Glossary

What is zero-access encryption?

Zero-access encryption means your data is stored encrypted with keys the service provider doesn’t have, so the provider can’t read it, even if it wanted to or was ordered to. The keys are created and kept on your devices, and only reach the provider’s servers in encrypted form.

Also called: stored with zero-access encryption

Updated September 2026. Sources are numbered and listed at the end.

How zero-access encryption works

Almost every big service says your data is “encrypted at rest.” That usually means the provider encrypts its disks with keys it manages itself,1 which protects against a stolen hard drive, not against the provider. Zero-access moves the keys to you.

Three terms that sound alike but promise different things.
Who holds the keysCan the provider read stored data?
Encryption at restThe providerYes
Zero-access encryptionYou, on your devicesNo
End-to-end encryptionSender and recipientNo, and it also covers the trip between them

For email, the two protections work together. Mail between people on the same encrypted service can be end-to-end encrypted the whole way. Mail from an ordinary provider arrives protected in transit by TLS. A zero-access service then encrypts it with your public key as it lands, so from that point on only your private key can open it. That is what the phrase “stored with zero-access encryption” means.

Your private key has to live somewhere you can reach from a new phone. Zero-access services store it encrypted with a secret derived from your password or a recovery phrase, and that derivation happens on your device, so the server only ever sees the locked version.

Why it matters

  • Breaches: if the servers are hacked, the attacker gets sealed data.
  • Insiders: staff can’t browse what they can’t decrypt.
  • Legal demands: a provider can only hand over what it can read. With zero-access, stored content comes out encrypted.
  • Profiling: a provider can’t scan stored mail for ads or AI features without the keys.

Where you’ll see it

The term is most common with encrypted email providers. The same idea appears elsewhere under other names, such as Apple’s optional Advanced Data Protection for iCloud, where Apple says it doesn’t hold the keys to the protected categories.2 It overlaps with “zero-knowledge,” a term borrowed from cryptographic proofs; our explainer on what zero-knowledge means covers the difference.

Zero-access in Secria

Every Secria Mail account, free included, uses zero-access encryption. Keys are created on your device and only ever reach our servers encrypted. Stored mail is sealed with keys we never hold, so we can’t produce its contents, and every message in it is protected with ML-KEM-1024 and X25519 on top. See how it works on Secria Mail or in the whitepaper.

Sources

  1. Google Cloud, Default encryption at rest.
  2. Apple, iCloud data security overview.

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about zero-access encryption

What does “stored with zero-access encryption” mean?+

It means the data is kept on the provider’s servers in a form only your keys can unlock. The provider stores it but can’t read it.

Is zero-access encryption the same as end-to-end encryption?+

Not quite. Zero-access covers data while it’s stored. End-to-end covers a message from the sender’s device to the recipient’s. Good encrypted email services use both.

Is zero-access the same as zero-knowledge?+

They’re often used for the same promise: the provider can’t see your data. Zero-knowledge originally names a type of cryptographic proof, so zero-access is the more precise term for storage.

Who can read my data with zero-access encryption?+

Only you, on your own devices, plus anyone you choose to share it with. The provider stores the encrypted data but doesn’t hold the keys to open it.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.