Phone SeizedToolsCould they get in?
Could they get in?
This does not answer “can it be cracked” — that is not a question a general-purpose page can answer, and it is not a question this site tries to. What it does answer, cited to vendor and government documentation, is a narrower one: in a given device state, does the maker’s own documentation say the decryption key for that data is available or not.
Pick a device family and a device state below (off/before first unlock, after first unlock, unlocked, or cloud & carrier). Every combination this site has sourced vendor or government documentation for is shown, cited; where nothing has been sourced for a combination, that is stated explicitly rather than left blank. Output is limited to what the cited documentation states about decryption-key availability — never a claim about what any named forensic tool can or cannot do.
iPhone
Off / before first unlock (BFU)
Keys not in memory (off / before first unlock)Apple states that shortly after an iPhone locks, the key for its most-protected ('Complete Protection') data class is discarded, rendering that class of data inaccessible until the passcode is entered again or the device is unlocked.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
Magnet Forensics reported on 13 Nov 2024 that on iOS 18, a device that has entered a locked state and has not been unlocked within 72 hours will reboot — which returns it to this off/before-first-unlock state.
Magnet Forensics blog, "Understanding the security impacts of iOS 18's inactivity reboot", 13 Nov 2024
“This means that once a device has entered a locked state and has not been unlocked within 72 hours, it will reboot.”
Read it at magnetforensics.comquote checked 2026-09-08
After first unlock (AFU)
Keys in memory (after first unlock)Apple states that the key for its most-protected ('Complete Protection') data class is discarded shortly after the device locks — a state that does not depend on whether the device was unlocked earlier in this boot cycle.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
Apple documents a separate, default Data Protection class for third-party app data not otherwise assigned to a class of its own — a different class from the one whose key is discarded at lock.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“This is the default class for all third-party app data not otherwise assigned to a Data Protection class.”
Read it at support.apple.comquote checked 2026-09-08
Unlocked
UnlockedApple states that the key for its most-protected data class is discarded only shortly after the device locks — while the device is unlocked, that key has not been discarded.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
Where Lockdown Mode is switched on, Apple states that connecting an iPhone to an accessory or another computer requires the device to be unlocked.
Apple, "About Lockdown Mode" (support.apple.com/en-gb/105120), as fetched 2026-09-08
“Device connections: to connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked.”
Read it at support.apple.comquote checked 2026-09-08
Cloud & carrier
Cloud & carrier copies may existApple's own law enforcement guidelines state that content in a customer's iCloud account, as it exists there, may be provided in response to a search warrant issued on probable cause, or the customer's consent.
Apple, "Legal Process Guidelines — Government & Law Enforcement within the United States", published October 2025, Apple
“iCloud content, as it exists in the customer's account, may be provided in response to a search warrant issued upon a showing of probable cause, or customer consent.”
Read it at apple.comquote checked 2026-09-08
Where Advanced Data Protection is switched on, Apple states it does not hold the encryption keys for the iCloud categories that use end-to-end encryption, and cannot help recover that data if the account holder loses access to their account.
Apple, "iCloud data security overview" (support.apple.com/en-gb/102651), as fetched 2026-09-08
“Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account.”
Read it at support.apple.comquote checked 2026-09-08
At a US border, CBP's own directive states that a passcode or other means of access obtained during the inspection may be used only to inspect the device and information subject to the border search itself, and may not be used to access information that is only stored remotely.
CBP Directive No. 3340-049B §5.3.2 (eff. 1 Jan 2026)
“Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely.”
Read it at cbp.govquote checked 2026-09-08
Android (stock)
Off / before first unlock (BFU)
Keys not in memory (off / before first unlock)Android's file-based encryption documentation states that Credential Encrypted storage, the default storage location, is only available after the user has unlocked the device — meaning it is not available before that first unlock.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Android's file-based encryption documentation states that Device Encrypted storage is available both during Direct Boot mode — before the device is first unlocked — and after.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Device Encrypted (DE) storage, which is a storage location available both during Direct Boot mode and after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
After first unlock (AFU)
Keys in memory (after first unlock)Android's file-based encryption documentation states that Credential Encrypted storage, the default storage location, is only available after the user has unlocked the device.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Unlocked
UnlockedAndroid's file-based encryption documentation states that Credential Encrypted storage, the default storage location, is only available after the user has unlocked the device — which includes while it is currently unlocked.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Cloud & carrier
Cloud & carrier copies may existAt a US border, CBP's own directive states that a passcode or other means of access obtained during the inspection may be used only to inspect the device and information subject to the border search itself, and may not be used to access information that is only stored remotely.
CBP Directive No. 3340-049B §5.3.2 (eff. 1 Jan 2026)
“Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely.”
Read it at cbp.govquote checked 2026-09-08
GrapheneOS
Off / before first unlock (BFU)
Keys not in memory (off / before first unlock)GrapheneOS is built on top of standard Android file-based encryption, under which Credential Encrypted storage — the default storage location — is only available after the user has unlocked the device.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
GrapheneOS documents an auto-reboot timer, set to 18 hours by default and adjustable between 10 minutes and 72 hours, or off — after that time a locked device reboots, returning it to this off/before-first-unlock state.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“The timer is set to 18 hours by default, but can be set to values between 10 minutes and 72 hours, or turned off.”
Read it at grapheneos.orgquote checked 2026-09-08
After first unlock (AFU)
Keys in memory (after first unlock)GrapheneOS documents an auto-reboot timer, set to 18 hours by default and adjustable between 10 minutes and 72 hours, or off — a locked device that has been unlocked earlier this boot reverts to off/before-first-unlock once that timer runs out.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“The timer is set to 18 hours by default, but can be set to values between 10 minutes and 72 hours, or turned off.”
Read it at grapheneos.orgquote checked 2026-09-08
GrapheneOS documents a USB-C default of 'Charging-only when locked,' which it states significantly reduces attack surface when the device is locked.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“The default is Charging-only when locked , which significantly reduces attack surface when the device is locked.”
Read it at grapheneos.orgquote checked 2026-09-08
Unlocked
UnlockedGrapheneOS is built on top of standard Android file-based encryption, under which Credential Encrypted storage becomes available once the device has been unlocked.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
GrapheneOS documents a duress PIN or password option that, once entered anywhere the device credentials are requested, irreversibly wipes the device, including any installed eSIMs.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).”
Read it at grapheneos.orgquote checked 2026-09-08
Cloud & carrier
Cloud & carrier copies may existAt a US border, CBP's own directive states that a passcode or other means of access obtained during the inspection may be used only to inspect the device and information subject to the border search itself, and may not be used to access information that is only stored remotely.
CBP Directive No. 3340-049B §5.3.2 (eff. 1 Jan 2026)
“Passcodes or other means of access obtained during a border inspection will only be utilized to facilitate the inspection of devices and information subject to border search. Passcodes or other means of access may not be utilized to access information that is only stored remotely.”
Read it at cbp.govquote checked 2026-09-08
If biometrics (fingerprint or face unlock) are enabled
Everything above is about what a device’s own encryption makes available in each state — it does not change depending on whether a fingerprint or face unlock is also enabled. Whether someone can be legally compelled to present a fingerprint or face, as opposed to a passcode, is a separate, jurisdiction-specific legal question this tool does not answer:
Read more, sourced the same way:
Last reviewed 2026-09-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.