How SimpleumSafe encrypts, opens, and syncs files
SimpleumSafe stores imported files and their file information in encrypted form inside a Safe. Some previews are decrypted only in memory; other previews or editing workflows use a protected working copy. Exporting or sharing, however, creates a decrypted copy outside the Safe. Synchronization data exchanged between your devices also remains encrypted.
You can organize documents, scans, photos, and PDFs in a protected archive, find them again, and use them on several devices. This page starts with what matters in everyday use. The technical details follow later.
Quick overview
- Add files: SimpleumSafe copies the content and file information into the Safe and stores both in encrypted form. The original file outside the Safe remains unchanged in its previous location.
- Keep files in the Safe: Contents, file names, and other file information remain encrypted while stored inside the Safe.
- Preview and edit: SimpleumSafe processes suitable previews directly in memory. If an app requires a regular file, SimpleumSafe provides a working copy in a protected temporary area on the Mac.
- Export and share: A decrypted copy is created at the selected destination. It is outside the Safe’s protection and must be protected separately.
- Synchronize devices: SimpleumSafe transfers encrypted changes between local Safes. Synchronization keeps devices up to date, but it is not a backup.
- Protect your password and backups: Simpleum Media cannot recover a forgotten Safe password. Keep the required recovery material secure and maintain a tested backup.
You decide how deep you want to go
This article is deliberately structured from the most important information to the technical details. If you mainly want to know how your files are protected during storage, opening, and synchronization, you already have the essential answers and can safely stop here. Continue reading if you want to learn more about working copies, passwords, encryption keys, and synchronization data.
When you add files
SimpleumSafe provides its own file management system inside the Safe. During import, a copy of the selected file is transferred into this protected area. Its contents, file name, and other file information are stored there in encrypted form.
The original source file remains outside the Safe unless you delete it yourself or protect it in another way. This matters when you import a document from Downloads, a scanner, or another app.
What this gives you: inside the Safe, you can organize, search, and retrieve documents as you would in a normal archive. The stored contents and file information remain protected.
When you preview or edit files
A file stored in encrypted form must temporarily become readable for a preview or editing. Depending on the file type, file size, and selected workflow, SimpleumSafe uses two different approaches.
Preview directly in memory: SimpleumSafe decrypts suitable files completely in memory (RAM) for its integrated preview. This is especially common for images and smaller text documents. SimpleumSafe does not create an additional decrypted preview or working file in the file system in this case. The readable data exists in memory only while it is being processed.
Protected temporary working copy: If a preview or selected editing app requires a regular file, SimpleumSafe temporarily provides a working copy.
On the Mac, SimpleumSafe places that copy in an encrypted temporary workspace:
- The file is copied into the protected workspace.
- The preview or selected editing app works with this copy.
- Changes are imported back into the Safe.
- After the editing app closes, the temporary working copy is deleted.
When SimpleumSafe quits, this temporary storage is locked. SimpleumSafe creates a new temporary storage area every time it starts. The area is limited to 100 GB.
The authorized editing app can read the working copy while it is open. The app or operating system may create its own recent-item entries, caches, backups, or cloud copies outside SimpleumSafe’s control. For sensitive documents, use only apps and services you trust.
When you export or share files
When you export or share a file, another app or selected storage location must be able to use it. A decrypted copy is therefore created at that destination.
This copy is outside the Safe. SimpleumSafe’s protection does not automatically continue to apply to it. Carefully check where you export, which app you use, and whether the destination is adequately protected.
Where a Safe should be stored
A Safe should be stored locally on your Mac, iPhone, or iPad.
Do not manually place the Safe in a cloud folder such as iCloud Drive or Dropbox. A Safe internally contains a database, among other data. Ordinary file or folder synchronization can leave these related components in an inconsistent state.
If you want to use the same Safe on several devices, use the synchronization built into SimpleumSafe instead.
When you synchronize devices
SimpleumSafe can synchronize encrypted changes through iCloud, directly over wireless networking, or through a shared folder between Macs. Simpleum Media does not operate a dedicated synchronization server for these methods.
Synchronization transfers the structure and file information first, followed by the actual file contents. With large amounts of data or a slow connection, folders and gray file names may therefore appear on another device while the contents are still being transferred. The name returns to its normal appearance as soon as the file has arrived completely.
The synchronized information remains encrypted during this transfer. Synchronization also propagates changes and deletions, however, so it does not replace a separate, tested backup.
Technical details
Password and key file
When you create a Safe, SimpleumSafe generates random encryption keys. They are stored in an encrypted Safe key file. The Safe password itself is not stored in the Safe.
When opening the Safe, SimpleumSafe attempts to unlock the required key material with the entered password. A successful result confirms the password. The password cannot be read from the Safe because it is not stored there.
Simpleum Media therefore cannot retrieve a forgotten Safe password. Access also depends on the required key or recovery material. Anyone who obtains this material, access to an already unlocked device, or control of a configured device may be able to read the Safe. Keep your password and recovery material secure and, where possible, separate.
Encrypted contents and file information
Document contents are not the only sensitive information. File names such as “Taxes 2024,” “Insurance,” or “ID” can already reveal information about an archive. SimpleumSafe therefore also encrypts file names and other imported file information.
The content of an imported file is stored as an encrypted file inside the Safe. Its internal file name is a random, meaningless value that contains neither the original name nor other information about the source file.
The original file name, other imported file information, and internal management data are stored in encrypted form in a database. For an assessment of this architecture in the context of future quantum computers, read “Quantum Computers and Encryption: What Does This Mean for SimpleumSafe?”.
Synchronization data and key material
For synchronization, SimpleumSafe records changes such as additions, edits, and deletions in a synchronization directory. Another configured device reads these encrypted changes and applies them to its local Safe.
The normal synchronization destination does not contain the separate Safe key file. Copied synchronization data and the Safe password alone are therefore not sufficient to decrypt the Safe. This protection boundary assumes that an attacker has not also obtained key or recovery material, an unlocked endpoint, or control of an already configured device.
Try SimpleumSafe
Would you like to organize your documents in an encrypted archive and use them across your Apple devices? Explore the available purchase options.
View purchase options 7-day free trial* Free tests or trials may not be available during discount promotions.Learn more
- Technical White Paper: encryption keys, metadata, temporary storage, and synchronization architecture
- Features and functional limits: imports, previews, editing, exports, and synchronization
- Secure Temporary Storage on macOS: the protected location for macOS working copies
- SimpleumSafe security: passwords, backups, and device protection
- Purchase options