Our approach
Our approach
We do not invent cryptography. We assemble and document hardware on top of published, auditable open-source projects — GrapheneOS, Qubes, Tails, OpenWRT, blue-merle (and coreboot/Heads on our legacy models) — and we state precisely what each build does and does not change.
What we do
Harden, verify, document.
- Replace the stock firmware/OS with a hardened, open build and verify it boots as expected.
- Document every choice and link to the upstream project so you can verify it yourself.
- Ship from a sober threat model: we describe the adversary a build helps against, not a vague promise of safety.
What we will not say
- No device is “unbreakable”. Every product page lists its limits with the same weight as its features.
- A VPN is not anonymity. Disk encryption does not protect an unlocked, running device.
- Cellular basebands and most internal radios are proprietary and not audited by us.
- Hardware can be physically attacked given time and resources. We reduce attack surface; we do not eliminate it.
The declines ledger
| 0 | Third-party origins loaded no CDN, no external fonts; everything from our own origin |
| 0 | Analytics / trackers no audience measurement, no advertising scripts |
| 0 | Server access logs kept Traefik accessLog is off — no visitor IP log |
| 0 | Dark patterns / countdowns no fake scarcity, no urgency timers, ever |
| 0 | Loading skeletons / toasts everything is server-rendered; loading theatre is a tell |
| 0 | Cursor effects / scroll hijack the page does not chase you or fight your scroll |
Every security claim on this site is caveated and, where possible, points to an upstream source you can read.
See the threat models