Pixel 8a — GrapheneOS
Refurbished Google Pixel 8a (Akita) reflashed with GrapheneOS, a hardened Android-based OS with verified boot under user-controlled keys, hardware memory tagging, and optional sandboxed Google Play. 128 GB storage.
Monero · EU · upstream open-source
Mass surveillance is the default. We answer it by disappearing. De-Googled phone, router with a changeable IMEI, encrypted laptop and protection tools: the full arsenal to stay private — clear, precise, verifiable. Tutorials and training included, to communicate and browse without leaving a trace. Monero payment.
Three lines
Each line starts from a defined adversary. We assemble to order and document every choice.
Refurbished Google Pixel 8a (Akita) reflashed with GrapheneOS, a hardened Android-based OS with verified boot under user-controlled keys, hardware memory tagging, and optional sandboxed Google Play. 128 GB storage.
A 13th-gen Intel ThinkPad X1 Carbon Gen 11 (1 TB NVMe) provisioned for Qubes OS compartmentalisation. The proprietary firmware is retained — this generation is not supported by Coreboot or Heads — so hardening here is OS-level, not firmware-level.
GL.iNet Mudi V2 (GL-E750V2) portable LTE router running our maintained ekaii fork of blue-merle: SIM-swap-driven IMEI randomization, MAC/BSSID randomization with vendor-OUI mimicry, and tmpfs-backed wiping of client connection logs. Changing an IMEI is restricted or unlawful in some jurisdictions; the buyer is responsible for compliance.
Boot chain
On the laptop line, every boot stage is measured before it runs. If anything changes between two power-ons, the attestation no longer matches — and you see it.
The CPU starts from immutable boot ROM. Nothing modifiable has run yet.
coreboot measures each stage (a SHA-256 hash) into the TPM before executing it.
coreboot.orgHeads checks its own integrity, then the signatures on your /boot files.
osresearch.netA secret only you set is shown (a word or a TOTP code). If the chain changed, it won't match.
Our approach
We do not invent cryptography. We reduce attack surface on top of auditable work — and we show the limits with the same weight as the features.
What we do
What this does not protect against
Threat models
A device is only useful against a defined adversary. Start from the profile closest to yours.
Transparency
Start from your threat model, then compare what each line actually changes.