he's using IOS https://xcancel.com/DefuseSec/status/1812613899109425375#m
He should have probably used GrapheneOS which limits forensics capabilities and with duress enabled, but idk how practical it would have been in that situation (very suspicious behavior). He's Canadian and GrapheneOS is endorsed by CitizenLab :/ so probably heard about it and he's a very competent security researcher from reading his blog posts.