All articles

What is zero-knowledge encryption? A plain guide

Kent — founder, former banking CTO/CIO · May 6, 2026

They can't read it

Zero-knowledge encryption means a service can store your data without ever being able to read it.

Your information is scrambled — encrypted — on your own device before it's sent anywhere, and the key to unscramble it never leaves you. So the company holding your data has "zero knowledge" of what's actually inside.

How it works

Locked before it leaves your device

Your information is scrambled on your device — your phone or computer — before it ever reaches a company's servers, with a key derived from your password that never leaves you.

The company can still sync your data across your devices, back it up, and keep it safe from loss — but every copy it holds is a locked box it has no way to open. It never receives your password, and it never stores your key.

Diagram: your data is encrypted on your device with a key that never leaves it; only the scrambled version travels, over an encrypted connection, to the company, which stores only data it cannot read.

Regular vs. zero-knowledge

It's not whether they encrypt — it's who holds the key

Most online services encrypt your data too. The difference is who can unlock it.

Regular encryption

The service holds the keys. It can decrypt and read your data whenever it wants — and so can anyone who compromises it.

Zero-knowledge encryption

The service never holds your key. It can never read your data — even if it's asked to, even if it's breached.

Regular encryption mostly protects your data from outside attackers, in transit or storage. Zero-knowledge protects it from outsiders and from the company itself.

Two terms, two questions

Zero-knowledge vs. end-to-end

You'll often see the two together. They overlap — but they answer slightly different questions.

End-to-end encryption

Data in motion. Encrypted on one device, decrypted only on another — no one in between, not even the service relaying it, can read it along the way.

Zero-knowledge

Data at rest. The service storing your data holds no key, so it can't read what it keeps. Ever.

A service can have one without the other — a messaging app can be end-to-end encrypted yet keep readable backups on its servers; a storage service can encrypt files at rest yet hold the keys itself. Simply Once is deliberately both: your vault is end-to-end encrypted between your devices and zero-knowledge on our servers, so your information is unreadable to us in transit and in storage. (And if "security" versus "privacy" itself feels fuzzy, here's the difference in plain English.)

Why it matters

It takes the company off the list

Zero-knowledge removes the company from the list of people who can see your private information. In practice:

A breach exposes nothing usable

Attackers get only scrambled data — with no key anywhere on the servers to unlock it.

Nothing to mine or sell

The company can't quietly analyze, profile, or monetize information it cannot read.

Nothing readable to hand over

It can't be compelled to produce your data in readable form — it simply doesn't have it.

Even in a data breach, a legal demand, or an insider abusing their access, your data stays unreadable to everyone but you.

When it's breached

What a breach actually looks like

Picture two password managers, both broken into the same way. With ordinary encryption, the attacker who gets in can often reach the keys too — and your logins spill out in readable form. That's how most credential leaks actually happen. With zero-knowledge encryption, the same attacker walks away with nothing but scrambled blobs and no key to open them — exposed on paper, useless in practice.

The same logic holds for a subpoena or a rogue employee — there's simply nothing readable to hand over or peek at. That's the difference between a company that promises not to look and one that built itself so it can't.

Two hands holding a small closed wooden box with a brass keyhole — with zero-knowledge encryption, you hold the only key.

The tradeoff

You hold the only key

Because the company never has your password or your key, it genuinely can't recover your data if you forget your master password — no "reset password" email can unlock a vault only you can open.

That's the point, not a flaw — it's what makes the privacy real. It's also why a good zero-knowledge service helps you set up recovery options and trusted emergency access in advance, so you and the people you trust aren't locked out.

How to tell

Spotting the real thing

Three things a genuinely zero-knowledge service will be true of — and one red flag.

It can't show you your own data without your password. No support agent, no admin console, no exceptions.
It can't reset your master password for you. A real "we can't recover it" policy is the signature of real zero-knowledge.
It says plainly that encryption happens on your device — before anything is uploaded, not after.
The red flag: if a company can email you your stored data, or restore access without your master password, it isn't truly zero-knowledge — it's holding a key it could use.

Where Simply Once fits

Simply Once is built this way. Your passwords, documents, and IDs are encrypted on your device with zero-knowledge, end-to-end encryption — so not even we can read them. See exactly how, down to the specific encryption used, on our security page.

Part of the guides to protecting your personal data and organizing your family's information →

Get the monthly note

One useful, jargon-free email a month on keeping your digital life organized and protected — no spam, unsubscribe anytime.

No spam, ever. Unsubscribe anytime.