Duress & WraithVault

This is the feature WraithLink is built around. It answers a question ordinary encryption ignores: what happens when someone makes you unlock the phone?

Three credentials, three outcomes

You enterWhat happens
Your normal PINYour everyday phone opens as usual. Nothing unusual happens.
Your decoy-duress PINThe everyday phone still opens normally - but in the background the hidden WraithVault (and, optionally, other secondary profiles) is destroyed. There is no reboot and nothing on screen changes.
Your panic credentialThe device's encryption keys are destroyed and the phone powers down. Everything is gone, everywhere.

Following the same rule GrapheneOS uses for its wipe credential: if a duress credential happens to equal your real one, the real one wins - you can never lock yourself out by coincidence.

Why a decoy, not a fake screen

A lot of "duress" features just show a second home screen with fake apps. That fails the moment the attacker looks closely, because the real data is still sitting on the disk. Our model is the opposite. Your everyday phone is real - genuinely used, with real messages and photos and apps - so it survives scrutiny. The things you actually need to protect never live there; they live in WraithVault. The decoy PIN doesn't fake anything. It opens the real front and quietly removes the back room.

How the destroy works

When the decoy-duress PIN is recognised, WraithVault's storage key is evicted and destroyed first - a near-instant operation - so the data is unrecoverable even if the phone is snatched away a second later. The profile itself is then removed in the background. Because the key is gone, what remains on flash is indistinguishable from random noise.

WraithVault

WraithVault is a hardened secondary profile - not Android's "private space". We chose a full profile on purpose: private space lets its apps bypass your VPN, and it cannot be backed up. WraithVault respects your VPN and Tor routing, and it can be backed up (which matters, because a decoy destroy is only safe if you can restore). It is hidden as far as the OS allows: off the lock-screen profile switcher, out of quick settings, no cross-profile notifications, and suppressed in the user list where possible.

Back up before you arm the destroy. The setup wizard enforces this. A silent destroy is a feature only if losing the vault is recoverable. Back WraithVault up to your paired X47 desktop over the exclusive link, or, if you don't run X47, to an encrypted USB-C drive you keep somewhere safe. Never store the backup on the phone itself - that would both give the vault away and let it survive the very destroy it's meant to enable.

USB and backups

WraithLink blocks USB data while the screen is locked, which defeats forensic bridges. It does not block USB when unlocked, so your encrypted USB-C backup drive still mounts normally. The wizard sets this combination for you; don't switch USB to "always off" or your backup drive won't work.

The honest limit

Casual and coercion-grade, not forensic. The decoy destroy defeats theft, coercion, and someone inspecting the phone in front of you. It does not defeat an adversary who images your storage before you ever enter a PIN. For that, use the panic wipe. See the security model for the full picture.