Apple iCloud Encryption: Discrepancies in Data Category Counts
- Apple’s official documentation contains a notable discrepancy regarding the total count of data categories protected under its optional Advanced Data Protection setting for iCloud, according to conflicting figures...
- When a user turns on Advanced Data Protection, their trusted devices retain sole access to the encryption keys for the majority of their iCloud data, providing end-to-end encryption.
- However, separate pages within the Apple iCloud security guide present conflicting metrics.
Apple’s official documentation contains a notable discrepancy regarding the total count of data categories protected under its optional Advanced Data Protection setting for iCloud, according to conflicting figures published across the company’s support pages and security guides.
Apple’s iCloud Documentation Contradicts Itself on Encryption Metrics
When a user turns on Advanced Data Protection, their trusted devices retain sole access to the encryption keys for the majority of their iCloud data, providing end-to-end encryption. According to support documentation at support.apple.com, the total number of protected data categories rises from 14 to 23 when the feature is enabled.
However, separate pages within the Apple iCloud security guide present conflicting metrics. Depending on the specific security guide page or support resource consulted, the documentation lists either 14 and 23 encrypted data categories, or higher figures counting 15 and 25 categories.
How Cloud Keys Are Managed on Apple Servers
Conceptually, Advanced Data Protection changes how cloud keys are managed on Apple servers. All CloudKit Service keys generated on device and later uploaded to available-after-authentication iCloud Hardware Security Modules (HSMs) in Apple data centers are deleted from those HSMs, according to support.apple.com.

Instead, those keys are kept entirely within the Apple Account’s iCloud Keychain protection domain. They are handled like existing end-to-end encrypted service keys, meaning Apple can no longer read or access them. The feature also automatically protects CloudKit fields that third-party developers choose to mark as encrypted, along with all CloudKit assets.
Trusted Devices and Irrevocable Key Deletion
When a user enables the setting, their trusted device performs two primary actions. First, it communicates the intent to other participating devices by writing a signed value into its iCloud Keychain device metadata, which Apple servers cannot remove or modify while it synchronizes.

Second, the device initiates the removal of available-after-authentication service keys from Apple data centers. Because these keys are protected by iCloud HSMs, the deletion is immediate, permanent, and irrevocable. The device then begins an asynchronous key rotation operation to create new service keys controlled solely by the user’s trusted hardware.
Security Restrictions on iCloud.com Web Access
Turning on Advanced Data Protection automatically disables web access to data at iCloud.com, because iCloud web servers no longer possess the keys required to decrypt and display user information. Users can choose to re-enable web access, but doing so requires explicit authorization on a trusted device during each visit to iCloud.com, according to support.apple.com.
Authorization arms the trusted device for web access for the following hour, accepting requests from specific Apple servers to upload individual service keys from an allow list. Server requests cannot induce the device to upload service keys for data not intended for web viewing, such as Health data or passwords stored in iCloud Keychain.
