Earlier quoted context omitted.
This is so wrong. The only thing that isn't user-encrypted so far is the iPhone backup on their server (Of course it is encrypted but Apple have the key to decrypt it as needed). The official explanation so far is that if the user forgot the password a user-encrypted backup would just become some useless junk. This is (officially) the sole remaining non user-encrypted personal data on apple server that authority can…
The burden of proof should be on Apple's site. Given their secrecy all you can do is pray or switch to open source.
Of course that will never be as audit friendly as an Open-Source code. But don't call it a secret, while you actually just didn't search for the information...