OPS ONLINE LDN --:--:-- PROGRAMME PHONE BATCH 026 OPEN
CSSLTD // PHONE.026
CSS-PHONE.026 // POCKET OPERATOR UNIT

The phone that doesn't phone home.

The CSSLTD PHONE is a hand-built sovereign mobile communications device — de-Googled to the bootloader, hardened at every layer, equipped with hardware kill-switches for cellular, Wi-Fi, microphone, and cameras. It ships with the same operator identity bundle as our laptops and workstations — nine privacy-grade platform accounts, a YubiKey 5C NFC, a 12-month CITADEL comms licence, and a printed credential set sealed in tamper-evident packaging. No Google services. No carrier bloat. No telemetry. No exceptions.

CSSLTD ▸ SECURE PHONE POCKET OPERATOR UNIT ▸ OS: GRAPHENEOS ▸ GOOGLE: REMOVED ▸ BASEBAND: ISOLATED ▸ KILL SWITCHES: ARMED ▸ IDENTITY: 9 PLATFORMS ▸ CITADEL: CONNECTED ▸ YUBIKEY: PROVISIONED CELL WIFI MIC CAM NFC INTEGRITY VERIFIED · SHA-256 ATTESTATION CYBERSENTINEL · CSS-PHONE.026 · SALISBURY UK
4× hardware kill-switches
9 identity platforms
04 / Threat Model

What your current phone is doing right now.

Your phone is the single most surveilled object you own. It has your location, your contacts, your biometrics, your conversations, and a persistent link to your real-world identity through the SIM. Here's what it's sending.

// VECTOR 01

Google Services & Play Protect

Every stock Android phone runs Google Play Services — a closed-source root-level daemon with access to location, contacts, installed apps, Wi-Fi networks, and device identifiers. It phones home continuously. You cannot disable it without root. Even "privacy settings" are suggestions it can override.

// VECTOR 02

SIM identity & cell tracking

Your SIM links your device to your government-issued ID. Your carrier knows your location within metres, 24/7, and is compelled by law to hand that data to authorities on demand. IMSI catchers (Stingrays) can acquire your IMSI/IMEI passively within range.

// VECTOR 03

Baseband processor

The cellular modem is a closed-source second OS running independently on your phone with direct memory access. It can be exploited remotely over the air. You have no visibility into what it does. On stock phones, it shares the main application processor's memory space.

// VECTOR 04

Always-on microphone & camera

Software kill-switches in settings are requests, not guarantees. A compromised app or OS-level exploit can activate sensors silently. Without hardware disconnection, the microphone and cameras are always physically powered and accessible.

// VECTOR 05

App-level surveillance

Every installed app has a declared (and often exceeded) permission set. Keyboard apps log keystrokes. Fitness apps track location. Messaging apps upload contact lists. The permission model on stock Android is advisory at the Play Services level.

// VECTOR 06

Cloud backup exfiltration

Google Drive backup captures messages, call logs, Wi-Fi passwords, app data, photos, and device settings. This data is accessible to Google and, via legal process, to any requesting government. iCloud equivalent on iOS. Both are enabled by default.

05 / The Build

De-Googled. Hardened. Kill-switched.

The CSSLTD PHONE starts as a factory-sealed Pixel device — the only platform with verified boot support for a non-vendor OS. We strip it down, flash GrapheneOS, install hardware kill-switches for all four radio/sensor paths, configure the full privacy stack, provision the identity bundle, and seal it in tamper-evident packaging before handover.

Hardware kill-switches.

Not software toggles. Physical switches wired into the mainboard that electrically disconnect the component. When the switch is off, the circuit is broken. No software exploit can override a severed wire.

📡

Cellular modem

Isolates the baseband processor from power and data lines. No cell signal, no IMSI exposure, no remote baseband exploits.

📶

Wi-Fi / Bluetooth

Cuts the wireless radio entirely. No probe requests, no MAC exposure, no Bluetooth beacon. The device becomes RF-silent on the WLAN band.

🎙

Microphone

Severs the microphone circuit at the hardware level. Cannot be re-enabled by any software, OS update, or exploit until physically switched on.

📷

Cameras

Disconnects both front and rear cameras from the mainboard. No ambient-light workaround, no "sensor access" — the circuit doesn't exist when off.

Full hardware specification.

Base device
Google Pixel 9 Pro · factory-sealed · SIM-free NEWonly Pixel supports verified boot with non-vendor OS
OS
GrapheneOS · latest stable · OTA-capablede-Googled AOSP fork with hardened malloc, exec-based spawning, MAC randomisation, verified boot
Kill-switches
4× hardware: cellular, Wi-Fi/BT, microphone, cameras INSTALLEDphysical slide-switches wired to mainboard breakpoints · non-reversible mod
Encryption
Full-disk encryption · PIN + YubiKey NFCTitan M2 secure element backed · hardware-attested keystore
SIM
Anonymous MVNO prepaid SIM · no ID registrationcash-purchased prepaid from privacy-respecting MVNO · replaceable · not linked to operator identity
Auth
YubiKey 5C NFC NEWFIDO2 · PIV · OpenPGP · device unlock via NFC · same key as desktop/laptop fleet
VPN
Mullvad VPN · always-on · kill-switch enforcedWireGuard · account-number-only · no email registration · paid in Monero
DNS
Encrypted DNS-over-HTTPS via Mullvadno cleartext DNS queries leave the device under any circumstances
Tor
Tor Browser + Orbot system-wide proxypre-configured with bridges · stream isolation across apps
Comms
SimpleX · Session · Element · CITADELno phone-number-based messenger installed · Signal deliberately excluded
Email
Proton Mail + Tutanota · Tor-registeredno phone number required for either · both support PGP
Password mgr
Vaultwarden (self-hosted compatible) + KeePassDXoffline vault for high-value secrets · Vaultwarden for team sync
Notes
Standard Notes Pro · e2eecross-platform encrypted notes synced to desktop/laptop stack
Camera
Secure Camera (GrapheneOS) · no EXIF leakagestrips GPS, device identifiers from all captures · no cloud upload path
Browser
Vanadium (hardened Chromium) + Tor BrowserVanadium for clearnet with strict settings · Tor Browser for .onion
Faraday
MOS Equipment RF-shielding pouch included INCLUDEDsignal-blocking pouch for transport · tested to -80dB attenuation
06 / Security Stack

Five layers. No gaps.

Every phone we ship closes the same five attack surfaces. No layer is optional, no layer is a software toggle. Each one is verified before the tamper-seal goes on.

// LAYER 01

Hardware isolation

Four kill-switches provide physical circuit-break isolation for cellular, Wi-Fi/Bluetooth, microphone, and cameras. Baseband processor shares no memory with the application processor under GrapheneOS. Titan M2 hardware security module provides tamper-resistant key storage.

  • Physical kill-switches wired to mainboard breakpoints
  • Application/baseband processor isolation
  • Titan M2 secure element for key attestation
  • Faraday pouch for full RF isolation during transport
// LAYER 02

De-Googled OS

GrapheneOS removes every Google service, framework, and telemetry endpoint from the AOSP base. Verified boot ensures only the signed GrapheneOS image can load. No Google Play Services, no Firebase, no SafetyNet callbacks, no usage reporting.

  • Zero Google services or frameworks
  • Verified boot with locked bootloader
  • Hardened memory allocator (hardened_malloc)
  • Exec-based app spawning (no zygote preforking)
// LAYER 03

Network hardening

All traffic routes through Mullvad VPN (WireGuard) with an OS-level kill-switch — if the tunnel drops, all traffic stops. DNS is encrypted end-to-end. Tor Browser and Orbot are pre-configured for .onion access and system-wide proxying. MAC address randomisation on every connection.

  • Always-on VPN with system kill-switch
  • Encrypted DNS (DoH via Mullvad)
  • Per-connection MAC randomisation
  • Tor + bridges for censorship circumvention
// LAYER 04

Communication security

No phone-number-based messenger is installed. All communication runs through end-to-end encrypted channels that don't require — or accept — a phone number for registration. Signal is deliberately excluded because it requires a phone number.

  • SimpleX Chat — no identifiers, decentralised
  • Session — onion-routed, no phone number
  • Element/Matrix — federated, self-hostable
  • CITADEL — CSSLTD relay, Signal Protocol, no phone
// LAYER 05

Identity separation

The operator's real-world identity is never linked to the device. The SIM is an anonymous prepaid. All platform accounts are registered over Tor, paid in Monero, and tied to an operator codename. GrapheneOS user profiles provide app-level compartmentalisation.

  • Anonymous MVNO SIM — no ID registration
  • 9 platform accounts — Tor-registered, Monero-paid
  • Separate user profiles for compartmentalisation
  • No biometric unlock configured (PIN + YubiKey only)
07 / Identity Bundle

Nine platforms. Zero phone numbers.

Every PHONE ships with a unique operator identity across nine privacy-grade platforms — registered over Tor, paid in Monero, tied to an operator codename you choose. None of them require a phone number. None of them are linked to your real-world identity. Credentials are printed once on tamper-evident paper, sealed, and handed over with the unit. CSSLTD does not retain copies after handover.

[01] EMAIL
Proton Mail
e2ee · Switzerland · Tor login
Proton Visionary plan. Custom domain optional. Includes Proton VPN, Drive (500 GB), Calendar, and Pass. Tor .onion access configured.
[02] EMAIL
Tutanota
e2ee · Germany · no phone required
Premium plan. Independent second email for compartmentalisation. Different jurisdiction from Proton. Automatic encryption to external recipients.
[03] VPN
Mullvad VPN
account number only · WireGuard
No email, no name. Monero-paid. WireGuard config pre-installed with OS-level kill-switch. Always-on by default.
[04] MESSAGING
Session
onion-routed · no phone · decentralised
Session ID generated on-device. Messages routed via onion request protocol. No server-side metadata. No phone number at any point.
[05] MESSAGING
SimpleX Chat
no identifiers · decentralised · self-hostable
No user identity at all — not even a random ID. Connections via one-time invitation links. Pre-configured with CSSLTD relay on .onion for team use.
[06] MESSAGING
Element / Matrix
federated · e2ee · self-hostable
Matrix account on a privacy-respecting homeserver. Cross-signed device verification. Room-level encryption. Compatible with desktop/laptop fleet.
[07] PASSWORDS
Vaultwarden
self-hosted compatible · e2ee
Bitwarden-compatible vault. Can sync with team Vaultwarden instance or run offline. YubiKey FIDO2 as second factor.
[08] NOTES
Standard Notes
e2ee · cross-platform
Standard Notes Pro. End-to-end encrypted notes that sync across all CSSLTD devices — phone, laptop, workstation. No unencrypted data at rest.
[09] CITADEL COMMS
CSSLTD CITADEL
Signal Protocol · self-hosted relay
CSSLTD-operated encrypted communications platform. Signal Protocol Double Ratchet. No phone number linkage. 12-month licence included. Dedicated mobile client pre-installed.

All identities are registered over Tor, paid via Monero or cash, and tied to an operator-codename of your choosing — never to a real-world name, address, or phone. Credentials are printed once, on tamper-evident paper, sealed, and handed over physically with the unit. CSSLTD does not retain copies of any credentials after handover. If you lose them, they're gone.

08 / Provisioning Process

Twelve steps. One sealed unit.

Every PHONE goes through the same provisioning sequence. No shortcuts, no batch-optimised steps. Each unit is built individually, tested individually, and signed individually.

Unbox & verify seal

Factory-sealed Pixel unboxed in a clean environment. Seal integrity verified and photographed. Serial number logged against the order.

Hardware kill-switch install

Device opened under magnification. Four hardware kill-switches wired to mainboard breakpoints for cellular, Wi-Fi/BT, microphone, and cameras. Solder joints inspected under 10× magnification.

GrapheneOS flash

Bootloader unlocked. GrapheneOS flashed from verified source. Bootloader re-locked. Verified boot confirmed — only the signed GrapheneOS image will load from this point.

OS hardening

Network settings locked: Mullvad always-on, kill-switch enforced, DNS-over-HTTPS, MAC randomisation. User profiles created for compartmentalisation. Auto-reboot timer set.

App stack installation

All applications installed via F-Droid or direct APK with hash verification. No Google Play Store. Every APK SHA-256 recorded in the build manifest.

Identity bundle provisioning

Nine platform accounts registered over Tor, paid in Monero, configured with the operator's chosen codename. Credentials printed on tamper-evident paper.

YubiKey provisioning

YubiKey 5C NFC provisioned with FIDO2, PIV, and OpenPGP keys. Registered as second factor on all nine platforms. NFC device unlock configured.

Anonymous SIM activation

Cash-purchased prepaid SIM from privacy-respecting MVNO inserted. No ID registration. Carrier-level identity not linked to the operator identity bundle.

Kill-switch testing

Each hardware kill-switch tested in both positions. RF emission verified with spectrum analyser. Microphone and camera disconnect confirmed with diagnostic tools. All four must pass.

48-hour burn-in

Device runs continuously for 48 hours under load. Battery cycling, thermal monitoring, connectivity stress-testing. Any anomaly restarts the build.

Build attestation

SHA-256 manifest of every installed APK, OS build, and configuration file. Signed by CSSLTD offline key. Attestation sealed in tamper-evident envelope with the unit.

Tamper-evident packaging

Phone, YubiKey, credential set, Faraday pouch, and attestation sealed in tamper-evident bag. Photographed. Couriered direct to named recipient. No freight forwarder.

09 / Invoice

The price sheet.

Transparent, itemised, non-negotiable. Every PHONE ships with the same package at the same price. We don't offer "basic" or "premium" tiers — every operator gets the full stack.

Component GBP
Pixel 9 Pro · factory-sealed · SIM-freeonly platform supporting verified boot with non-vendor OS · sourced direct
£ 1,099
Hardware kill-switch installation · 4×cellular · Wi-Fi/BT · microphone · cameras · wired to mainboard breakpoints · non-reversible
£ 2,499
GrapheneOS flash, lock & hardeningflash · re-lock bootloader · verified boot · OS hardening · network lockdown · profile configuration
£ 999
Privacy app stack · installed & configuredF-Droid sourced · APK hash-verified · Tor · Orbot · SimpleX · Session · Element · Vanadium · KeePassDX · Standard Notes
£ 499
Identity bundle · 9 platforms · 12 monthsProton Visionary · Tutanota Premium · Mullvad VPN · Session · SimpleX · Element/Matrix · Vaultwarden · Standard Notes Pro · CITADEL
£ 2,499
YubiKey 5C NFC · operator-provisionedFIDO2 · PIV · OpenPGP · NFC unlock · same key as desktop/laptop fleet
£ 99
Anonymous MVNO SIM · 12-month prepaidcash-purchased · no ID registration · replaceable · not linked to operator identity
£ 249
Faraday RF-shielding pouchMOS Equipment · tested to -80dB · transport-grade signal blocking
£ 79
Build attestation, documentation & secure courierSHA-256 manifest · signed attestation · operator manual · tamper-evident packaging · direct courier to named recipient
£ 499
48-hour burn-in, QA & kill-switch verificationbattery cycling · thermal monitoring · RF emission testing · spectrum analyser verification per switch
£ 499
Per unit · ex-VAT
£10,000
VAT applied at point of invoice based on jurisdiction · £2,000 UK VAT · ships UK / EU · 3–5 weeks lead time
// NO DISCOUNTS · NO BASIC TIER · NO STRIPPED VERSION // Every PHONE ships with the full stack. We don't sell "just the phone" or "just the OS flash." The threat model requires every layer; selling half a solution would compromise the entire chain. The price is the price.

Guarantees.

// UNDERWRITTEN

Compromise insurance

Every PHONE is covered by a Lloyd's-syndicate-underwritten policy for the licence period. If the unit is compromised through a fault in our build — not your OPSEC — we pay.

£10,000 per unit
// HARDWARE

5-year warranty

Parts and labour. Kill-switches, mainboard, display, battery. If it breaks through normal use, we fix or replace it. Tamper-evident re-seal on return.

5 years
// LIFETIME

Lifetime re-provision

OS re-flash, identity renewal, app stack update — for the life of the unit. Send it back, we re-provision it to current standards and return it sealed.

// ATTESTATION

Build attestation

SHA-256 manifest of every APK, OS build, and config file. Signed by our offline key. You can verify every binary on the device against the attestation at any time.

SHA-256 · signed
// PAYMENT // 50% on order, 50% on shipment. GBP / EUR / CHF wire, or Monero / Bitcoin to a dedicated wallet. Refundable in full up to provisioning-start.
10 / Operator's Q&A

Questions you should be asking.

Why a Pixel and not a Pinephone or Librem 5?

Because verified boot matters more than marketing. The Pixel is the only non-Apple device that supports verified boot with a non-vendor OS — meaning you can lock the bootloader after flashing GrapheneOS and the device will cryptographically verify the OS hasn't been tampered with on every boot. The Pinephone and Librem 5 cannot do this. They also have significantly weaker hardware security modules, no Titan M2 equivalent, and their Linux-based mobile OS stacks are years behind GrapheneOS in practical hardening. We chose the platform that is actually most secure, not the one that looks most ideological on paper.

Why not just install GrapheneOS myself?

You can, and we encourage it. GrapheneOS is free and their web installer works well. What you can't do yourself is: install hardware kill-switches (requires microsoldering), source an anonymous prepaid SIM without ID linkage, register nine platform identities over Tor paid in Monero without touching your real identity, provision a YubiKey across all nine platforms, verify kill-switch function with a spectrum analyser, run a 48-hour burn-in, and produce a signed build attestation. The phone is the easy part. The operational infrastructure around it is the hard part — and the part that actually protects you.

Why no Signal?

Signal requires a phone number. That's the beginning and the end of the argument. In our threat model, linking a communications platform to a phone number — which is linked to a SIM, which is linked (in most jurisdictions) to a government ID — breaks the identity separation model at the root. We use the Signal Protocol (via CITADEL), but not the Signal app. SimpleX, Session, and Element all function without a phone number.

What happens when Google stops supporting the Pixel 9 Pro?

GrapheneOS provides extended support beyond Google's EOL date. When security updates eventually stop, we offer a full re-provision onto the current Pixel generation — same identity bundle, same kill-switch installation, same build process. Your operator identity migrates; the hardware is replaced. This is covered under the lifetime re-provision guarantee at our standard provisioning labour rate (device cost separate).

Can I use this as my daily phone?

Yes, but understand what "daily" means here. There is no Google Play Store, no Google Maps, no Gmail app, no banking apps that require SafetyNet attestation. You will use Organic Maps instead of Google Maps, Proton Mail instead of Gmail, and you will not have access to most mainstream apps. If your daily life requires Uber, Instagram, or mobile banking — this is not your daily phone. If your daily life requires secure communications, verified anonymity, and hardware-level control over your own device — this is the only daily phone that makes sense.

How does this fit with the SENTINEL laptop or NITRO workstation?

Same identity bundle, same YubiKey, same platforms, same threat model. The PHONE runs the mobile clients for the same nine platforms your laptop and workstation use. SimpleX, Session, Element, Proton, Tutanota, Mullvad, Vaultwarden, Standard Notes, CITADEL — all sync across devices. Your YubiKey 5C NFC works via USB-C on the laptop/workstation and via NFC on the phone. One identity, three form factors.

I just want the kill-switch mod on my existing Pixel. Do you offer that?

No. The kill-switch installation is one step in a twelve-step process. Without the full OS hardening, identity bundle, network lockdown, and attestation, the kill-switches are a false sense of security on a still-compromised platform. We don't sell partial solutions because partial solutions get people hurt. If you want just GrapheneOS, install it yourself — it's free and well-documented.

Your pocket. Your rules.

The CSSLTD PHONE ships sealed, attested, and provisioned. Plug in your YubiKey, set your PIN, and the unit is operational. No configuration required.

orders@cyberssl.co.uk · engineering@cyberssl.co.uk · PGP 0x4F2A on request · CITADEL @ops.cyberssl