Some sort of “checked C” in iBoot: https://support.apple.com/guide/security/memory-safe-iboot-i...
Data is encrypted with your security policy, so if that changes (e.g. you disable SIP) it doesn’t expose it: https://support.apple.com/guide/security/sealed-key-protecti...
Details on what the SRD is and how it works: https://support.apple.com/guide/security/apple-security-rese...