And you can be sure it didn’t add a ‘recovery’ key, how?
You need some implicit trust in a system to use it. And at worst, you can probably reverse engineer the (unencrypted) BitLocker metadata that preboot authentication reads.
Key ring contents (and what is done with them) are typically much harder to verify as they’re encrypted.