Recovery planning

Mac disaster recovery starts before the Mac fails

A replacement Mac is useful only when you still have the encrypted repository, the authority to unlock it and a clear recovery order.

Reviewed 2026-08-18

Keep the two required parts apart

The repository contains encrypted recovery points. The Recovery Kit contains the portable private recovery identity. Store them separately so one failed disk, account or theft does not remove both.

Use more than one destination

A local disk makes large recovery fast. iCloud Drive or compatible S3 storage can hold the primary repository off the Mac. Additional encrypted replicas can live on another filesystem, WebDAV, compatible S3, Google Drive or Dropbox.

Practice the smallest useful recovery

Run ElseKept’s safe test extraction and confirm a representative file can be authenticated and extracted. Separately confirm an off-device copy is visible and downloaded. These checks answer different questions.

On the new Mac

  1. Install macOS and ElseKept.
  2. Connect the primary repository or a committed encrypted replica.
  3. Provide the Recovery Kit to unlock it into the new Mac’s device-only Keychain.
  4. Recover ordinary files first and verify a representative sample.
  5. Recover credentials and developer configuration into staging for review.
  6. Keep the original repository unchanged until the new Mac is healthy.

ElseKept is not a bootable clone and does not reinstall macOS or third-party applications. It restores supported data and configuration after the operating system is available.