What zero-knowledge actually means
The term gets thrown around loosely in marketing. Here's what it means precisely.
In a zero-knowledge architecture, files are encrypted on the client's device before they are uploaded to the server. The encryption key never touches the server. The provider stores only encrypted data that they literally cannot decrypt, because they never had the key in the first place.
This is the strongest privacy model available for cloud-based file transfer. Even if the provider is hacked, served with a subpoena, or compromised by a malicious employee, your files remain encrypted with a key the provider never possessed.
The "zero-knowledge" part refers to what the provider knows about your data: nothing. They can see file sizes, timestamps, and metadata, but the actual content of your files is mathematically inaccessible to them.
How zero-knowledge encryption works
A simplified look at the technical flow, no cryptography degree required.
Key generation
Your device generates a unique encryption key. This key is created locally and never leaves your device (or is derived from a password only you know).
Local encryption
Your files are encrypted on your device using that key before anything is uploaded. The server never sees the unencrypted data.
Encrypted upload
The encrypted data is transmitted to the server over TLS. The server stores encrypted blobs it cannot read. It has no way to decrypt them.
Key stays with you
The encryption key remains on your device or is shared directly with your recipient (often via a link fragment that the server never sees). The provider is never in the loop.
Zero-knowledge file transfer tools
If you've determined you need true zero-knowledge file transfer, these are reputable options.
Tresorit
Zero-knowledgeTrue zero-knowledge architecture built from the ground up. Files are encrypted client-side before upload, and Tresorit never has access to your encryption keys. Swiss jurisdiction adds legal privacy protections. Designed for businesses with strict compliance requirements.
From $14/user/mo
SendSafely
Zero-knowledgeClient-side encryption with an API-first approach. Files are encrypted in the browser before upload, and encryption keys are embedded in the link fragment (never sent to the server). Good for developers who need to integrate secure file exchange into existing workflows.
From $30/user/mo
SpiderOak
Zero-knowledgeZero-knowledge cloud backup and storage. Your data is encrypted locally before it leaves your device, and SpiderOak cannot access your files or passwords. Focused on backup and sync rather than file delivery.
From $6/mo (personal)
Keybase (now Zoom)
End-to-end encryptedEnd-to-end encrypted file sharing and messaging. Open-source cryptography. Since the Zoom acquisition, the long-term direction of the product is uncertain, but the existing file sharing functionality remains strong.
Free
The trade-offs of zero-knowledge
Zero-knowledge is the strongest privacy model, but strength comes with real costs. Be honest about what you're giving up.
No password recovery
If you lose your encryption key or password, your data is gone. The provider cannot help you because they never had your key. There is no "forgot password" for your encrypted files.
No server-side processing
The server cannot read your files, which means no server-generated thumbnails, no full-text search, no automated virus scanning, and no content-based workflows. The server sees only encrypted blobs.
Key management complexity
Someone has to manage encryption keys. In zero-knowledge, that someone is you (or your client). This adds friction, especially for non-technical users who just want to upload a document.
Limited collaboration features
Features like payment gates, server-side audit trails, automated expiration enforcement, and admin oversight require the server to have some level of access or control. Zero-knowledge limits what the platform can do on your behalf.
When zero-knowledge matters most
There are real situations where zero-knowledge is the right, or only, choice. If any of these apply to you, prioritize zero-knowledge architecture.
- ✓Attorney-client matters involving active litigation against a government entity
- ✓Whistleblower protection where the platform itself could be compelled to produce data
- ✓National security or intelligence contexts
- ✓Situations where you fundamentally do not trust any third-party provider
- ✓Journalism involving sources who face physical danger if identified
- ✓Political dissidents communicating under authoritarian regimes
When it's not necessary
For most professional document delivery, server-managed encryption with strong access controls and cryptographic erasure provides practical security without the usability costs.
- –Routine tax document delivery between a CPA and their clients
- –Legal document exchange for standard transactions (closings, contracts, filings)
- –Financial statements shared between advisors and clients
- –Insurance documents, medical records for standard professional use
- –Any situation where server-side features (audit trails, auto-expiration, payment gates) are more valuable than zero-knowledge privacy
Honest comparison: zero-knowledge vs. DeadVault's model
DeadVault uses AES-256-GCM with per-file keys, but the server manages those keys. That's not zero-knowledge. Here's exactly how the two models differ.
| Zero-Knowledge | DeadVault | |
|---|---|---|
| Who holds encryption keys | You (the user) | Server (per-file keys, wrapped with master key) |
| Can provider read your files | No, never | Technically possible (server manages keys) |
| Password recovery | Impossible | Standard account recovery |
| Server-side audit trails | Limited (server can't see content) | Full access logging |
| Automatic expiration | Possible but key management is client-side | Server-enforced with cryptographic erasure |
| Payment gates | Not possible (server can't gate decrypted content) | Built-in |
| Client setup required | Often requires key exchange or account setup | Simple link, no account needed |
| Response to subpoena | Provider can hand over encrypted blobs they cannot decrypt | Provider could technically decrypt if keys exist (keys are destroyed on expiration) |
Neither model is universally "better." They serve different threat models and use cases.
Frequently asked questions
Honest answers about zero-knowledge encryption and where DeadVault fits.
DeadVault isn't zero-knowledge.
It's server-managed encryption with cryptographic erasure, a different security model designed for professional document delivery. Your files are encrypted with AES-256-GCM using per-file keys, and those keys are destroyed when your box expires.
If you need true zero-knowledge, we've listed tools above that provide it. If you need secure, simple document delivery with automatic destruction and audit trails, that's what DeadVault does.