The files worth keeping out of plaintext.

Not everything needs to be encrypted. These are the things most people already wish were not sitting readable in a folder that half their software can reach.

The machine that runs agents

Your development machine is also where you keep everything else. A coding agent with broad permissions, an MCP server, or a package postinstall script reads whatever is readable on it. Keeping the documents that have nothing to do with the work outside of plaintext limits what any of them can reach.

Source trees · Credentials in dotfiles · Client repositories

Identity documents

These are the files that are worth the most to whoever ends up with them, and they usually sit in a sync folder because that is where a scanner put them. There is no reason for them to be readable on disk between the times you actually need them.

Passport scans · Driver's licence · Birth certificates

Work you are under contract to protect

If a client's material leaks off your laptop, the contract does not care how it happened. Encrypted-at-rest storage is a control you can describe plainly when someone asks how you handle their files.

NDA material · Design files · Unreleased work

Finances and household records

A tax return is a complete identity package in one PDF. Keeping the household paperwork in one encrypted place is both easier to find later and less useful to anything that gets a look at your disk.

Tax returns · Statements · Insurance and property records

The honest scope

  • SLIK is in development. These are everyday storage examples, not claims of specialized medical, legal, or archival compliance.
  • File-content encryption is separate from account information, service metadata, and the local search index, which can contain filenames and extracted text.
  • SLIK does not detect or block malware and does not sandbox or monitor AI agents. It changes what they can read.
Understand the encryption boundary ↗

Start with the folder you would least like read.

Download for Mac
Use cases — SLIK