The implementation seems reasonable, but how are the private keys shared between devices? It should pass through Apple some time since a phone can decrypt a laptop’s location. Or do they use bluetooth whenever near?
Apple really tries to get this right. Some countries(like China) require the computers to physically live in the country, so there could be special implementation details that alleviate some of those security guarantees, but we don't really know.
Of course, if you live in China and rely on any vendor that operates in China to protect you from the Chinese govt, you probably are wrong.