Encryption at rest
AES-256-GCM. Every record in your vault is encrypted before it is written to storage, including your backups.
Specifics, not adjectives. If you want to verify any of this, the application is a single file you can read.
AES-256-GCM. Every record in your vault is encrypted before it is written to storage, including your backups.
PBKDF2-SHA256 at 600,000 iterations. Deliberately slow, so guessing your password by brute force is impractical.
A single data key encrypts your vault. That key is separately wrapped by your password and by your recovery phrase, so either opens it and neither reveals the other.
Twelve words drawn with the browser’s cryptographic random number generator, on your device. Never transmitted, never stored by us.
A direct, encrypted connection between two devices you own, paired with codes you exchange yourself. Your records never pass through a server. Finding each other across networks uses a public STUN server, which sees only IP addresses, never your data.
Your backup is the same encrypted blob your vault already is, sealed on your device before it is sent. We store the ciphertext, its size, when it was made and how many records it holds, so we can show you what you are about to restore. We hold no key that opens it. Enrolling a device uses a code sent to your email address, which gates access to the file and not its contents: without your password it is noise either way.
Every backup carries a version number. A device sends the version it believes is current, and the server refuses a mismatch rather than applying it. This is what stops an old laptop waking up, backing itself up, and quietly replacing weeks of newer work. When it happens you are shown both sides and offered a merge.
Your licence is an ECDSA P-256 signature verified on your device against a public key inside the app. It travels in the URL fragment, which browsers never send to servers.
We cannot reset your password. We cannot recover your recovery phrase. We cannot decrypt your backups. We cannot read a single invoice, client or figure you have entered. And if we are compelled to hand over what we hold, what we hold is an encrypted file. We can be made to produce it. Nobody can be made to open it, because the key is not ours to give.
Simpl runs in a browser, and a browser fetches its code from our server every time you open it. That means you are trusting us to keep serving honest code, in a way you would not have to with a signed application you installed once. It is a real limitation and it is shared by every browser-based encrypted product, password managers included. We reduce it: a strict content security policy, no analytics or third-party scripts of any kind inside the application, and everything served as one self-contained file. We would rather tell you this than claim a guarantee nobody in this category can honestly make.
Found a security problem? Email lee@creativeseed.co.za. I will acknowledge it and work with you on a fix and a disclosure timeline.