We consolidate, back up, and make sure your grandchildren can still see them in forty years.
Your family's entire visual history is scattered across iCloud, Google Photos, an old Dropbox, a NAS that hasn't been backed up in three years, and a spouse's account you can't get into. This is what we fix.
Nobody meant to lose them. They accumulated across platforms over twenty years, with no strategy, no owner, and no plan for what happens when a service shuts down or someone dies.
Your iPhone backs up to iCloud. Your spouse's Android goes to Google Photos. The kids' photos are in a shared Dropbox folder from 2019. You have two hard drives from old laptops in a closet. Nobody knows what's on them, nobody knows how to get into them, and there's a decent chance the most important videos of your kids' early years exist in exactly one place — a cloud account you're paying $2.99 a month for without thinking about it. One lapsed credit card, one account termination, one forgotten password — and it's gone.
Most families have made an implicit bet on Apple or Google. That bet is fine — until an iCloud account gets locked due to a billing dispute, a two-factor authentication device breaks, or Apple decides to change their storage policy. iCloud Family Sharing is a product, not a backup strategy. The same is true for Google Photos. A single-cloud approach means a single point of failure for twenty years of irreplaceable family history. When it fails, there is no recovery path.
Your Synology NAS is running in your home office. It's on the same physical premises as a house fire, a flood, a power surge, or a theft. A local NAS is excellent redundancy for routine hardware failure — it is not a disaster recovery strategy. Without a geographically separate copy, a single physical event at your home address removes every photo and video you've ever taken. Most families discover this situation after the event. There is no version of "after the event" that ends well.
Your spouse dies unexpectedly. The iCloud account is locked — Apple doesn't allow account sharing and the Digital Legacy contact was never set up. The Google Photos library requires a password your spouse never shared. The Synology NAS admin credentials are in a password manager your spouse owned. Twenty years of family photographs are technically accessible, legally inaccessible, and practically gone. This is not a morbid edge case — it is the default outcome when no one plans for it, and it happens in families at every income level.
The 3-2-1 rule has been the professional standard for data protection for thirty years. Three copies of your data. Two different storage media. One offsite. Most families have one copy, on one medium, at one location. We fix that.
3 copies — your primary and two independent backups. If one fails, two remain. If two fail simultaneously (essentially impossible in our architecture), one still remains.
2 different media — not two copies on the same Synology NAS. One local (NAS), one cloud. Different hardware failure profiles, different attack surfaces, different failure modes.
1 offsite — geographically separate from your home. Not your vacation house. Not your office in the same building. A different city. A fire or flood that destroys your home does not touch it.
Configured correctly, not just turned on. iCloud Family Sharing set up with proper household structure. Storage tier sized to your actual library. Digital Legacy contacts designated for every family member. This is your primary working library — the one you browse and share from day to day.
A cold storage cloud account you do not interact with daily. Costs roughly $7/month for a 1TB library. Not your primary cloud provider — independent platform, independent failure profile, independent account credentials. Automated sync runs nightly. You will likely never touch this unless you need it. That's the point.
A Synology NAS in your home configured with RAID 1 (mirrored drives) and full disk encryption. Fastest recovery path — if you need to access a specific photo or folder, you're not waiting on a cloud download. The NAS also runs the automated backup job that replicates to your cold cloud storage nightly. Encrypted so a physical theft of the unit does not expose your content.
Once per year, we export a full encrypted archive of your media library onto a purpose-built encrypted USB drive stored in your home safe or safe deposit box. This is your disaster-recovery copy of last resort — independent of all cloud services, all network connections, and all hardware. If every other copy fails, this one doesn't require internet access to recover from.
You don't manage the architecture. You tell us where the photos are. We build the rest, test the restore paths, document everything, and hand it back to you.
We ingest from every source: iCloud, Google Photos, Dropbox, old hard drives, old phones, DVDs, external drives in drawers. Every source gets audited for what's actually on it — most clients discover content they had forgotten existed on a device they assumed was empty. Everything lands in one organized, de-duplicated library. No more scattered copies across platforms you barely remember subscribing to.
Twenty years of syncing across platforms means you have the same photo in three places with three different filenames and three different timestamps. De-duplication removes the noise without removing the content — you keep one clean copy, not twenty variations of it. On average, clients reduce library size by 30–50% through de-duplication alone. That's storage you were paying for that wasn't protecting anything.
We provision, configure, and encrypt the Synology NAS. RAID 1 for drive redundancy. Encryption keys stored in your household 1Password vault. The backup job is configured, tested, and documented. You receive a one-page runbook for the NAS — what it does, how it works, and who to call if a drive indicator light turns red. The runbook lives in your household documentation package alongside everything else Sentinel manages for you.
The Synology NAS runs a nightly backup job to your cold cloud storage provider (Backblaze B2 or Wasabi). The job is configured with your credentials, tested against a known restore scenario before handoff, and monitored for failure. If a backup job fails, it's part of your quarterly review. You are never in a situation where you believe your offsite backup is running and it isn't.
A backup that hasn't been tested is not a backup. It's a guess. As part of your ongoing membership, Sentinel runs a restore test every ninety days — we pull a random sample of content from your cold storage copy and verify it decrypts and opens correctly. We check backup job logs for errors, verify storage capacity, and confirm all three copies are current. You receive a one-paragraph confirmation after each test. Silence means everything is working.
Once per year, we export and encrypt a full archive of your media library onto an encrypted drive for your safe. This is scheduled as part of your annual tech review. The drive is labeled, dated, and documented in your household runbook. Your estate attorney has instructions for locating it. Your heirs will be able to access it without needing to know your cloud passwords, your NAS configuration, or anything else — just the drive and the decryption key stored in your digital estate documentation.
A family photo archive should be accessible to your family. It should not be accessible to everyone your kids have ever shared a Google account with, or to anyone who can guess the iCloud password your spouse has been using since 2015.
iCloud Family Sharing and Google Photos shared albums both have default settings that expose more than you realize. We configure shared access for your household so your children have access to family photos without having access to your financial documents, your health records, or your private communications. Family sharing is set up with explicit permissions, not inherited from a single account that owns everything.
A Google account your child uses for school, YouTube, and Google Docs should not also be the account that owns your family's photo library. We separate the kids' device management from the family media archive — your children have appropriate accounts for their age and context, and the family photo library lives in a properly owned, properly secured location that you control.
Grandparent videos, wedding footage, first steps, graduation recordings — these are the files that matter most and are almost always the least protected. They're large, they're scattered, and they're often on a specific device that hasn't been backed up. We identify these explicitly during the media audit, flag them for priority consolidation, and ensure they have representation in every copy of your backup architecture, including the annual physical cold copy.
Your media archive is part of your estate. The heirs listed in your will need to be able to access it — not just the physical property you're leaving behind, but twenty years of family history stored in systems they don't know how to navigate. We document your media archive in your digital estate package, with access instructions, decryption keys, and account credentials stored in a form your executor and heirs can actually use. The photo library doesn't disappear when you do.
Digital estate planning — including media archive inheritance documentation — is covered in depth at Sentinel Digital Estate →
We'll audit every device, account, and drive your family's media lives on. You'll receive a complete inventory of what you have, where it is, what's at risk, and exactly what it would take to protect all of it.