Duress Mode: Silent Local Vault Wipe

You are being forced to unlock your phone. Someone is watching. You draw a pattern on the grid, and the vault you designated opens normally. Behind that ordinary screen, Vaultaire removes the local indexes and recovery mappings for the other vaults on that device and prevents the wiped state from automatically propagating through sync.

Duress mode in Vaultaire lets you designate one vault as a coercion trigger. Drawing that vault’s pattern opens it normally while removing non-duress vault indexes and local recovery mappings from the current device. Existing encrypted iCloud backups and peer-device copies are intentionally left unchanged.

What Is Duress Mode?

Duress Mode is the last line of defense. It is a feature you hope you never need, designed for the moment when everything else has failed — when someone is standing over you, demanding access to your private files, and you have no choice but to comply.

Here is how it works: you designate one vault as your duress vault. You fill it with content that looks believable — a few harmless photos, some mundane documents. Then you assign it a pattern, just like any other vault. In the ordinary unlock interface, it looks and opens like a normal vault; filesystem and cloud evidence remain outside that narrow presentation claim.

The difference is what happens when you draw that pattern. A normal vault pattern opens its own vault. The duress pattern does that too, showing the designated vault’s contents on screen, but it also triggers a local wipe of the indexes and recovery mappings that make the other vaults accessible on that device.

No confirmation dialog appears. No warning sound plays. The person watching you sees a vault open and its files appear. What the interface does not announce is that other local vault indexes have been deleted, local recovery mappings have been cleared, pending backup work has been stopped, and the device must use explicit phrase-based recovery before a wiped vault can return.

The Local Wipe Boundary

Duress Mode is a destructive local control for users who have decided that removing vault access from the device is safer than exposing it under coercion. The local wipe is immediate and has no undo button. Recovery is a separate process and depends on a prior encrypted backup plus the vault’s recovery phrase.

How It Works Under the Hood

Understanding the mechanics matters because Duress Mode has a narrower boundary than a universal erasure claim. It changes state on the current device; it does not promise to erase CloudKit, another device, filesystem history, or evidence already collected by an attacker.

Step 1: You Draw the Duress Pattern

When you draw the pattern assigned to your duress vault, Vaultaire recognizes it as a duress trigger. The app begins two operations simultaneously: it starts decrypting and displaying the designated vault’s contents, and it initiates local cleanup of the indexes and recovery mappings for every other vault.

Step 2: Local Access State Is Removed

Vaultaire uses one device-wide Keychain salt for local pattern derivation, not a separate salt for each vault. Duress Mode does not destroy that shared salt. Instead, it clears the encrypted local recovery database and deletes every vault index except the designated vault’s index. Because each index contains the wrapped random master key and the file map for that vault, removing it takes the non-duress vault out of the app’s usable local state.

The encrypted blob pool can remain because vaults share that storage. Without the deleted index, Vaultaire has no file map or wrapped master key with which to open the removed vault locally. The app also clears local recovery mappings so the ordinary recovery screen cannot immediately enumerate or restore those vaults.

Step 3: Cloud Recovery Is Preserved but Isolated

Existing encrypted iCloud backup is deliberately preserved as a recovery path. The device resets pending backup work and enters an isolation boundary so the local wipe is not uploaded as an ordinary deletion and hidden vaults are not pulled back automatically. Later recovery is explicit, one vault at a time, and requires that vault’s recovery phrase rather than only the pattern disclosed under coercion.

Step 4: The Duress Vault Opens Normally

While the local cleanup runs, the designated vault opens through the normal interface. Vaultaire suppresses analytics before starting, attempts to revoke active shares created from that vault, regenerates its recovery phrase, and clears the duress designation afterward. The app presents no duress confirmation or completion message, but completion time depends on local work and any network revocations; Vaultaire does not promise a universal sub-second deadline.

Local
Current Device Wipe Scope
0
Separate Wipe Notices
Phrase
Required for Later Recovery

What the Silent Interface Does and Does Not Hide

The immediate interface is designed to avoid announcing Duress Mode to someone watching over your shoulder. That is a useful presentation property, not proof that every forensic observer sees identical device state. Filesystem artifacts, CloudKit records, another synced device, or prior access to the phone can fall outside what the app can conceal.

No Confirmation Dialog

Most destructive actions in software come with a warning: "Are you sure?" Duress Mode has no such warning. A confirmation dialog would be a dead giveaway. The moment you draw the pattern, the action is taken. You cannot accidentally trigger it unless you accidentally draw a specific, complex pattern on a 5×5 grid — which is not something that happens by chance.

No Separate Delay Screen

The app opens the designated vault while it performs local cleanup and share-revocation work. The flow is designed not to add a separate warning screen, but device performance, vault state, and network conditions vary. Vaultaire does not claim timing equality that an observer with instruments could never distinguish.

No In-App Wipe Notice

Vaultaire disables analytics before the wipe and does not show a “vaults deleted” notification. On that device, the preserved vault is the one that remains accessible through the app. This does not erase evidence outside the app’s current local state, and it should not be treated as a promise of undetectability under forensic examination.

What Local State Is Removed

Precision matters here. Duress Mode removes specific local structures needed to find and open non-duress vaults, while preserving shared encrypted blob storage and any encrypted iCloud backup. It is a local access-state wipe, not a claim that every physical copy has been overwritten.

The Encrypted Recovery Database

The local recovery database maps recovery phrases and legacy pattern fields to vault access. Duress Mode clears that database, then creates a new recovery entry only for the designated vault. This removes local recovery mappings for the other vaults without pretending that Vaultaire used or destroyed a separate salt for each one.

The Non-Duress Vault Indexes

Each encrypted vault index contains its file records and the random master key wrapped by that vault’s pattern-derived key. Duress Mode deletes every index except the designated vault’s. The PBKDF2 algorithm and iteration count are public implementation parameters; security does not depend on erasing them.

The Encrypted Data

The shared encrypted blob pool is retained because it also contains the designated vault’s content. Data that belonged only to deleted indexes can become unreachable through the app, but Vaultaire does not claim secure physical overwrite of every flash-storage block. Deleted indexes or prior state may also persist in storage layers beyond the app’s control.

Forensic Reality

After Duress Mode, the app exposes the preserved vault and no plaintext cross-vault registry. That limits what the ordinary interface reveals. It does not prove that a forensic examiner cannot infer prior vault activity from deleted indexes, filesystem snapshots, storage volume, CloudKit, peer devices, or evidence collected before the wipe.

When to Use Duress Mode

Duress Mode is designed for situations where you face physical coercion or legal compulsion and have decided that removing local vault access is preferable to exposing it. This is a personal decision with serious implications, and Vaultaire gives you the tool without making the decision for you.

Border Crossings

Border-search powers and traveler obligations vary by country and circumstance. Drawing the duress pattern before handing over your phone leaves one vault accessible in the interface and removes other local access state, but it cannot guarantee that an examiner finds no filesystem artifacts, encrypted backups, peer copies, or prior evidence.

Physical Coercion

If someone is forcing you to unlock your phone under threat, you need a way to limit what the ordinary interface reveals. Duress Mode lets you draw a pattern that looks like cooperation. The coercer sees the designated vault open, while the interface does not announce the simultaneous local cleanup of other vault access state.

Device Seizure

If you have reason to believe your device will be confiscated, Duress Mode can remove non-duress vault access from the current app installation before handoff. It cannot guarantee that a forensic analyst has nothing to examine, especially if the device was already compromised or other copies and system artifacts exist.

Journalist and Source Protection

Journalists working in hostile environments, activists operating under surveillance, and anyone whose data could endanger themselves or others. Duress Mode turns a moment of vulnerability into a moment of protection.

Setting Up Your Duress Vault

Configuring Duress Mode takes about two minutes. Doing it well — making it convincing — takes a bit more thought.

Designate the Vault

In Vaultaire's settings, you designate one vault as the duress vault. This vault will be the one that opens when the duress pattern is drawn, so it needs to contain content that looks real and satisfies an observer's expectations. An empty vault is suspicious. A vault with clearly fake content is suspicious. A vault with a handful of normal-looking personal photos is perfect.

Stock It With Believable Content

Put content in your duress vault that someone would expect to find in a private vault: a few personal photos, maybe a scan of a document, some files that look private enough to justify locking but innocuous enough to survive scrutiny. The goal is not to fool a forensic investigation — it is to satisfy the person standing in front of you in the moment.

Choose a Natural Pattern

The duress pattern should be something you can draw under stress, quickly, without hesitation. If you draw another valid pattern, you may open another vault or an empty state instead. Practice the trigger in a safe test setup. Like every Vaultaire pattern, it must connect at least six dots and make at least two direction changes.

Test It

Before you ever need it, test Duress Mode in a safe environment. Create some test vaults, designate a duress vault, and trigger it. Verify that the other vaults are gone. Verify that the duress vault opened normally. Then set it up for real.

There Is No Undo

This needs to be said clearly: once Duress Mode triggers, there is no undo button for the local wipe. Vaultaire support cannot reconstruct your pattern or recovery phrase. If you enabled encrypted iCloud backup beforehand and retained the recovery phrase, you can later restore one vault at a time. Without both, the deleted local access state may leave you unable to recover the vault.

The other indexes and local recovery mappings are gone from the active app state. The device-wide salt and shared encrypted blob pool are not the wipe target, and encrypted cloud backups are preserved. This boundary is deliberate: it removes access from the coerced device while keeping a phrase-controlled recovery path for the owner.

Duress Mode is designed for people who understand this tradeoff and have decided, in advance, that they would rather remove immediate access from the current device than expose the vault under coercion. If you cannot safely retain the recovery phrase and an encrypted backup, assume the local wipe may cost you access to that vault.

The tradeoff is specific rather than absolute. Local deletion begins without confirmation, while later recovery is possible only through the separate cloud and recovery-phrase path. Test the feature with non-sensitive data before deciding whether that behavior matches your threat model.

Frequently Asked Questions

What happens if I accidentally draw the duress pattern?

The local wipe starts immediately and has no confirmation step. Vaultaire removes non-duress vault indexes and local recovery mappings from that device while preserving the designated vault. If encrypted iCloud backup was enabled, later recovery remains possible with each vault’s recovery phrase. Choose and test the duress pattern carefully.

Can I recover my vaults from an iCloud backup after triggering Duress Mode?

Yes, if an encrypted backup exists. Duress Mode is local to the current device and intentionally preserves encrypted iCloud backups. The device is isolated from automatic sync after the wipe, and recovery requires an explicit action with the recovery phrase for one vault at a time. The coerced pattern alone is not enough to revive a wiped vault.

Can a forensic analyst tell that Duress Mode was triggered?

Vaultaire suppresses analytics before the wipe, shows no confirmation, and preserves the designated vault, so the in-app flow is intentionally quiet. That is not a guarantee against forensic detection. Deleted files, filesystem state, CloudKit records, peer devices, backups, or an already compromised device may provide evidence that other data existed or changed.

Does the duress vault itself get destroyed?

No. The designated vault remains intact, opens normally, and receives a new recovery phrase. Its duress designation is then cleared, so the same vault continues as an ordinary vault after the event.

Can I have multiple duress vaults?

No. You designate exactly one vault as the duress vault. This constraint is intentional — having multiple duress triggers would increase the risk of accidental activation and complicate the mental model. One vault, one pattern, one outcome.

Is Duress Mode legal?

Laws vary by jurisdiction and circumstance, especially when a device or its contents may be evidence or subject to a preservation duty. Vaultaire does not provide legal advice. Ask a qualified lawyer about your situation before relying on a destructive feature.

Prepare for the Worst

Set up Duress Mode now, while you have the luxury of time. When you need it, there will not be time to configure it.

Download Vaultaire Free