Pixel — vue 360°

glisser pour tourner

Capabilities

Boot & firmware

Verified bootstock (upstream)

The bootloader is re-locked under GrapheneOS keys: the device refuses to boot a tampered system. Provided by GrapheneOS + Titan M2, re-locked at the workshop.

Source

Secure elementstock (upstream)

Titan

Dedicated chip that stores keys and throttles PIN attempts (Titan M2 on Pixel, dTPM on some ThinkPads).

Source

Guaranteed updatesstock (upstream)

≥ 2031

Security-update window documented by the manufacturer. Shown only when it is guaranteed.

Source

System & data

No Google by defaultstock (upstream)

No Google service required. Play Services, if you want them, run sandboxed without privileges.

Source

Hardware memory taggingstock (upstream)

ARM MTE + hardened_malloc catch many memory-corruption bugs as they happen (Tensor G3/G4/G5).

Source

Encrypted at reststock (upstream)

FBE

Data is encrypted while the device is locked (FBE on phones, LUKS applied at the workshop on laptops).

Source

Per-app sensors/networkstock (upstream)

GrapheneOS toggles network, sensors, storage and contacts per app (Network/Sensors toggles, Storage/Contact Scopes).

Source

Theft & coercion

Duress PIN → wipeonsecret workshop

A duress PIN triggers an irreversible wipe. A last resort: it destroys, it does not protect you from being forced to enter the real code. GrapheneOS function, armed with you at handover.

Source

Auto-reboot (18 h)onsecret workshop

18 h

The device reboots after inactivity and returns to the 'before first unlock' state, far more resistant to extraction. Interval set at the workshop.

Source

Locked = charge-only USBonsecret workshop

When the screen is locked, the USB port carries power only — data is cut off.

Source

Workshop & support

Installed, verified at the workshoponsecret workshop

We flash, verify integrity and re-lock every unit. For USB keys we provide the signature-verification procedure — don't take our word for it.

Provisioned, ready to useonsecret workshop

Baseline apps installed, permissions and battery exemptions set: RustDesk, FMD, ntfy, F-Droid, SimpleX, Aegis, OpenKeychain, Organic Maps (+ built-in Vanadium).

Support — attended onlyonsecret workshop

Our RustDesk fork (server and key baked in), self-hosted relay. Always initiated by you: you open the app and read us the ID + a one-time password. No MDM, no permanent access, revocable.

Locate / wipe remotelyonsecret workshop

Self-hosted FMD (fmd.onsecret.net), no Google. Best-effort: a device that is off or offline cannot be wiped immediately.

Best-effort: no effect if the device is offline.

Push without Googleonsecret workshop

ntfy UnifiedPush (push.onsecret.net, deny-all), one credential and token per device — no FCM dependency.

Encrypted support channelonsecret workshop

SimpleX preconfigured: our SMP server added, a 1-1 with the support bot and the clients group wired up in advance.

Faraday packoption

+35 €

A Faraday sleeve added as an option — the same one we sell on its own for €79.

stock (upstream) onsecret workshop option absent

What this does not protect against

  • Does not protect the cellular baseband: proprietary, unauditable modem firmware; cellular leaks location and metadata to the carrier.
  • Does not resist advanced physical extraction of a device seized powered-on and unlocked.
  • Does not make you anonymous: IMEI, SIM, IP and accounts remain identifying — use Tor/VPN separately.
  • Does not protect against coercion: anyone who can compel an unlock gains access.

What the workshop does to this device

Our pipeline

  1. GrapheneOS reflash, bootloader re-locked under GrapheneOS keys, integrity verified.
  2. Baseline apps installed, permissions and battery exemptions set (RustDesk, FMD, ntfy, F-Droid, SimpleX, Aegis, OpenKeychain, Organic Maps; built-in Vanadium).
  3. USB protection: data cut off while the device is locked.
  4. Tokens minted per device on our infrastructure (deny-all notifications, locate/wipe enrolment, pinned relay key).
  5. RustDesk preconfigured — our build, server and key baked in: zero setup for you.
  6. Guided hardening with you at handover: 6+ word diceware passphrase, duress PIN, auto-reboot (18 h), SimpleX channel wired to support.
  7. Customer sheet handed over; encrypted inventory kept at the workshop.

What you can ask us

  • Support session: you open RustDesk and read us the ID + one-time password. Never the other way round.
  • Emergency locate / wipe: on your authenticated request, via our self-hosted FMD (best-effort).
  • Questions: preconfigured SimpleX, or Signal / PGP / anonymous ticket.
  • Revocation: anytime — we remove the peer and the tokens.
  • Re-provisioning after a factory reset.

What we do not do

  • No access without you: no Device-Owner, no MDM, no persistent agent. The client code is our fork, published.
  • We see neither your browsing, nor your messages, nor your traffic. The relay is self-hosted and end-to-end encrypted.
  • Remote wipe is not a guarantee: a device seized and taken offline is protected only by its encryption and your code.
  • We cannot recover a lost passphrase. That is by design.

Choose within the range

Pixel 8a — GrapheneOS« Compact & sober »€833 Monero€1,190 cardPixel 9 Pro — GrapheneOSHERE« The balanced one »€1,253 Monero€1,790 cardPixel 10 Pro — GrapheneOS« The newest »€1,575 Monero€2,250 card
Differences
Secure element Titan M2 Titan Titan M2 + StrongBox
Guaranteed updates ≥ May 2031 ≥ 2031 ≥ 2032

Same protections across the whole range. You choose the hardware and the update window, not the level of security.

Tight budget or small size → 8a. Camera, screen and RAM → 9 Pro. Longest update window → 10 Pro.

What it is

What this is

A refurbished Pixel 9 Pro, OS replaced with GrapheneOS, bootloader re-locked under your keys (verified boot active). Recent Pixels expose hardware memory tagging (MTE), on by default to make whole classes of memory-corruption exploits fail fast.

Honest positioning

GrapheneOS raises the cost of compromising the OS; it does not change the radio. The baseband, SIM and IMEI still identify you to the carrier.

Usage guide

Verify integrity

On arrival: locked bootloader (yellow screen + key fingerprint, compare to the install page) and hardware attestation via Auditor.

Hardening

  • USB-C port control: data off while locked.
  • Auto-reboot to return to before-first-unlock.
  • Storage/Contact Scopes instead of blanket permissions.
  • Network: route via Orbot/Tor.
  • Duress PIN (wipe): understand it and your local law first.

Specifications

DeviceGoogle Pixel 9 Pro
Storage256 GB (fixed, non-expandable)
RAM16 GB LPDDR5X
SoCGoogle Tensor G4 + Titan secure element
OSGrapheneOS, bootloader re-locked with GrapheneOS keys
Hardware securityARM MTE, hardened_malloc, IOMMU-isolated baseband
UpdatesGoogle firmware guaranteed through 2031

After purchase

Your device arrives already prepared — this guide is for redoing everything yourself or checking our work.

Open the full guide

Vérifier l'intégrité

À la réception : bootloader verrouillé (écran jaune + empreinte de clé à comparer à la page d'installation) et attestation matérielle via Auditor.

Durcissement

  • Contrôle du port USB-C : données coupées quand verrouillé.
  • Redémarrage auto pour revenir à l'état avant-premier-déverrouillage.
  • Storage/Contact Scopes plutôt que permissions globales.
  • Réseau : routez via Orbot/Tor.
  • Code de contrainte (effacement) : à comprendre selon votre juridiction.

Verifiable sources

Support