Encrypting Local State in 2026: Secure Enclave, AES-GCM and the Pitfalls of Key Derivation
A long-form treatment of how we design the encryption envelope for every on-device store. We cover Secure Enclave key storage, AES-GCM page-level encryption, key rotation strategy, the practical limits of biometric gating and why we still recommend opt-in passcode fallback even when biometrics succeed.