Transparency notice · Updated 11 September 2026

What you can verify about ZeroLatch.

Check how the service works, who can recover your files, and what you should back up separately. Here are the current facts and the work still to do.

What you can check today

  • Explore the recipient example. See the instructions, check-in sequence and opening experience using fictional content. The sample does not send email or test a real release.
  • Check delivery processing. View the most recent worker check and up to seven recorded runs. This is not independent monitoring of every service dependency.
  • Keep a separate backup. Follow the file-download and recovery checklist, and rehearse access with your recipient.
  • Read the security model. Simple and Private have different key-recovery responsibilities.

Security review and key custody

No completed independent security audit or certification is published here. Automated software checks and browser walkthroughs do not replace an independent audit or a real sender-to-recipient file-opening test.

Simple keys are currently wrapped using a server environment encryption key. An authorised application service can recover the content key. Migration to an independently managed key-management service is not complete.

Private uses a password or recovery phrase that must reach your recipient separately. ZeroLatch cannot replace a lost Private secret. Recipient addresses, schedules and other operational metadata remain visible to the service. Neither mode is universally zero-knowledge.

Service continuity and support

Check-ins, release processing and recipient access require ZeroLatch and its providers to remain available. There is no independent escrow, guaranteed offline continuation or lifetime service guarantee. Keep originals and an alternative recovery arrangement.

For help, contact support@zerolatch.com. For a vulnerability, contact security@zerolatch.com. No guaranteed response time or round-the-clock emergency support is offered. Never email passwords, Private phrases, release links or sensitive files.

Historical notices

Previous warrant canary: inactive

The previous canary was dated 11 February 2026 and due for renewal on 11 May 2026. That renewal was not verified. Updating this transparency page does not renew the canary.

No current signed statement about government or legal requests is provided. Do not interpret this page, its update date, or the missing renewal as proof that a particular request has or has not occurred.

moved the transparency notice to this address, added verification links, key-custody limits, recovery guidance and support scope. Preserved the previous canary here without renewing it or issuing a new legal-request statement.