Our Security Process
What happens before a phone reaches your door.
1. Verified GrapheneOS Builds
Every device ships on GrapheneOS's official, signed release, checked against GrapheneOS's own release verification before we touch the hardware. We don't run modified or unofficial builds.
2. Hardware Sourcing & Inspection
Devices are sourced through channels we've used before and inspected for physical tampering before configuration begins. If a unit doesn't pass inspection, it doesn't ship.
3. Threat-Model-Based Configuration
We configure profiles, VPN and Tor routing, and app permissions based on the threat model you select, not a generic template applied to every order.
4. Pre-Shipment Testing
Before a device leaves us, we test sandboxing, network isolation, and update integrity against an internal checklist.
5. Ongoing Security Updates
We track GrapheneOS security releases and can help you apply them. Devices remain covered by GrapheneOS's own support window for their hardware generation.
