FAQ
Do I need a specific phone?
Yes: Égide runs exclusively on a Google Pixel under GrapheneOS, in Device Owner mode. It is the only hardware whose security chip and verified boot reach the required level. The supported models are the phones from the Pixel 7 onwards: Pixel 7, 7 Pro and 7a, Pixel 8, 8 Pro and 8a, Pixel 9, 9 Pro, 9 Pro XL, 9 Pro Fold and 9a, Pixel 10, 10 Pro, 10 Pro XL, 10 Pro Fold and 10a, plus the Pixel Fold. Tablets are excluded: Égide needs a phone. The full list of devices supported by GrapheneOS is published at grapheneos.org/faq#supported-devices. The assistant guides you from end to end, including the installation of GrapheneOS.
How do I get Égide?
Free of charge, and without going through us. There is no shop and no access request: you open the installation assistant, plug in a compatible Pixel, and it does the rest. We ask for no name, no address and no identity document, and there is no account to create. Install the application
What exactly is free?
The installation, and every protection that fires from the device itself: repeated wrong codes, prolonged lock, tamper resistance, choice of wipe mode, camouflage, security updates. They never expire. What is paid for are the remote wipe and the wipe if the phone is cut off from the network. The detail of both
Could the software crash or wipe my phone by mistake during this test phase?
That is a real risk: Égide is still under active development and does not yet have the maturity of a released product. It is provided “as is”, without warranty, at the tester's own risk. See the current-status section at the top of the terms of use for the exact scope of this limitation.
Do you keep access logs (IP address, etc.)?
No. Neither our web server nor our application is configured to write an access log: no IP address, no visited URL and no visit timestamp is retained by the site. Our host, however, operates the network and the machine: its own logs are not ours to control. See the privacy policy.
How do I know Égide is not spyware, like some booby-trapped “secure phones”?
The doubt is healthy, and history proves it right. Several phones sold as “secure” turned out to be exactly the opposite. The ANOM network, dismantled in 2021 (Operation Trojan Shield), was in fact run by the FBI: every message was secretly copied to the police, unknown to the people using it. Phantom Secure before it, then EncroChat in 2020 and Sky ECC in 2021, were closed proprietary systems, cracked or booby-trapped because no one outside the vendor could see what they really did.
What these cases have in common is not technical, it is human: in each one, you had to take the vendor's word for it. That is the reflex everyone has, and it is exactly the one these devices exploited. A security promise you cannot verify is worth nothing, however reassuring it sounds. Égide is built on the opposite principle: do not trust us, verify.
In practice, Égide installs on an ordinary Google Pixel under GrapheneOS, an open system audited by independent third parties, not on closed proprietary hardware. Above all, you can examine it yourself as a “black box”: observe, with the tools of your choice, every network request it makes, when and to where.
This is also how you flush out a backdoor. A backdoor needs to listen: spyware typically opens a “port” that waits for an incoming connection to receive commands, and a simple network scan would reveal it. Égide listens for nothing. It accepts no incoming connection; it only makes outgoing calls, all of which you can see.
What you will observe: in normal use, Égide queries its update channel about once a day, nothing else. If you enable remote wipe, it additionally queries a dedicated Tor (.onion) address, generated at installation and specific to your device alone, never linked to your identity on EndlessLock's side, where a device is designated only by an opaque identifier, with no name and no login account. That same update channel reports the state of your premium credit, which is what the daily round trip is for. If you do not enable remote wiping, no request to that dedicated address is sent. None of this rests on our word: it is all observable.
Since then, part of the answer no longer even requires watching: it can be read. The core of Égide, the part that decides on an erasure and describes every request the application can make, is published, together with the tests that lock it down. What stays closed is the execution machinery, and the repository declares the full list of it.
Is Égide's code public?
In part, and we would rather say so than claim to be “open source”. What is published is what decides: the rules that trigger an erasure, every network request the application can make, the cryptography of the device identity, and the tests that lock all of it down. That is what you need in order to answer the question “does this application spy on me, and can it be turned against me?”.
What is not published is the execution machinery: how the erasure is carried out, how Égide obtains its full powers over the phone, and how it resists being uninstalled. Those parts tell an honest reader nothing; they tell a thief a great deal. The repository still declares the exhaustive list of operations that closed part can perform, so that you know what exists. The details are on the Security page.
Do I need to be an expert?
No. Every step is guided from your browser. If you can plug in a USB cable, you can install Égide.
Is Égide visible on the phone?
By default, yes: Égide has its icon like any other app. You can then turn camouflage on from its settings: Égide leaves the app list, an ordinary utility takes its place, and that utility genuinely works. Égide's interface reopens when you type into it the opening code you chose; the protections, for their part, never stopped running. That code never reaches us: if you lose it, nobody can reopen Égide, not even us.
How is premium paid for?
On a separate service, the top-up portal, never on this site: no page here will ask you for a card or a wallet. There you buy premium credit, in blocks, in Monero or by card. Monero involves no middleman; a card, on the other hand, shows the operation to your bank and to the payment provider. See the plans
What happens to my phone when premium expires?
It stays protected. The free protections carry on without interruption; only the premium options stop triggering a wipe.
What happens if I lose my wipe program?
It cannot be replaced. It is generated on your side, during installation, and we hold no copy of it: nobody, ourselves included, can make you another one for a phone that is already installed.
Losing it means one thing only: you can no longer trigger the remote wipe of that one device. No other. The phone's automatic protections carry on working normally.
For now, getting a wipe program back means reinstalling the phone entirely. A feature is in development to generate that program directly from the Égide app, without reinstalling.
After a wipe, do I have to start over?
In almost every case, yes: a full wipe resets the phone, and a targeted wipe uninstalls Égide along the way. You therefore go through the installation assistant again, which stays free and open to all.
One exception: if you turned off self-destruction, that is Égide removing itself after wiping, a targeted wipe only deletes the secret space and Égide stays in place. That is not the default setting.
The premium service is attached to the device and is found again after a reinstall on the same phone.
Can you wipe my phone for me?
No, and that is deliberate. The remote wipe program is generated in your own browser and is never transmitted to our servers. You alone can trigger the wipe: nobody can compel us to do what we are technically incapable of.
Does a breach of your servers put me at risk?
No. On the enrolment side, our servers hold only public keys; on the showcase side, nothing at all, not even a database; on the top-up side, a premium credit designated by an obfuscated, derived fingerprint. No identity anywhere. Your device's security rests on a key sealed inside its processor, out of our reach.
Is this legal?
Protecting one's own data is in principle a legitimate purpose, and payment in Monero is not prohibited in itself. Actual use must nevertheless comply with the law, with sanctions, with the rights of third parties and with professional duties. Égide prohibits in particular installation without authorisation, monitoring or wiping without right, harming others, and the destruction of evidence or of data subject to a retention obligation.
What happens if your website disappears?
Nothing for your phone. Everything that protects you runs on the device itself, and the update channel is a separate Tor service that does not depend on this site. The showcase only presents the product: its disappearance disarms nothing.