How zero-access encryption works
Almost every big service says your data is “encrypted at rest.” That usually means the provider encrypts its disks with keys it manages itself,1 which protects against a stolen hard drive, not against the provider. Zero-access moves the keys to you.
| Who holds the keys | Can the provider read stored data? | |
|---|---|---|
| Encryption at rest | The provider | Yes |
| Zero-access encryption | You, on your devices | No |
| End-to-end encryption | Sender and recipient | No, and it also covers the trip between them |
For email, the two protections work together. Mail between people on the same encrypted service can be end-to-end encrypted the whole way. Mail from an ordinary provider arrives protected in transit by TLS. A zero-access service then encrypts it with your public key as it lands, so from that point on only your private key can open it. That is what the phrase “stored with zero-access encryption” means.
Your private key has to live somewhere you can reach from a new phone. Zero-access services store it encrypted with a secret derived from your password or a recovery phrase, and that derivation happens on your device, so the server only ever sees the locked version.
Why it matters
- Breaches: if the servers are hacked, the attacker gets sealed data.
- Insiders: staff can’t browse what they can’t decrypt.
- Legal demands: a provider can only hand over what it can read. With zero-access, stored content comes out encrypted.
- Profiling: a provider can’t scan stored mail for ads or AI features without the keys.
Where you’ll see it
The term is most common with encrypted email providers. The same idea appears elsewhere under other names, such as Apple’s optional Advanced Data Protection for iCloud, where Apple says it doesn’t hold the keys to the protected categories.2 It overlaps with “zero-knowledge,” a term borrowed from cryptographic proofs; our explainer on what zero-knowledge means covers the difference.
Zero-access in Secria
Every Secria Mail account, free included, uses zero-access encryption. Keys are created on your device and only ever reach our servers encrypted. Stored mail is sealed with keys we never hold, so we can’t produce its contents, and every message in it is protected with ML-KEM-1024 and X25519 on top. See how it works on Secria Mail or in the whitepaper.
Related terms
Sources
- Google Cloud, Default encryption at rest.
- Apple, iCloud data security overview.
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.