Hardened Android foundation
Built from the security focused GrapheneOS and AOSP foundation rather than a conventional consumer Android build.
Public purchase and installation will open once the supported device builds have completed validation and the signed releases are ready.
Obris SecureOS is built for people who think about mobile security as an operational security problem, not simply a privacy settings problem.
Obris SecureOS is an independently developed mobile operating system based on the open source GrapheneOS project and the Android Open Source Project. We retain the hardened Android foundation while developing additional Obris functionality around device compartmentalisation, controlled access and high risk mobile OPSEC.
A compatible FIDO2 YubiKey is required to complete a new SecureOS account and access the SecureOS installer after purchase.
Obris SecureOS uses Android user separation so everyday phone activity and sensitive work do not need to share the same operational environment.
The Obris Security User is designed so that it is not activated through the ordinary everyday device workflow. Through the supported Obris workflow, activation requires the enrolled YubiKey.
This creates a deliberate distinction between access to the normal phone and access to the sensitive environment. Possession of an unlocked everyday device alone is not intended to activate the Security User. This is different from using a YubiKey only as two factor authentication for a website or individual application.
Strong OPSEC is not only about stopping unauthorised access. It is also about reducing the amount of sensitive information that needs to remain decrypted and active during ordinary device use.
Obris SecureOS is built on GrapheneOS and AOSP, then adds an Obris controlled Security User workflow, physical YubiKey activation, communication restrictions, signed releases and verified installation for supported Pixel devices.
Built from the security focused GrapheneOS and AOSP foundation rather than a conventional consumer Android build.
Sensitive applications, accounts and data can remain separate from the everyday Owner environment.
A compatible enrolled FIDO2 YubiKey forms part of the protected Security User activation workflow.
Cellular SMS and outgoing cellular calls are restricted inside the Security User so sensitive communications remain inside approved encrypted applications.
Release metadata and images are cryptographically verified, and the installer returns the supported device to a locked bootloader state.
The duress workflow removes the protected Security User while leaving the ordinary Owner environment available without requiring a reboot.
Obris SecureOS is derived from GrapheneOS and the Android Open Source Project. References to GrapheneOS describe the upstream technical foundation and do not imply that Obris SecureOS is an official GrapheneOS product.
Obris SecureOS does not promise an “unhackable phone.” It is designed to provide stronger technical controls for users who want a more deliberate operational boundary between ordinary mobile use and sensitive information.
Obris SecureOS is a separate operating system distribution developed and maintained independently by Obris Group. GrapheneOS and Android are separate projects and trademarks of their respective owners.