← Blog
Legal8 min read

Zero-knowledge cloud storage for lawyers: why it matters for attorney-client privilege

Privilege depends on confidentiality being preserved. Here is why provider key custody is the part of the cloud question that deserves the most attention.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Confidentiality is a technical question, not only an ethical one Professional rules generally require reasonable steps to preserve client confidences. In a cloud context, "reasonable steps" has quietly become a technical assessment: who, other than the lawyer and the client, has the ability to read the document?

The three encryption levels, and why only one changes the answer - **In transit (TLS).** Protects against network interception. The provider still receives plaintext. - **At rest.** Protects against a stolen disk. The service decrypts on demand, so staff systems and legal process can still yield readable files. - **Client-side / zero-knowledge.** Keys exist only on user devices. The provider stores ciphertext and cannot produce plaintext at all.

Only the third level removes the provider from the confidentiality circle.

Who is inside the circle by default With conventional storage, the circle silently includes provider administrators, support tooling, backup and indexing systems, integrated third-party applications, and any party able to compel disclosure from the provider. None of these people signed your engagement letter.

What zero-knowledge changes in practice - A subpoena to the vendor produces ciphertext and operational metadata, not documents. - An intrusion into the vendor produces the same. - An internal support tool has nothing to display. - Access to a matter is granted by sealing a key to a specific person, and removing them rotates the remaining keys.

What it costs you No provider-side full-text search across everything (search happens through indexes computed on your own device), no administrator who can reset a password and recover data, and a dependency on an offline recovery kit. These are not gaps; they are the direct consequence of the guarantee. A provider that can rescue you can also be compelled to expose you.

Inadvertent disclosure remains a human problem Cryptography does not fix autocomplete. The countermeasures that do are procedural and mechanical: per-recipient links instead of attachments, passphrases communicated on a second channel, expiry dates on every disclosure, and a habit of revoking links when a matter closes.

Talking to clients about it Clients increasingly ask where their documents live. The strongest possible answer is architectural: the provider hosting them cannot read them, access is per-matter, and every grant and revocation is recorded. That is a conversation about design, not about trust — which is exactly the kind of conversation a lawyer prefers to have.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload