The feature
Why it matters
Prepare a normal-looking keeper vault and a separate high-stakes pattern for a coercion scenario.
01
A normal unlock with exceptional consequences
The duress vault is prepared in advance with content the user is willing to reveal. When its designated pattern is drawn, the interface opens that keeper vault rather than displaying a special emergency screen.
Behind that ordinary-looking transition, NullVault commits a forward-only local change that leaves the keeper and invalidates the references used to reopen the other local vaults. There is no confirmation step during activation because such a prompt would disclose the action.
02
Understand the irreversible boundary
Duress affects NullVault's local store on that device. It cannot retrieve or erase files already exported, content photographed with another device, recipient copies, filesystem snapshots outside the documented model, or every remote backup immediately.
This feature should be configured and rehearsed only with non-critical test content first. An accidental duress unlock can make the other local vaults inaccessible, and support cannot simply reverse the committed local action.
Documentation basis
Documented claims
- Android's reviewed duress profile opens a benign keeper while invalidating the other local vaults, with final release gates still required.
- The iOS local implementation includes forward-only duress behavior and explicitly limits remote-cleanup and copy-removal claims.
Know the boundary
Important limitations
- Duress is destructive to local access and can cause irreversible loss when used accidentally.
- It cannot erase exports, external photographs, recipient copies, operating-system snapshots, or all remote data on demand.
- A person with control of an already-authorized session or previously captured key material may fall outside the action's guarantees.
Clear answers
Questions about this feature
Is the duress vault the same as an ordinary decoy?
No. An ordinary decoy opens non-destructively. The designated duress pattern also performs an irreversible local invalidation of the non-keeper vault references.
Does duress delete encrypted backups and exported copies?
No such universal deletion is claimed. Remote cleanup can be delayed or unavailable, and exported, photographed, or recipient-held copies remain outside the local action.
Can NullVault undo an accidental duress unlock?
Do not assume it can. The local action is intentionally forward-only, so configure and use it with exceptional care.