What sealing one secret actually involves
Key encapsulation runs against a local ML-KEM-768 public key. The content key is derived with HKDF-SHA256, with domain separation per widget and per version so two secrets never end up under the same derived key. The secret is then sealed with AES-256-GCM under a random 96-bit nonce.
The consequence of doing it per secret rather than per vault is that opening one thing does not open everything, and re-encrypting one thing does not mean rewriting the whole store. Secure notes use exactly the same envelope: the title is list metadata, the body is an encrypted secret.