Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Koofr describes several layers of security, but standard Koofr storage is not presented as end-to-end or zero-knowledge encrypted. It says transfers use SSL/TLS, files are encrypted on its servers, and each file is stored in at least three physically separate locations. For client-side, zero-knowledge encryption, Koofr offers the optional Koofr Vault. Your account also supports TOTP authentication and FIDO2 passkeys, with an important recovery caveat: Koofr says support cannot restore access if you lose your second factor and recovery codes.

What Koofr’s security claims mean

Koofr’s security descriptions cover different points in a file’s journey. They are useful protections, but they do not all answer the same question: who can decrypt your files?

  • In transit: Koofr says file transfers use SSL/TLS, which protects data as it moves between your device and the service. Koofr’s safety help page and its features page describe this protection.
  • On Koofr’s servers: Koofr says files are encrypted after upload. Server-side encryption protects stored data, but it does not by itself mean that only you hold the key or that Koofr cannot access file contents.
  • Client-side encryption: Koofr identifies Vault as its optional client-side encryption feature. In Koofr’s description, files are encrypted on your device before upload and only you know the encryption key. That is the distinction that matters if you specifically need a zero-knowledge storage option.

Koofr also says metadata, including file names and ownership information, is stored separately from file contents, and that decryption keys and metadata are kept separate from content. These are Koofr’s descriptions of its systems, not independently verified findings.

Does Koofr use end-to-end or zero-knowledge encryption by default?

Koofr’s materials describe server-side encryption for ordinary storage and identify Vault separately as client-side, zero-knowledge encryption. On that basis, do not treat standard Koofr storage as end-to-end or zero-knowledge encrypted. If your requirement is that the provider should not know the key used to decrypt file contents, Koofr points to Vault.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Vault changes

Koofr says Vault encrypts files on your device before they leave it and that only you know the encryption key. The company also says Vault is open source, so its functionality can be inspected. Those statements describe Koofr’s model; the official pages reviewed do not establish an independent cryptographic audit or security review of Vault. See Koofr’s privacy page for its description of Vault.

Where Koofr stores files and what its privacy policy says

Koofr identifies its controller as Koofr d.o.o., headquartered in Ljubljana, Slovenia. Separately, it says its file servers are in Germany, within the EU, in ISO 27001-certified data centers. The stated certification applies to the data centers; it is not evidence here that every Koofr security control has been independently certified. Koofr describes its hosting and controller details in its privacy policy and privacy help page.

Information and activity records

Koofr’s privacy policy says an account requires a name and email address. Paid purchases may involve additional billing details, with payment processing handled by a third-party processor. The policy also says the service logs selected account events, including password changes, uploads, deletions, and link creation, and retains those event logs for three months.

The same policy says account deletion is processed no later than 30 days after a request, except for records Koofr must retain by law, such as invoices. These are policy statements and may change; consult the current Koofr privacy policy for the terms that apply to your account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Koofr’s stated use of data

Koofr says it does not use third-party tracking tools or marketing newsletters, and does not sell or give data to advertisers. Its privacy policy names service-associated providers, including payment processing and accounting, as exceptions. These are the company’s stated practices rather than independent audit findings.

How to protect your Koofr account

File encryption does not prevent someone from taking over an account with a compromised password. Koofr documents TOTP authentication and passkeys as second-factor choices. A TOTP app produces one-time codes; Koofr’s passkeys use FIDO2 and are designed to verify the site domain, which Koofr says provides stronger phishing protection than one-time codes. Passkeys can use device biometrics, a device PIN, a smart device, or a physical security key such as a YubiKey. Details are in Koofr’s two-factor authentication guide.

  1. Use a unique, strong password. Avoid reusing a password from another service.
  2. Enable a second factor. Choose a TOTP app or a passkey; you can add multiple second factors.
  3. Save the recovery codes securely. Koofr provides ten one-time codes. Keep them somewhere separate from the device or account they protect, such as a secure password manager or a protected offline copy.
  4. Set up an alternative factor if practical. An additional factor can help if your primary device is lost or unavailable.

The recovery process is a meaningful trade-off: Koofr says the recovery codes are the way back in if you lose access to your second factor, and that its support team cannot restore access to an account with 2FA enabled. Read Koofr’s guidance on losing a second factor before turning 2FA on, and keep the codes accessible without making them easy for someone else to obtain.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available evidence does—and does not—establish

Koofr’s official pages describe transport encryption, server-side encryption, file redundancy, data separation, hosting location, privacy practices, Vault, and account-security options. They do not establish an independent penetration-test result, an independent cryptographic review, or a regulator’s finding about Koofr. The ISO 27001 statement concerns the data centers Koofr says it uses, not a blanket independent certification of Koofr’s service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

So, “safe” depends in part on your needs. Koofr describes protections for files in transit and at rest, redundancy, and account second factors. If your requirement is that Koofr should not know the decryption key, use Vault rather than assuming standard storage has that property. For the account itself, protect the password, enable a second factor, and make the recovery process part of your setup.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.