the secure edition · pixel · in development
the same, hardened.
endospore brings diaspore's amnesiac roaming to Pixel + GrapheneOS — adding a hardware
secure element for key custody, locked verified boot under our own key, and GrapheneOS's hardening,
for the security vertical. Same accountless, zero-knowledge roaming store and prepaid credits.
Join the waitlist
Read the source →
Everything diaspore isAmnesiac, accountless, roaming, client-encrypted — the same profile roams between both editions.
Secure-element key custodyThe Pixel's Titan M2 holds keys in hardware with brute-force throttling — well beyond a TEE.
Locked verified boot, our keyThe bootloader relocks against our own root of trust; tamper and it refuses to boot.
GrapheneOS hardeninghardened_malloc, exploit mitigations, and a stricter sandbox underneath the roaming layer. Based on GrapheneOS.