the secure edition · pixel · in development

the same, hardened.

endospore brings diaspore's amnesiac roaming to Pixel + GrapheneOS — adding a hardware secure element for key custody, locked verified boot under our own key, and GrapheneOS's hardening, for the security vertical. Same accountless, zero-knowledge roaming store and prepaid credits.

Join the waitlist Read the source →
Everything diaspore isAmnesiac, accountless, roaming, client-encrypted — the same profile roams between both editions.
Secure-element key custodyThe Pixel's Titan M2 holds keys in hardware with brute-force throttling — well beyond a TEE.
Locked verified boot, our keyThe bootloader relocks against our own root of trust; tamper and it refuses to boot.
GrapheneOS hardeninghardened_malloc, exploit mitigations, and a stricter sandbox underneath the roaming layer. Based on GrapheneOS.
based on GrapheneOS source · published at first release part of nowhere · available now: diaspore