Blog ·

Zero knowledge, zero servers — how Keepsake syncs without touching your data

The engineering story: why we built sync on an encrypted operation log through the user's own cloud, and what that buys you.

"End-to-end encrypted" usually still means our servers, our accounts, our availability. We wanted something stricter: a vault where the company's infrastructure is not part of your threat model because it doesn't exist. Here's how that works.

The storage nobody uses

Almost everyone already pays for private cloud storage — Drive, OneDrive, iCloud, a NAS. Document apps ignore it and build their own clouds, because their business models want your data close. Keepsake does the opposite: sync targets a private app folder in storage you own. Google and Microsoft grant apps a scoped, hidden folder (drive.appdata, OneDrive's approot) that the app can use without seeing anything else in your account. WebDAV and plain folders cover everything from Nextcloud to a USB stick.

Ciphertext is the only export

Before a byte leaves your device it is framed as KPS2: AES-256-GCM with a random 96-bit nonce and the ciphertext bound to its identity via AAD. Your cloud provider stores opaque blobs with meaningless names. A breach of your Drive account yields encrypted bytes — the keys never left your devices.

Sync without a referee

The hard part of serverless sync is conflict resolution — there's no central authority to declare a winner. Keepsake syncs an append-only operation log: every change (add document, edit tag, delete) is an operation; devices exchange encrypted operation batches and each device replays the global set. The merge is field-level, deterministic and order-independent — edit a tag on your phone and a note on your PC, and both survive on both devices. Deletions are tombstones, so they propagate too.

Two details we're particularly careful about:

  • Replay protection: each batch is cryptographically bound to its device, sequence number and epoch. A malicious (or confused) cloud that re-serves an old batch is detected, not silently applied.
  • Convergence proof: our test suite seeds randomized three-device histories with partial, interleaved syncs and asserts every device converges to the identical state — and that the next sync is a strict no-op. The same fixtures run against the C#, Kotlin and TypeScript implementations, byte-for-byte.

What this buys you

  • No subscription hostage. Documents live on your devices and your storage; stop paying and you lose conveniences, never access.
  • No breach letter. Our website database holds at most your email and a license record. Documents cannot leak from servers that don't hold them.
  • No shutdown risk. Licenses verify offline (Ed25519 signatures), the vault format is published, and any device can rebuild the whole vault from the cloud folder alone.

The full design — threat table included, ❌ rows and all — is on the security page.


← All posts · RSS · Get launch updates by email

Was this page helpful?

If something here is missing, wrong, or just unclear, say so — corrections to these pages usually start as a comment.

Leave a comment Ask the community →

Comments

No comments yet — be the first.

Sign in to comment — website account only; your vault never touches it.