Skip to content

Glossary

Secure Enclave

The Secure Enclave is an isolated security subsystem in Apple chips that protects keys, biometric data and FileVault secrets from the main OS.

The Secure Enclave is a dedicated secure subsystem built into Apple silicon and into the Apple T2 Security Chip on supported Intel Macs. It is isolated from the main application processor and runs its own firmware, so a compromise of macOS does not automatically expose the secrets it holds. It has its own boot process, a hardware random number generator and protected memory.

On a Mac, the Secure Enclave handles sensitive operations such as Touch ID matching and the protection of keys used for data encryption, including the keys behind FileVault. It enforces limits on passcode and password attempts and can generate private keys that never leave the enclave. Apps and system services can ask it to sign or decrypt with those keys without ever seeing the key material.

For defenders, the Secure Enclave is the reason hardware-backed protections on modern Macs are strong: disk encryption keys and biometric templates are not simply files an attacker can copy from the drive.

Read the FileVault guide to see how it supports disk encryption.