Why CipherDrive Stores Some Key Material on Your Device

For usability, CipherDriveâ„¢ may store local key material, wrapped keys, or unlock state in your browser or device. This can let you reopen encrypted storage without entering a PIN or passphrase every time.

Why store anything locally?

A zero-knowledge service still needs a practical way for your trusted client to decrypt files. If every page refresh required you to rebuild the full key hierarchy from scratch, the product could become unnecessarily difficult to use.

Local key state can provide continuity on a device you already trust.

What may be stored locally?

Depending on the active client and security configuration, local state may include:

The exact implementation can change over time and may differ by client or feature.

Does local key storage break zero-knowledge?

No. Zero-knowledge in CipherDrive concerns the server-side storage boundary. Keeping required key material on a user's own trusted device is compatible with a system in which Ackaia servers do not ordinarily possess the plaintext master key or file keys.

The tradeoff

Convenience creates an endpoint-security responsibility. If an attacker controls your browser, operating system, device account, extension environment, or already-unlocked session, local key material may be exposed.

This is considered a compromised-endpoint risk, not a server-side zero-knowledge failure.

When local key material may disappear

You may need to unlock the vault again after events such as:

How to protect a trusted device

Important: No cloud encryption model can fully protect plaintext after the trusted endpoint itself has been compromised.