Drill · delivery
Verify a delivered device
Procedure taughtVerify a received device is the one onsecret prepared: re-locked bootloader, GrapheneOS attestation, expected apps, matching client sheet.
How do you know the phone you received is exactly the one described? Trust is verified, not bought. Walk the checks — each is reproducible by you.
Start here
At boot, a brief warning screen about the bootloader state appears. What should you see?
GrapheneOS expects a re-locked bootloader ("locked") under its own keys — that is what makes verified boot verifiable.
Bootloader locked, GrapheneOS keysGood move
ConsequenceExpected. A re-locked bootloader means verified boot is active under the keys of the system you run. That is exactly the state onsecret ships the device in.
SourcesGrapheneOS — Auditor / attestation
To go beyond the boot screen, how do you prove system integrity?
The Auditor app (hardware attestation)Good move
ConsequenceThe right method. GrapheneOS Auditor uses hardware attestation to verify that the system and bootloader are intact — a cryptographic check, not a visual impression.
SourcesGrapheneOS — Auditor / attestation
Final check: does the content match the client sheet?
Expected open-source apps, no Google appsGood move
ConsequenceCompliant. The kit (RustDesk, WireGuard, ntfy/FMD, SimpleX, Aegis, OpenKeychain, Organic Maps) is the one described, everything is open-source, no Google apps. Sheet and device match.
Unknown apps or accounts are presentPitfall
ConsequenceReport it. A device genuinely prepared by onsecret adds nothing to the system and installs only the announced kit. Any discrepancy should be verified via support before use.
I trust the boot logoNuance
ConsequenceInsufficient. A logo or wallpaper can be imitated; hardware attestation cannot. Use Auditor for real proof rather than appearance.
SourcesGrapheneOS — Auditor / attestation
Final check: does the content match the client sheet?
Expected open-source apps, no Google appsGood move
ConsequenceCompliant. The kit (RustDesk, WireGuard, ntfy/FMD, SimpleX, Aegis, OpenKeychain, Organic Maps) is the one described, everything is open-source, no Google apps. Sheet and device match.
Unknown apps or accounts are presentPitfall
ConsequenceReport it. A device genuinely prepared by onsecret adds nothing to the system and installs only the announced kit. Any discrepancy should be verified via support before use.
Bootloader unlockedPitfall
ConsequenceRed flag. An unlocked bootloader breaks the verified-boot chain: any software could have been flashed. This is NOT the onsecret delivery state — contact support before using the device.
SourcesGrapheneOS — Auditor / attestation
To go beyond the boot screen, how do you prove system integrity?
The Auditor app (hardware attestation)Good move
ConsequenceThe right method. GrapheneOS Auditor uses hardware attestation to verify that the system and bootloader are intact — a cryptographic check, not a visual impression.
SourcesGrapheneOS — Auditor / attestation
Final check: does the content match the client sheet?
Expected open-source apps, no Google appsGood move
ConsequenceCompliant. The kit (RustDesk, WireGuard, ntfy/FMD, SimpleX, Aegis, OpenKeychain, Organic Maps) is the one described, everything is open-source, no Google apps. Sheet and device match.
Unknown apps or accounts are presentPitfall
ConsequenceReport it. A device genuinely prepared by onsecret adds nothing to the system and installs only the announced kit. Any discrepancy should be verified via support before use.
I trust the boot logoNuance
ConsequenceInsufficient. A logo or wallpaper can be imitated; hardware attestation cannot. Use Auditor for real proof rather than appearance.
SourcesGrapheneOS — Auditor / attestation
Final check: does the content match the client sheet?
Expected open-source apps, no Google appsGood move
ConsequenceCompliant. The kit (RustDesk, WireGuard, ntfy/FMD, SimpleX, Aegis, OpenKeychain, Organic Maps) is the one described, everything is open-source, no Google apps. Sheet and device match.
Unknown apps or accounts are presentPitfall
ConsequenceReport it. A device genuinely prepared by onsecret adds nothing to the system and installs only the announced kit. Any discrepancy should be verified via support before use.
What this drill proves
A trustworthy device is verified: re-locked bootloader, hardware attestation via Auditor, an open-source kit matching the sheet. This is the same principle as our anti-scam verification service — proof over promise.
- Attestation proves system integrity at the moment of the check, not the absence of any future threat.
- A boot screen that "looks right" proves nothing; only hardware attestation counts.
- This procedure verifies the device, not your usage: security then depends on your configuration.
Sources: GrapheneOS — Auditor / attestation