Monero · EU · upstream open-source

Becomeuntraceable.

Mass surveillance is the default. We answer it by disappearing. De-Googled phone, router with a changeable IMEI, encrypted laptop and protection tools: the full arsenal to stay private — clear, precise, verifiable. Tutorials and training included, to communicate and browse without leaving a trace. Monero payment.

0Third-party origins
3Hardware lines
4Threat models
Single origin
No third-party scripts
Payment
Monero (XMR)
Sources
Upstream, dated
Monero payment, no logsVerifiable upstream sources.onion service readyPII encrypted at rest

Three lines

One line per use, not a catalogue.

Each line starts from a defined adversary. We assemble to order and document every choice.

Phones

Pixel 8a — GrapheneOS

Refurbished Google Pixel 8a (Akita) reflashed with GrapheneOS, a hardened Android-based OS with verified boot under user-controlled keys, hardware memory tagging, and optional sandboxed Google Play. 128 GB storage.

From€1,1907 days
Laptops

ThinkPad X1 Carbon Gen 11 — hardened

A 13th-gen Intel ThinkPad X1 Carbon Gen 11 (1 TB NVMe) provisioned for Qubes OS compartmentalisation. The proprietary firmware is retained — this generation is not supported by Coreboot or Heads — so hardening here is OS-level, not firmware-level.

From€2,09014 days
Routers

GL.iNet Mudi V2 — blue-merle (ekaii)

GL.iNet Mudi V2 (GL-E750V2) portable LTE router running our maintained ekaii fork of blue-merle: SIM-swap-driven IMEI randomization, MAC/BSSID randomization with vendor-OUI mimicry, and tmpfs-backed wiping of client connection logs. Changing an IMEI is restricted or unlawful in some jurisdictions; the buyer is responsible for compliance.

From€6907 days

Boot chain

Own the boot chain, not just the device.

On the laptop line, every boot stage is measured before it runs. If anything changes between two power-ons, the attestation no longer matches — and you see it.

  1. Power on

    The CPU starts from immutable boot ROM. Nothing modifiable has run yet.

  2. Measure the firmware

    coreboot measures each stage (a SHA-256 hash) into the TPM before executing it.

    coreboot.org
  3. Verify the boot path

    Heads checks its own integrity, then the signatures on your /boot files.

    osresearch.net
  4. Attestation

    A secret only you set is shown (a word or a TOTP code). If the chain changed, it won't match.

  5. Hardened OS ready

    Hands off to Qubes or Tails. The keys stay yours; nothing phones home.

    qubes-os.org

Our approach

Harden what can be hardened. Say so when it can't.

We do not invent cryptography. We reduce attack surface on top of auditable work — and we show the limits with the same weight as the features.

What we do

  • Replace the stock firmware/OS with a hardened, open build and verify it boots.
  • Document every choice and link to the upstream project, so you can verify it yourself.
  • Start from a sober threat model: the adversary we help against, not a promise of safety.

What this does not protect against

  • No device is “unbreakable”; given time and resources, hardware can be attacked physically.
  • A VPN is not anonymity; encryption does not protect an unlocked, running device.
  • Cellular basebands and most radios remain proprietary and are not audited by us.

Choose by your adversary, not by a promise.

Start from your threat model, then compare what each line actually changes.

Support