Start typing to search

GemiGuard

Knowledge Base · GuardDo · EncroChat · Sky ECC · ANOM

GuardDo Pixel: how to verify a secure phone

GuardDo Pixel, a Google Pixel sold in Russia with its own closed-source firmware, makes security claims no buyer can verify. We ran the checks a buyer should run on any “secure phone” on GuardDo and on a properly configured GrapheneOS Pixel; each finding is dated and linked to its source.

Guide Published Updated 11 min read

A Google Pixel 10 Pro smartphone on a dark background, with a small magnifying-glass icon in the corner

The short answer

In September 2026 every check we could run on GuardDo Pixel gave the same result: its security claims come with no evidence a customer can verify.

  • Its test results are not published.
  • The source code address it gives did not answer.
  • The code it has published is GrapheneOS code with the name changed.
  • Its firmware is signed with its own keys, so the customer cannot confirm what operating system actually runs on the phone.

A claim that cannot be checked has to be taken on trust. Owners of EncroChat, Sky ECC and ANOM phones took the same kind of promise on trust.

What EncroChat, Sky ECC and ANOM showed

  • EncroChat sold its phones “at a cost of around EUR 1 000 each”, “presented … as guaranteeing perfect anonymity”. In spring 2020 adversaries put “a technical device in place to go beyond the encryption technique and have access to the users’ correspondence”, and read the traffic until 13 June 2020, when the company discovered it.
  • Sky ECC was where many went next: “Many users of EncroChat changed over to the popular Sky ECC platform, after EncroChat was unveiled in 2020.” From mid-February 2021, adversaries read “the information flow of approximately 70 000 users of Sky ECC”; it was made public on 9 March 2021.
  • ANOM was run by an adversary from its first day in 2018: every message its users sent was read for three years before it was made public in June 2021.

All three were closed-source “secure phones” sold on a promise. Device owners and security researchers could not read the code, check the keys, or see the servers. The lesson is not about who bought these devices: “trust us” is not a security feature, and a buyer should ask for what can be verified.

Eight checks for any secure phone

CheckWhat to ask forSource
1. Source codeThe code for the features you are paying for, public, with instructions to build itNIST SP 800-218, practice PS.2
2. Release integrityPublished hashes of the release files; NIST’s example: “Post cryptographic hashes for release files on a well-secured website.”NIST SP 800-218, PS.2.1
3. Independent evidenceTests by someone other than the seller, with the method and results publishedGoogle’s review guidance
4. Owner verificationA way to confirm on the phone itself which system it runs: the verified boot key hash and hardware attestationAndroid Verified Boot; Android key attestation; attestation.app
5. Update historyDated public releases; “Provide timely security updates, patches and notifications to customers.”UK Software Security Code of Practice, 3.5
6. Security contactA published way to report vulnerabilitiesCISA and FBI, Secure by Demand Guide
7. Identifiable companyWho is legally responsibleCompany registries
8. Visible customer evidenceReviews you can read, not only a ratingGoogle’s review guidance

The checks applied to GuardDo Pixel, September 2026

CheckWhat we found
1. Source codeGuardDo’s published address for its “open” code, git.guarddo.net/opensource, answered with an error (HTTP 502) on 27 September 2026 at 14:11, 14:20 and 15:00. Its GitLab group holds 27 repositories, all created on 29 July 2026: 14 contain only a template README and 12 a single commit named “init”. None contains a build manifest or build instructions. The code for the hidden space and the destruction functions is not among them. The one file we compared, GosPackageState.java, is GrapheneOS’s file with one word changed: “GrapheneOS-specific” became “SecureOS-specific”. GuardDo’s website does not mention GrapheneOS.
2. Release integrityIts build server (jenkins.guarddo.net) is public. It shows one job and one kept build (#1472, 2 September 2026) and offers no files to download. Its log names GrapheneOS components (hardened_malloc), a renamed GrapheneOS package (app.guarddo.gmscompat), CalyxOS’s microG files and LineageOS’s setup wizard. No release hashes are published.
3. Independent evidenceIts site says, in Russian, that the phone was “tested on Cellebrite UFED” and that “we test our devices in the most closed laboratories in the world”. It names no report, tool version, date or laboratory. The only reviews we found are two Habr posts by one author; the second says GuardDo’s developers asked for it.
4. Owner verificationThe firmware is signed with GuardDo’s own keys, and no key hash or attestation method is published, so the owner cannot confirm what the phone actually runs.
5. Update historyNo public changelog or update page.
6. Security contactNo vulnerability disclosure policy found; guarddo.ru/.well-known/security.txt answers 403.
7. Identifiable companyYes: GUARDDO LLC, Moscow, tax number 7743462865, registered on 23 December 2024 (Russian tax registry).
8. Visible customer evidenceEach phone page tells search engines “4.9 from 120 reviews” in its hidden data. No review is shown on the page.

The same checks applied to a GrapheneOS Pixel

CheckWhat we found
1. Source codePublic at github.com/GrapheneOS, with build instructions at grapheneos.org/build.
2. Release integrityOfficial releases are signed, and the verified boot key hash of every supported model is published.
3. Independent evidenceArs Technica and Android Authority (both 30 October 2025) reported leaked Cellebrite documents listing locked Pixels on current GrapheneOS as inaccessible.
4. Owner verificationThe phone shows its key hash at start-up, to compare with the published one; the Auditor app confirms the system with the phone’s own hardware.
5. Update historyA dated public changelog, with six releases in September 2026.
6. Security contactsecurity@grapheneos.org, in a signed security.txt.
7. Identifiable organisationThe GrapheneOS Foundation.
8. Our phonesWe install official GrapheneOS releases. Every phone we ship can be verified with checks 4 and 5 on the day it arrives.

How to check the phone you receive from GemiGuard

  1. At start-up, a Pixel running any system other than Google’s shows a yellow notice with the system’s key hash. Compare it with the hash GrapheneOS publishes for your model.
  2. Pair the phone with the Auditor app on a second phone: any Android phone running Android 13 or later with a camera. The app confirms the system and the locked bootloader in the phone’s own hardware.
  3. Check updates in Settings → System → System update. The installed version should appear in the GrapheneOS release list.

What we supply

We supply the Pixel 9 and Pixel 10 families with GrapheneOS already installed, configured and updated. Current models are on our GrapheneOS page.

Related: Which phones run GrapheneOS · Which operating system a Pixel runs · The IMEI on a Google Pixel.

Buy a Pixel with GrapheneOS: models

Sources

EncroChat, Sky ECC and ANOM

  • Eurojust, “Dismantling of an encrypted network sends shockwaves through organised crime groups across Europe”, 2 July 2020. — eurojust.europa.eu
  • Eurojust, “New major interventions to block encrypted communications of criminal networks”, 10 March 2021. — eurojust.europa.eu
  • Australian Federal Police, “AFP-led Operation Ironside smashes organised crime”, 8 June 2021. — afp.gov.au

The checks

  • NIST SP 800-218, Secure Software Development Framework, practices PS.2 and PS.2.1. — nvlpubs.nist.gov
  • Department for Science, Innovation and Technology and the National Cyber Security Centre, Software Security Code of Practice, updated 15 January 2026. — gov.uk
  • CISA and FBI, Secure by Demand Guide, August 2024. — ic3.gov
  • Google Search Central, “How to write reviews”. — developers.google.com
  • Android Open Source Project, Verified Boot. — source.android.com
  • Android Developers, key attestation. — developer.android.com
  • Auditor app, about and tutorial. — attestation.app

GuardDo, read 27 September 2026

  • GuardDo Pixel 10 product page. — guarddo.ru
  • GuardDo, About page. — guarddo.ru
  • GuardDo’s published source address. — git.guarddo.net
  • GuardDo’s GitLab group. — gitlab.com
  • GuardDo’s build server. — jenkins.guarddo.net
  • Russian Federal Tax Service, company register, record for tax number 7743462865. — egrul.nalog.ru
  • Habr, “GuardDo Pixel versus GrapheneOS” (in Russian), 8 April 2026. — habr.com
  • Habr, “GuardDo Pixel: a review of a phone with a secret” (in Russian), 10 June 2026. — habr.com

GrapheneOS and the Cellebrite reports

  • GrapheneOS source code. — github.com
  • GrapheneOS, build instructions. — grapheneos.org
  • GrapheneOS, web installer: verified boot key hashes. — grapheneos.org
  • GrapheneOS, release list, read 27 September 2026. — grapheneos.org
  • GrapheneOS, usage guide: system updates. — grapheneos.org
  • GrapheneOS, security.txt. — grapheneos.org
  • Ryan Whitwam, “Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking”, Ars Technica, 30 October 2025. — arstechnica.com
  • Android Authority, “Leak reveals how secure Pixel phones are with GrapheneOS”, 30 October 2025. — androidauthority.com

Frequently asked questions

What is GuardDo Pixel?

A Google Pixel sold by the Moscow company GUARDDO LLC with its own firmware, from 175,000 roubles for a Pixel 10 (27 September 2026).

Is GuardDo Pixel open source?

The address it gives for its code answered with an error on 27 September 2026. The repositories it has published contain no build instructions and none of the code for its advertised functions. The one file we compared is GrapheneOS’s, with the name changed.

Has GuardDo Pixel been tested against Cellebrite?

GuardDo says so. It publishes no report, tool version, date or laboratory.

Is GuardDo Pixel based on GrapheneOS?

Its published code and build log contain GrapheneOS components. Its website does not name GrapheneOS.

What happened to EncroChat, Sky ECC and ANOM phones?

All three were infiltrated by adversaries. EncroChat’s traffic was read in spring 2020 and the breach was made public in July 2020; about 70,000 Sky ECC users were read from February 2021, made public in March 2021; ANOM was run by an adversary from its start in 2018 until it was made public in June 2021.

How do I check that my phone runs what the seller says?

Compare the key hash shown at start-up with the maker’s published hash, and verify the phone with the Auditor app on any Android 13 or later phone.

PIXEL · ANDROID · GRAPHENEOS

Which operating system a Google Pixel runs, and what GrapheneOS replaces

Every Google Pixel ships with Android: Google’s own build of it. GrapheneOS replaces that build with its own, also based on the Android Open Source Project, on the same hardware. It removes Google’s privileged services from the system.

DEVICES · PIXEL · GRAPHENEOS

Which phones run GrapheneOS, and why only Pixel

GrapheneOS runs on Google Pixel only: every model from the Pixel 6 to the Pixel 10a is supported, the Pixel 8 and later are recommended, and the project’s hardware requirements, from verified boot to a secure element and hardware memory tagging, rule out every other brand. With Google’s support-end date for each model.

IMEI · PIXEL · GRAPHENEOS

The IMEI on a Google Pixel: where it is stored and what changing it takes

Where the IMEI physically lives on a Tensor Pixel, the three layers that hold it in place, why it is an integrity check inside signed modem firmware rather than a hardware fuse, what IMEI spoofing modules actually change, and why none of it buys anonymity on a cellular network.

Get in touch through a channel that suits you

Tell us which Pixel model you need — and get the price, lead time and delivery confirmed right in Telegram.