The short answer
In September 2026 every check we could run on GuardDo Pixel gave the same result: its security claims come with no evidence a customer can verify.
- Its test results are not published.
- The source code address it gives did not answer.
- The code it has published is GrapheneOS code with the name changed.
- Its firmware is signed with its own keys, so the customer cannot confirm what operating system actually runs on the phone.
A claim that cannot be checked has to be taken on trust. Owners of EncroChat, Sky ECC and ANOM phones took the same kind of promise on trust.
What EncroChat, Sky ECC and ANOM showed
- EncroChat sold its phones “at a cost of around EUR 1 000 each”, “presented … as guaranteeing perfect anonymity”. In spring 2020 adversaries put “a technical device in place to go beyond the encryption technique and have access to the users’ correspondence”, and read the traffic until 13 June 2020, when the company discovered it.
- Sky ECC was where many went next: “Many users of EncroChat changed over to the popular Sky ECC platform, after EncroChat was unveiled in 2020.” From mid-February 2021, adversaries read “the information flow of approximately 70 000 users of Sky ECC”; it was made public on 9 March 2021.
- ANOM was run by an adversary from its first day in 2018: every message its users sent was read for three years before it was made public in June 2021.
All three were closed-source “secure phones” sold on a promise. Device owners and security researchers could not read the code, check the keys, or see the servers. The lesson is not about who bought these devices: “trust us” is not a security feature, and a buyer should ask for what can be verified.
Eight checks for any secure phone
| Check | What to ask for | Source |
|---|---|---|
| 1. Source code | The code for the features you are paying for, public, with instructions to build it | NIST SP 800-218, practice PS.2 |
| 2. Release integrity | Published hashes of the release files; NIST’s example: “Post cryptographic hashes for release files on a well-secured website.” | NIST SP 800-218, PS.2.1 |
| 3. Independent evidence | Tests by someone other than the seller, with the method and results published | Google’s review guidance |
| 4. Owner verification | A way to confirm on the phone itself which system it runs: the verified boot key hash and hardware attestation | Android Verified Boot; Android key attestation; attestation.app |
| 5. Update history | Dated public releases; “Provide timely security updates, patches and notifications to customers.” | UK Software Security Code of Practice, 3.5 |
| 6. Security contact | A published way to report vulnerabilities | CISA and FBI, Secure by Demand Guide |
| 7. Identifiable company | Who is legally responsible | Company registries |
| 8. Visible customer evidence | Reviews you can read, not only a rating | Google’s review guidance |
The checks applied to GuardDo Pixel, September 2026
| Check | What we found |
|---|---|
| 1. Source code | GuardDo’s published address for its “open” code, git.guarddo.net/opensource, answered with an error (HTTP 502) on 27 September 2026 at 14:11, 14:20 and 15:00. Its GitLab group holds 27 repositories, all created on 29 July 2026: 14 contain only a template README and 12 a single commit named “init”. None contains a build manifest or build instructions. The code for the hidden space and the destruction functions is not among them. The one file we compared, GosPackageState.java, is GrapheneOS’s file with one word changed: “GrapheneOS-specific” became “SecureOS-specific”. GuardDo’s website does not mention GrapheneOS. |
| 2. Release integrity | Its build server (jenkins.guarddo.net) is public. It shows one job and one kept build (#1472, 2 September 2026) and offers no files to download. Its log names GrapheneOS components (hardened_malloc), a renamed GrapheneOS package (app.guarddo.gmscompat), CalyxOS’s microG files and LineageOS’s setup wizard. No release hashes are published. |
| 3. Independent evidence | Its site says, in Russian, that the phone was “tested on Cellebrite UFED” and that “we test our devices in the most closed laboratories in the world”. It names no report, tool version, date or laboratory. The only reviews we found are two Habr posts by one author; the second says GuardDo’s developers asked for it. |
| 4. Owner verification | The firmware is signed with GuardDo’s own keys, and no key hash or attestation method is published, so the owner cannot confirm what the phone actually runs. |
| 5. Update history | No public changelog or update page. |
| 6. Security contact | No vulnerability disclosure policy found; guarddo.ru/.well-known/security.txt answers 403. |
| 7. Identifiable company | Yes: GUARDDO LLC, Moscow, tax number 7743462865, registered on 23 December 2024 (Russian tax registry). |
| 8. Visible customer evidence | Each phone page tells search engines “4.9 from 120 reviews” in its hidden data. No review is shown on the page. |
The same checks applied to a GrapheneOS Pixel
| Check | What we found |
|---|---|
| 1. Source code | Public at github.com/GrapheneOS, with build instructions at grapheneos.org/build. |
| 2. Release integrity | Official releases are signed, and the verified boot key hash of every supported model is published. |
| 3. Independent evidence | Ars Technica and Android Authority (both 30 October 2025) reported leaked Cellebrite documents listing locked Pixels on current GrapheneOS as inaccessible. |
| 4. Owner verification | The phone shows its key hash at start-up, to compare with the published one; the Auditor app confirms the system with the phone’s own hardware. |
| 5. Update history | A dated public changelog, with six releases in September 2026. |
| 6. Security contact | security@grapheneos.org, in a signed security.txt. |
| 7. Identifiable organisation | The GrapheneOS Foundation. |
| 8. Our phones | We install official GrapheneOS releases. Every phone we ship can be verified with checks 4 and 5 on the day it arrives. |
How to check the phone you receive from GemiGuard
- At start-up, a Pixel running any system other than Google’s shows a yellow notice with the system’s key hash. Compare it with the hash GrapheneOS publishes for your model.
- Pair the phone with the Auditor app on a second phone: any Android phone running Android 13 or later with a camera. The app confirms the system and the locked bootloader in the phone’s own hardware.
- Check updates in Settings → System → System update. The installed version should appear in the GrapheneOS release list.
What we supply
We supply the Pixel 9 and Pixel 10 families with GrapheneOS already installed, configured and updated. Current models are on our GrapheneOS page.
Related: Which phones run GrapheneOS · Which operating system a Pixel runs · The IMEI on a Google Pixel.
Buy a Pixel with GrapheneOS: models
Sources
EncroChat, Sky ECC and ANOM
- Eurojust, “Dismantling of an encrypted network sends shockwaves through organised crime groups across Europe”, 2 July 2020. — eurojust.europa.eu
- Eurojust, “New major interventions to block encrypted communications of criminal networks”, 10 March 2021. — eurojust.europa.eu
- Australian Federal Police, “AFP-led Operation Ironside smashes organised crime”, 8 June 2021. — afp.gov.au
The checks
- NIST SP 800-218, Secure Software Development Framework, practices PS.2 and PS.2.1. — nvlpubs.nist.gov
- Department for Science, Innovation and Technology and the National Cyber Security Centre, Software Security Code of Practice, updated 15 January 2026. — gov.uk
- CISA and FBI, Secure by Demand Guide, August 2024. — ic3.gov
- Google Search Central, “How to write reviews”. — developers.google.com
- Android Open Source Project, Verified Boot. — source.android.com
- Android Developers, key attestation. — developer.android.com
- Auditor app, about and tutorial. — attestation.app
GuardDo, read 27 September 2026
- GuardDo Pixel 10 product page. — guarddo.ru
- GuardDo, About page. — guarddo.ru
- GuardDo’s published source address. — git.guarddo.net
- GuardDo’s GitLab group. — gitlab.com
- GuardDo’s build server. — jenkins.guarddo.net
- Russian Federal Tax Service, company register, record for tax number 7743462865. — egrul.nalog.ru
- Habr, “GuardDo Pixel versus GrapheneOS” (in Russian), 8 April 2026. — habr.com
- Habr, “GuardDo Pixel: a review of a phone with a secret” (in Russian), 10 June 2026. — habr.com
GrapheneOS and the Cellebrite reports
- GrapheneOS source code. — github.com
- GrapheneOS, build instructions. — grapheneos.org
- GrapheneOS, web installer: verified boot key hashes. — grapheneos.org
- GrapheneOS, release list, read 27 September 2026. — grapheneos.org
- GrapheneOS, usage guide: system updates. — grapheneos.org
- GrapheneOS, security.txt. — grapheneos.org
- Ryan Whitwam, “Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking”, Ars Technica, 30 October 2025. — arstechnica.com
- Android Authority, “Leak reveals how secure Pixel phones are with GrapheneOS”, 30 October 2025. — androidauthority.com