Something isn’t quite right on this page.
The minimum requirements mention:
“Must use standard, audited encryption.”?
I am assuming we imply e2ee here, else what relevant encryption are we talking about?
Then the card of photoprism itself contains the text “It does not include E2EE, …”
Probably TLS for the sync portion. This requirement feels like something @dngray might’ve added so I’ll ask him here if he knows. E2EE is already covered by the first requirement:
Cloud-hosted providers must enforce end-to-end encryption.
Might be able to just remove the line you mentioned as redundant, since it seems like it’s already covered by the line above.
The reason photo-prism was allowed was because it could be self hosted. There are relatively few products in this space with any kind of E2EE though so we could relax that criteria.