Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Sync.com says its core storage service encrypts files on your device before upload, so Sync does not hold the key needed to read them. But that protection depends partly on your account settings: if email-based password reset is enabled, Sync keeps an encrypted copy of your private encryption key in escrow to help restore access. That recovery option is the main qualification to Sync’s zero-knowledge claim.

What “zero knowledge” means for Sync.com

In a zero-knowledge storage model, the provider is not supposed to have the key needed to decrypt your stored files. Sync describes its core service as end-to-end encrypted by default: files are encrypted on your device before they are sent to Sync.com. Sync’s SOC 3 report says client-side file encryption uses 256-bit AES, and that file data sent over public networks is protected with TLS. These are descriptions in Sync’s own report, not an independent assessment of its implementation. Sync security information

This model concerns access to file contents. It does not mean that every feature or account configuration has precisely the same encryption properties. Sync’s terms say selected content may temporarily use a different level of encryption to support some optional features; the details can depend on the plan, privacy settings, and features in use. Sync.com Terms of Service

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can Sync.com read your files?

For core storage under Sync’s stated design, Sync says it does not possess the key needed to read your files. The important exception is email-based password reset: when that feature is enabled, Sync stores an encrypted copy of your private encryption key in escrow. Sync says this does not expose your password, but it temporarily gives its automated systems access to the account encryption key for recovery.

#1 Best Overall
Integral 16GB Crypto-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Rugged Double-Layer Waterproof Design
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password

Sync’s Terms of Service, section 17.2, puts the distinction plainly: “When this feature is enabled, your Account is not configured on a strictly zero-knowledge basis, as Sync must retain the technical ability to assist in recovering access to your Account by using the escrow key.” Sync.com Terms of Service

So the most accurate answer is conditional: Sync says the core storage design is end-to-end encrypted, but an account with email-based password reset enabled is not strictly zero knowledge under Sync’s own definition. The available sources do not establish independent cryptographic testing or a complete feature-by-feature list of exceptions.

Rank #2
Integral 8GB Courier-197 256-Bit Hardware Encrypted 3.0 USB Secure Flash Memory Drive - Certified to FIPS 197, Brute-Force Password Attack Protection & Super USB3.0 Transfer Speeds
  • Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
  • Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
  • Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
  • Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
  • SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac

What happens if you forget your password?

Sync says it does not store or transmit your password. If email-based password reset is enabled for your account, the escrowed encryption key provides a recovery path. If you disable that feature, Sync says it permanently deletes the escrowed key and cannot recover the account if you forget the password. Sync Help Center

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check your plan before changing this setting: Sync says some plans may require email-based reset or may not allow it to be disabled. The choice is therefore between stricter control over the recovery key and an additional way to regain account access. Sync advises keeping your password safe or setting up a supported recovery route.

Rank #3
Integral 4GB Crypto-197 256-Bit 3.0 USB Flash Drive Encrypted - FIPS 197 Certified, Brute Force Password Attack Protection & Waterproof Double Layer Design
  • Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
  • Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
  • Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
  • Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
  • Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.

How to choose your recovery setting

  • Keep email-based reset enabled if the recovery route matters more to you than a strictly zero-knowledge configuration. Sync’s automated systems can use the escrow key to assist with account recovery.
  • Disable email-based reset if you prefer Sync not to retain that escrowed key, and you accept that forgetting your password can make the account unrecoverable through this route.
  • Verify your plan and current settings before deciding. Sync says availability and requirements can vary by plan, and its terms also note that optional features can affect encryption treatment.

Sync’s help pages cover password recovery and password reset. Use the account’s current settings and plan information to confirm which options are available to you.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What if Sync.com is forced to hand over stored data?

Sync’s stated design means that, for core files encrypted on your device, Sync says it does not hold the key needed to decrypt them. The answer is not an unconditional guarantee about every account state or every feature: email recovery involves key escrow, and Sync’s terms describe possible exceptions for selected content and optional features. The available materials describe Sync’s own security claims; they do not establish how a particular legal demand would be handled in every circumstance.

Best Value
Kingston Ironkey Keypad 200 16GB Encrypted USB | Alphanumeric Keypad | Multi-Pin Access | XTS-AES 256-bit | FIPS 140-3 Level 3 Certified | Brute Force & BadUSB Protection | IKKP200/16GB,Blue
  • FIPS 140-3 Level 3 (Pending) Certified Military-Grade Security
  • OS/Device Independent
  • XTS-AES Hardware Encryption
  • Enforced Alphanumeric PIN
  • Multi-PIN (Admin and User) Option
Rank #4
Kingston IronKey Vault Privacy 50 16GB Encrypted USB
  • FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
  • Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
  • Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
  • New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
  • Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.