What each part protects — and where it stops
Every row below states a capability and the limit that goes with it. A capability written without its limit is a marketing claim, not a security statement.
Handset platform
GrapheneOS on a Google Pixel, with verified boot and the bootloader relocked after provisioning.
LimitGrapheneOS and Pixel are third-party names; no endorsement or partnership is implied. The hardware security chip is present on the Pixel generations that ship with it, and platform protections depend on the exact model and build — we state results only for models we have actually measured.
A duress PIN destroys the GhostWire vault when it is entered at the lock screen.
LimitIt destroys the GhostWire vault. It is not a factory reset of the whole phone, and it cannot recover anything afterwards.
USB auto-wipe can be armed by the owner so a data connection triggers destruction of the vault.
LimitRequesting USB auto-wipe ARMS it. The trigger only becomes active once the USB-C port mode is changed manually on the handset — arming alone does not make it live. This is an operator step, and it is stated here because discovering it later is how people lose data they meant to keep.
GrapheneOS system updates and the GrapheneOS Apps store keep working on a GhostWire handset.
LimitWe do not block platform updates to make a GhostWire feature pass. Updates are the customer's to apply.
Per model
Two columns that must not be read as one. The security chip is Google's published specification for that model. The cellular-security column is what GhostWire itself has measured on that model, with the date; a model that has not been measured says so.
| Model | Security chip — Google's published specification, checked 21 September 2026 | Native cellular-security controls — GhostWire measurement |
|---|---|---|
| Pixel 7 Pro | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 7a | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 8 | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 8 Pro | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 8a | Titan M2 | Measured 19 September 2026: the modem answers REQUEST_NOT_SUPPORTED to all three controls, so no app or OS build can switch them on with this modem firmware |
| Pixel 9 | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 9a | Titan M2 | Not measured yet. No claim is made for this model. |
| Pixel 10a | Titan M2 | Not measured yet. No claim is made for this model. |
Measurements are per model, build and modem firmware. The method and every capture are published in the GhostWire repository (cellular capability survey and matrix).
Messaging and calls
Pairing uses a hybrid key exchange: X25519 together with ML-KEM-768, mixed into the session root. An attacker must break both the classical and the post-quantum primitive.
LimitBoth handsets must be on a current build to pair. There is no fallback to a classical-only handshake.
On v2 sessions, a fresh ML-KEM-768 encapsulation every turn — post-quantum forward secrecy for message content.
LimitA v1 session holds one static post-quantum secret and has no ratchet, so it resists harvest-now-decrypt-later but does not give that per-turn property. The two are genuinely different and we do not describe them as one. "GhostWire is post-quantum", unqualified, is not a claim we make.
Calls on a current pairing carry post-quantum-rooted frame encryption above DTLS-SRTP, so relayed call media is not protected by the transport alone.
LimitThose frame keys derive from the pairing-time root, not a fresh exchange per call, so compromise of that root exposes calls derived from it. A session migrated from an older pairing has no frame layer at all and is DTLS-SRTP only.
Identity on current pairings is hybrid: a classical signature alongside a post-quantum one.
LimitA session migrated from an older pairing still faces only classical authentication against an attacker active at handshake time.
The pairing ceremony shows a safety number that binds the post-quantum key, so a downgrade attempt makes the two handsets disagree.
LimitThe ceremony has to actually be performed. A pairing where both operators skip the comparison is not protected by it.
Dead drops use a fresh post-quantum encapsulation per drop.
LimitThis describes the post-quantum dead-drop mechanism, which is the one the app uses. An older classical dead-drop code path exists in the core library and is not used by the app.
Notifications on a locked handset are content-free: the phone learns that something is waiting, not what it says.
LimitThe fact that something arrived, and when, is still observable to whoever can see the network.
Key custody
Keys are generated and stay on the handsets. There is no escrow, no key-management service and no server-side copy. The relay routes ciphertext it cannot read.
LimitThis means nobody — including us — can recover a vault for a customer who loses their PIN. That is the trade, and it is not reversible after the fact.
The vault is encrypted at rest with a memory-hard key derivation over the vault PIN.
LimitA short, guessable PIN is still a short, guessable PIN. Key derivation raises the cost of an offline attack; it does not remove it.
Counter-surveillance suite
Shield reports what the handset's own radio interfaces let it observe, and says when it could not observe something.
LimitShield does NOT detect IMSI catchers and we do not claim it does. Confirming a fake base station needs privileged modem access that an ordinary Android application does not have.
Safe Room reports what the phone's own sensors can measure about a space.
LimitThis is not a professional RF bug sweep. Full detection requires dedicated sweep hardware, which the phone is not.
SCARAB and Privacy Audit inspect the device's own configuration, permissions and installed-app risk surface, offline.
LimitThey audit this handset. They cannot see what a network, a carrier or another device is doing.
Vehicle Scanner looks for the wireless signatures a phone can see near a vehicle.
LimitA tracker that is passive, wired, or outside the radio bands a phone receives will not appear. A clear result is not proof that a vehicle is clean.
Router and VPN (pilot)
The GhostWire router option carries a VPN with a kill switch and a Radio Watch observer that records what the router itself can see about its own connection.
LimitPILOT, not accepted product. Radio Watch observes the ROUTER's connection. It cannot see a handset's independent cellular signalling, and it cannot establish that no surveillance is present. Availability and supported firmware are stated at the point of sale, not assumed here.
Relay, TURN and metadata
Call signalling travels sealed to the relay: the relay never holds the key that would open it.
LimitSealed signalling does not hide that a connection happened.
Calls connect directly between handsets wherever the network allows.
LimitWhere a firewall forces relaying, the TURN provider can see that two addresses are connected and for how long — that is what a TURN server is. On every call, including direct ones, STUN additionally observes that an address gathered candidates at a given time. Neither sees what is said.
A handset collects messages from its own queue using a token the relay holds no key for.
LimitThat queue token is visible at the TLS edge. It is a stable mailbox pseudonym — a long-term identifier the relay can use to link one handset's activity across sessions. It is not a name, a number or an address book entry, and it is not nothing.
Curated applications
A curated repository offers a reviewed set of third-party applications, delivered with signature and source checks.
LimitAdmitted applications are reviewed, but they remain third-party software used at the customer's own risk. Review is not a warranty, and we do not control what an upstream project ships next.
Lifecycle: provisioning, support, updates, recovery, resale
Each unit is provisioned from a signed build, with its identity recorded, and receives signed mandatory over-the-air updates.
LimitAn update still has to be applied on the handset. We do not silently change a phone in someone's pocket.
Support attaches to a unit's recorded identity, so a new owner does not have to exchange codes manually.
LimitSupport sees the unit's service state. It does not see message content, contacts or keys, because those never leave the handset.
A unit can be transferred to a new owner through the reseller flow.
LimitTransfer is a deliberate operation. It is not automatic, and a previous owner must not retain control after it.
Boxed stock that has not been sold is deliberately offline.
LimitAn unsold boxed unit that has never checked in is inventory, not a failed or missing device, and we do not report it as one.
Independent audit status
GhostWire is built on audited primitives. The whole product has not yet had an independent whole-product audit, and we do not claim one.
Report a security issue
Send findings to info@pharoahtechnology.co.uk. We will confirm receipt. Please do not test against handsets or infrastructure you do not own.
What GhostWire resists, and what it does not
GrapheneOS, Pixel and third-party product names are the marks of their owners; no endorsement or partnership is implied.