Move out of privacy --- privacy is a dead end, nobody has ever capitalized on it successfully (see: the original PGP, Zero Knowledge Systems, that stupid data center in the pylon off the coast of England).
Rewrite your content to focus on shared hosting. Emphasize that you don't keep the keys to the backup data. Consider an OEM deal with a Slicehost-like provider. Backup services at hosting providers fucking blow.
People won't pay much for privacy, but businesses will pay a decent premium over basic hosting for CYA security.
Take your crypto content off the front page; ironically, I think you're decreasing its value by fronting it like this. Instead, brand it: 100% audit-ready, fully transparent, something like that: "the only secure backup provider with [blah blah blah]".
I should have to click to see that stuff. For normal users, they should just see the stamp of assurance and a page they can click to with lots of docs.
I'm a lot less concerned about the clientside security here and more concerned with the serverside --- even though I know intellectually it doesn't matter much, because the security has been factored out to the client. That could mean one of many things, including these two:
(1) People are never going to get over their concern about serverside security and you're going to have to do so something to demonstrate that the server code and associated web apps are secure.
(2) You're not doing enough with your pitch to emphasize that your design moves security off the server and onto the clients, where the customers control it.
How do you do dynamic updates? Spend less time sniping at SSL, because SSL is still the weak link in this system.