Likely with 'CloudKit End to End Encryption', see page 57 here:
https://www.apple.com/business/docs/iOS_Security_Guide.pdf> CloudKit end-to-end encryption
> Apple Pay Cash, User keywords, Siri Intelligence, and Hey Siri use CloudKit end-to-end encryption with a CloudKit service key protected by iCloud Keychain syncing. For these CloudKit containers, the key hierarchy is rooted in iCloud Keychain and therefore shares the security characteristics of iCloud Keychain—the keys are available only on the user’s trusted devices, and not to Apple or any third party. If access
to iCloud Keychain data is lost (see “Escrow security” section later in paper), the data in CloudKit is reset, and if data is available from the trusted local device it is re-uploaded to CloudKit.