Recovering your Ackaia ID account and recovering your encrypted CipherDriveâ„¢ files are two different processes.
This distinction is one of the most important parts of CipherDrive's zero-knowledge security model.
Ackaia ID is responsible for your account identity and authentication. Depending on the available recovery options and security checks, account recovery may help you regain access to:
your Ackaia ID;
non-cryptographic account credentials;
account and profile settings;
product entitlements;
subscriptions and account-management functions.
Ackaia may require identity, security, fraud-prevention, or recovery checks before restoring account access. Ackaia may also revoke sessions or reset non-cryptographic credentials when necessary to protect an account.
CipherDrive protects supported stored files with client-side encryption. The cryptographic hierarchy can involve:
a vault passphrase, PIN, or local unlock secret;
a key-encryption key;
an encrypted master key;
the master key;
encrypted per-file keys;
per-file encryption keys.
Under normal operation, Ackaia does not ordinarily possess the plaintext master key or plaintext file keys required to decrypt your stored file contents.
If the client no longer has the cryptographic material needed to unlock that hierarchy, Ackaia may be technically unable to reconstruct it for you.
Imagine that you forget your Ackaia ID password but still have the CipherDrive key material on your trusted device.
After a successful Ackaia ID recovery, you may be able to sign in again and continue accessing the vault because the necessary cryptographic material is still available locally.
Now imagine the opposite: your Ackaia ID works, but the only device containing the required vault key is lost and you do not have the applicable recovery secret.
In that case, you may be able to authenticate normally but still be unable to decrypt the files.
If Ackaia could always generate a replacement key capable of decrypting your existing files without your original cryptographic material, Ackaia would effectively retain a recovery path to your plaintext data.
CipherDrive is designed to avoid that normal server-side decryption capability.
Zero-knowledge has a real tradeoff: reducing Ackaia's ability to read your files also reduces Ackaia's ability to recover them when user-controlled cryptographic secrets are permanently lost.
Even when file contents cannot be decrypted, Ackaia may still have operational information associated with your account, such as:
account and subscription information;
storage usage;
encrypted object sizes;
upload, update, deletion, or access timestamps;
folder relationships;
sharing status;
transfer usage;
security and account-recovery events;
other operational records described in the Privacy Policy.
This information can help with account troubleshooting, but it does not provide the missing cryptographic key required to decrypt an encrypted file.
Protect any recovery information CipherDrive provides.
Do not keep your only recovery method on the same device as your only vault access.
Maintain independent backups of important files.
Before replacing, wiping, selling, or losing access to a trusted device, confirm that you still have another valid way to unlock your vault.
Do not clear local encryption-related data unless you understand how you will restore access.
Never send vault secrets or private keys to ordinary support channels.
If you need help, explain whether the problem is:
Account access: you cannot authenticate to Ackaia ID; or
Vault/file access: you can authenticate, but CipherDrive cannot unlock or decrypt your encrypted files.
This distinction helps support identify the correct troubleshooting path without asking you to expose sensitive cryptographic material.