SecureStoreStatus
Whether this device can actually keep a secret at rest right now, and if not, why.
The capability flag for SecureStore, and — like BiometricAvailability — deliberately not a Boolean. An encrypted store fails for reasons a caller can act on: a corrupted Keystore keyset survives an app-data clear, a Keychain refuses writes to an app with no keychain-sharing entitlement, a device with a broken TEE never recovers. "false" tells a payments flow nothing about whether to retry, re-provision, or refuse to store the token at all.
Every state carries a reason that is safe to log. It never contains a stored value or key name.
Inheritors
Types
The store was opened and a write/read-back/delete round-trip succeeded.
The store could not be opened, or did not return what it was given. reason carries the detail.