Ackaia may use third-party service providers to help operate CipherDriveâ„¢ and the wider Ackaia ecosystem.
These providers do not all receive the same information. Their access depends on the service they provide, the architecture involved, and the safeguards that apply.
Current Ackaia privacy documentation identifies categories such as:
cloud hosting providers;
storage infrastructure providers;
network delivery and infrastructure providers;
payment processors and billing providers;
email and communications providers;
security, logging, monitoring, and fraud-prevention providers;
analytics or performance-measurement providers;
customer-support and ticketing tools;
abuse-prevention providers;
child-safety technology providers;
professional legal, accounting, insurance, and audit providers.
No. A provider should receive only the information reasonably needed for its defined role.
For example, a payment processor may need transaction and payment information but has no operational reason to receive the plaintext contents of an encrypted file. A storage infrastructure provider may store encrypted blobs without possessing the user-controlled key required to decrypt them.
Ackaia states that service providers are authorized to process information only for defined purposes and are subject to contractual, legal, and technical safeguards as appropriate to their role.
Ackaia's security program also applies provider-risk and access-control principles to material systems.
Infrastructure vendors can change as Ackaia changes regions, payment options, support systems, security tooling, or service architecture.
A hard-coded support article can become inaccurate even when the underlying privacy commitments have not changed.
For the current provider or subprocessors information that Ackaia publishes, use the CipherDrive Trust Profile and current legal documentation as the authoritative source.
Ackaia's privacy policies describe provider disclosures as necessary to deliver defined services, not as a sale of encrypted file contents for advertising.
Individual third-party services can also have their own legal obligations and privacy notices where they interact directly with you, such as a payment processor.
Not inherently.
The core question is what the provider receives and whether it has the keys required to decrypt the encrypted data. CipherDrive's zero-knowledge design aims to keep supported file contents encrypted before storage regardless of the underlying storage-infrastructure provider.
Provider transparency should be treated as a living record. Check the Trust Center when you need the current vendor or regional processing picture.