What happened at the border
In July 2026, The New York Times reported on a US citizen stopped at the border and asked to unlock a phone. The code typed in was, prosecutors say, a duress password (also called a duress PIN) — a special passcode that erases the device instead of opening it. What followed was a federal felony charge for destroying evidence: the first known case of its kind, still undecided, and a new light on every panic-wipe feature in any product.
Why deleting can be worse than showing
The charge rests on a simple idea: if officials have the right to examine something, destroying it while they wait looks like shredding documents during a raid — and an erased phone cannot prove its own innocence. There is a practical problem too, far beyond borders: a wipe is visible. One moment the data exists; the next, right in front of the person demanding it, it is gone. Whether that person is an official, an abusive partner, or a thief, visible destruction tends to escalate the moment, not end it.
The other way: have nothing to find
Deniability flips the question from “how do I destroy my data under pressure?” to “why should the pressure find anything at all?” In Sealby, every code opens its own vault — so you keep one filled with ordinary, harmless things and open exactly that one on demand. Sealby stores no list of vaults, no count, nothing that says “there is more here”; a vault you have not opened looks like random leftover data. Showing the harmless vault is full cooperation. Nothing was deleted. There was simply nothing else to find.
Sealby’s duress PIN: moving, not destroying
For situations worse than a border queue, Sealby still has a duress PIN — built differently from a self-destruct. You mark a harmless decoy vault; entering its PIN opens it normally and quietly removes your other vaults from that device, once. At the same moment the phone stops syncing — on purpose — so the wipe never reaches your iCloud backup. The encrypted copy of your vaults stays in your own iCloud, and each one comes back on a new device with its recovery phrase. Your data did not die. It left the phone.
Moved is not destroyed — but be honest about the law
With backup on, Sealby’s duress feature is not a destruction tool — the device carries nothing while your data survives, encrypted, under your control. But an engineering difference is not a legal shield: removing data during a lawful search could still be treated as obstruction, and no app feature changes that. The law on duress codes is unsettled and varies by country; the first US case is still being argued, and this article is not legal advice. What good design can genuinely do is make the desperate option unnecessary — when nothing can prove your private vaults exist, opening a decoy is usually answer enough.
If the risk is real for you
Lead with the decoy, not the wipe. If your situation truly calls for the duress PIN: turn on iCloud backup first, so triggering it moves your data instead of losing it; put believable content in the decoy; choose a PIN you could never type by accident; and write each vault’s recovery phrase down somewhere safe, away from the device. Those words are what your data ultimately answers to — the phone is just the thing that carries it.