Workshop transparency
How we prepare your device
For this audience, specificity is the proof. Here, step by step, is what actually happens between the moment we receive a device and the moment it reaches you — setting names included. Nothing is done behind your back.
Preparation, step by step
- 01
Sourcing & intake
We source a supported device, inspect it on arrival and record its condition. A questionable unit goes back; it does not enter preparation.
- 02
Flash the OS
We install GrapheneOS (phones) or the appropriate firmware/OS (coreboot/Heads, OpenWRT depending on the line), from the upstream project’s official images.
- 03
Re-lock the bootloader
On Pixels, the bootloader is re-locked to re-enable verified boot under GrapheneOS’s keys. This is the step many skip — it is what the protection depends on.
- 04
Baseline apps & permissions
We install baseline apps and pre-grant permissions so the device is usable out of the box without exposing more than necessary.
- 05
USB-C data protection
We enable USB-port data protection (the aapm_usb_data_protection setting): by default the port carries power, not data. Useful when travelling and at public charging points.
- 06
Offline maps
We preload offline maps (Western Europe + Mediterranean, ~30–45 GB) for navigation with no network request and no mapping account.
- 07
Guided hardening — with you
Together, we set up the options that only matter if you understand them: diceware-generated credentials, a duress PIN, auto-reboot after inactivity, useful battery exemptions.
- 08
Enrol on the support nodeoptional
Only if you take “care”: your device is associated with our self-hosted support node (RustDesk fork, relay and keys on our infrastructure). Every session is at your initiative, with a one-time password you read to us.
- 09
Device record & attestation
We create an online device record and a preparation attestation, so you can verify what was done — instead of taking our word for it.
What preparation does NOT do
- No persistent agent, no MDM, no backdoor — technically impossible on an unrooted device you control.
- No permanent access: without “care” there is no assistance link at all; with “care”, every session requires you to read out a one-time ID and password.
- We never see your traffic, your messages or your keys. Preparation prepares; it does not monitor.
- Preparation does not change the device’s physical limits (baseband/carrier radio, physical extraction by an adversary who has the device and the means).
To go further: