← Blog
Comparison7 min read

Dropbox vs encrypted alternatives for client work

Where mainstream cloud suites excel, where they leave client material readable, and how to decide which files justify moving to a zero-knowledge workspace.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

The fair version of the comparison Mainstream cloud suites are excellent products. Sync is reliable, integrations are everywhere, collaborative editing works, and everyone already knows how to use them. Pretending otherwise helps nobody.

They are also built to read your files. Preview generation, search indexing, collaborative editing and AI features all require access to plaintext. That is not a flaw; it is what makes those features possible.

What that means for client work When you store a client's material with a provider that can read it, three things follow:

  • Confidentiality depends on that provider's staff, policy and legal exposure — not on cryptography.
  • An NDA promising that client material stays confidential becomes a statement about a third party's behaviour.
  • Access control is a permission list. Permission lists drift, and a misconfiguration produces readable data.

What an encrypted alternative changes In a zero-knowledge workspace, access is the ability to decrypt. Membership means holding a key sealed to you. Removing someone rotates keys rather than editing a list. A misconfiguration cannot produce plaintext for someone without a key envelope, and neither can the provider.

What you give up Be honest about this before migrating:

  • No provider-side universal preview or server-side search index; both move to your device.
  • No third-party integrations that read your content.
  • No password reset that recovers data; recovery depends on an offline kit.
  • Real-time collaborative editing is more constrained than in a suite built around server-side documents.

A workable split Most firms do not need to move everything.

  • Keep in the mainstream suite: marketing assets, public documents, internal admin, anything already shareable.
  • Move to an encrypted workspace: client deliverables, contracts and NDAs, unreleased creative work, source code, financial models, personnel and medical data.

The test is simple: would a leak of this file cost money, a client or a reputation? If yes, the key belongs with you.

Migration without drama Move one client or one project first. Set up the encrypted space, move current material, redirect intake and delivery to protected links, then leave the old folder read-only for a month before archiving it. Extend once the habit sticks.

The commercial angle The comparison is increasingly made for you by buyers. Security questionnaires ask who can read supplier-held data. Being able to say "not my provider, and here is why" is a differentiator that costs nothing to maintain once it is true.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload