Threat model

What GhostWire resists, and what it does not

A security product is defined as much by the attacks it does not stop. This page states both, so a buyer can decide whether the boundary fits their situation.

Last reviewed: 21 September 2026

In scope — what GhostWire is designed to resist

A network observer, including the operator of the network you are on.

LimitContent is end-to-end encrypted and the relay routes ciphertext it cannot read.

A "harvest now, decrypt later" adversary recording traffic today to break it with a future quantum computer.

LimitThe hybrid handshake means both the classical and the post-quantum primitive must fall. Session-generation caveats above still apply.

Someone who takes the handset.

LimitVault encryption at rest, a duress PIN that destroys the vault, and optional USB auto-wipe once the port mode is set.

A compromised or hostile app store.

LimitCurated distribution with signature and source checks, on a platform that verifies boot.

Out of scope — what it does not defend against

An adversary who already controls the handset you are holding.

LimitMalware with the right privileges, or physical access with the vault unlocked, defeats an encrypted messenger. No messenger fixes this.

The person you chose to talk to.

LimitNothing stops a recipient screenshotting, recording, repeating or handing over the conversation.

Coercion of a person.

LimitA duress PIN helps against a device search. It does not help against someone compelling you to unlock normally.

Traffic analysis and the existence of a conversation.

LimitEncryption hides content. It does not hide that a handset is connected, when, or from which address. See the relay and TURN rows above.

Anything on the cellular layer that the handset's own radio does not expose.

LimitConfirming a fake base station needs privileged modem access an ordinary application does not have. We do not claim IMSI-catcher detection.

Losing your own PIN.

LimitThere is no escrow and no recovery. This is deliberate and it is not reversible.

Claims we deliberately do not make

  • Absolute security. No GhostWire page says the product cannot be broken, intercepted or traced. Such a claim would itself be a vulnerability, because it invites a buyer to behave as if the limits above did not exist.
  • "GhostWire is post-quantum" without qualification, while any v1 session exists.
  • IMSI-catcher or fake-base-station detection.
  • A professional RF bug sweep from phone sensors alone.
  • An independent whole-product security audit. It has not happened yet.
  • Any capability for evading law enforcement. GhostWire is a privacy product for lawful use.

Independent audit status

GhostWire is built on audited primitives. The whole product has not yet had an independent whole-product audit, and we do not claim one.

Report a security issue

Send findings to info@pharoahtechnology.co.uk. We will confirm receipt. Please do not test against handsets or infrastructure you do not own.

What each part protects — and where it stops

GrapheneOS, Pixel and third-party product names are the marks of their owners; no endorsement or partnership is implied.