PRIVACY
What is zero-knowledge, end-to-end encryption?
Zero-knowledge, end-to-end encrypted cloud storage encrypts your files on your own device, before they are uploaded. The provider stores the encrypted files but never holds the keys that unlock them, so it cannot read what you store. You keep the keys, which also means you carry the responsibility for not losing them.
Almost all cloud storage is encrypted in some form. Very little of it is encrypted in a way that stops the provider reading your files.
This article explains where that line falls, what happens to a file after it leaves your device, and what you give up in exchange for the privacy you get.
Quick answer: what is zero-knowledge, end-to-end encrypted cloud storage?
Zero-knowledge, end-to-end encrypted cloud storage encrypts your files on your own device, before they are uploaded. The provider stores the encrypted files but never holds the keys that unlock them, so it cannot read what you store.
Five things to know:
- How it differs from ordinary encryption. Most providers encrypt your files after receiving them, using keys they generate and hold. They can read your files whenever they choose.
- What the two terms mean. End-to-end encryption (E2EE) describes where the encryption happens, which is on your device. Zero-knowledge describes what the provider knows, which is nothing.
- How it works. Your password derives a key, that key unlocks your master key, and your master key unlocks a separate key for every file. None of it happens on the server.
- What it does not cover. File contents, file names and thumbnails are encrypted. Account details such as your email and IP address are not, and a compromised device breaks the model.
- The trade-off. A provider using this model cannot reset your password for you. Your recovery key is the only way back into your account.
Full explanation below.
In this blog
- Quick answer: what is zero-knowledge, end-to-end encrypted cloud storage?
- What are the three levels of cloud storage encryption?
- Zero-knowledge and end-to-end encryption: what is the difference?
- What happened when researchers tested MEGA‘s encryption?
- How does MEGA use zero-knowledge, end-to-end encryption?
- Frequently asked questions
What are the three levels of cloud storage encryption?
Encryption has protected information for a long time, and it matters most when your data is stored or shared online. Not all encryption offers the same protection, though, and the difference comes down to a single question: who holds the key?
Here are the three levels you will come across in cloud storage.
Level 1: no encryption
Data stored without encryption can be read by anyone with access to it. No key is needed.
Think of it as storing an important document at a bank, where the bank leaves it on a desk in the back office. Staff can read it or copy it whenever they like, and so can anyone who wanders in.
Almost every service that handles your files encrypts them to some degree, so this is now rare. It still turns up in older systems and in some free file-hosting tools.
Level 2: encryption the provider controls
Encryption scrambles your data so that only someone with the key can read it. The methods in common use are strong: AES, the standard most providers rely on, has been a US federal standard since 2001 and remains unbroken in practice.
So for cloud storage, the question is not whether your files are encrypted. It is who encrypts them, and when.
Most providers receive your file first and encrypt it afterwards, on their servers. They generate and hold the key. That means they can read your file whenever they choose, and your file is exposed on the way to them.
Back to the bank. This time they put your document in their safe. Far better than the desk, but it is not private. Staff saw the document on the way in, and they hold the key to the safe. You are trusting them not to look, not to misuse what they see, and not to leave the key where someone else finds it.
This is how most mainstream cloud storage works, and the providers are open about it. Google‘s own documentation states that by default Google manages the encryption keys for Workspace content. Its client-side encryption option, where the customer controls the keys instead, is a separate feature available only on certain editions – and Google notes that when it is switched on, files ”aren‘t scanned for phishing and malware, because Google‘s servers don‘t have access to the content.”
That sentence is the whole distinction in miniature. When the provider can scan your files, it can read them.
Level 3: zero-knowledge, end-to-end encryption
Your file is encrypted on your device, before it goes anywhere. The service stores the encrypted file and has no way to decrypt it, even though it is the one holding it.
Now you lock your document in your own safe before handing it to the bank. Nobody else can open it, because only you have the key.
When a cloud storage service uses zero-knowledge, end-to-end encryption, you do not have to trust it not to look at your files. It cannot.
Zero-knowledge and end-to-end encryption: what is the difference?
The two terms describe different things, which is why you usually see them written together.
End-to-end encryption (E2EE) describes where the encryption happens. Your file is encrypted on your device and decrypted only on a device you control. Nothing in between can read it.
Zero-knowledge describes what the provider knows, which is nothing. It never holds a key that can open your files.
In cloud storage the two normally go together, but not always. A service can encrypt files end to end between users and still keep a recovery key on its own servers, so it can restore your account if you forget your password. The files travel encrypted, but the provider can still open them. That is end-to-end encrypted without being zero-knowledge.
You will also see two other terms used for the same idea. Client-side encryption means the encryption happens in the client, meaning your app or browser, rather than on the server. Zero-access encryption means the provider has no access to your files. Both describe the same arrangement from a different angle.
Providers make these claims themselves, and the claims are not always as strong as they sound. If you want to check one rather than take it at face value, we have written a separate guide on how to verify real zero-knowledge protection.
What happens to your file after you upload it?
Your password unlocks a key, that key unlocks other keys, and those keys unlock your files. None of it happens on the server.
Here is the sequence MEGA uses, which is documented in full in our Security White Paper:
- Your password becomes a key. When you log in, your device runs your password through a key derivation function to produce a key. Your password itself is never sent to us.
- That key unlocks your master key. Your master key is generated on your device when you create your account, and it is stored with us only in encrypted form.
- Every file gets its own key. Files are not encrypted with one account-wide key. Each file is given its own key, encrypted in turn by your master key.
- Files are encrypted before upload. Your file is split into chunks and each chunk is encrypted on your device. What arrives on our servers is already unreadable. File names, thumbnails and previews are encrypted too.
- Sharing works by sharing keys, not files. When you share a folder, your device encrypts that folder‘s key using the recipient‘s public key. Only they can unwrap it.
Because every private key is encrypted with your master key before it reaches us, and your master key is itself encrypted with a key derived from your password, there is no point in that chain where we hold something that opens your files.
You do not have to take our word for the implementation. MEGA publishes the full source code of its client applications, so anyone who wants to check what the software actually does can read it.
What does end-to-end encryption not protect?
No encryption model covers everything, and a provider that suggests otherwise is overselling.
E2EE protects the contents of your files. It does not hide the fact that you have an account. We still store account information such as your email address and IP address, because the service cannot operate without it, and that information is protected by policy rather than by mathematics.
The model also assumes your own device is secure. If someone installs malware on your laptop or phone, they can read your files at the moment you open them, whatever happens in the cloud afterwards. Encrypted storage is not a substitute for keeping your device locked down.
What happens if you forget your password?
Zero-knowledge, end-to-end encryption involves a real trade-off, and this is it.
Because we cannot decrypt your files under any circumstances, we also cannot reset your password for you. There is no back door for us to use on your behalf, which is the point, but it means the usual ”forgot password” safety net does not exist in the same form.
Instead you get a recovery key: a unique code that lets you reset your password yourself. Technically, your recovery key is your master key, which is why it can do this and why nobody else can be given a copy.
Two things follow from that. If you lose both your password and your recovery key, the files stored in your account cannot be recovered by anyone, including us. And because the recovery key is so powerful, resetting a password with it also requires confirmation by email, so the recovery key on its own is not enough for someone else to take over your account.
Export your recovery key when you set up your account, and store it somewhere separate from your password.
What happened when researchers tested MEGA‘s encryption?
Any provider making strong cryptographic claims should expect those claims to be tested. MEGA‘s have been, publicly, and the results are worth setting out because they are still cited in discussions about MEGA‘s security.
In 2022, researchers at ETH Zürich published five attacks against MEGA‘s cryptographic design. They reported the findings to us in March 2022 under a 90-day disclosure window, and we released updates to all client software on 21 June 2022, before the research was made public. The most practical of the attacks required an adversary who already controlled MEGA‘s server infrastructure, or who could mount a successful man-in-the-middle attack on the connection, and who could then wait for the account holder to log in at least 512 times. MEGA was not aware of any user account being compromised through any of them, and we paid the researchers a vulnerability reward.
A second team published a follow-up at Eurocrypt 2023, showing that the checks added in the first round of fixes could themselves be exploited. They reported it in September 2022, we acknowledged it the next day, and the fixes shipped in web client version 4.32.4 with a security update published in March 2023.
Two points are worth making plainly, because summaries of this research often drop one or the other.
The first is that these were design weaknesses found by cryptographers with MEGA‘s published source code in front of them, not breaches. Every attack assumed an adversary in control of MEGA‘s own infrastructure. None of them was ever observed being used against an account. The second is that the researchers were clear that the patches addressed the specific attacks.
We link to the original research rather than paraphrasing it, because publishing our source code is not much use as a transparency measure if we then ask you to take our summary of the findings on trust.
Who needs zero-knowledge cloud storage?
Not everybody needs zero-knowledge cloud storage. For holiday photos and a copy of your CV, mainstream cloud storage is usually fine.
It matters more when the contents of a file would cause real harm if read by someone else:
- client files held under professional confidentiality, in law, accountancy, medicine or therapy
- identity documents, passports and financial records
- research data, source material and anything given to you in confidence
- business documents covered by a contractual or regulatory duty of care
If you are weighing up options rather than looking for a definition, our guide to secure and private cloud storage in 2026 compares the main providers, and our look at what encrypted storage actually costs covers the price side.
How does MEGA use zero-knowledge, end-to-end encryption?
Everything you store with MEGA is encrypted on your device before it reaches us, using the key chain described above. That applies to files, file names, thumbnails and the folders you share.
You control who else sees a file and what they can do with it. All users can set permissions on shared folders, and Pro and Business subscribers can also password-protect links and set expiry dates on them.
We publish our client source code and our Security White Paper so the claims on this page can be checked rather than believed.
Frequently asked questions
What is the difference between zero-knowledge and end-to-end encryption?
End-to-end encryption describes where encryption happens: on your device, before upload. Zero-knowledge describes what the provider knows, which is nothing. A service can be end-to-end encrypted and still hold a recovery key that lets it open your files, so the two are not automatically the same thing.
Can a cloud storage provider read your files?
Most can. If the provider generates and stores the encryption keys, it has the technical ability to read what you store, whatever its policy says. Only providers using zero-knowledge encryption are unable to.
Is Google Drive end-to-end encrypted?
Not by default. Google encrypts Drive content in transit and at rest, and manages the keys itself. Google Workspace offers client-side encryption as a separate feature on some editions, where the customer controls the keys instead.
Is end-to-end encrypted cloud storage slower or harder to use?
Encrypting and decrypting on your device adds a little work, but on modern hardware you are unlikely to notice it during everyday uploads and downloads. The real difference is account recovery: you have to look after your own recovery key, because nobody can reset your password for you.
Does end-to-end encryption protect file names as well as file contents?
With MEGA, yes. File names, thumbnails and previews are encrypted alongside the file contents. Not every provider does this, so it is worth checking: a service that encrypts contents but leaves file names readable gives away a good deal about what you are storing.
Is zero-knowledge encryption the same as client-side encryption?
They describe the same arrangement from different angles. Client-side encryption means the encryption happens on your device rather than the server; zero-knowledge means the result is that the provider holds no usable key. In practice, a service doing one properly is doing the other.