tier property
hardware: the key is non-exportable in the secure keystore (iOS Secure Enclave /
Android StrongBox) and every signing / key-agreement operation runs in-chip —
achievable only with P-256. software: the key is held in app memory during use,
stored hardware-wrapped at rest. Maintainers MAY apply stricter policy (shorter
sessions, more frequent step-up) to software-tier devices.
Implementation
final KeyCustodyTier tier;