iOS does not let an app invent its own VPN. It offers two doors, both in Apple's Network Extension framework: the VPN client built into the system, which speaks IKEv2 and IPSec, and packet tunnel providers, extensions an app ships to carry other protocols. SSHive uses both. An IKEv2 or IPSec profile is handed to the system client, with its password stored as a Keychain reference that iOS reads when it connects. An OpenVPN profile runs in SSHive's own tunnel extension, a separate process that iOS starts and manages.
That is why the VPN is a real one: iOS routes traffic into it at the system level, it shows in the iOS VPN settings, and it keeps running independently of SSHive's window. It is also why SSHive takes care to disconnect it. A VPN started for a session is closed when that session ends, and if you leave the app during a remote desktop session that brought up a VPN, SSHive ends both, so that no tunnel stays connected behind your back.
The sequence on call: the alert arrives, you open the saved SSH profile. SSHive checks whether the server answers on the current network; from home it does not, so the VPN comes up, then the SSH session opens through it. You investigate, close the session, and the VPN goes down with it.
As for secrets, the VPN password and the IPSec shared secret are stored in the iOS Keychain, where the system can use them without showing them to anyone. The .ovpn file itself is kept in the app's data on the device. No .mobileconfig configuration profile is installed on the iPhone.