CipherDrive™ is designed to reduce unnecessary provider access to your files, but your account, browser, device, recovery material, and sharing habits remain important parts of the security boundary.
Use a strong, unique password.
Protect the email account used for recovery.
Enable multi-factor authentication when available.
Do not reuse credentials from unrelated services.
Review suspicious sign-in activity promptly.
Revoke sessions you no longer recognize or need.
Keep any vault PIN, passphrase, recovery credential, local key, or device key private.
Do not send cryptographic secrets to ordinary support channels.
Do not store your only recovery method on the same device as your only vault access.
Use a strong vault secret where the product allows user-selected secrets.
Confirm that you have a valid recovery path before wiping or replacing a trusted device.
Install security updates for:
your operating system;
your browser;
security software where applicable;
the CipherDrive client or application;
other software that can access downloaded files.
Old browsers or operating systems may contain vulnerabilities that can bypass the protection expected from client-side encryption.
Browser extensions can have powerful access to pages, URLs, clipboard data, downloads, and browser storage.
For sensitive workflows:
remove extensions you do not need;
avoid extensions from unknown publishers;
review permissions before installation;
consider a dedicated browser profile with minimal extensions.
If someone can unlock your computer or phone while your CipherDrive session or vault is available, server-side encryption may not protect the plaintext they can access locally.
Use strong device authentication and configure automatic locking when appropriate.
Do not unlock a sensitive CipherDrive vault on:
hotel business-center computers;
library computers;
internet cafés;
shared family or workplace devices you do not control;
devices managed by an unknown administrator.
Send links through trusted channels.
Do not post sensitive links publicly.
Revoke links that are no longer needed.
Assume a recipient can keep a copy after decryption.
Once a file is downloaded in readable form, its protection depends on the destination device.
Consider full-disk encryption, secure local backups, access permissions, and safe disposal for downloaded copies.
For important files, keep an independent backup outside the one CipherDrive vault you depend on.
Zero-knowledge encryption can prevent Ackaia from recovering files if all valid key material is lost.
Users handling especially sensitive information should consider:
a dedicated or hardened device;
a dedicated browser profile;
minimal browser extensions;
stronger passphrases;
strict link-sharing procedures;
separate recovery-material storage;
an independent encrypted backup strategy.
Security is shared: CipherDrive protects the storage architecture, while you remain responsible for the credentials, keys, sessions, devices, links, and exported files under your control.