Skip to content
Cette page est affichée en anglais.La traduction française est prévue mais pas encore rédigée. Rien ici n’est traduit automatiquement, car une affirmation de sécurité mal traduite est une affirmation fausse.Lire en anglais

BRAND · ASSET PACK · IDENTITY RULES

The asset pack on the device, and the rules the mark is set by

GuardTalkOS ships a palette-locked asset pack rather than default artwork. This page states what is in it, how the mark may be used, and what is never done with it.

What ships on the device.

The build carries its own visual layer instead of the base platform's default artwork. That layer is a fixed asset pack, not a theme engine and not a customisation surface.

On-device brand system

live

Boot animation, wallpapers, launcher and app icons ship as a palette-locked asset pack.

Limit · Cosmetic. It changes nothing about the threat model, and is listed last for that reason.

The pack contains four things:

  • The boot animation — the mark, monotone, on #0A0B0C obsidian, played once at boot.
  • Wallpapers — obsidian grounds carrying the chevron field, at the display densities the target devices use.
  • The launcher — a fixed grid on the same ground, with mono labels.
  • App icons — one drawn set for the applications the image actually ships.

Every asset is locked to the palette. The grounds are obsidian #0A0B0C and carbon #121417, the text is paper #F6F7F5, and signal green #C3FF61 marks only what is live. No asset introduces a colour outside that set, and none is generated on the device.

Be exact about what this is worth. Seeing GuardTalkOS artwork tells you the image booted with its asset pack. It is not verification, and an attacker who controlled the image would control the artwork too.

Verification is the verified-boot key hash shown at boot, and the release digest you check for yourself. Verify a release →

Nothing in the pack changes the threat model. It is listed here, and last on the feature catalogue, for that reason. The hardening catalogue →

The mark, and the rules that hold it.

The mark is three ascending chevrons locked into a hexagonal shield, monotone by rule, so it holds in etching, embroidery and one-colour print. The wordmark is drawn artwork: never re-typeset, re-spaced or substituted with a system font, including Space Grotesk. Clear space is one chevron height (X) on every side, and nothing enters that zone: no type, no rules, no other logo. Signal green is rationed to roughly a tenth of any surface, never tinted, never a wash and never decorative.

Sizes follow from the same rule. The full lockup holds down to 132px wide, and below that the mark is used alone. The mark holds to 24px, and a simplified single-chevron master takes over at 16px.

Colour has a job, not a mood.

Four accents exist on this surface, and each carries exactly one meaning. That is what lets a reader trust a colour at a glance instead of decoding it.

  • Signal green #C3FF61 — live, enforced, yours. A state that holds today, a primary action, a verified result.
  • Caution #FFB020 — alpha, planned, pending. It is the most common accent here because the build is alpha, and it is never tidied into green.
  • Tripwire #FF5247 — a surface removed or a delivery path blocked, in the diagrams only. It is never a call to action and never a headline.
  • Anon #5BC8FF — Tor transport and .onion artefacts, and nothing else.

State is never carried by colour alone. Every status label prints its word beside the colour: live, alpha, planned, pending. That survives one-colour print, a monochrome display, and a reader who does not see the hue. Where every state comes from →

The OS lockup.

This surface signs off with the family lockup plus a mono OS tag. The tag is type, not artwork, and it does not alter the wordmark it sits beside.

// confirm §19.9OS lockup construction and the asset pack's approved web uses

Until that is confirmed, this site renders the family lockup and reserves the space the tag will occupy. It does not improvise a lockup and publish it as if it were approved.

What is never done with these marks.

  • Not stretched, squashed, rotated or tilted.
  • Not recoloured off-palette, and the green is never tinted or screened back.
  • Not placed on a muddy ground; obsidian and white are the only safe grounds for the green mark.
  • Not given shadows, glows, gradients or effects, on the mark or the lockup.
  • Not re-typeset, in any weight of any typeface, for any reason.

One rule matters more than the rest on this surface. No upstream mark is ever used to represent GuardTalkOS. No GrapheneOS logo appears as a badge for this build, and no Android robot or Tor onion does either. That holds in assets, diagrams, slides and social images alike.

The reason is not caution about trademarks alone. Borrowing an upstream mark implies an endorsement that does not exist, and it turns credit into a claim. Upstream is credited in words and links, on every page where its work is present. Lineage and attribution → · Licences →

Where the assets and the brand book live.

The full identity system is the GuardTalk brand book: mark anatomy, lockups, clear space, colour discipline, typography, motif and misuse. This page is a summary of the parts that govern this surface. The GuardTalk brand book

The on-device pack ships inside the image. It is not offered as a download here, and this site publishes no download control of any kind. Why images are to go over Tor →

Press and partner requests for the mark go through the family contact on the parent site, which is also where the usage terms sit. Trademarks and names →

The identity is the smallest thing here.

An asset pack changes nothing about what the build removes. The catalogue does.