Guide
Encrypted backup for macOS
Azivault is built around encrypted repositories: backup contents are encrypted locally, and recovery depends on material you control.
What encryption protects
Azivault encrypts backed-up file contents before they are written into the repository. It also treats file and directory names as sensitive repository metadata rather than leaving them as plain folder trees in the destination.
That matters for offsite and shared storage. A storage provider, misplaced external disk, or network destination should not receive readable copies of your backed-up files.
Recovery material
When you create a plan, Azivault asks for a recovery password and can store a copy of the repository key in Keychain. If iCloud Keychain sync is selected, another Mac signed into the same account may be able to unlock the repository without retyping the recovery password.
Keep the recovery password outside the Mac being backed up. If the Mac is lost and the Keychain route is unavailable, that password is the durable way to recover the repository key.
Encrypted does not mean untestable
Test restore after the first backup run. Open Restore, reveal a completed run in Finder, copy a file to a temporary folder, and confirm it opens. A good encrypted backup strategy proves both the encryption and the unlock path.
Use encryption with destination choice
Azivault can store encrypted repositories in local folders, external drives, network drives, and S3-compatible storage. The destination should still be reliable, monitored, and recoverable; encryption is one layer of the backup system, not the whole system.
See also how to restore files and Azivault's backup philosophy. For a factual comparison with another backup app that documents its encrypted data format, see Arq and Azivault.
FAQs
Does Azivault encrypt backups by default?
Yes. Azivault's supported repositories are encrypted. Files are encrypted locally before repository data is stored on folder or S3-compatible destinations.
What unlocks an Azivault repository?
Azivault can use a repository key stored in Keychain, including iCloud Keychain when selected, or the recovery password saved when the plan was created.
Can Azivault read my files in cloud storage?
Azivault processes files locally to make backups, but the stored repository objects are encrypted before they reach S3-compatible storage.