Usually the state is managed by methods of the class only, with these methods providing the public access or “api”.
This is like a facade or a shop front. The menu you order from but not the kitchen or the chef.
This means you interact with the class just through the methods.
Sometimes the methods are simple - it can be a get and set method wrapping a state.
Why bother? Why not just make the state public?
Because then other classes start to depend on the inner workings of the class in order to not be broken.
For example suddenly you realise a string has to be valid e.g. it is an email address.
With a getter and setter later on you can add validation to the setter if you wish.
—-
When I said “Anyone outside” this might be misleading. I should say any code outside the class. This is not really for security - as you said if the other developer has the source they can change it and use the changed source. You don’t enforce security with classes.
Rather than security, the purpose of classes is abstraction: the goal of reducing the cognitive load. The load on your brain.
For example most programming languages will provide classes to open a file. You can now work with the file system in an abstract way without writing code that cares about Unix/windows file system differences in your code that is doing something else.
This means someone can write a program to scan your disk for mp3 files and catalog them without knowing the details of the files stem, and in such a way that if in the future the file system classes are updated to handle say NAS your mp3 hunter program still works.
Even better it gets a new feature for free!