What is com.apple.sbd on Mac?
Last updated: 2026-07-31
com.apple.sbd is Apple's on-demand Secure Backup Daemon for encrypted iCloud Keychain recovery records, escrow metadata, and related key recovery. It is not Time Machine or a service that backs up your entire Mac.
What it is
com.apple.sbd is Apple's Secure Backup Daemon. It is an on-demand, user-level system process whose main known role is supporting encrypted recovery data for iCloud Keychain. That work includes Keychain keybags, recovery metadata, escrow records, and some protected iCloud encryption keys.
The word “Backup” in the daemon's name can be misleading. com.apple.sbd is not Time Machine, and it does not back up the ordinary files or complete contents of a Mac to iCloud. Its backup role concerns security material used to establish, protect, and recover access to encrypted data.
Apple's public security documentation describes the architecture behind iCloud Keychain synchronization, escrow, and recovery. However, Apple does not publish a complete, item-by-item list of every data category currently handled by com.apple.sbd. Its confirmed identity and local configuration provide a useful outline, but they do not justify treating the process as the sole component responsible for every part of iCloud Keychain.
Why it talks to the network
com.apple.sbd does not need to run continuously. Its local launch configuration shows that macOS can start it after a Keychain backup notification from the security subsystem, a change in iCloud key-value storage state, or an XPC request from another system component. This is demand-driven behavior rather than evidence of a fixed daily schedule.
Network activity can occur when com.apple.sbd establishes or updates a Keychain recovery record, helps a trusted device join or recover, retrieves or submits escrow metadata, or participates in restoring a Keychain. The other end of those connections belongs to Apple services involved in iCloud key-value storage or CloudKit, Apple Account authentication, and hardware-security-module-protected iCloud escrow.
Apple has not published a fixed domain list specifically for com.apple.sbd. A connection to Apple infrastructure is consistent with its role, but the available research does not support naming a permanent set of hosts or claiming that every connection follows one unchanging route.
There is also no evidence that com.apple.sbd runs exactly once per day. Its current launch configuration contains notification and XPC triggers, not a daily timer. Claims about a “daily backup” usually borrow wording from whole-device iCloud Backup on iPhone and iPad, which is a different service and should not be applied to this Mac process.
How much traffic is normal
There is no verified normal traffic range for com.apple.sbd. Apple does not publish an expected minimum, maximum, or typical number of megabytes, so a precise allowance would be guesswork.
Based on the process's documented responsibilities, its traffic would usually consist of intermittent transfers of encrypted Keychain-related data, keybags, recovery material, and control metadata. That should ordinarily be much smaller than transferring photos, videos, or files through iCloud Drive. This is a relative expectation, not a measured limit.
A larger short-lived transfer may occur when the feature is first enabled, a device joins the trusted set, or a recovery operation takes place. The research does not establish a numeric threshold for those events either. To decide whether activity on a particular Mac is unusual, use the Mac's actual per-process history instead of comparing it with an invented universal figure.
Can you turn it off
The practical recommendation is to keep com.apple.sbd available. Apple does not provide a dedicated setting that turns this daemon off.
Force-blocking com.apple.sbd may prevent iCloud Keychain recovery records from being created or updated. It may also interfere with a new trusted device joining, cause device recovery to fail, or disrupt recovery of encryption keys for some protected iCloud data. Simply terminating the running process is not a permanent disable method: because it is managed by launchd, macOS can start it again when one of its triggers occurs.
macOS does offer System Settings > [your name] > iCloud > See All > Passwords > Sync this Mac for turning off password and Keychain synchronization. That setting is not a dedicated com.apple.sbd switch, however, and the available evidence does not show that changing it completely prevents the daemon from running.
Blocking com.apple.sbd is therefore not a well-supported network or memory optimization. The process normally exits when idle, and there is no reliable evidence that it continuously transfers large amounts of data. The possible cost is damage to security recovery workflows, while the claimed performance benefit has not been established.
What people get wrong
- “com.apple.sbd is Time Machine or whole-Mac iCloud Backup.” It is neither.
com.apple.sbdworks with security escrow and recovery material, not ordinary Mac file backups.
- “com.apple.sbd uploads plaintext passwords to Apple.” Apple documents iCloud Keychain synchronization and recovery data as end-to-end encrypted. Escrow records are also protected by strict recovery authentication and hardware security modules. That does not support the claim that this process sends readable passwords to Apple.
- “com.apple.sbd runs once every day.” This has not been verified. Its launch configuration uses security notifications, iCloud state changes, and XPC requests, with no daily timer. Apple's description of daily whole-device iCloud Backup for iPhone and iPad is not evidence about this Mac daemon.
- “Disabling com.apple.sbd is a safe way to reduce network or memory use.”
com.apple.sbdis an on-demand process that can exit while idle. Forced disabling may break escrow, trusted-device enrollment, or recovery operations, while no reliable evidence shows that it is normally a continuous high-traffic service.
- “Blocking com.apple.sbd must immediately stop all real-time iCloud Keychain synchronization.” That conclusion goes beyond the available evidence. Apple describes Keychain synchronization and Keychain recovery as separate services. The evidence connects
com.apple.sbdmore directly to backup, escrow, and recovery, but Apple has not published a process-level map showing which components perform every part of continuous synchronization.
- “com.apple.sbd is the same as the Linux tool called sbd.” It is unrelated to either the encrypted-netcat-style Linux tool or the cluster SBD daemon. The shared short name does not imply a shared purpose or implementation.
Seeing what it actually used
If com.apple.sbd appears unusually active, the next step is to measure that Mac rather than rely on an unsupported universal estimate. Open Bytetally's per-process statistics, find com.apple.sbd, and check whether the traffic was a brief event or continued over time. Compare the timing with recent Keychain setup, trusted-device enrollment, or recovery activity before deciding that the usage is abnormal.
Related processes
Common questions
What is com.apple.sbd on my Mac?
com.apple.sbd is an Apple user-level system process involved in encrypted iCloud Keychain recovery backups, escrow records, keybags, and recovery operations.
Does com.apple.sbd upload my passwords to Apple?
It does not upload plaintext passwords. Apple documents iCloud Keychain synchronization and recovery data as end-to-end encrypted, with escrow records protected by strict recovery authentication and hardware security modules.
Can I disable com.apple.sbd?
Apple provides no dedicated switch for com.apple.sbd. Blocking it may disrupt iCloud Keychain escrow records, trusted-device enrollment, and recovery of protected iCloud keys.
How much data should com.apple.sbd use?
There is no verified normal traffic range. Its transfers are expected to be intermittent and generally smaller than photo, video, or iCloud Drive synchronization, though setup and recovery may produce a larger short burst.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account