Skip to content
این صفحه به انگلیسی نمایش داده می‌شود.ترجمهٔ فارسی آماده‌سازی شده اما هنوز نوشته نشده است. هیچ‌چیز در اینجا ترجمهٔ ماشینی نیست، زیرا یک ادعای امنیتی که بد ترجمه شود، ادعایی نادرست است.خواندن به انگلیسی

ABOUT · LINEAGE · ATTRIBUTION

The quiet endpoint of a system built for the hunted.

GuardTalkOS closes the gap a secure operating system alone cannot: the network. It removes it from the phone and hands it to a device you hold.

Why this operating system exists.

A commercial spyware industry sells interception and implant suites to state customers. Those products are aimed at named people, not at crowds. The people they are aimed at are journalists, human-rights defenders, lawyers, opposition figures and the organisations around them.

That targeting is documented, not speculated. Forensic research labs and news organisations have published case after case involving the Pegasus and Predator families of tooling. The pattern in those cases is consistent, and it is the pattern this build was designed against.

Delivery is a network event. A link opens a browser. A crafted message reaches a media parser before the owner has touched the screen. An implant that lands then beacons out to a server it was told to call.

A hardened phone with a full internet path still carries every one of those surfaces. It carries them well — modern hardening makes them expensive to exploit — but it carries them. GuardTalkOS takes the other route and removes the path instead of hardening it. How that works →

liveWi-Fi on this build reaches one peer, the GuardTalk Gateway, and no cellular data path is offered. where this ends →

Lineage and attribution.

This build stands on work its authors did not do, and the credit is not a courtesy. It is the difference between a project you can trace and a rebadged image you cannot.

  • The Android Open Source Project — the base this build starts from, under the Apache License 2.0. source.android.com
  • GrapheneOS — the hardened-Android practice this build follows, and the project we send people to when a full phone is what they need. grapheneos.org
  • The Tor Project — the transport the system's traffic leaves through, and the way releases are to be distributed (planned — see Releases). torproject.org

We comply with each project's licence and naming rules, and we publish those obligations rather than assert them. Licences and attributions →

None of these projects endorses GuardTalk. GrapheneOS is separate and independent, and has no relationship with this product. No upstream mark, logo or screenshot appears anywhere on this site, and none ever will.

Where a protection is inherited from upstream, this site describes it as inherited. It is never presented as authored here. A mechanism we did not write is credited to the people who wrote it, on the page where the mechanism is claimed.

Who this is for, and who it is not for.

This build is for people commercial spyware actually hunts. Journalists working with sources whose exposure is a danger. Human-rights defenders and the lawyers who represent them. Field staff at organisations that have already lost a device to an implant.

What those readers have in common is an adversary model, not a job title. They need zero-click delivery to fail because the channel is absent, not because a mitigation held. They need exfiltration to be a visible event at a boundary they own, rather than a silent one.

This build is not for anyone who needs an ordinary smartphone. There is no browser, no app store, no sideload path, no Bluetooth, no NFC and no location service. There is no cellular data path, so the phone cannot work away from its Gateway.

If that is you, run GrapheneOS. It is the better choice for that job, and we say so on the home page, in the footer and here. The honest comparison →

The system this OS belongs to.

GuardTalkOS is one component of five, separated by one air gap. It is never sold alone, and it is not complete alone.

  1. GuardTalkOS — the endpoint. A phone with no direct internet path.
  2. The GuardTalk Gateway — the hardware appliance you own and hold. It is the phone's only network peer.
  3. The Messenger — the application the conversation runs in.
  4. Rotating infrastructure — the reachable services the system's traffic crosses, rotated rather than fixed.
  5. The Tor admin console — administration, reachable over Tor only.

Each of those four is described on the parent site. This page says nothing about them that the parent surface does not. The Gateway · The system threat model

The headline protections on this site are properties of the system, not of the image. Without the Gateway, GuardTalkOS is a stripped ROM with a Wi-Fi radio and no checkpoint. We would rather tell you that here than let you discover it in the field.

Open source, and what it obliges.

The OS sources and this site's sources are published, and the build path is documented rather than described. Build it yourself →

Published source is not proof on its own. It is the thing that makes proof possible, and the proofs here are at different stages.

Published hashes per release are live. A user-held verified-boot key is alpha. Reproducible builds are planned, and stay labelled that way until a third party can rebuild an image and reach the same digest.

We hold no audit and claim no certification. On-device validation is under validation, under active bisect, and the whole build is alpha. What that means, dated →

Every state on this site is read from one file, content/status.json. Code never promotes a state. A person does, in that file, with a changelog entry.

How this site and this architecture were built.

This site and the product architecture behind it were built with an AI agentic engine, the AEGIS delivery engine, working from a written brief. That covers the site's structure, its component library and the first draft of this prose.

A person directed that work, reviewed every claim on every page, and holds responsibility for what is published. We record it because leaving it out would be a small dishonesty, on a site whose whole argument is that you should check things.

It is a working method rather than a feature. It appears nowhere else on this site, and it is not a reason to prefer this build.

It changes nothing about the trust model. The source is published, the hashes are published, and the verified-boot key is one you generate and hold. Nothing here asks you to trust the method that produced the page.

The site itself runs no model and calls none. It has no analytics, no cookies and no third-party origin, so reading this page sends nothing anywhere. How that is verifiable →

Where to check us.

Read the limits before the features: the threat model states what this build does not protect against, including running it without its Gateway. Read the threat model →

Then check the rest for yourself. The status board is dated and shows what is live, what is under validation and what is planned. The verification page teaches the AVB key and hash workflow. The licences page lists what we inherited and from whom.

Status → · Verify → · Licences → · Warrant canary →

Read the limits before the promises.

The threat model is the page this one is accountable to. It states what the operating system does not do, and where the Gateway takes over.