your privacy seriously." Ask what is collected and for how long. Seriousness is not a property of a system.
"Your data is encrypted." Ask which of three: in transit, at rest, or end-to-end. Only the third excludes the provider, and the first two are true of nearly everything.
"We never sell your data." Ask whether it is shared, licensed, disclosed to processors, or transferred if the company is acquired. Sell is one narrow verb, and a company can honour that sentence precisely while doing all of the rest.
Phrases that do carry something
Each of these constrains future behaviour or would be embarrassing if false, which is what makes them worth reading.
A named retention period. A number is checkable and it bounds the exposure.
A statement of what happens on password reset. This one answer reveals the architecture: a service that can restore your files necessarily holds a route to your key.
A published security contact and disclosure policy. It costs something to run, and its existence says researchers are received rather than threatened.
An external assessment with a date and a scope. The scope matters more than the assessment — an audit of the login page is not an audit of the product, and a statement that gives neither is decoration.
An explicit statement of what the service cannot do. The strongest signal available, because nobody writes down a limitation they were not forced into by their own design.
Why vendors talk this way
Not always cynicism, and assuming cynicism makes you worse at reading the field.
Precise claims are harder to write, need review before publication, age badly, and can be made untrue by an architecture change nobody looped marketing into. Vague claims survive reorganisation, refactoring and acquisition. The incentive favours vagueness even among honest teams.
So vagueness is not evidence of dishonesty. It is only evidence that you have learned nothing, which is a different problem and still yours.
The one-question test
Could a competitor with the opposite architecture make this same claim without lying?
If yes, the claim has not told you anything about this product. If no, you have found the sentence worth reading twice.
Close
Most security copy is written to make you stop asking. The useful habit is to notice the moment you stopped, and to ask the next question anyway — usually some version of and who holds the key?
