Glossary
Sealed System Volume (SSV)
The Sealed System Volume is the cryptographically hashed, read-only macOS system volume introduced in Big Sur, booted from a verified snapshot.
The Sealed System Volume (SSV), introduced in macOS Big Sur (11), protects the operating system by cryptographically sealing the System volume. Every file's content and metadata is covered by a tree of hashes whose root is verified at boot, and the Mac actually boots from a read-only APFS snapshot of that volume.
Any modification breaks the seal, and the system will not boot from an unsealed volume unless security policy is lowered. User data, third-party software and most forensic artifacts live on the separate, writable Data volume.
For investigators, SSV means persistence in Apple's system directories is far less likely on a healthy machine, so attention shifts to the Data volume, such as launchd plists in /Library. See Apple Silicon forensics.