docs: add MM-145 design plan — P-256 keypair via Secure Enclave
Completed brainstorming session. Design includes:
- New device_key.rs module with compile-time SE/simulator split
- Raw FFI via security-framework-sys (SecKeyCreateRandomKey + kSecAttrTokenIDSecureEnclave)
- DER → raw r||s conversion for ATProto-compatible signatures
- 4 implementation phases