Learn
What Is Zero-Knowledge Encryption?

Most cloud services encrypt your data. They will tell you so on their security pages, often with reassuring language about "bank-level" or "military-grade" encryption. What they are less likely to explain is that, in most cases, they hold the keys to that encryption. They can decrypt your data whenever they choose, or whenever they are asked to. Zero-knowledge encryption is a different arrangement entirely: the service provider stores your data but possesses no means to read it.
The term "zero knowledge" refers to the amount of information the provider has about the contents of your data: none. They know you have data stored with them. They can see how much storage you use, when you last logged in, and other operational details. But the substance of your files, notes, photos, and documents remains opaque to them at every stage.
How standard encryption works in cloud services
To understand zero-knowledge encryption, it helps to first understand what most services do.
When you upload a file to a typical cloud storage service, it travels over an encrypted connection (HTTPS) to the provider's servers. This is encryption in transit, and it prevents anyone intercepting the data between your device and the server from reading it. Once the file arrives, the provider encrypts it again for storage. This is encryption at rest, and it protects the file if the physical storage hardware is stolen or accessed without authorisation.
Both of these protections are valuable, but they share a common property: the service provider manages the encryption keys. The provider encrypted the data, and the provider can decrypt it. This means the provider can read your files if it needs to, for instance to comply with a legal request, to scan for prohibited content, to index your files for search, or to feed your data into machine learning models.
In this model, encryption protects your data from outsiders, but your relationship with the provider is still one of trust. You are trusting them not to misuse their access, trusting their employees to behave responsibly, and trusting their systems to be secure enough that an attacker who breaches their infrastructure cannot also compromise the keys.
What zero-knowledge encryption changes
In a zero-knowledge system, encryption and decryption happen on your device. The encryption key is derived from something only you know (typically your password, or a key stored only on your devices) and is never transmitted to the provider's servers. The provider receives and stores only encrypted data, and it does not possess the key needed to decrypt it.
This is a structural guarantee, not a policy promise. The provider cannot read your data, because it lacks the technical means to do so. A rogue employee cannot peek at your files. A government subpoena can compel the provider to hand over your data, but what they hand over is encrypted ciphertext that is useless without your key. An attacker who breaches the provider's servers finds only encrypted blobs.
The distinction between "we choose not to read your data" (a policy) and "we cannot read your data" (an architectural property) is the core of zero-knowledge encryption. Policies can change. Companies get acquired, terms of service are updated, and internal practices evolve. Architectural constraints are more durable.
How zero-knowledge encryption relates to end-to-end encryption
Zero-knowledge encryption and end-to-end encryption are closely related and sometimes used interchangeably, though each term highlights a different facet of the same principle.
End-to-end encryption describes the mechanism: data is encrypted on one device and can only be decrypted on another authorised device, with no intermediary able to access the plaintext. It emphasises the path the data travels and the fact that the "ends" of the communication are the only places where data is readable.
Zero-knowledge encryption describes the outcome from the provider's perspective: the provider has zero knowledge of your data's contents. It emphasises what the provider can and cannot see.
For cloud storage, a properly implemented end-to-end encrypted system is also a zero-knowledge system. When your files are encrypted on your device before upload and the provider never receives your key, the provider has zero knowledge of the file contents. The two terms describe the same protection from different vantage points.
Where the distinction matters is in how services frame their offerings. A service might describe itself as "end-to-end encrypted" for messaging but only use standard server-side encryption for stored files. Asking whether a service is zero-knowledge for all data types, not just specific features, gives you a clearer picture of your exposure.
Practical implications
Zero-knowledge encryption changes the relationship between you and your service provider in several concrete ways.
The provider cannot help you recover lost data. If you forget your password or lose the device that holds your encryption key, the provider cannot reset your access. They do not have a copy of your key and cannot regenerate it. Most zero-knowledge services offer recovery mechanisms, such as a recovery key you generate when you create your account, which you must store safely. But if you lose both your password and your recovery key, your data is gone. This is the most significant trade-off, and it is worth understanding before you commit to a zero-knowledge service. Good providers are transparent about this. They explain it during onboarding and make the recovery key process prominent rather than burying it in settings.
The provider cannot comply with content-level data requests. If a government agency or court orders the provider to produce your files, the provider can hand over only the encrypted data. Without your key, this data is unreadable. This is a meaningful protection in jurisdictions with broad surveillance powers, and it matters for anyone managing sensitive personal or professional data.
The provider cannot train AI on your encrypted data. This is an increasingly relevant consideration. Many cloud and productivity services use customer data to improve their AI models. If your data is encrypted with a key the provider does not hold, it is technically impossible for them to feed it into training pipelines. For people who want AI features in their workspace without giving up privacy, zero-knowledge encryption makes this possible: the AI processes data on your device or in a way that the provider does not retain access to the decrypted content.
The provider cannot scan your files for content moderation. Services like Google Drive and Dropbox scan files for malware, copyright violations, and illegal content. With zero-knowledge encryption, this server-side scanning is not possible. This is a double-edged consideration: it means your files are genuinely private, but it also means the provider cannot protect other users from malicious files shared through their platform.
Which services offer zero-knowledge encryption
The number of services offering zero-knowledge encryption has grown in recent years, though it remains a minority approach, particularly among the largest providers.
For cloud storage, Fabric implements zero-knowledge encryption as a foundational design choice. Proton Drive offers it as part of the Proton ecosystem. Tresorit and SpiderOak have long positioned themselves as zero-knowledge storage options. Among mainstream services, Google Drive and Dropbox use server-side encryption where the provider holds the keys, though Dropbox has experimented with client-side encryption for enterprise customers. Apple's iCloud offers an optional Advanced Data Protection mode that extends end-to-end encryption to most stored data.
For email, Proton Mail is the most well-known zero-knowledge provider. Tutanota (now Tuta) is another. Standard email providers like Gmail, Outlook, and Yahoo Mail do not offer zero-knowledge encryption.
For messaging, Signal provides zero-knowledge by default for messages. WhatsApp uses the Signal Protocol for message encryption but collects metadata that Signal does not. Most other major messaging platforms do not offer zero-knowledge encryption as the default.
For note-taking and productivity tools, the landscape is still developing. Most popular tools (Notion, Evernote, Google Docs) use server-side encryption. Some newer tools are building zero-knowledge encryption into their core architecture, recognising that who owns your data in cloud storage is a question more people are asking.
The trade-offs
Zero-knowledge encryption involves real trade-offs, and being honest about them is important for making an informed choice.
Recovery is your responsibility. This bears repeating, because it is the most common source of frustration. If you lose your password and your recovery key, there is no "forgot password" flow that can help. The provider's support team genuinely cannot restore your access. Before choosing a zero-knowledge service, ensure you have a reliable plan for storing your recovery credentials, whether that is a password manager, a physical backup, or another secure method.
Server-side search is more complex. When the server cannot read your data, it cannot build a traditional search index. Zero-knowledge services must use alternative approaches: building search indices on your device, using encrypted search techniques, or downloading and decrypting data locally before searching. These approaches work, but they may be slower or more resource-intensive than server-side search for very large collections. Some services, like Fabric with its search capabilities, have invested in making client-side and privacy-preserving search performant, but it remains a more technically demanding problem than simply indexing plaintext on a server.
Some collaborative features require careful engineering. Sharing an end-to-end encrypted file with someone means securely sharing the decryption key with them. Collaboration in a zero-knowledge system requires cryptographic key exchange protocols that add complexity. Most well-implemented services handle this transparently, but the underlying engineering is more involved than in systems where the server can simply grant access to files it can already read.
Performance overhead exists but is usually minor. Encryption and decryption on your device consume processing power. For modern devices and typical file sizes, this overhead is negligible. For very large files or bulk operations, you may notice a slight delay compared to services where these operations happen on powerful servers. The gap is narrowing as devices become more capable and as encryption implementations improve.
Not all features may be available. Some features that users expect from cloud services, such as thumbnail previews generated on the server, automated content tagging, or server-side format conversion, are harder to implement in a zero-knowledge model. Providers must either perform these operations on your device or find creative technical solutions. A mature zero-knowledge service will have addressed most of these, but newer or less resourced providers may offer a narrower feature set.
Why zero-knowledge encryption matters in the age of AI
The rise of AI services has added a new dimension to the encryption conversation. AI systems are data-hungry by nature. Large language models, image generators, and other AI tools are typically trained on vast datasets, and cloud providers have an obvious incentive to use customer data for this purpose.
Several major providers have updated their terms of service in recent years to reserve the right to use customer data for AI training and model improvement. Even when they offer opt-out mechanisms, the default is often to include your data. For people who use cloud services for sensitive personal, creative, or professional work, this creates a tension: you want the convenience and features of a cloud service, but you may not want your data becoming training material.
Zero-knowledge encryption resolves this tension architecturally rather than through policy. If the provider cannot decrypt your data, they cannot feed it to an AI training pipeline, regardless of what their terms of service say. This is particularly relevant for developers storing proprietary code, researchers with unpublished findings, freelancers with client work, or anyone whose data has value that would diminish if it were absorbed into a public model.
It is worth noting that zero-knowledge encryption does not prevent you from using AI features. A service can offer AI-powered assistance that processes your data on your device or in a way that decrypts it only for you, without the provider retaining access. The key distinction is between AI that works for you (processing your data at your request, with the results available only to you) and AI that works on you (processing your data for the provider's benefit).
How to evaluate zero-knowledge claims
When a service claims zero-knowledge encryption, a few questions help you assess the claim.
Where does encryption happen? If encryption occurs on the server, the server has access to the plaintext at some point, and the system is not truly zero-knowledge. Encryption should occur on your device before data leaves it.
Who holds the keys? In a zero-knowledge system, the provider never possesses your encryption key. If the provider can reset your password and restore your access without a separate recovery key, they likely hold or can derive your encryption key, which means they can access your data.
Is the implementation audited? Independent security audits provide assurance that the encryption works as described. Look for published audit reports from reputable firms. Open-source implementations allow the broader security community to review the code.
What is the scope? Does zero-knowledge encryption apply to all data types and features, or only to certain ones? A service might encrypt file contents but leave filenames, metadata, or thumbnails unencrypted. Understanding the scope helps you assess your real exposure.
What is data portability like? A good zero-knowledge service makes it straightforward to export your data. If leaving the service is difficult, that is a concern regardless of the encryption model.
Frequently asked questions
What does "zero knowledge" mean in the context of encryption?
It means the service provider has no knowledge of the contents of your data. They store your encrypted files but do not possess the keys needed to decrypt them. They cannot read, scan, analyse, or share your data's contents, because they lack the technical means to access it.
How is zero-knowledge encryption different from regular encryption?
Most cloud services encrypt your data but hold the encryption keys themselves. This means they can decrypt your data when needed. Zero-knowledge encryption means the keys exist only on your devices. The provider encrypts and stores your data but cannot decrypt it. The difference is between "protected from outsiders" and "protected from everyone, including the provider."
Can a zero-knowledge service recover my account if I forget my password?
Typically, no. Because the provider does not hold your encryption key, they cannot reset your access. Most zero-knowledge services provide a recovery key during setup that you should store safely. If you lose both your password and recovery key, your data is likely unrecoverable. This is the most important trade-off to understand.
Can zero-knowledge services still offer AI features?
Yes, but the AI processing must happen in a way that the provider does not retain access to your decrypted content. This might mean processing happens on your device, or in a secure environment where only you can see the results. The provider cannot use your encrypted data for AI training or model improvement, because they cannot read it.
Is zero-knowledge encryption slower than regular cloud storage?
The encryption and decryption operations add a small amount of processing time on your device, but for most use cases the difference is imperceptible. Where you may notice a difference is in features that typically rely on server-side processing, like search, which must use alternative approaches in a zero-knowledge system. Modern implementations have made significant progress in minimising these differences.
Which popular services use zero-knowledge encryption?
For cloud storage, Fabric, Proton Drive, Tresorit, and SpiderOak offer zero-knowledge encryption. For email, Proton Mail and Tuta do. For messaging, Signal offers it by default. Major services like Google Drive, Dropbox, and most email providers use server-side encryption where the provider holds the keys. Apple's iCloud offers optional Advanced Data Protection that extends end-to-end encryption to most data.
Does zero-knowledge encryption protect against data breaches?
It significantly reduces the impact of a server-side breach. If an attacker compromises the provider's servers, they gain access only to encrypted data that they cannot decrypt without your key. This is a much better outcome than a breach of a service that holds encryption keys, where the attacker may gain access to readable data. For more on this, see our page on understanding data breaches.
Can the government force a zero-knowledge provider to hand over my data?
A government can compel the provider to hand over whatever data they have, but in a zero-knowledge system, that data is encrypted. Without your key, it is unreadable. The provider cannot comply with a request for your data's contents, because they do not have the technical ability to decrypt it.
What is the difference between zero-knowledge encryption and zero-knowledge proofs?
These are different concepts that share the "zero knowledge" label. Zero-knowledge encryption means the provider knows nothing about your data's contents. A zero-knowledge proof is a cryptographic technique where one party proves they know something (like a password) without revealing the thing itself. Some zero-knowledge encryption systems use zero-knowledge proofs as part of their authentication process, but the concepts are distinct.
Should I choose a zero-knowledge service for everything?
That depends on your priorities. Zero-knowledge encryption provides the strongest privacy protection but comes with trade-offs in account recovery and, in some cases, feature availability. For sensitive data (financial records, client files, personal documents, creative work in progress), the protection is worth the trade-offs. For data where convenience matters more than confidentiality, you may find standard encrypted services acceptable. Many people use a mix of both, keeping sensitive material in a zero-knowledge workspace and less sensitive data elsewhere.


