If a device with CipherDriveâ„¢ access is lost, stolen, infected, or otherwise compromised, act as though account sessions, local key material, share links, and decrypted files on that device may be exposed.
Do not perform recovery actions from the suspected compromised device if you can avoid it.
Use another device that you trust and that has current security updates.
From the trusted device:
review active sessions where available;
revoke the lost or suspicious session;
change your Ackaia ID password if credentials may have been exposed;
secure the email account used for recovery;
enable or review additional authentication controls where available;
check for unexpected account changes.
CipherDrive may provide controls to clear local keys, remove remembered devices, sign out sessions, or require reauthentication.
Use the controls currently available to reduce the chance that the lost device can continue using previously remembered access.
If the device had access to sensitive share links, consider revoking and replacing those links.
A malicious extension, malware, browser history, clipboard history, or local application could have captured complete URLs.
Assume plaintext files downloaded to the compromised device may have been exposed. CipherDrive cannot remotely re-encrypt or erase copies that already exist outside its controlled storage.
Do not accidentally erase the last trusted device or recovery material capable of unlocking your vault.
Before clearing keys on remaining devices, verify that you still have a valid way to decrypt the vault.
Contact Ackaia promptly if you observe:
unknown sessions;
unexpected sign-ins;
unknown sharing activity;
unexpected account or billing changes;
security alerts you did not trigger;
suspected exploitation of a CipherDrive vulnerability.
Provide timestamps, error messages, session details, and other non-secret troubleshooting information.
Never send passwords, vault PINs, recovery phrases, master keys, file keys, or other private cryptographic material to ordinary support channels.
Do not assume changing a password on the infected device solves the problem. Malware can continue stealing new credentials or local keys.
Follow appropriate device-remediation procedures, which may include professional incident response, reinstallation, credential rotation from a clean device, and review of other accounts accessed from the compromised endpoint.
Ackaia can revoke or restrict server-side sessions, links, and product access where supported. Ackaia cannot reliably recall plaintext files already downloaded, screenshots already taken, or key material already stolen by a compromised endpoint.