- Gate every layer behind AppLockView when the lock is enabled and
lock on launch and on backgrounding; the passcode lives only in the
Keychain (AppLockVault) and the enable state defaults to off.
- Add the lock section to Settings: enable/setup, change passcode and
disable all require the current passcode via a shared passcode
sheet; Face ID / Touch ID unlock prompts automatically and can be
toggled with passcode confirmation.
- Add NSFaceIDUsageDescription to both app targets, cover the passcode
policy with tests, guard the feature in verify.sh and document it in
SECURITY.md.