Understanding Local Keys and Remembered Vault Access

CipherDrive™ may store local cryptographic state on your browser or device so that you do not have to enter a vault PIN or passphrase every time you access encrypted storage.

What “remembered vault access” means

Depending on the client and feature, CipherDrive may keep:

The exact implementation can change by client and protocol version.

Why store keys locally?

Without remembered local state, a user might need to rebuild the complete vault unlock process every time the application is opened.

Local storage improves usability while still allowing the server-side architecture to avoid keeping plaintext master or file keys.

What is the security tradeoff?

If someone compromises the trusted device, browser profile, operating system, user account, extension environment, or active session, they may be able to access local key material or use the already-unlocked vault.

This is why remembered access should be used only on devices you trust.

What happens if browser data is cleared?

Clearing cookies, IndexedDB, site storage, application data, or other browser state can remove remembered key material.

You may then need to unlock the vault again using the valid recovery or vault mechanism for that client.

Before clearing local encryption-related data, make sure you still have another valid way to unlock the vault.

What happens on a new device?

A new device does not automatically inherit cryptographic access simply because you can sign in to Ackaia ID.

Account authentication and vault decryption are separate. The new client may require an applicable vault secret, recovery method, device enrollment, or other cryptographic process before encrypted files can be opened.

When should remembered access be removed?

Clear or revoke local access when:

Does deleting local keys delete cloud files?

Not necessarily. Removing local key material and deleting encrypted cloud objects are different actions.

However, if the removed local key was your last valid path to the vault and no recovery method exists, the encrypted files may become permanently inaccessible even though the ciphertext remains stored.