The CSSLTD PHONE is a hand-built sovereign mobile communications device — de-Googled to the bootloader, hardened at every layer, equipped with hardware kill-switches for cellular, Wi-Fi, microphone, and cameras. It ships with the same operator identity bundle as our laptops and workstations — nine privacy-grade platform accounts, a YubiKey 5C NFC, a 12-month CITADEL comms licence, and a printed credential set sealed in tamper-evident packaging. No Google services. No carrier bloat. No telemetry. No exceptions.
Your phone is the single most surveilled object you own. It has your location, your contacts, your biometrics, your conversations, and a persistent link to your real-world identity through the SIM. Here's what it's sending.
Every stock Android phone runs Google Play Services — a closed-source root-level daemon with access to location, contacts, installed apps, Wi-Fi networks, and device identifiers. It phones home continuously. You cannot disable it without root. Even "privacy settings" are suggestions it can override.
Your SIM links your device to your government-issued ID. Your carrier knows your location within metres, 24/7, and is compelled by law to hand that data to authorities on demand. IMSI catchers (Stingrays) can acquire your IMSI/IMEI passively within range.
The cellular modem is a closed-source second OS running independently on your phone with direct memory access. It can be exploited remotely over the air. You have no visibility into what it does. On stock phones, it shares the main application processor's memory space.
Software kill-switches in settings are requests, not guarantees. A compromised app or OS-level exploit can activate sensors silently. Without hardware disconnection, the microphone and cameras are always physically powered and accessible.
Every installed app has a declared (and often exceeded) permission set. Keyboard apps log keystrokes. Fitness apps track location. Messaging apps upload contact lists. The permission model on stock Android is advisory at the Play Services level.
Google Drive backup captures messages, call logs, Wi-Fi passwords, app data, photos, and device settings. This data is accessible to Google and, via legal process, to any requesting government. iCloud equivalent on iOS. Both are enabled by default.
The CSSLTD PHONE starts as a factory-sealed Pixel device — the only platform with verified boot support for a non-vendor OS. We strip it down, flash GrapheneOS, install hardware kill-switches for all four radio/sensor paths, configure the full privacy stack, provision the identity bundle, and seal it in tamper-evident packaging before handover.
Not software toggles. Physical switches wired into the mainboard that electrically disconnect the component. When the switch is off, the circuit is broken. No software exploit can override a severed wire.
Isolates the baseband processor from power and data lines. No cell signal, no IMSI exposure, no remote baseband exploits.
Cuts the wireless radio entirely. No probe requests, no MAC exposure, no Bluetooth beacon. The device becomes RF-silent on the WLAN band.
Severs the microphone circuit at the hardware level. Cannot be re-enabled by any software, OS update, or exploit until physically switched on.
Disconnects both front and rear cameras from the mainboard. No ambient-light workaround, no "sensor access" — the circuit doesn't exist when off.
Every phone we ship closes the same five attack surfaces. No layer is optional, no layer is a software toggle. Each one is verified before the tamper-seal goes on.
Four kill-switches provide physical circuit-break isolation for cellular, Wi-Fi/Bluetooth, microphone, and cameras. Baseband processor shares no memory with the application processor under GrapheneOS. Titan M2 hardware security module provides tamper-resistant key storage.
GrapheneOS removes every Google service, framework, and telemetry endpoint from the AOSP base. Verified boot ensures only the signed GrapheneOS image can load. No Google Play Services, no Firebase, no SafetyNet callbacks, no usage reporting.
All traffic routes through Mullvad VPN (WireGuard) with an OS-level kill-switch — if the tunnel drops, all traffic stops. DNS is encrypted end-to-end. Tor Browser and Orbot are pre-configured for .onion access and system-wide proxying. MAC address randomisation on every connection.
No phone-number-based messenger is installed. All communication runs through end-to-end encrypted channels that don't require — or accept — a phone number for registration. Signal is deliberately excluded because it requires a phone number.
The operator's real-world identity is never linked to the device. The SIM is an anonymous prepaid. All platform accounts are registered over Tor, paid in Monero, and tied to an operator codename. GrapheneOS user profiles provide app-level compartmentalisation.
Every PHONE ships with a unique operator identity across nine privacy-grade platforms — registered over Tor, paid in Monero, tied to an operator codename you choose. None of them require a phone number. None of them are linked to your real-world identity. Credentials are printed once on tamper-evident paper, sealed, and handed over with the unit. CSSLTD does not retain copies after handover.
All identities are registered over Tor, paid via Monero or cash, and tied to an operator-codename of your choosing — never to a real-world name, address, or phone. Credentials are printed once, on tamper-evident paper, sealed, and handed over physically with the unit. CSSLTD does not retain copies of any credentials after handover. If you lose them, they're gone.
Every PHONE goes through the same provisioning sequence. No shortcuts, no batch-optimised steps. Each unit is built individually, tested individually, and signed individually.
Factory-sealed Pixel unboxed in a clean environment. Seal integrity verified and photographed. Serial number logged against the order.
Device opened under magnification. Four hardware kill-switches wired to mainboard breakpoints for cellular, Wi-Fi/BT, microphone, and cameras. Solder joints inspected under 10× magnification.
Bootloader unlocked. GrapheneOS flashed from verified source. Bootloader re-locked. Verified boot confirmed — only the signed GrapheneOS image will load from this point.
Network settings locked: Mullvad always-on, kill-switch enforced, DNS-over-HTTPS, MAC randomisation. User profiles created for compartmentalisation. Auto-reboot timer set.
All applications installed via F-Droid or direct APK with hash verification. No Google Play Store. Every APK SHA-256 recorded in the build manifest.
Nine platform accounts registered over Tor, paid in Monero, configured with the operator's chosen codename. Credentials printed on tamper-evident paper.
YubiKey 5C NFC provisioned with FIDO2, PIV, and OpenPGP keys. Registered as second factor on all nine platforms. NFC device unlock configured.
Cash-purchased prepaid SIM from privacy-respecting MVNO inserted. No ID registration. Carrier-level identity not linked to the operator identity bundle.
Each hardware kill-switch tested in both positions. RF emission verified with spectrum analyser. Microphone and camera disconnect confirmed with diagnostic tools. All four must pass.
Device runs continuously for 48 hours under load. Battery cycling, thermal monitoring, connectivity stress-testing. Any anomaly restarts the build.
SHA-256 manifest of every installed APK, OS build, and configuration file. Signed by CSSLTD offline key. Attestation sealed in tamper-evident envelope with the unit.
Phone, YubiKey, credential set, Faraday pouch, and attestation sealed in tamper-evident bag. Photographed. Couriered direct to named recipient. No freight forwarder.
Transparent, itemised, non-negotiable. Every PHONE ships with the same package at the same price. We don't offer "basic" or "premium" tiers — every operator gets the full stack.
Every PHONE is covered by a Lloyd's-syndicate-underwritten policy for the licence period. If the unit is compromised through a fault in our build — not your OPSEC — we pay.
Parts and labour. Kill-switches, mainboard, display, battery. If it breaks through normal use, we fix or replace it. Tamper-evident re-seal on return.
OS re-flash, identity renewal, app stack update — for the life of the unit. Send it back, we re-provision it to current standards and return it sealed.
SHA-256 manifest of every APK, OS build, and config file. Signed by our offline key. You can verify every binary on the device against the attestation at any time.
Because verified boot matters more than marketing. The Pixel is the only non-Apple device that supports verified boot with a non-vendor OS — meaning you can lock the bootloader after flashing GrapheneOS and the device will cryptographically verify the OS hasn't been tampered with on every boot. The Pinephone and Librem 5 cannot do this. They also have significantly weaker hardware security modules, no Titan M2 equivalent, and their Linux-based mobile OS stacks are years behind GrapheneOS in practical hardening. We chose the platform that is actually most secure, not the one that looks most ideological on paper.
You can, and we encourage it. GrapheneOS is free and their web installer works well. What you can't do yourself is: install hardware kill-switches (requires microsoldering), source an anonymous prepaid SIM without ID linkage, register nine platform identities over Tor paid in Monero without touching your real identity, provision a YubiKey across all nine platforms, verify kill-switch function with a spectrum analyser, run a 48-hour burn-in, and produce a signed build attestation. The phone is the easy part. The operational infrastructure around it is the hard part — and the part that actually protects you.
Signal requires a phone number. That's the beginning and the end of the argument. In our threat model, linking a communications platform to a phone number — which is linked to a SIM, which is linked (in most jurisdictions) to a government ID — breaks the identity separation model at the root. We use the Signal Protocol (via CITADEL), but not the Signal app. SimpleX, Session, and Element all function without a phone number.
GrapheneOS provides extended support beyond Google's EOL date. When security updates eventually stop, we offer a full re-provision onto the current Pixel generation — same identity bundle, same kill-switch installation, same build process. Your operator identity migrates; the hardware is replaced. This is covered under the lifetime re-provision guarantee at our standard provisioning labour rate (device cost separate).
Yes, but understand what "daily" means here. There is no Google Play Store, no Google Maps, no Gmail app, no banking apps that require SafetyNet attestation. You will use Organic Maps instead of Google Maps, Proton Mail instead of Gmail, and you will not have access to most mainstream apps. If your daily life requires Uber, Instagram, or mobile banking — this is not your daily phone. If your daily life requires secure communications, verified anonymity, and hardware-level control over your own device — this is the only daily phone that makes sense.
Same identity bundle, same YubiKey, same platforms, same threat model. The PHONE runs the mobile clients for the same nine platforms your laptop and workstation use. SimpleX, Session, Element, Proton, Tutanota, Mullvad, Vaultwarden, Standard Notes, CITADEL — all sync across devices. Your YubiKey 5C NFC works via USB-C on the laptop/workstation and via NFC on the phone. One identity, three form factors.
No. The kill-switch installation is one step in a twelve-step process. Without the full OS hardening, identity bundle, network lockdown, and attestation, the kill-switches are a false sense of security on a still-compromised platform. We don't sell partial solutions because partial solutions get people hurt. If you want just GrapheneOS, install it yourself — it's free and well-documented.
The CSSLTD PHONE ships sealed, attested, and provisioned. Plug in your YubiKey, set your PIN, and the unit is operational. No configuration required.