Understanding SimpleumSafe

What is High-Security Synchronisation?

A Mac and a mobile device each have their own local encrypted Safe and exchange locked data packages along arrows in both directions.
Each device keeps its local Safe. Encrypted changes are exchanged between devices, rather than an unprotected shared Safe.

You archive an important contract on your Mac. Later, you need it on your iPhone while away from home, or want to look up an invoice on your iPad. Your documents should be available on all your own devices, without travelling between them unprotected.

This is exactly why we developed SimpleumSafe’s high-security synchronisation.

SimpleumSafe creates its own local, encrypted Safe on each configured device. Synchronisation transfers encrypted changes between these Safes. This keeps your devices up to date without requiring you to place unencrypted documents in a shared cloud folder.

The essentials at a glance

  • Each device has its own local Safe. Your Mac, iPhone and iPad do not work together in an unprotected central data store.
  • You choose the synchronisation method that suits you. SimpleumSafe supports iCloud through CloudKit, a direct connection between devices and a shared folder between Macs.
  • Files and file information remain encrypted. This includes sensitive details such as file names, folders and information about changes.
  • The separate Safe key file is not stored in the normal synchronisation destination. A copied set of synchronisation data and knowledge of the Safe password alone are therefore not enough to decrypt the data.
  • Simpleum Media does not operate its own synchronisation server. Depending on your chosen method, data is exchanged through Apple’s CloudKit infrastructure, directly between your devices or through a folder of your choice.

Your encrypted data travels; the keys stay with you.

What does synchronisation do?

Think of each local Safe as its own locked archive. When you add a document on your Mac, SimpleumSafe records this change in encrypted form. Another configured device receives the change, applies it to its local Safe and downloads the file’s content, which is also encrypted.

The same applies when you rename files, move them to another folder, edit them or delete them. Synchronisation keeps the local Safes on your devices in step. Once the transfer succeeds, the document is also available in the other device’s local Safe.

The cloud or shared folder serves as a transfer route. It is not a place where SimpleumSafe manages your documents unencrypted. The synchronised file content, file information and change data remain encrypted.

Three synchronisation methods for different situations

You can choose the method that best suits your devices and the way you work.

iCloud through CloudKit

A convenient option for your Apple devices. Encrypted changes are exchanged through Apple's CloudKit infrastructure whenever the devices have a suitable connection.

Learn about iCloud synchronisation

Directly between devices

A Mac, iPhone or iPad can exchange encrypted changes directly when nearby. This does not require a separate cloud storage route.

Learn about direct synchronisation

A shared folder between Macs

Two Macs can use a shared folder as their synchronisation route, for example on a NAS, network drive or removable storage device.

Learn about folder synchronisation

Whichever route you choose, SimpleumSafe uses the same basic approach: each configured device has its local Safe and exchanges only encrypted synchronisation data.

Adding your Safe securely to another device

Before a new device can participate in synchronisation, it needs to be configured once. This requires two things: a synchronisation configuration and your Safe password.

  1. Create a synchronisation configuration: On a device that is already configured, SimpleumSafe creates an encrypted configuration record for the Safe and the chosen synchronisation method.
  2. Transfer it directly: Transfer this configuration between nearby devices or as a file. It is not simply placed in the normal synchronisation destination.
  3. Enter the Safe password: On the new device, also enter your Safe’s password.
  4. Set up the local Safe: The new device sets up its local Safe and starts receiving the encrypted changes and file content.

The synchronisation configuration contains key material that the new device needs. Although it is encrypted with the Safe password, you should therefore treat it as sensitive security material and avoid storing it together with an untrusted copy of the synchronisation data.

Why we developed this synchronisation architecture

An ordinary file transfer answers just one question: how does a file get from A to B? For an encrypted Safe, that is not enough. It also matters which information is visible along the way and which key material an attacker could obtain.

SimpleumSafe therefore uses a specially developed synchronisation architecture based on established encryption methods. It protects the documents themselves, their associated file information and the change log. At the same time, the separate Safe key file remains outside the normal synchronisation destination.

This creates an additional barrier: even if someone copies the synchronisation data from a cloud or shared folder and also knows your Safe password, the separate Safe key file is still missing. Synchronisation data and the password alone are therefore not enough to decrypt the data.

You now know the essentials

Each configured device has its own local, encrypted Safe. SimpleumSafe can transfer changes through iCloud, directly between devices or through a shared folder between Macs. Files, file information and change data remain encrypted. The normal synchronisation destination does not contain the separate Safe key file. If this explanation answers your question, you can stop here. The following sections explain the technical details and the limits of this protection.

Which data is synchronised?

In simple terms, a Safe consists of several protected components:

  • Encrypted file content: the data in your imported documents, images and other files.
  • Encrypted metadata: for example, the file name, folder assignment, file size, and creation and modification dates.
  • Encrypted transaction data: information about which content has been added, changed, moved or deleted.
  • Safe key file: the password-protected file containing the Safe’s randomly generated encryption keys.

During ongoing synchronisation, SimpleumSafe records changes in encrypted transaction data. Another configured device reads new transactions, applies them to its local Safe and receives the associated encrypted file content.

Even the file names of the encrypted data do not reveal the original document name. The article “How does SimpleumSafe work?” explains more about Safe structure, key management and storage. The full technical documentation is available in the SimpleumSafe Technical Whitepaper.

Synchronisation destination and configuration are different

This distinction is at the heart of high-security synchronisation.

The normal synchronisation destination

The synchronisation destination is the route or data store through which configured devices exchange their encrypted changes. It may be the CloudKit data store, a direct communication partner or a shared folder.

The normal synchronisation destination contains encrypted Safe data, but not the separate Safe key file.

The synchronisation configuration

The synchronisation configuration is only needed to set up another device. It identifies the Safe and the chosen synchronisation method and contains the key material the new device needs. It is encrypted with the Safe password and transferred directly as a file or over a connection between nearby devices.

After setup, the new device continues working with its local Safe and the normal synchronisation route. The synchronisation configuration is distinct from the ongoing synchronisation data.

What happens if synchronisation data is attacked?

An attacker might try to copy encrypted synchronisation data from CloudKit, a shared folder or a storage device. With this data alone, the attacker cannot decrypt the Safe. Even knowing the Safe password is not enough on its own, because the separate Safe key file is missing from the normal synchronisation destination.

This is a strong protection boundary, but it is not an absolute guarantee against every attack scenario. It no longer applies in the same way if an attacker also obtains a synchronisation configuration, key or recovery material, an unlocked device, or control of a device that has already been configured.

Protect not only your password, but also your devices, recovery keys and transferred synchronisation configurations. Keep SimpleumSafe and your devices’ operating systems up to date.

Why do file names sometimes appear grey?

Synchronisation takes place in two successive steps:

  1. First, SimpleumSafe transfers the encrypted structure and file information. Folders and file names can therefore already appear on the other device.
  2. The associated encrypted file content is transferred afterwards. Once all the content has arrived, the file name is displayed normally again.

With large files, many changes or a slow connection, some time may pass between these steps. A grey file name therefore normally means that the entry is already known, but the actual file content has not yet been fully transferred.

Synchronisation is not a backup

Synchronisation gives your devices the same current state. This also includes deletions and unwanted changes. If a file is deleted on one device and that change is synchronised, the deletion can also reach the other local Safes.

A backup has a different purpose: it preserves independent earlier states from which you can recover data after an error, hardware failure or attack. Multiple synchronised devices therefore make everyday access easier, but do not replace a separate, tested backup.

Our guide “Why backups are part of digital security” explains how these two layers of protection work together.

Which synchronisation method suits you?

For most people with several Apple devices, iCloud through CloudKit is the most convenient route. If you want to synchronise devices directly without a cloud, you can use device-to-device synchronisation. Between Macs, you can also use your own shared folder.

If you want to set up a new Safe or add another device, follow the relevant instructions step by step. The SimpleumSafe support overview provides starting points for iCloud, direct synchronisation and folder synchronisation.

This leaves you in control of the transfer route, while your documents remain encrypted during synchronisation.