The summary.
THE MODEL IS DEFENCE IN DEPTH, EACH LAYER ASSUMING THE ONE ABOVE MAY FAIL
Hardware keys, secure boot, a read-only system volume, code signing, sandboxing and privacy consent.
What it does not protect against is a user persuaded to grant permission or install something.
MOST BUILD FAILURES ARE SIGNING MISMATCHES
Between the identifier, the certificate, the profile, the entitlements and the team. The error messages are rarely clear about which.
ESTABLISH EARLY WHETHER A CAPABILITY IS PERMITTED AT ALL
Building something that cannot be shipped is an expensive discovery.
Request the minimum entitlements — more brings review scrutiny and user suspicion.
A MISSING PERMISSION USAGE DESCRIPTION CRASHES THE APPLICATION
And vague descriptions are rejected at review. Check that third-party libraries provide their privacy declarations.
PUT EVERY CREDENTIAL IN THE KEYCHAIN, WITH THE MOST RESTRICTIVE ACCESSIBILITY THAT WORKS
Preference storage is unencrypted and included in backups.
BIOMETRICS CONFIRM PRESENCE, NOT SERVER IDENTITY
Release a stored token after local authentication, and always provide a fallback.