No encryption system protects against every threat. CipherDrive™ is designed to provide strong protection against specific classes of risk while stating its limitations clearly.
If an attacker obtains encrypted file blobs from storage infrastructure without the required user-controlled cryptographic keys, the files are intended to remain unreadable.
Ackaia employees and ordinary internal systems should not need plaintext access to stored encrypted file contents. The zero-knowledge model reduces what internal access to storage infrastructure can expose.
AES-GCM authenticated encryption is designed so that altered ciphertext fails authentication during decryption.
Per-file keys provide separation between encrypted objects rather than using a single file-content key for all files.
Server-side revocation can stop future access through the revoked CipherDrive sharing path.
Malware, a compromised operating system, or an attacker controlling your browser can access data when it exists in plaintext locally or steal key material.
An extension with powerful permissions may be able to inspect URLs, page content, clipboard data, local storage, or decrypted information.
If you provide credentials, vault secrets, or share links to an attacker, cryptography cannot automatically undo that disclosure.
A weak PIN or passphrase can reduce resistance to offline guessing if an attacker obtains applicable encrypted key material.
Someone who can legitimately decrypt a shared file can copy, download, screenshot, forward, or redistribute it.
Once content is downloaded or exported in plaintext, its security depends on the destination system.
CipherDrive does not promise zero metadata. Storage size, timestamps, object relationships, transfer usage, sharing status, IP addresses, and other operational records can remain visible.
Where applicable, CipherDrive's Risk Assessment Engine may process files before encryption to generate safety signals.
Ackaia may be unable to restore encrypted files if required user-controlled key material is permanently lost.
Encryption alone does not automatically satisfy every legal, contractual, regulatory, archival, government, healthcare, financial, or classified-information requirement.
Use CipherDrive for what its architecture is designed to do: reduce unnecessary provider access to stored file contents. Do not treat zero-knowledge as a universal guarantee against endpoint compromise, user error, or authorized recipients.