If we ever "lose user account data" and ask you to sign up again (or remove account functionality entirely), then you should not trust this site any longer.
If this were to happen (extremely unlikely), then this site would now be an FBI honeypot.
You would also likely start to see "mods" (not us) encouraging all to post violence.
I believe you can trust this site for as long as your user accounts work, which will hopefully be forever.
Keep in mind that to verify whether your user accounts do work, you also need to check whether an incorrect password doesn't work.
Good idea.
And when they threaten your (insert someone you care about) with endless IRS audits if you do not give them the key to the canary?
Do not fear the government which tortures you, fear the government which can compromise you without so much as a slap.
It's about mitigating risk. Of course in security there's always the "what if an asteroid breaks down our wall" possibility.
The risk of them torturing the password from him before (at most) 24 hours is so ridiculously small it's not worth considering. Additionally, they must have access to his machine since no one wants to memorize the long private keys. Furthermore, this minuscule risk can be further mitigated by using a dead man's switch (destroy key) or logless vpns or tor (anonymity).
It's far more likely they obtain the key by hacking or social engineering. If he uses best practices, this risk becomes extremely tiny as well.
And if you select three mods (or, hell, all of them), and give each of them a key, and sign the canary with all three (or all) of the keys, it makes it that much harder.