Available on iOS and Android

iOS & Android

Duress vault

A designated NullVault duress pattern opens a prepared benign vault while invalidating the local references needed to reopen the other local vaults. It is an irreversible, device-local emergency action—not remote erasure.

The feature

Why it matters

Prepare a normal-looking keeper vault and a separate high-stakes pattern for a coercion scenario.

01

A normal unlock with exceptional consequences

The duress vault is prepared in advance with content the user is willing to reveal. When its designated pattern is drawn, the interface opens that keeper vault rather than displaying a special emergency screen.

Behind that ordinary-looking transition, NullVault commits a forward-only local change that leaves the keeper and invalidates the references used to reopen the other local vaults. There is no confirmation step during activation because such a prompt would disclose the action.

02

Understand the irreversible boundary

Duress affects NullVault's local store on that device. It cannot retrieve or erase files already exported, content photographed with another device, recipient copies, filesystem snapshots outside the documented model, or every remote backup immediately.

This feature should be configured and rehearsed only with non-critical test content first. An accidental duress unlock can make the other local vaults inaccessible, and support cannot simply reverse the committed local action.

Platform details

How support differs

iOS

IOS

Available on iOS

Available now

Destructive local duress configuration is available on iPhone.

  • The chosen pattern opens the designated keeper vault through the normal unlock flow.
  • The same committed local transaction removes references to non-keeper vaults from the active local store.
  • Remote cleanup is best-effort and does not erase recipient exports or other prior copies.
A

ANDROID

Available on Android

Available now

Destructive duress protection is available on Android.

  • A designated pattern opens the prepared benign vault.
  • Other local vault references are invalidated through the reviewed destructive-duress transaction.
  • Exported encrypted backup files remain outside the local duress action.

Documentation basis

Documented claims

Know the boundary

Important limitations

Clear answers

Questions about this feature

Is the duress vault the same as an ordinary decoy?

No. An ordinary decoy opens non-destructively. The designated duress pattern also performs an irreversible local invalidation of the non-keeper vault references.

Does duress delete encrypted backups and exported copies?

No such universal deletion is claimed. Remote cleanup can be delayed or unavailable, and exported, photographed, or recipient-held copies remain outside the local action.

Can NullVault undo an accidental duress unlock?

Do not assume it can. The local action is intentionally forward-only, so configure and use it with exceptional care.