CipherDriveâ„¢ is designed to protect lawful private files with client-side encryption, but it is also designed not to become infrastructure for severe abuse, malware, exploitation, fraud, or other prohibited activity.
For that reason, some safety checks may happen before client-side encryption is complete.
After a file has been encrypted under CipherDrive's zero-knowledge storage model, Ackaia does not ordinarily possess the user-controlled keys required to read the stored plaintext content.
If safety systems operated only after encryption, the service could lose important technical opportunities to identify known severe-risk material before it enters encrypted storage.
For applicable file types or workflows, CipherDrive may therefore perform a limited pre-encryption safety step designed to generate technical risk signals.
Depending on the workflow and current safety system, CipherDrive may generate technical signals such as:
cryptographic hashes;
perceptual hashes;
media fingerprints;
file signatures;
similarity indicators;
known-content match indicators;
malware indicators;
risk scores;
blocked-upload records;
other technical metadata needed for safety and enforcement.
Those signals may be compared with trusted safety, malware, abuse-prevention, or child-protection systems.
No.
The pre-encryption safety boundary and the encrypted-storage boundary serve different purposes.
Once a supported file has completed client-side encryption and entered ordinary encrypted storage, Ackaia does not gain a general server-side key that can later decrypt that file.
No. The published CipherDrive architecture describes automated technical-signal generation and comparison.
A safety signal does not automatically mean that an Ackaia employee opens or reads the underlying plaintext file. Internal review can be based on metadata, risk indicators, account activity, moderation records, legal notices, or other information available without defeating CipherDrive's zero-knowledge protections.
The Risk Assessment Engine exists for purposes such as:
child safety;
detecting known CSAM indicators;
malware and ransomware prevention;
fraud and phishing prevention;
severe-abuse detection;
protecting users, victims, and infrastructure;
legal and policy compliance.
It is not intended for advertising, behavioral profiling, selling information about user files, or commercial mining of encrypted content.
Depending on the confidence, severity, policy, and legal context, CipherDrive may:
block the upload;
prevent storage;
disable sharing;
preserve technical records;
restrict account capabilities;
suspend or terminate an account;
report suspected illegal activity where required or appropriate;
cooperate with lawful child-protection or legal processes.
CipherDrive's privacy commitment applies to stored encrypted content. Safety checks before encryption are a separate, disclosed boundary.