Skip to content
NordSecure
Verify

Don't trust us. Check.

Every claim on this site about how your phone was prepared can be tested by you, with software we do not control, in about five minutes.

A shop that tells you how to catch it lying is making a different kind of claim than one that asks to be believed.

We could tell you the bootloader is re-locked and the system is untouched. Instead, here is how to confirm it without taking our word for anything — using an app published by the operating system's own project, checked against keys we do not hold.

How to check, step by step

  1. 1

    Look at the boot screen

    Power the phone on and watch the first screen. A device whose bootloader is unlocked says so, every single boot, with a warning that cannot be suppressed. Silence there is the first signal that verified boot is properly locked.

  2. 2

    Install the Auditor app

    The GrapheneOS project publishes an attestation app called Auditor. Install it from the OS's own app repository or from F-Droid — deliberately not from a link we control, because the point is to use software whose provenance does not depend on us.

  3. 3

    Run a local attestation

    Auditor can check the device it is running on. It asks the phone's security chip to prove, cryptographically, which operating system booted and whether verified boot is enforcing. The hardware answers, not the software being questioned.

  4. 4

    Pair a second device for the strongest check

    Auditor's strongest mode uses a second phone as the auditor and yours as the auditee. The pair remember each other, so future checks detect changes since the first pairing — including a system swapped while the phone was away from you.

  5. 5

    Read the result honestly

    You are looking for a locked bootloader, a verified-boot state of 'green', and the operating system identified as GrapheneOS. If any of those is wrong, something is wrong — and you should tell us, because we would want to know.

Walk through it, and check your result

Tick each step as you do it, then answer what you saw. Everything stays in your browser.

What did the result show?

Is the bootloader locked — no warning screen on power-on?

Does Auditor report the verified-boot state as green / enforcing?

Is the operating system identified as GrapheneOS?

Your device passes verification

Locked bootloader, verified boot enforcing, and GrapheneOS confirmed — that's exactly what a genuine, unmodified device should report. The hardware said so, not us.

What this proves

  • The bootloader is locked, so the phone will not silently boot a modified system.
  • The operating system that booted is the one it claims to be, signed with the expected key.
  • The security chip — not an app, and not us — is the thing making the statement.

What it doesn't

  • It does not prove the hardware was never physically opened before it reached you.
  • It does not audit the apps you install afterwards, or the permissions you grant them.
  • It does not make your network traffic private — that is a separate problem, and a VPN's job.

If the check fails

Tell us, with the result on screen. A failed attestation on a phone we prepared means either we made a mistake or something happened to the device in transit — and both are things we need to know about rather than argue with. We would rather replace a device than have one in the world that does not do what this page says it does.