Skip to content
این صفحه به انگلیسی نمایش داده می‌شود.ترجمهٔ فارسی آماده‌سازی شده اما هنوز نوشته نشده است. هیچ‌چیز در اینجا ترجمهٔ ماشینی نیست، زیرا یک ادعای امنیتی که بد ترجمه شود، ادعایی نادرست است.خواندن به انگلیسی

Questions, answered plainly

The thirteen questions we are asked most. Each answer names the mechanism that decides it, or the limit that bounds it. Every "not yet" is a plain "not yet".

Why no browser?

A browser is the largest untrusted-input parser a phone runs. It is also the classic first stage of a targeted infection: a link, an engine, a chain. GuardTalkOS ships none live. The component is not built into the image, so there is no engine to reach, and no browser bug to race a patch against.

There would also be nowhere for it to go. The only network peer this device is configured to reach is the GuardTalk Gateway, and no cellular data path is offered.

Limit: removing the browser removes one parser, not all of them. The Messenger still renders media that arrives from outside, and that surface is real. Where this ends.

Can I install apps?

No. There is no app store, no sideload path and no USB debugging route onto the device live. The app set is what ships in the image: the launcher, the Messenger and the Gateway pairing tools.

That is the trade. An installable app set is a delivery channel, and a delivery channel is what commercial spyware needs most. Changing the app set means changing the image and signing it with a verified-boot key you hold. That path is documented on build it yourself.

It is not a button on the phone.

Limit: a small app set is a statement about how many apps can be attacked, not a guarantee about the ones that remain.

Does it have cellular?

No cellular data path is offered. That is deliberate: there is nothing to harden around.

The Wi-Fi link to the Gateway is the only network path in the build live. Traffic leaves the system through the device you own and hold, or it does not leave.

Limit: the modem hardware is still in the phone. What this operating system can state is that it offers no data path over it. Baseband and firmware behaviour sits below the OS and is named as out of scope in the threat model.

Is it anonymous?

No operating system makes you anonymous. Traffic leaves the system through Tor, which hides network location from most observers, not from a global observer correlating both ends. See the threat model.

Anonymity is a property of a whole practice — the accounts you use, the people you contact, the times you are active. An operating system can support that practice or undermine it. This one supports it by removing the direct internet paths that leak identity without asking you first.

Why not just run GrapheneOS?

If you need a fully functional smartphone, you should. GrapheneOS is the stronger choice for general-purpose use, standalone operation, maturity and patch cadence. GuardTalkOS is for a narrower adversary model: when zero-click delivery must have no channel, and exfiltration must cross a checkpoint you hold.

The longer answer is on the comparison page. That page is pending counsel review, so today it carries the approved positioning and nothing more.

Is it GrapheneOS?

No. It is a separate build, made by a separate team, for a narrower job.

We comply with the upstream naming and licence obligations, and the notices are published on licences. No GrapheneOS mark or screenshot appears anywhere on this site.

Can I run it without the Gateway?

You can, but you shouldn't. The Gateway is what inspects traffic, blocks beacons and drops the link if a tunnel fails. Without it, GuardTalkOS is a stripped ROM with a Wi-Fi radio and no protection at the network boundary.

This is why the site never sells the operating system on its own. The headline protections here are properties of the system. Running the endpoint without the checkpoint keeps the inconvenience and removes the point of it.

Which devices?

The Pixel 8 and Pixel 9 families are the target devices. We target them for the reason the upstream project gives: hardware-backed verified boot, isolated radios, and long firmware support lifetimes. Other hardware does not ship them.

This site writes target, never supported, until on-device validation lifts and a cadence exists // confirm §19.4device posture and codename matrix. The codenames in the build today, and the ones still to be confirmed, are listed on devices.

Limit: a target device is a device we build for. It is not a promise of a support lifetime, and no such promise is made on this site yet.

How often is it updated?

No cadence is committed: // confirm §19.4update cadence — do not invent.

On-device validation is under active bisect, and a cadence promised before that lifts would be a number rather than a commitment. The channel model is alpha today; beta and stable are planned channel names. What is live, what is being proven and what is planned is dated on the status board.

Is it audited?

Not yet. We don't claim audits we don't hold. The build is alpha and on-device validation is in progress. See the status board.

We hold no certification either, and none is implied anywhere on this site. When an independent review does happen, this page will link the report and its scope. A review whose scope is not published tells you nothing, and we would rather publish nothing than that.

What does it not protect against?

The full list, with the mechanism beside each limit, is the threat model. The short version:

  • Firmware, baseband and Wi-Fi-chipset implants. They sit below the operating system and outside its reach.
  • The surfaces that remain. The Wi-Fi stack, the Messenger and the launcher parse untrusted input, and a well-resourced 0-day can still reach them.
  • A compromised device at the other end of your conversation.
  • Global traffic correlation against Tor, by an observer who can watch both ends.
  • Physical coercion beyond the system's duress behaviour, which is described only in the family's wording.
  • Human error, which no operating system removes.
  • Running GuardTalkOS without the Gateway.

Maturity is a limit too, and it belongs on this list. This build is alpha, it has no public security research track record, and nothing here has been proven by time.

Why Tor-only downloads?

So the artefact you install can't be intercepted or swapped on the clearnet, and so distribution doesn't depend on a vendor CDN. Hashes and the signing-key fingerprint are published here; verify before you install.

Tor-only distribution is planned, so it is described as a target, not as a shipped property. What is already true is simpler: this site carries no download control of any kind. Clearnet gives you the hashes, the fingerprint and the method on verify.

Can GuardTalk read my data or unlock my phone?

No. You hold the verified-boot key; we hold no keys and ship no backdoor. The source is there so you don't have to take that on faith.

The mechanism behind that answer is the trust anchor: a custom AVB key (avb_pkmd.bin) that you generate and keep alpha. Your device accepts an image only if a key you chose to trust signed it. You can check the key it booted with.

Limit: verified boot attests the OS image, not the bootloader, radio or baseband firmware beneath it. A key you hold protects you from us. It does not protect you from someone who owns the hardware underneath.

Read the threat model, then decide.

An FAQ answers the questions people ask. The threat model answers the one that decides it — who this protects you from, and where that protection stops.