Stored as encrypted blobs:
master key (optional — can be external/hardware)
control keys
delegated keys
recovery key seeds
guardian references
Keys never leave the Vault except in signed form.