COMING SOON

Obris SecureOS is preparing for public release.

Public purchase and installation will open once the supported device builds have completed validation and the signed releases are ready.

ABOUT OBRIS SECUREOS

A different approach to mobile security.

Obris SecureOS is built for people who think about mobile security as an operational security problem, not simply a privacy settings problem.

Obris SecureOS is an independently developed mobile operating system based on the open source GrapheneOS project and the Android Open Source Project. We retain the hardened Android foundation while developing additional Obris functionality around device compartmentalisation, controlled access and high risk mobile OPSEC.

View SecureOS plans Open customer portal
YubiKey required

A compatible FIDO2 YubiKey is required to complete a new SecureOS account and access the SecureOS installer after purchase.

Two environments.
One physical device.

Obris SecureOS uses Android user separation so everyday phone activity and sensitive work do not need to share the same operational environment.

01
EVERYDAY

Owner Environment

02
PROTECTED

Security User

Purpose
Normal everyday smartphone use.
Sensitive activity requiring stronger operational separation.
Applications & data
Everyday applications, accounts and routine phone data.
Separate application data, accounts, sessions and credential protected storage.
Communications
Normal calls, messaging, navigation and browsing.
Obris Chat for end to end encrypted messaging plus encrypted voice and video.
Cellular access
Normal cellular services remain available.
Cellular SMS and outgoing cellular calls are restricted by Obris policy.
Network path
Obris VPN can be used when required.
Protected communications are designed around the Obris VPN path rather than direct internet fallback.

Activation controlled by YubiKey.

The Obris Security User is designed so that it is not activated through the ordinary everyday device workflow. Through the supported Obris workflow, activation requires the enrolled YubiKey.

This creates a deliberate distinction between access to the normal phone and access to the sensitive environment. Possession of an unlocked everyday device alone is not intended to activate the Security User. This is different from using a YubiKey only as two factor authentication for a website or individual application.

KNOWNormal credentialProtects ordinary device access.
HAVEEnrolled YubiKeyRequired to activate the protected environment.

Protect data by reducing when it is accessible.

Strong OPSEC is not only about stopping unauthorised access. It is also about reducing the amount of sensitive information that needs to remain decrypted and active during ordinary device use.

01Everyday useOwner remains available for normal phone activity.
02YubiKey activationProtected environment is deliberately activated.
03Sensitive workSecurity User data is available only when required.
04Return to OwnerProtected environment can return to an inactive state.

A hardened foundation.
Clear operational separation.

Obris SecureOS is built on GrapheneOS and AOSP, then adds an Obris controlled Security User workflow, physical YubiKey activation, communication restrictions, signed releases and verified installation for supported Pixel devices.

01

Hardened Android foundation

Built from the security focused GrapheneOS and AOSP foundation rather than a conventional consumer Android build.

02

Separate Security User

Sensitive applications, accounts and data can remain separate from the everyday Owner environment.

03

Physical YubiKey control

A compatible enrolled FIDO2 YubiKey forms part of the protected Security User activation workflow.

04

Restricted communications

Cellular SMS and outgoing cellular calls are restricted inside the Security User so sensitive communications remain inside approved encrypted applications.

05

Signed releases and verified installation

Release metadata and images are cryptographically verified, and the installer returns the supported device to a locked bootloader state.

06

Duress controls

The duress workflow removes the protected Security User while leaving the ordinary Owner environment available without requiring a reboot.

Obris SecureOS is derived from GrapheneOS and the Android Open Source Project. References to GrapheneOS describe the upstream technical foundation and do not imply that Obris SecureOS is an official GrapheneOS product.

Reduce exposure. Separate sensitive activity. Control when protected information becomes accessible.

Obris SecureOS does not promise an “unhackable phone.” It is designed to provide stronger technical controls for users who want a more deliberate operational boundary between ordinary mobile use and sensitive information.

Obris SecureOS is a separate operating system distribution developed and maintained independently by Obris Group. GrapheneOS and Android are separate projects and trademarks of their respective owners.