Skip to content
NordSecure
How it works

From your order to a phone that's private by default

You choose the device. We do the technical heavy lifting. You get a phone that protects you the moment it powers on — no setup expertise required.

  1. 1

    Choose your device

    Pick a supported Pixel and storage. We only sell devices that officially support privacy-hardened Android, so verified boot can be fully re-locked afterwards.

  2. 2

    We flash & harden

    We install privacy-hardened Android (GrapheneOS) by hand and apply our hardening: private DNS, sensible security defaults, and optional sandboxed Google Play so your everyday apps still work.

  3. 3

    Verified boot re-locked

    We re-lock the bootloader with the operating system's own verification keys. Your phone checks its own integrity at every boot and warns you if anything was tampered with.

  4. 4

    Ships to you

    Your device ships in discreet, unbranded packaging with tracking. You complete first-boot setup yourself, so your PINs, keys, and logins are only ever known to you.

What happens on first boot

The phone arrives wiped, with nothing signed in. That is deliberate: the setup you do yourself is the part we could not hand over to anyone else, even if we were asked to.

You set the PIN and passphrase

The disk encryption key is derived from a secret you choose on first boot. We never see it, which is the entire reason we do not set it for you — a phone we could unlock is a phone someone could make us unlock.

You choose whether Google Play exists

If you asked for sandboxed Play we leave it available to install; you decide whether to sign in, and with which account. Nothing is signed in when it reaches you.

You verify the device, if you want to

The OS project publishes an attestation app that checks the phone's integrity independently of us. It will tell you the truth about whether verified boot is locked and the system is unmodified — including if we had got it wrong.

You restore your own data

Move over your apps and files at your own pace. There is no migration wizard tied to a cloud account, which is slower on day one and quieter forever after.

After it arrives

What keeps working, what we help with, and what nobody can do for you — including us.

Updates come from the OS project, not from us

Security updates arrive over the air directly from GrapheneOS on their schedule. We are not in the path and cannot delay or alter them — which also means your phone keeps updating normally regardless of what happens to this shop.

Support is for the setup, not the software

We help with getting started, configuration questions, and working out whether an app problem is the OS or the app. We do not develop the operating system and cannot make a bank's app accept it.

We cannot unlock or recover your device

No remote access, no management profile, no recovery key held on your behalf. If the passphrase is lost, the data is gone — by design, and it applies to us exactly as it applies to anyone else.

Questions about a specific app or setup step are worth asking before you order — the FAQ covers the common ones, and we answer the rest.

What's done before it ships

Every device leaves us in the same hardened state. No two-hour setup guide, no half-finished configuration.

  • Privacy-hardened Android (GrapheneOS), installed by hand
  • Verified boot re-locked with the OS's own keys
  • Private DNS configured out of the box
  • Automatic reboot to a stronger at-rest state
  • Optional sandboxed Google Play — apps without the surveillance
  • No Google account, no telemetry, no bloatware
Verify it yourself with public tools → Clean updates, no middleman 30-day money-back

Got a NordSecure eSIM? Here's its life cycle

Our travel eSIMs work the same privacy-first way as our phones — no account, no email, nothing to register.

  1. Step 1

    Buy — card or crypto

    Pick a country and either a fixed data plan or your own amount. No sign-up, no email — pay and you're done.

  2. Step 2

    Save your ICCID + PIN

    Shown exactly once at checkout. The ICCID is your eSIM's own number and your username; the PIN is your password. They can't be recovered — store them safely.

  3. Step 3

    Log in & claim within 14 days

    Scan your activation QR from the account page. Logging in claims your eSIM — unclaimed orders are voided after 14 days.

  4. Step 4

    Top up & spend, forever

    Add more data anytime to the same eSIM — no new QR, nothing to reinstall.

Get an eSIM or log in to yours.

What next?

You now know what happens to the device. The obvious follow-ups are what it costs, and how to confirm we did it.

Your first order can be live in minutes

A hardened phone, an anonymous eSIM, a real number or a one-time code — bought without a name. Card or crypto, nothing stored.

Just need travel data? Browse anonymous eSIMs