I am evaluating NextCloud for a solution for which I have a requirement that files cannot exist on non encrypted disks or the files themselves cannot be individually read or cached.
I have read a lot about NextCloud's encryption documentation but it does not seem to cover any aspects of whether: (a) if someone gains unauthorised access to the server itself, can the files be read or is it possible to NC to use full disk encryption with no server side caching? (b) Is it possible to lock out even devs/admins from file repositories unless they have the key - similar to accessing a remotely hosted encrypted disk image?
apols but I'm very new to the system and these are dealbreakers for evaluation