Solo service businesses — tattoo artists, home cleaners, nail technicians, mobile service providers — hold materially sensitive client data: photos of in-progress work, home addresses, visit schedules. The default tool for tracking that information is the calendar app that ships with the phone — Calendar on iOS, Google Calendar on Android — a piece of software whose main feature is propagating its contents everywhere it can. iCloud and Google Drive. Spotlight and Google Search. Siri and the Google Assistant. Lock-screen widgets. Share extensions. Any third-party app that asks for calendar access.
That is the wrong default for this data. clientAPT is the opposite default: a system whose main feature is keeping the data inside one device, behind several locks, with no exits.
The threat model assumes the worst plausible adversary for a small business — someone steals the phone while it is unlocked and tries to extract addresses, contacts, and photographs. That person fails. The deeper threat — a coerced unlock — is addressed by a duress PIN that opens a populated but fake vault. The real vault remains sealed.