Docs / Sync

Sync directly between trusted devices.

9Secure discovers nearby devices and synchronizes selected vaults through mutually authenticated, end-to-end encrypted local-network sessions.

Meet the local-network requirements

  • Keep both devices unlocked, awake, and on the same local network.
  • Allow local-network discovery when the operating system asks.
  • Turn on Sync on both devices. This creates or loads each device's Sync identity.
  • Keep enough free storage for the selected vaults and attachments.

9Core can carry Sync over any connection supplied by the native app, with mutual authentication and end-to-end encryption independent of transport. Current apps supply only a direct local-network connection. They do not use a 9Secure account, cloud vault, hosted relay, or remote internet Sync.

Pair devices

  1. Open Sync on both devices.
  2. Select Pair a Device or Pair Device.
  3. Under Local Network Devices, select Pair beside the intended device.
  4. On the chooser, select the number shown on the other device.
  5. Compare both screens in person. Do not confirm a number received through a message or supplied by someone else.
  6. Select Confirm on both devices only after the number matches.

The six-digit number is a short authentication check inside a cryptographic pairing handshake. Pairing finishes only after bilateral confirmation and acknowledgement. Cancel and restart if the names or numbers do not match.

Review device trust

Paired devices appear under My Desktop Devices or My Mobile Devices. A device card remains visible while offline so you can review trust and subscriptions.

  • Local Network means the paired peer is currently reachable.
  • Offline means it is trusted but not currently reachable.
  • Forget removes the trusted peer and turns off its local vault subscriptions. It does not delete your local vaults.

Forget acts immediately. Current apps do not ask for confirmation, and using that device again requires pairing it again.

Pairing establishes device identity. Vault access is still controlled per vault. If pairing expires, use Forget Device before pairing that device again.

Choose vault subscriptions

Each paired-device card contains one switch per visible vault. Turn on only the vaults that should synchronize with that device.

A subscription transfers complete vault contents inside the encrypted Sync session, including items, history state, and attachments. It is not a field-level sharing rule. Keep separate vaults when different devices need different data.

Run and verify Sync

  1. Enable the intended vault switches on the paired-device card.
  2. Select Sync for one reachable device, or Sync All for all eligible devices.
  3. Keep the devices awake until the status reports completion.
  4. Open each expected vault on the receiving device.
  5. Verify representative items and attachments before relying on the receiving copy.

Sync All changes to Cancel Sync during an active run. 9Secure processes eligible peers in sequence and can make another pass when needed.

Understand convergence and conflicts

9Core reconciles the current materialized state of the whole vault. Most concurrent changes converge deterministically using stamped updates from each device. Deleted fields and attachments retain tombstones so an older peer does not silently recreate them.

History entries merge separately by operation ID. History is useful for inspection, but it is not the authority for current Sync state and does not provide general undo or point-in-time restore.

If two devices produce different values with the same update stamp, 9Secure reports a Sync conflict instead of choosing silently. Open the named item, edit and save the affected field on one device to create a new update, then Sync again.

Remove locally or delete everywhere

Choose deletion scope carefully:

  • Local removal deletes the managed copy from this device and keeps metadata that can make the vault available again from a subscribed paired device.
  • Delete across all synced devices creates a global deletion request. Other devices must authenticate it and can show Delete Vaults Everywhere? with Keep Vaults or Delete Everywhere.

Global deletion cannot be undone through the app. Confirm that a tested independent recovery copy exists before choosing it.

Download an available vault

Available Vaults lists locally removed vaults advertised by a paired device.

  1. Open Available Vaults.
  2. Select Download to This Device beside the vault.
  3. Wait for the follow-up Sync to finish.
  4. Open the vault and verify its contents.

A globally deleted vault does not appear as available.

Lock, suspend, and turn off Sync

Locking stops active Sync runtime. Suspend or background behavior follows the platform's lock setting. After unlock or resume, Sync restarts only if its saved enabled preference remains on.

Turn Off Sync stops discovery, pairing activity, transport, and active Sync. It does not automatically forget existing paired-device trust records.

Sync is not a backup system. Deletion and valid updates can propagate. Keep tested recovery copies using the platform-supported options described in Security Architecture.

Troubleshoot without weakening trust

  1. Read the exact network and Sync status. Offline, Local network unavailable, and Waiting for local network describe different states.
  2. Keep both apps unlocked and confirm Sync is on.
  3. Confirm both devices are on the same local network and that local discovery is allowed by the OS and firewall.
  4. Reopen pairing on both devices and wait for discovery. Do not bypass the number comparison.
  5. Verify the vault subscription switch on both relevant device cards.
  6. Check free storage before retrying a large vault or attachment transfer.
  7. For a reported field conflict, edit and save that field on one device, then Sync again.
  8. Use Forget and re-pair only when the trust record is expired or intentionally being replaced.

A failed connection does not expose plaintext vault contents to unauthenticated network observers, but it also does not prove that Sync completed. A trusted paired endpoint can decrypt content it receives. Verify received data.