I've heard that companies store their private keys offline "in a safe that will never be opened" and stuff like that (the context for this is a console developer like Microsoft keeping the Xbox private keys offline in a safe).
How would they still sign code with their private keys if they're fully locked away? Does someone go and physically get the keys to sign the code? Is this a figure of speech that I don't understand?