How we prepare your device
We describe exactly what happens to your device, and how you can check it without having to trust us.
Sourcing
New devices from official retail channels. We record the invoice reference and IMEI number per order.
What we do
- 01The box is opened — it has to be, to install an operating system.
- 02The device is booted.
- 03GrapheneOS is installed.
- 04The bootloader is re-locked.
- 05The device is factory reset and powered off.
We never claim the device arrives in an unopened, factory-sealed Google box. That is impossible once an operating system is installed.
How you verify it yourself
- 01Install the GrapheneOS Auditor app on first boot.
- 02Or use the GrapheneOS remote attestation service.
- 03This confirms the device runs an unmodified, official GrapheneOS build with a locked bootloader.
This check requires no trust in the seller: verification is cryptographic, between your device and GrapheneOS.
Sealing
We close the packaging with a numbered tamper-evident seal. The seal number is included in your shipping email.
What we never do
- No accounts created.
- No keys or seed phrases generated or stored.
- No custom builds.
- No extra certificates installed.
This check requires no trust in the seller: verification is cryptographic, between your device and GrapheneOS.