The Risk Assessment Engine is CipherDriveâ„¢'s automated safety, abuse-prevention, malware, CSAM, policy, and risk-signal infrastructure.
Its purpose is to help prevent a privacy-first storage service from being used as infrastructure for exploitation, malware, fraud, severe abuse, or other prohibited activity.
The Risk Assessment Engine may operate:
before a file is encrypted and uploaded;
when Public Links or sharing features are used;
when technical account or activity signals indicate elevated risk;
during trust, safety, security, or legal review where applicable.
The exact checks depend on the file type, workflow, feature, current product configuration, and safety requirements.
Published CipherDrive documentation identifies examples such as:
mathematical hashes;
perceptual hashes;
file fingerprints;
file signatures;
malware indicators;
CSAM-related indicators;
known-content match indicators;
similarity indicators;
risk scores;
Public Link risk indicators;
account, session, IP, object, timestamp, and event identifiers associated with a risk event.
Depending on the relevant safety purpose, signals may be compared with trusted, reputable, public, private, industry-recognized, or otherwise authorized systems for:
child safety;
known CSAM detection;
malware detection;
anti-abuse operations;
fraud prevention;
severe-risk identification.
No. The zero-knowledge claim applies to supported stored content after client-side encryption has completed.
The Risk Assessment Engine is an explicitly disclosed safety boundary that can operate before encryption or on technical and operational signals available to the platform.
It does not provide Ackaia with a universal decryption key for stored CipherDrive files.
Not necessarily.
Automated systems can produce incomplete signals, ambiguous results, or false positives. A risk indicator may therefore trigger additional restrictions or review rather than being treated as a universal factual or legal determination.
Depending on severity and applicable policy, some high-confidence or legally significant matches may require immediate protective action.
Ackaia publishes the existence, purpose, boundaries, and categories of signals used by the Risk Assessment Engine, but does not publish sensitive configurations or evasion-enabling detection details.
Revealing precise thresholds, private signatures, internal datasets, or bypass logic could make the safety system easier to evade and weaken protections for users and victims.
According to CipherDrive's public security documentation, it is not intended for:
advertising;
commercial behavioral profiling;
selling information about user files;
general-purpose mining of private encrypted content.
Privacy-first does not mean abuse-blind. CipherDrive attempts to preserve a strong encrypted-storage boundary while maintaining targeted safety controls before or around that boundary.