What CipherDrive Protects You From — and What It Doesn't

No encryption system protects against every threat. CipherDrive™ is designed to provide strong protection against specific classes of risk while stating its limitations clearly.

CipherDrive is designed to help protect against

Storage infrastructure compromise

If an attacker obtains encrypted file blobs from storage infrastructure without the required user-controlled cryptographic keys, the files are intended to remain unreadable.

Casual or unauthorized internal access

Ackaia employees and ordinary internal systems should not need plaintext access to stored encrypted file contents. The zero-knowledge model reduces what internal access to storage infrastructure can expose.

Ciphertext tampering

AES-GCM authenticated encryption is designed so that altered ciphertext fails authentication during decryption.

One file key exposing every file

Per-file keys provide separation between encrypted objects rather than using a single file-content key for all files.

Server-side revocation can stop future access through the revoked CipherDrive sharing path.

CipherDrive does not guarantee protection against

A compromised device

Malware, a compromised operating system, or an attacker controlling your browser can access data when it exists in plaintext locally or steal key material.

Malicious browser extensions

An extension with powerful permissions may be able to inspect URLs, page content, clipboard data, local storage, or decrypted information.

Phishing

If you provide credentials, vault secrets, or share links to an attacker, cryptography cannot automatically undo that disclosure.

Weak vault secrets

A weak PIN or passphrase can reduce resistance to offline guessing if an attacker obtains applicable encrypted key material.

Recipients you intentionally authorize

Someone who can legitimately decrypt a shared file can copy, download, screenshot, forward, or redistribute it.

Files outside CipherDrive

Once content is downloaded or exported in plaintext, its security depends on the destination system.

Metadata required for service operation

CipherDrive does not promise zero metadata. Storage size, timestamps, object relationships, transfer usage, sharing status, IP addresses, and other operational records can remain visible.

Content before encryption

Where applicable, CipherDrive's Risk Assessment Engine may process files before encryption to generate safety signals.

Loss of all cryptographic recovery paths

Ackaia may be unable to restore encrypted files if required user-controlled key material is permanently lost.

Every regulated or classified use case

Encryption alone does not automatically satisfy every legal, contractual, regulatory, archival, government, healthcare, financial, or classified-information requirement.

Use CipherDrive for what its architecture is designed to do: reduce unnecessary provider access to stored file contents. Do not treat zero-knowledge as a universal guarantee against endpoint compromise, user error, or authorized recipients.