Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.
Z.ai's ZCode uploaded encrypted developer workspaces to Alibaba Cloud by default, with the private key held by Z.ai, preventing developers from accessing their own data. The company claims this was a feature for recovery and that data is destroyed post-upload, but this destruction cannot be independently verified. This incident draws parallels to a previous issue with Grok Build, highlighting concerns about transparency and security in AI coding tools.
- 1. Z.ai's ZCode uploaded encrypted developer workspaces to Alibaba Cloud by default, with the private key held by Z.ai, preventing developers from accessing their own data.
- 2. The company claims this was a feature for recovery and that data is destroyed post-upload, but this destruction cannot be independently verified.
- 3. This incident draws parallels to a previous issue with Grok Build, highlighting concerns about transparency and security in AI coding tools.
Article analysis
Skim this article about "Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.": 3 key takeaways and more.
Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.
skim AI Analysis | The Next Web
The Next Web on Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.: skim's analysis surfaces 3 key takeaways. Z. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
Z.ai's ZCode uploaded encrypted developer workspaces to Alibaba Cloud by default, with the private key held by Z.ai, preventing developers from accessing their own data. The company claims this was a feature for recovery and that data is destroyed post-upload, but this destruction cannot be independently verified. This incident draws parallels to a previous issue with Grok Build, highlighting concerns about transparency and security in AI coding tools.
Key Takeaways
- Z.ai's ZCode uploaded encrypted developer workspaces to Alibaba Cloud by default, with the private key held by Z.ai, preventing developers from accessing their own data.
- The company claims this was a feature for recovery and that data is destroyed post-upload, but this destruction cannot be independently verified.
- This incident draws parallels to a previous issue with Grok Build, highlighting concerns about transparency and security in AI coding tools.
Statement Breakdown
- Claimed Facts: 40% of statements the article presents as facts
- Opinions: 40% of statements classified as editorial or subjective
- Claims: 20% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article presents a critical analysis of Z.ai's security practices, citing developer observations and comparisons to past incidents. While it raises valid concerns, it relies heavily on anonymous sources and lacks direct confirmation from Z.ai regarding the destruction of data. The article's investigative nature is strong, but the absence of definitive proof for all claims tempers its overall credibility.
Bias assessment: Investigative Skepticism. The article adopts a highly critical and skeptical stance towards Z.ai's actions and statements. It consistently questions the company's explanations and highlights potential security vulnerabilities and privacy breaches. The framing emphasizes a lack of transparency and user control, suggesting a deliberate attempt to downplay or obscure problematic features.
Note: This article investigates potential security and privacy issues with Z.ai. While it raises important questions, some claims are based on developer observations and lack direct company verification. Readers should approach the information with a critical eye and seek further confirmation.
Credibility flag: Investigative, Caution Advised
Claimed Facts (8)
- This is a factual statement about an observation made by a specific individual.
- This states a verifiable action taken by named individuals for a specific publication.
- This describes the content of the observed archive, presented as a factual observation.
- This is a direct report of a statement made by a source regarding the functionality of the software.
- This is a factual report of another individual's observation and public statement.
- This is a factual statement about a lack of response from a specific entity to a specific request.
- This is a factual statement about the actions of the publication and the status of a document.
- This is a factual statement about a past incident involving another company and its alleged actions.
Opinions (10)
- This is a statement of inability and a reason provided by a source, reflecting their experience and interpretation.
- This is an explanatory statement that offers a perspective on the nature of Git directories versus working directories.
- This is a statement of fact about Git history, but framed as a consequence and potential risk, implying an opinion on its significance.
- This continues the previous point, highlighting sensitive information that could be exposed, reflecting a concern.
- This is a comparative statement that offers an opinion on the relative security challenges of different AI tools.
- This is a broad statement about industry weaknesses and a specific example, reflecting a critical opinion on AI security.
- This is an interpretation of Z.ai's statement, framing it as a deliberate design choice rather than an accidental bug.
- This is a prescriptive statement offering advice based on the author's interpretation of the situation.
- This is a philosophical statement contrasting the nature of bugs and default settings, implying a judgment on Z.ai's actions.
- This is a rhetorical statement that dismisses the need for an external answer, implying the answer is obvious and unfavorable to Z.ai.
Claims (10)
- While the apology and resolution are stated, the article immediately casts doubt on the resolution's verifiability, making the claim of 'resolved' questionable in context.
- This claim is presented as a statement from Z.ai, but the article immediately questions its verifiability, labeling it as something that 'cannot be checked'.
- This is a question posed by Ferstar, highlighting the lack of a mechanism for verification, which implicitly casts doubt on Z.ai's claim of data destruction.
- This statement frames Z.ai's explanation as a potential misrepresentation, suggesting they are rebranding a flaw as a feature, which is an interpretation rather than a verified fact.
- While the policy might mention this, the article implies this is the *only* control, which might be an oversimplification or misinterpretation of the policy's scope, especially in light of the upload issue.
- This statement, while potentially true about the Optimization Program, is used to highlight a perceived loophole or lack of control over data transmission, implying a deliberate omission by Z.ai.
- This is a speculative statement connecting the privacy policy's limitations to the observed upload behavior, implying a deliberate exploitation of this gap by Z.ai.
- This is an assumption about a developer's expectations based on their reading of the policy, which is subjective and not definitively provable.
- While this describes xAI's response, it's presented as a benchmark for Z.ai, implying Z.ai's lack of similar actions is a deficiency, which is an opinionated comparison.
- This claim relies on an anonymous source whose authorization to speak is explicitly stated as lacking, making the information difficult to verify and potentially biased by the source's position.
Key Sources
- Ferstar — Chinese developer
- Minxiao Chang — Reporter
- Wency Chen — Reporter
- South China Morning Post — Media Outlet
- Feng Ruohang — Blogger
- Alibaba — Cloud Storage Provider
- TNW — Media Outlet
- xAI — AI Company
- Elon Musk — Founder of xAI
- Tang Jie — Founder of Z.ai
- Software engineer at a leading Chinese robotics company — Anonymous Software Engineer
- Tuxi — Shanghai developer
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Next Web coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 20th September 2026.