the text
what kind of data it is: its DEK's class, and the row
/admin/encryption counts it on
'cell' to seal under this cell's own DEKs where a cell key is held (#98); anything else seals under the service's
{ realm }: the realm whose DEK seals it, when that is not
the ambient realm (a flush writing another realm's rows)
the ciphertext, or null without a key-encryption key
Seals text under the data encryption key of its realm and class, itself wrapped under the key-encryption key, which never leaves this file (#391).