Decoy Vault vs. Duress Vault: How Plausible Deniability Actually Works
Most security features protect your files from someone who never gets your password. But there is a harder problem: what happens when someone makes you open your vault?
Borders. A jealous partner. A thief who watched you type your PIN. In these moments a lock is not enough, because you are being forced to unlock it yourself. This is where two features come in that are constantly confused for each other — the decoy vault and the duress vault.
They sound like the same idea. They are actually opposites. One shows someone something. The other destroys something. Knowing the difference is the whole game.
What "Plausible Deniability" Actually Means
Plausible deniability is the ability to hand over something convincing so that no one keeps digging for the real thing. If you refuse to unlock your phone, you have just announced that there is something worth hiding. If you unlock it and it looks completely ordinary, the pressure stops.
The goal is not to win the argument. It is to make the argument end before anyone reaches your actual private files. Decoy and duress vaults are two very different ways to get there.
The Decoy Vault: Hide That There's Anything to Hide
A decoy vault is a second, harmless vault that opens with a different PIN or pattern.
You set up two unlock codes. One opens your real vault. The other opens an alternate space you have stocked with a few boring, plausible files — some screenshots, a couple of documents, nothing sensitive. If you are ever forced to open the app, you enter the decoy code. The person sees a real, working vault with real, unremarkable content and has no reason to believe a second one exists.
Nothing is deleted. Your true vault is still there, still encrypted, completely invisible. You have simply pointed the pressure at a room you were happy to let them see.
The Duress Vault: Destroy Rather Than Surrender
A duress vault answers a different, more serious question: what if the safest outcome is that the files no longer exist?
With Vaultine's duress feature you designate a specific "duress" unlock. When that code is entered, the app opens an empty vault and instantly wipes your real vaults in the background. To the person forcing you, it looks like you cooperated and there was simply nothing there. In reality, the sensitive data is gone — beyond recovery — the moment the duress code is used.
This is a deliberately drastic tool. You reach for it when exposure would be far worse than loss.
Decoy vs. Duress at a Glance
| Decoy Vault | Duress Vault | |
|---|---|---|
| What opens | A second, harmless vault | An empty vault |
| What happens to real files | Nothing — they stay hidden | They are wiped instantly |
| Best when | You want the search to stop | You want the data gone |
| Reversible? | Yes, your real vault is intact | No, the wipe is permanent |
They are two separate features, and they are not mutually exclusive. You can run a decoy vault for everyday plausibility and keep a duress code in reserve for the rare, serious case.
When You'd Reach for Each
- Border crossings and travel. In many countries you can be compelled to unlock a device. A decoy vault lets you comply calmly with something that looks complete.
- A device someone else knows well. An ex, a roommate, a family member who knows your habits. A decoy vault ends the "what's in there?" conversation without a confrontation.
- High-stakes coercion. When the contents themselves are the danger, a duress vault means there is nothing left to hand over.
None of This Works Without Real Encryption Underneath
Here is the part people miss: decoy and duress tricks are only as strong as the encryption beneath them. If your "hidden" files are just moved or renamed, a decoy is theater — anyone who plugs the device into a laptop finds the real data regardless of which PIN you typed. (We wrote about exactly this in Why the 'Hidden' Folder Isn't Really Hidden.)
For plausible deniability to mean anything, the real vault has to be genuinely unreadable — not merely out of sight. That means every file encrypted, on your device, with a key only you hold.
How Vaultine Handles It
Vaultine is built around this exact threat model:
- Both features, separate and independent. Set a decoy vault, a duress vault, or both — each with its own unlock.
- Real encryption underneath. Every file is encrypted on your device with AES-256-GCM before it is ever stored, so the hidden vault is unreadable, not just invisible.
- Your key, derived from your unlock. A 5×5 pattern or a secure PIN generates the key. No account, and the key never leaves your device.
- Everywhere you carry files. The same vault works on iPhone, Mac, Android, and Windows.
Decoy and duress are not gimmicks. They are answers to the specific moment when someone is standing over you asking you to open up. Decide now which answer you want ready — because that is not the moment to start setting it up.
Take real control of your privacy with Vaultine.