A protected system inside your iPhone
Your iPhone runs apps, messages, web pages and background services. Each adds places where a security mistake could appear.
The Secure Enclave is a separate, protected security system for a narrow job: protecting sensitive keys and making security decisions. It has its own processor and memory, separated from the main system.
Think of it as a safe inside a busy office. Staff can ask the safe to unlock something when the rules are met, but they do not get to take the key out of the safe.
Keys can be used without being revealed
When it creates a key, the Secure Enclave keeps the key inside its protected system. An app may ask it to use the key after Face ID or a passcode check, but gets the result—not the raw key.
Malware that reaches an ordinary part of the phone may still have a much harder time reaching a Secure Enclave key.
What the Secure Enclave helps protect
Face ID and Touch ID. Biometric information is protected inside the Secure Enclave. The rest of the phone gets an approval or rejection.
Apple Pay. It helps protect the payment credentials used to approve a transaction.
Passcode limits. It enforces increasing delays after wrong passcode attempts, making rapid guessing harder.
Device encryption. It helps keep storage-encryption keys tied to the device that created them.
Why device-bound keys help
A key made in the Secure Enclave is tied to that device. It cannot simply be copied to another phone and used there.
For example, a thief who copies encrypted data from a locked iPhone still lacks the device-bound key and passcode. The data is not a ready-to-open file.
Where its protection ends
The Secure Enclave protects keys, not every part of your digital life. If your phone is unlocked, authorised apps can use protected keys and read their data.
It cannot fix phishing, a shared password or a malicious app you approved. Practical takeaway: use a strong passcode, install updates and lock your phone when you are not using it.
How Sealby uses it
Sealby uses the Secure Enclave to help protect the device-bound key for your vault. The key is created for that iPhone and used there, rather than kept in ordinary app memory.
Unlocking a vault combines your device with your PIN or passphrase. A copied encrypted backup does not include a ready-to-use device key.