01 What zero-knowledge actually means

Most cloud storage works the way you'd expect a filing clerk to work: you hand them a document, they put it in a drawer, and if someone important asks to see it, they can open the drawer. Google Drive, Dropbox and OneDrive all encrypt your files — at rest and in transit — but they hold the keys. That means they can preview your files, index your content for search, and comply with a court order by handing over readable data.
Zero-knowledge flips the model. Services like Proton Drive, Sync.com, MEGA and Tresorit encrypt your files on your device, before anything reaches their servers. They store only the ciphertext — scrambled data they have no key to unlock. The provider literally cannot read your files, cannot hand them to an advertiser, and cannot produce readable content in response to a subpoena. When they say they can't see your stuff, it's structural, not a policy choice.
End-to-end encryption (E2E) is the mechanism that makes this work. The keys live with you — derived from your password, stored in your apps — and the service never sees them. That's the meaningful distinction from "encrypted storage" in the ordinary sense.
02 The trade-offs are real
Zero-knowledge is not free. The moment a service can't read your files, several things stop working.
No server-side search or preview. Google Drive can search inside a PDF; Proton Drive can't, because the content is opaque to the server. Search works only on local, decrypted copies. For most files this is fine. For a large document archive it's a genuine friction.
Password recovery is hazardous. If your keys come from your password and you lose that password, recovery is hard by design — it varies by provider, but you may lose access to your files entirely. Proton and Sync.com both offer account recovery options, but they involve careful setup (recovery keys, trusted devices) that requires you to actually do the setup before disaster strikes. Skip it and you're on your own.
Sharing is more complex. Sharing a zero-knowledge file means sharing the decryption key along with the link — either embedded in the URL or sent separately as a password. This usually works cleanly in practice, but it means a share link carries real cryptographic weight. Leak the link, leak the key.
Collaboration features lag. Real-time co-editing requires the server to see the document. That's fundamentally incompatible with zero-knowledge. Proton Drive and Tresorit prioritise privacy over Google Docs-style collaboration; if you need both, you're choosing a trade-off, not a free lunch.
03 Who should actually care
For a lot of people — storing photos, sharing holiday videos, keeping work documents accessible — mainstream storage is fine. The risk of a Google engineer casually reading your tax return is vanishingly small. What's not small is the risk of data breaches, ad-targeting based on file content, or the slow drift of a provider's business model in directions you didn't sign up for.
Zero-knowledge storage makes sense if you handle sensitive client documents (legal, medical, financial), if you operate in a jurisdiction where government data requests are a real concern, or simply if you find the idea of a corporation holding the keys to your files philosophically uncomfortable. All are legitimate reasons.
Among the main players: Proton Drive is based in Switzerland and benefits from strong Swiss privacy law; it integrates well if you're already in the Proton ecosystem (Mail, VPN). Sync.com is Canadian-based and has offered zero-knowledge sync and sharing for years. Tresorit targets business users and has serious compliance credentials. MEGA — founded in New Zealand by Kim Dotcom, though he has since departed the company — offers a notably generous free tier and zero-knowledge encryption, though its corporate history is more complicated than the others.
None of them are perfect. All of them represent a genuine structural commitment to not being able to read your files — which is more than most of the cloud industry can honestly say.
Named in this guide
Proton Drive
Swiss privacy-focused cloud storage with E2E encryption; part of Proton AG
Sync.com
Canadian zero-knowledge cloud storage provider
Tresorit
business-oriented E2E encrypted storage with compliance focus
MEGA
New Zealand-founded cloud storage with generous free tier and zero-knowledge encryption
Kim Dotcom
MEGA's founder; has since departed the company