Two codes, two different jobs

A Decoy Vault and a Duress Vault solve different problems, and it's worth being precise about which one does what before you're relying on either.

The Decoy Vault opens on a second code and shows exactly what you stocked it with in advance — a set of ordinary files you chose. It's for the situation where you need to unlock something, and an empty vault would itself be suspicious.

The Duress Vault is a third code that opens an empty vault and wipes your real ones as it does. And it isn't left as a conspicuous empty shell afterwards: that vault becomes your main vault, as though nothing else had ever been on the device. It's for the situation where the files genuinely cannot survive the unlock — event photos that would identify someone, contacts that shouldn't be traced, planning notes that shouldn't exist to whoever is holding the phone. Both are configured by you ahead of time, not improvised in the moment.

Nothing to compel

Vaultine has no account system and no server that holds your files or your encryption key. The key is derived from your code, on your device, and it never leaves. That's a design decision with a practical consequence: there is no vendor-side copy of anything for anyone to request, subpoena or breach — because it was never there to begin with.

Separate vaults for separate things

Photos from an event, contacts for a campaign, and your own unrelated personal files don't have to share one vault. Vaultine supports as many separate vaults as you need, so organizing material can be kept apart from your personal life and from any other campaign you're involved in — on the same phone you already carry, or on a laptop, since Vaultine runs on Windows, macOS, iOS and Android alike.