Skip to content
NordSecure
Privacy-hardened Android (GrapheneOS) · Verified boot re-locked

Anonymous phones. Bought without a name.

A Google Pixel running privacy-hardened Android (GrapheneOS) — professionally flashed, hardened, and verified-boot re-locked. Add a Pixel eSIM for travel data in 170+ countries. No name, no ID, no account, ready the moment it arrives.

  • Verified boot re-locked
  • 30-day money-back
  • Ships EU-wide
5G
09:41
Encrypted No Google services
Checking service status…
eSIM destinations
170+eSIM destinations
accounts required
0accounts required
cryptocurrencies accepted
4cryptocurrencies accepted
money-back
30-daymoney-back
  • AES-256 encryption
  • Hardened OS
  • EU-wide shipping
  • 30-day money-back

Pay in cryptocurrency

  • BTCBitcoin
  • XMRMonero
  • LTCLitecoin
  • ETHEthereum

No card, no bank and no name in the transaction. Of the four, only Monero is private at the protocol level — the rest settle on public ledgers, so they are pseudonymous rather than anonymous.

Who it's for

Why people buy anonymous phones

  • Travel
  • Journalism
  • Everyday privacy
  • A second number for selling online
  • Avoiding SIM-swap fraud
  • Whistleblower protection
  • Activism
  • Digital nomads
  • Keeping work and personal apart
  • Frequent flyers
Why it's different

Security that's built in, not bolted on

Privacy-hardened Android brings defenses that stock phones simply don't ship with. Here's what's working for you, quietly, all the time.

Sandboxed apps

Apps run in tight sandboxes with no privileged access to the rest of your device — including optional, sandboxed Google Play.

It is the difference between an app being asked not to look and an app not being able to. Everything below follows from it.

Hardened memory

A hardened memory allocator and compiler mitigations block whole classes of exploits before they can run.

Per-app network control

Grant or revoke internet access for any app — even the ones that assume they're entitled to it.

Duress PIN

Set a secondary PIN that instantly wipes the device if you're ever forced to unlock it.

Auto-reboot

Idle devices reboot back into a stronger at-rest encryption state, shrinking the window for physical attacks.

No telemetry

No Google account, no background analytics, no data broker sitting quietly in the middle.

How it works

From order to unboxing in four steps

You choose the device. We do the technical heavy lifting. You get a phone that's private out of the box.

  1. 1

    Choose your device

    Pick a Pixel model and storage. We keep only officially supported devices.

  2. 2

    We flash & harden

    We install privacy-hardened Android and apply our hardened configuration.

  3. 3

    Verified boot re-locked

    The bootloader is re-locked with the OS's own keys — tamper-evident from boot.

  4. 4

    Ships to you

    Discreet, unbranded packaging. You complete first-boot setup yourself.

Stock vs hardened

The difference at a glance

Same Pixel hardware. A fundamentally different relationship with your data.

Stock Android compared with a privacy-hardened Pixel
FeatureStock AndroidHardened
Google account requiredEffectively yesNever
Background telemetryExtensiveNone from the OS
Per-app network controlLimitedFull toggle
Sensor and camera accessCoarsePer-app, revocable
Hardened memory allocatorNoYes
Verified boot after modificationLocked, but vendor-controlledLocked, with the new OS's own keys
Update sourceCarrier and vendor, often delayedDirect from the OS project
Duress and lockdown optionsBasic lockdownDuress PIN, auto-reboot, PIN scrambling
No trust required

Don't take our word for any of it

Security you have to take on faith isn't security. Everything we ship can be independently verified — by you.

A published verification guide

We document exactly how to confirm your device runs genuine, unmodified GrapheneOS — using public tools, not our word.

Read the verification guide

Checked against the project's own tooling

Attestation is the GrapheneOS project's, not ours. Their Auditor app and published guide verify the device's firmware and keys independently of anything we say.

GrapheneOS attestation guide

Verified boot, re-locked

Your phone cryptographically checks its own integrity at every boot and warns you if anything was ever tampered with.

An OS anyone can audit

GrapheneOS is fully open source. Every line of the system protecting you is public and reviewed by a worldwide community.

  • Crypto · cards on the phone
  • Ships from Denmark, tracked & discreet
  • 30-day money-back
Also from NordSecure

An eSIM for travel, as private as the phone

A prepaid eSIM for travel across 170+ countries — no ID, no SIM swap, nothing stored about you. Pay in crypto, scan a QR, and you're online in minutes.

Browse eSIM plans
  • No ID or KYC
  • Installs in 60 seconds
  • Top up anytime
  • Card
  • Crypto

Which eSIM supported devices we cover

Most phones sold in the EU since 2019 take an eSIM, but “most” isn't “yours” — regional variants of the same model sometimes leave the hardware out. Our free checker lists eSIM supported devices by make and model, so you know before you pay. Every phone we sell is eSIM-ready out of the box.

Check your device
From the blog

Privacy, in plain language

Guides and explainers on hardening your phone, staying private while travelling, and what the jargon actually means.

All articles
Questions

The things people ask first

No. GrapheneOS is an independent open-source project. We are not affiliated with it, not endorsed by it, and we do not speak for it.

What we sell is a service: we take a supported Google Pixel, install privacy-hardened Android (GrapheneOS), configure it, re-lock verified boot, and test it before it ships. The operating system itself is free software that anyone can download and install without paying us anything.

If you would rather do it yourself, you should — it is genuinely free, and the project publishes clear instructions. Our free hardening checklist covers the same configuration decisions we make, whether or not you buy from us.

Read the full answer

Your first order can be live in minutes

A hardened phone, an anonymous eSIM, a real number or a one-time code — bought without a name. Paid in crypto, nothing stored.

Just need travel data? Browse anonymous eSIMs