Encryption on this Mac
Repository secrets are random and wrapped to trusted recovery identities before encrypted bytes reach a destination.
Security model
ElseKept keeps recovery authority with the user, verifies stored objects and avoids an ElseKept account or app telemetry.
Repository secrets are random and wrapped to trusted recovery identities before encrypted bytes reach a destination.
The separately stored kit unlocks the repository on another Mac. Anyone holding both repository and kit can decrypt it.
Snapshots and replicas become visible only after required commits and authenticated checks succeed.
Privacy
ElseKept does not operate a storage cloud and does not collect app telemetry. Provider credentials remain device-only Keychain items. Storage providers receive encrypted backup objects plus normal service metadata such as size and timing.
Honest limits
ElseKept cannot defend against a compromised Mac while secrets are unlocked, a stolen Recovery Kit stored beside the only repository, or deletion by every configured storage provider. Keep the kit separately and use more than one destination.