"Zero-knowledge" is one of the most overused phrases in security marketing. So let's be precise about what it means at SendOrchard and why it changes what's possible — and what isn't — even under a court order.
The keys live with you, not us
In a zero-knowledge system, the encryption keys that unlock your data are derived from secrets only you hold, and they never leave your devices in a form we can use. We store ciphertext. We do not store the keys to it.
What this means in practice
If a government serves us a valid legal order for the contents of your encrypted mail, we can hand over only what we have: encrypted blobs we cannot decrypt. We're not refusing — we're technically unable. That's a far stronger guarantee than a privacy policy promise.
The honest limits
Zero-knowledge applies to message content. Some metadata — who emailed whom and when — is unavoidable to route mail at all. We minimise it, retain it briefly, and publish a Transparency Report of every request we receive. We believe being clear about the limits is part of being trustworthy.
Verifiable, not just promised
Our encryption libraries are open source so anyone can audit how keys are handled. Trust shouldn't require taking our word for it.