The origins and philosophy of GrapheneOS
GrapheneOS started in 2014 as CopperheadOS, a project founded by Daniel Micay on a radical premise: build a mobile operating system where security is not a layer bolted on top, but the foundation of the design itself. After a split with the company Copperhead in 2018, the project was renamed Android Hardening and, finally, GrapheneOS. Since then it has become the reference standard for security on Android devices.
The fundamental difference between GrapheneOS and any other Android — including Google's stock Android — is architectural. Where manufacturers add features on top of the Android Open Source Project (AOSP), GrapheneOS works from AOSP but rebuilds the deepest layers of the system: the kernel, the hardware drivers, the runtime and the process isolation mechanisms. The result is a system where every app lives in a hardened cage and the operating system trusts nothing by default.
Sandboxing and granular permissions
Hardened sandboxing is the crown jewel of GrapheneOS. On conventional Android, apps hold certain permissions they can share between themselves. On GrapheneOS, each app is isolated far more strictly, and the system applies additional restrictions even to native code. That means that even if a malicious app managed to run, its ability to read data from other apps, reach the microphone or camera, or talk to the outside world is drastically limited.
GrapheneOS also implements per-session permission control: instead of granting permanent access to the camera, contacts or location, you can authorise it only while you are using the app. When the app moves to the background, the permission is revoked automatically. This approach removes one of the biggest privacy risks: apps that collect data without your knowledge while you are not actively using them.
Per-app network mode is another substantial improvement. You can decide, app by app, whether it has access to WiFi, mobile data, both or neither. You can also disable the device sensors entirely — microphone, camera, accelerometer, gyroscope — with a single switch at the hardware level, not the software level.
No Google: a security advantage, not a limitation
One of the most widespread myths about GrapheneOS is that it "has no Google" and is therefore less functional. The reality is more nuanced and far more interesting. GrapheneOS does not include Google Play Services by default, and that is precisely one of its greatest security strengths. Play Services is a set of proprietary APIs with privileged access to the system, which Google uses to collect usage, location and behavioural data.
But GrapheneOS lets you install Google Play Services in a compatibility sandbox — without elevated privileges — through its default app store. That means you can run apps that depend on Google Play Services (WhatsApp, Signal, or most banking apps) without giving Google access to the core of the system. It is the best of both worlds: compatibility with the Android ecosystem without compromising security.
The recommended app store, Apps (the GrapheneOS app that acts as a client for several sources), lets you install apps from Google's Play Store anonymously, using a temporary account or no account at all. For open source apps, F-Droid and Accrescent are the main alternatives.
Immediate security updates
In the standard Android ecosystem, security updates pass first through Google, then the chip maker (Qualcomm, MediaTek), then the device maker (Samsung, Xiaomi) and finally the carrier. That process can take weeks or months, and many devices stop receiving updates after barely two or three years.
GrapheneOS breaks that chain. The development team ships security updates within hours, often the same day Google releases the monthly Android patches. Support also runs for the full service life of the supported hardware — currently Google Pixel — which means a Pixel 6 bought in 2021 still receives full GrapheneOS updates in 2026, and will keep receiving them for as long as the hardware can run the system.
Which phones can run GrapheneOS
GrapheneOS only installs on Google Pixel phones, and not on a whim: they are the only Android devices that combine a dedicated security chip (Titan M2), verified boot that supports alternative operating systems without losing verification, and seven years of guaranteed hardware patches. The project refuses to port the system to devices that cannot sustain that level of security — better to support little hardware properly than lots of hardware halfway.
In practice, any Pixel from the 8 series onwards is a solid buy today: an encrypted Pixel 8a is the cheapest way in (from €550), and the 10 series offers the longest update runway. Our GrapheneOS Pixel category lists every available model, each one with the system installed, verified and configured before shipping.
Common myths about GrapheneOS
"It's illegal, or it's for criminals." False: GrapheneOS is a legitimate open-source project, and using encryption is a recognised right in Spain and across the EU. We cover the legal detail in Is an encrypted phone legal in Spain?. The confusion comes from criminal networks like Encrochat, which were something else entirely: closed services with a central server — the exact opposite of the GrapheneOS model.
"Banking apps won't work." The vast majority do: sandboxed Google Play lets the Play Store run as a regular, unprivileged app, and with it banking, WhatsApp or any commercial app. A few apps that demand Google's integrity attestation may complain; that is what the training included with every device is for.
"It's only for technical people." Daily use is identical to regular Android: same screen, same gestures, same apps. What changes is what happens underneath. And when the device arrives already configured, the technical part disappears from the path entirely.
Is it worth it for the average user?
The short answer is yes, with caveats. If your threat model involves journalists, activists, lawyers, business owners handling sensitive information, or simply people who value their privacy and do not want to be the product of big tech, GrapheneOS is the best decision you can make today. Installation is remarkably simple — you do it from a web browser using WebUSB — and day-to-day use is practically identical to a Pixel running stock Android, but with far stronger security.
For many users, GrapheneOS is a revelation: a phone that works as it always did, with the apps you always had, but that does not leak your data to Google, does not track your location and does not let malicious software thrive. At Securfy we offer Pixel devices with GrapheneOS preinstalled and configured, ready to use from the first minute with no technical work on your side.



