Workshop transparency

How we prepare your device

For this audience, specificity is the proof. Here, step by step, is what actually happens between the moment we receive a device and the moment it reaches you — setting names included. Nothing is done behind your back.

Preparation, step by step

  1. 01

    Sourcing & intake

    We source a supported device, inspect it on arrival and record its condition. A questionable unit goes back; it does not enter preparation.

  2. 02

    Flash the OS

    We install GrapheneOS (phones) or the appropriate firmware/OS (coreboot/Heads, OpenWRT depending on the line), from the upstream project’s official images.

  3. 03

    Re-lock the bootloader

    On Pixels, the bootloader is re-locked to re-enable verified boot under GrapheneOS’s keys. This is the step many skip — it is what the protection depends on.

  4. 04

    Baseline apps & permissions

    We install baseline apps and pre-grant permissions so the device is usable out of the box without exposing more than necessary.

  5. 05

    USB-C data protection

    We enable USB-port data protection (the aapm_usb_data_protection setting): by default the port carries power, not data. Useful when travelling and at public charging points.

  6. 06

    Offline maps

    We preload offline maps (Western Europe + Mediterranean, ~30–45 GB) for navigation with no network request and no mapping account.

  7. 07

    Guided hardening — with you

    Together, we set up the options that only matter if you understand them: diceware-generated credentials, a duress PIN, auto-reboot after inactivity, useful battery exemptions.

  8. 08

    Enrol on the support nodeoptional

    Only if you take “care”: your device is associated with our self-hosted support node (RustDesk fork, relay and keys on our infrastructure). Every session is at your initiative, with a one-time password you read to us.

  9. 09

    Device record & attestation

    We create an online device record and a preparation attestation, so you can verify what was done — instead of taking our word for it.

What preparation does NOT do

  • No persistent agent, no MDM, no backdoor — technically impossible on an unrooted device you control.
  • No permanent access: without “care” there is no assistance link at all; with “care”, every session requires you to read out a one-time ID and password.
  • We never see your traffic, your messages or your keys. Preparation prepares; it does not monitor.
  • Preparation does not change the device’s physical limits (baseband/carrier radio, physical extraction by an adversary who has the device and the means).

To go further:

Support