A self-hosting roundup published in February 2026 sorts the category into two piles: an Office engine for .docx fidelity, and a zero-knowledge editor whose server never sees the document. That page names CryptPad for the second pile, and it says the server cannot search what it cannot read. Those sentences describe a real product class. They do not describe a document suite an organisation administers.
The two requirements contradict each other. If the server cannot read the file, the organisation that runs the server cannot audit it, cannot put a retention hold on the text, and cannot restore a readable copy without keys it does not hold. If the organisation must do those things, the operator can read the file. Encryption at rest does not split the difference. Key custody is the longer version of that sentence: a running system holds the keys it needs to serve the document.
Confirm CryptPad, or whichever pad you are actually evaluating, with its vendor. This page will not freeze a design on a third-party roundup. The dates and the product names on that page can move. The contradiction does not.
