Priviy
privacy-basicsINFO

What Is AES-256? What the Number Means, and What It Does Not Promise (2026)

Every storage provider advertises AES-256. The standard is real and the cipher is sound, but the label says nothing about who holds the key - which is the part that decides whether your files are private.

By Eric Gerard · Editor · Priviy3 min readPhoto: Pexels

Open any cloud storage pricing page and you will find it: AES-256, usually in bold, often beside the word "military-grade". It is a real standard and a sound cipher. It is also, on its own, close to meaningless as a privacy claim.

What the standard actually says

AES is defined by NIST in FIPS 197, published on 26 November 2001 and updated on 9 May 2023 - an update that, in NIST's own words, "makes no technical changes to the algorithm". The cipher comes from the Rijndael family, chosen as the winner of the AES competition in 2000.

The standard specifies three variants: AES-128, AES-192 and AES-256. All three transform data in blocks of 128 bits, and the number in the name refers to the length of the key, not the block.

That detail is worth keeping, because "256" is routinely presented as though it described the strength of everything around it. It describes one parameter of one cipher.

Why AES-256 is not "twice as good" as AES-128

Key length does not scale linearly into security. AES-128 is not weak, and there is no practical attack that breaks it. The realistic gap between the two variants is not something an attacker exploits today; it is a margin against future advances.

Choosing a provider because it says 256 rather than 128 is optimising a parameter that is not where your risk lives.

The part the label leaves out

Here is what matters, and no amount of key length answers it: AES-256 says nothing about who holds the key.

A provider can encrypt your files with AES-256, store them perfectly, and still be able to read every one of them - because it generated the key, it keeps the key, and it can use the key. Encryption at rest with a provider-held key protects your data from someone who steals the disks. It does not protect it from the provider, from a subpoena served on the provider, or from an employee with access.

The question that decides privacy is not which cipher but where the key is created and who can use it. That is the difference between encryption in general and zero-knowledge encryption, where the key never leaves your device.

How to read a provider's page

"AES-256 encryption" alone tells you almost nothing. Every serious provider uses a strong cipher; it is table stakes, not a differentiator.

Look for where the key is held. Phrases worth finding: client-side encryption, end-to-end, zero-knowledge, "we cannot reset your password". That last one is the most honest tell - a provider that can restore access to your files without your password can also read them.

Be wary of "military-grade". It is a marketing phrase, not a specification. It usually means AES-256, which is to say the same thing everyone else uses.

Check what is encrypted. File contents are the easy part. Filenames, folder structure, sharing metadata and timestamps are often not covered, and they reveal more than people expect.

The short version

AES-256 is a real standard, defined in FIPS 197, with a 128-bit block and a 256-bit key. It is sound, it is universal, and it is not a privacy claim. What decides whether your files are private is who holds the key - which is a question the label never answers.

One person holding out a bunch of keys above the open palm of another person, both in close-up against a grey wall
One person holding out a bunch of keys above the open palm of another person, both in close-up against a grey wall
A set of keys passing from one hand to another. The strength of the lock is not in question here; who ends up holding the key is, and that is exactly what an AES-256 label leaves unsaid.

Frequently asked questions

What is AES-256?
AES-256 is one of three variants of the Advanced Encryption Standard defined by NIST in FIPS 197, alongside AES-128 and AES-192. All three encrypt data in blocks of 128 bits; the number refers to the length of the key. The standard was published in November 2001 and updated in May 2023 with no technical change to the algorithm, and is based on the Rijndael cipher family selected in 2000.
Is AES-256 better than AES-128?
It has a longer key, but that does not translate into twice the security, and AES-128 has no practical break either. The difference is a margin against future advances rather than protection against an attack that exists today. Choosing a provider on 256 versus 128 optimises a parameter that is not where the real risk sits.
Does AES-256 mean my provider cannot read my files?
No, and this is the most common misreading. AES-256 describes the cipher, not who holds the key. A provider that generates and stores the key can decrypt everything it holds, whatever the key length. Only client-side or zero-knowledge encryption, where the key never leaves your device, prevents that.
What does 'military-grade encryption' mean?
It is a marketing phrase with no technical definition. In practice it almost always means AES-256, which is what nearly every provider uses. It signals nothing that distinguishes one service from another, and its presence on a page is not evidence of anything beyond a copywriter.
What should I check instead of the cipher?
Where the key is created and who can use it, and what exactly is encrypted. Filenames, folder structure, sharing metadata and timestamps are frequently left unencrypted even when file contents are protected. A useful test: if the provider can restore your access after you forget your password, it can also read your files.
Choix éditorial
4.5 / 5

Store your files privately → pCloud

Swiss privacy · 10 GB free · optional zero-knowledge Crypto

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre