{
  "cells": {
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says F-Droid Basic is its preferred app store and that its default F-Droid store installs during setup, while Aurora Store provides the option to install apps without a Google account and, for paid apps or if anonymous mode is not working, lets the user additionally enter Google account credentials in its settings (some paid apps may not work).",
      "fetch_event_id": "8d524537-cb6e-5c82-8e41-667a4644a625",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "App Stores F-Droid Basic F-Droid Basic is the preferred app store for CalyxOS. All the apps available in F-Droid are free and open source software, and contain no trackers or advertising. CalyxOS’ default app store, F-Droid installs during the Setup Wizard to enable seamless app downloads on your first day running CalyxOS. In addition to the standard F-Droid source for apps (aka “repository”), CalyxOS includes a source for CalyxOS apps, which allows us push out out-of-band updates for various apps when needed. In earlier versions, CalyxOS gave the client app (F-Droid) special privileges to streamline app updates, installs, and uninstalls. However, since CalyxOS 5.1.2 , these privileges have been dropped for new installs in favor of a newer client app (F-Droid Basic). Aurora Store Aurora Store is an alternative client to the standard Google Play Store . It uses the same standard catalog of apps and installs apps directly from the Google servers. Aurora Store provides the option to download and install applications without your Google account. If you want to install paid apps, or if anonymous mode is not working, you can additionally enter your Google account credentials in the Aurora Store settings (some paid apps may not work). CalyxOS gives Aurora Store special privileges so that app updates can be automatically installed. New app installs and uninstalls still must be confirmed as normal.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8f81bf43f85ba1899f2896d70be8dcc303684850cee155ef131cc9de9576a705",
      "source_url": "https://calyxos.org/docs/guide/apps/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "CalyxOS identifies a security assessment titled Calyx Institute HSM Provisioning Ceremony Scripts Security Assessment, dated January 23, 2026.",
      "fetch_event_id": "416ac719-7f48-5428-936e-c6ed2d87611f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Calyx Institute HSM Provisioning Ceremony Scripts Security Assessment January 23, 2026",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "94dec8f3715658abbbf6ccc23e04fa1b6f90524fd405d7c1f1a85d85be3e46ce",
      "source_url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-01-calyx-hsm-provisioning-ceremony-scripts-securityreview.pdf",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says personal information is kept on an encrypted basis while a person remains a Calyx member or registered user, then deleted promptly once retention is no longer required by policy or law.",
      "fetch_event_id": "862bc4a3-fa8b-5774-894f-b8a6d7af39dd",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Any personal information will be maintained and protected on an encrypted basis for as long as you are a Member or maintain your registration with us. If you cease being a Member of Calyx, your personal information will be deleted promptly once we are no longer required to retain such information in accordance with our retention policy and applicable law.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "103aff2e38454c4ddfe17e7002caa01a7068c5af50b4d6ba3b93342ca8433b8c",
      "source_url": "https://calyx.org/legal/privacy-policy",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.device_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says it tries to support devices as long as possible and publishes estimated operating-system-upgrade and security-update dates by device.",
      "fetch_event_id": "c5838136-c8da-563e-89c8-2278d0f7826c",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "CalyxOS utilizes Verified Boot (including bootloader re-locking) to keep the Android security model intact. Support length *Note that these are the current estimated dates. We try to support devices as long as possible, but it’s hard to determine feasibility years in advance, so we’ll keep updating these the closer we get to the dates. Google Pixel support dates Google Pixel Tablet support date Fairphone Motorola Upcoming devices Device(s) OS upgrades Security updates Pixel 10a March 2033* March 2033* Modern devices Device(s) OS upgrades Security updates The Fairphone (Gen. 6) Android 17* June 2033* Fairphone 5 Android 16* September 2031* Motorola moto g 5G - 2024 Android 16* March 2027* Motorola moto g84 5G Android 16* December 2026* Motorola moto g34 5G, g45 5G Android 16* January 2027* Pixel 9a April 2032 April 2032 Pixel 9, 9 Pro, 9 Pro XL, 9 Pro Fold August 2031 August 2031 Pixel 8a May 2031 May 2031 Pixel 8, 8 Pro October 2030 October 2030 Pixel Fold June 2028 June 2028 Pixel Tablet December 2026 June 2028 Pixel 7a May 2028 May 2028 Pixel 7, 7 Pro October 2027 October 2027 Pixel 6a July 2027 July 2027 Pixel 6, 6 Pro December 2026 December 2026 SHIFTphone 8 Android 16* December 2026* Extended support Device(s) OS upgrades Security updates Fairphone 4 Android 16 December 2026 Motorola moto g52 Android 16* December 2026 Motorola moto g42 Android 16* December 2026 Motorola moto g32 Android 16* December 2026 Pixel 5a (5G) Android 16* December 2026 Pixel 4a (5G) Android 16* December 2026 Pixel 5 Android 16* December 2026 No longer supported Device(s) OS upgrades Security updates OnePlus 8T, 9, 9 Pro Beta Android 12 May 2022 Pixel 4a Android 14 March 2025 Pixel 4, 4 XL Android 14 March 2025 Pixel 3a, 3a XL Android 14 March 2025 Pixel 3, 3 XL Android 14 March 2025 Pixel 2, 2 XL Android 11 February 2022 SHIFT SHIFT6mq Android 14 March 2025 Xiaomi Mi A2 Android 11 February 2022 * We generally intend to get monthly security updates out as soon as possible after their release. The process takes some time since we don’t get early access but generally the goal is to get them out to the stable channel in the same week as AOSP release. Major version updates (such as the current Android 17 release) take longer because we have to port all of our changes to the new version, which can be a lot of work.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "eba30281caf53c462f8285c4403fd08ab391e21cfb9049ef67a4c8e250a69548",
      "source_url": "https://calyxos.org/docs/guide/device-support/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "66efe83a-dd47-5955-bdb3-f1ce3118c22c",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Frequently Asked Questions 🙋 Get answers to some of the most common questions!",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "01d66d209d9dbd845cd648123b3f0e6363eb191eb56f10fabfae2ad548683b45",
      "source_url": "https://calyxos.org/docs/guide/faq/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
      "fetch_event_id": "a940eb47-8225-537c-bd6e-71aa3cd8bab3",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Calyx Institute End-User Terms of Service These terms apply to all Calyx services and websites.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "526f60b59c1037532eebbc2295f0f298a6830c2f8448d841d166b0a514823f48",
      "source_url": "https://calyx.org/legal/terms-of-service",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says it shares available personal information with law enforcement or government agencies with the user's written consent, under apparently valid legal process, or when applicable law requires disclosure.",
      "fetch_event_id": "94f6f192-4233-5e69-8f36-402b6803fbfe",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "V. How We Respond to Requests for Data from Law Enforcement and Government Agencies We will share personal information available to us with law enforcement or other government agency in any of the following circumstances: With the user’s written and signed consent; When the request is made pursuant to a warrant, subpoena, court order, or other apparently valid legal process; or When we are required in other instances to disclose personal information in order to comply with applicable law.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "103aff2e38454c4ddfe17e7002caa01a7068c5af50b4d6ba3b93342ca8433b8c",
      "source_url": "https://calyx.org/legal/privacy-policy",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says release.calyxos.org per-request logs are retained briefly before aggregation and destruction, while long-term aggregate data contains request totals by country and device model.",
      "fetch_event_id": "c06ba9fc-fbd7-551d-bd42-77c4e9a2fb07",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "How does Calyx Institute use the data collected by release.calyxos.org? We retain per-request logs for a short period of time before these logs are aggregated and destroyed. The per-request logs may include IP address, country of origin, and device model. The aggregated long term data includes total counts of requests by country and by device model. Per-request logs are kept strictly private without Calyx Institute.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c1f60bee67856ffd8362fa04811027089896fe7174862a047e129b9973caecf6",
      "source_url": "https://calyxos.org/docs/guide/security/network-activity/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS provides a work profile and says its apps will not access data from the main profile, even if they are duplicates.",
      "fetch_event_id": "cf6b1e6d-3da6-5d1d-a9a4-b8fffb7ff444",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "A work profile is available for all users on the phone. The CalyxOS team has made accessing the work profile easy. You do not need to restart or log out of the device. Swipe up on the homescreen to see all of your apps. Swipe left to see the apps in your work profile. These apps will not access the data from the main profile, even if they are duplicates.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "90cf187d6002b52105bd866034bc769e7eb736ad9adb1c742ac2ce1b884a9592",
      "source_url": "https://calyxos.org/docs/guide/getting-started/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS offers microG modes without a Google Account and a mode with a Google Account.",
      "fetch_event_id": "e480be80-d64d-5cfd-9a46-b83c4d6247c8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Options for running microG in CalyxOS 1. microG disabled 2. microG enabled, no Google Account, push notifications disabled 3. microG enabled, no Google Account, push notifications enabled (default) 4. microG enabled, with a Google Account",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "20243ef66f450f21a2c5b307d1196de8593cc06a8e7744e5e894684c1c1cfb8e",
      "source_url": "https://calyxos.org/docs/guide/microg/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says its development occurs in public source-code repositories, with source available on GitLab and mirrored to GitHub.",
      "fetch_event_id": "0f12a7e8-bdc8-54d0-b827-1c8a05675dd3",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "CalyxOS is Free and Open Source Software. Source code All development of CalyxOS takes place out in the open on public source code repositories. We would love to have you get involved. Our source code is available for review at gitlab.com/CalyxOS . It is also mirrored to github.com/CalyxOS .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a2b80820b395d6eabcefaf1492e5ce2a1ca198c05af7ac87f402ba28e1fd0c77",
      "source_url": "https://calyxos.org/docs/development/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says the operating system or microG initiates connections for system updates, anti-tracking-filter updates, optional online location services, and GPS-assistance data.",
      "fetch_event_id": "9351f943-2872-5e4f-82ca-030926324c10",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "CalyxOS connections These network connections are initiated by the operating system itself (or microG). Domain Purpose release.calyxos.org Used to check for Over-The-Air CalyxOS system updates. www.bromite.org To update the anti-tracking filters built into the OS. api.positon.xyz Used by microG as an online location service. Only used if you selected it, you can disable or modify it in microG settings. api.beacondb.net Used by microG as an online location service. Only used if you selected it, you can disable or modify it in microG settings. xtrapath1.izatcloud.net This is a service of Qualcomm to allow the baseband processor to more quickly achieve a lock on GPS satellites by downloading a list of the positions of known GPS satellites.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c1f60bee67856ffd8362fa04811027089896fe7174862a047e129b9973caecf6",
      "source_url": "https://calyxos.org/docs/guide/security/network-activity/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says installed devices automatically check for, download, and install frequent over-the-air updates from its servers, typically monthly after Android Open Source Project security releases.",
      "fetch_event_id": "754867fd-f5ab-58bb-884e-3d416eb3a79c",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Once CalyxOS is installed on the device, it will receive frequent Over-The-Air (OTA) updates directly from our servers automatically. OS updates The device automatically checks for, downloads and install updates. A reboot is required to finish updating, you will get a notification for that. Updates are typically done monthly, following Android Open Source Project security releases. You can check for updates and control update settings from Settings -> System -> Updates . A changelog can also be viewed there, or by tapping the update notification.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2ccb70aa9935b4d8cb72aacbaf72d5f60aa9f0b7dfb9442199246d31468b9a8d",
      "source_url": "https://calyxos.org/docs/guide/updates/",
      "table": "vendor"
    },
    "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "CalyxOS says it supports fully verified boot and bootloader re-locking to ensure the operating system has not been modified and maintain physical security equivalent to stock Android.",
      "fetch_event_id": "ac6b430f-7856-5d71-b878-2297de28e3b3",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verified Boot CalyxOS supports fully verified boot and bootloader re-locking to ensure that the OS has not been modified and maintain physical security equivalent to stock Android.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "17778217890e573a674ce67f656d91015e44fe6131b29561fddd59ff9dd73903",
      "source_url": "https://calyxos.org/features/list/",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says its standalone apps are developed by GrapheneOS and included in the OS; the list excludes apps with no GrapheneOS modifications or only minor ones.",
      "fetch_event_id": "2136ff90-fb2b-5365-8ba1-dde384dfe37b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Standalone apps These are standalone app projects developed by GrapheneOS and included in the OS. This does not include the many apps included by AOSP without modifications by GrapheneOS or with only minor modifications. App Store Auditor Camera Info Messaging PDF Viewer talkback : GrapheneOS fork of the open source TalkBack screen reader Vanadium : Privacy and security focused Chromium-based browser and WebView",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4552bbe656ba237c651764114cc0e3ea41164f10ebf4215bd9a00f9adce7ef9b",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/source.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "GrapheneOS says its code is continuously reviewed by external security researchers, companies, and organizations, with most review and audit results visible through public pull requests and issue trackers.",
      "fetch_event_id": "4f960779-62fd-5068-a2d7-8025ab02a8e1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Is GrapheneOS audited? Yes, the GrapheneOS code is reviewed by external security researchers, companies and organizations on a continuous basis. This is the main benefit of GrapheneOS being an open source project actively used by other organizations, but it is certainly not something to take for granted based on a project being open source. We put a lot of work into making our code well documented and easy to review. Auditing and code review cannot be done properly as a one time thing but rather need to be done continuously as the code changes. Most of the code review and auditing results for GrapheneOS can be seen from the public pull requests and issue trackers. For example, the French ANSSI organization uses a bunch of our work and has given us suggestions along with reporting issues including a couple issues in hardened_malloc where it could have a false positive detection of memory corruption and wrongly abort the process. [1] [2] We've built relationships with security researchers and organizations interested in GrapheneOS or using it which results in a lot of this kind of collaboration. This is not a one-time event but rather something that happens regularly as the code evolves, features are added and we ported to new release. The benefits of a group unfamiliar with the code spending a short time doing a shallow review are greatly overstated in marketing. We instead focus on having people very familiar with areas of the code regularly auditing all our changes. The large number of upstream Android security vulnerabilities discovered by GrapheneOS despite us not actively seeking them out speaks to the results of our review and testing.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a5cf1229f0d09e52d310e573ebfbd39eea980520d0213e21505291daaddda538",
      "source_url": "https://grapheneos.org/faq",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says deleting a profile wipes its corresponding Weaver slot, while a factory reset wipes all Weaver slots.",
      "fetch_event_id": "f151b415-6ac5-5d74-a644-d9aaa35bb64e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "How is disk encryption implemented? GrapheneOS uses an enhanced version of the modern filesystem-based disk encryption implementation in the Android Open Source Project. The officially supported devices have substantial hardware-based support for enhancing the security of the encryption implementation. GrapheneOS has full support for the hardware-based encryption features just as it does with other hardware-based security features. Firmware and OS partitions are identical copies of the images published in the official releases. The authenticity and integrity of these partitions is verified from a root of trust on every boot. No data is read from any of these images without being cryptographically verified. Encryption is out of scope due to the images being publicly available. Verified boot offers much stronger security properties than disk encryption. Further details will be provided in another section on verified boot in the future. The data partition stores all of the persistent state for the operating system. Full disk encryption is implemented via filesystem-based encryption with metadata encryption. All data, file names and other metadata is always stored encrypted. This is often referred to as file-based encryption but it makes more sense to call it filesystem-based encryption. It's implemented by the Linux kernel as part of the ext4 and f2fs implementation rather than running a block-based encryption layer. The advantage of filesystem-based encryption is the ability to use fine-grained keys rather than a single global key that's always in memory once the device is booted. Disk encryption keys are randomly generated with a high quality CSPRNG and stored encrypted with a key encryption key. Key encryption keys are derived at runtime and are never stored anywhere. Sensitive data is stored in user profiles. User profiles each have their own unique, randomly generated disk encryption key and their own unique key encryption key is used to encrypt it. The owner profile is special and is used to store sensitive system-wide operating system data. This is why the owner profile needs to be logged in after a reboot before other user profiles can be used. The owner profile does not have access to the data in other profiles. Filesystem-based encryption is designed so that files can be deleted without having the keys for their data and file names, which enables the owner profile to delete other profiles without them being active. GrapheneOS enables support for ending secondary user profile sessions after logging into them. It adds an end session button to both the global action menu accessed by holding the power button and the user switcher interface. This fully purges the encryption keys and puts the profiles back at rest. This can't be done for the owner profile without rebooting due to it encrypting the sensitive system-wide operating system data. Using a secondary profile for regular usage allows you to make use of the device without decrypting the data in your regular usage profile. It also allows putting it at rest without rebooting the device. Even if you use the same passphrase for multiple profiles, each of those profiles still ends up with a unique key encryption key and a compromise of the OS while one of them is active won't leak the passphrase. The advantage to using separate passphrases is in case an attacker records you entering it. File data is encrypted with AES-256-XTS and file names with AES-256-CTS. A unique key is derived using HKDF-SHA512 for each regular file, directory and symbolic link from the per-profile encryption keys, or the global encryption key for non-sensitive data stored outside of profiles. The directory key is used to encrypt the file names. GrapheneOS increases the file name padding from 16 bytes to 32 bytes. AES-256-XTS with the global encryption key is also used to encrypt filesystem metadata as a whole beyond the finer-grained file name encryption. The OS derives a password token from the profile's lock method credential using scrypt. This is used as the main input for key derivation. The OS stores a high entropy random value as the Weaver token on the secure element (Titan M on Pixels) and uses it as another input for key derivation. The Weaver token is stored alongside a Weaver key derived by the OS from the password token. In order to retrieve the Weaver token, the secure element requires the correct Weaver key. A secure internal timer is used to implement hardware-based delays for each attempt at key derivation. Only a total of 20 attempts is permitted. Weaver also provides reliable wiping of data since the secure element can reliably wipe a Weaver slot. Deleting a profile will wipe the corresponding Weaver slot and a factory reset of the device wipes all of the Weaver slots. The secure element also provides insider attack resistance preventing firmware updates before authenticating with the owner profile.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4b88c9d8d2f07794c5f5b4d0d4a231ea654f6c9ca375af07d2d1cfb7cbe1e123",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.device_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says devices sold through some carriers may be locked and prevent installation, while officially supported devices have builds and updates available from release tags.",
      "fetch_event_id": "a624c5b1-d9bb-5650-bf44-704ea226b9bb",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Which devices are supported? Devices sold in partnership with specific carriers may be locked by the carrier, which will prevent installing GrapheneOS. This is primarily an issue with US carriers and isn't common elsewhere in the world. To avoid this, either don't buy a carrier device, or make sure it can be unlocked. It's the same hardware/firmware/software either way but carriers dislike having devices able to bypass their paywall for tethering, etc., so they disable it for the devices they sell as part of contracts. GrapheneOS has official production support for the following devices: Pixel 10a (stallion) Pixel 10 Pro Fold (rango) Pixel 10 Pro XL (mustang) Pixel 10 Pro (blazer) Pixel 10 (frankel) Pixel 9a (tegu) Pixel 9 Pro Fold (comet) Pixel 9 Pro XL (komodo) Pixel 9 Pro (caiman) Pixel 9 (tokay) Pixel 8a (akita) Pixel 8 Pro (husky) Pixel 8 (shiba) Pixel Fold (felix) Pixel Tablet (tangorpro) Pixel 7a (lynx) Pixel 7 Pro (cheetah) Pixel 7 (panther) Pixel 6a (bluejay) Pixel 6 Pro (raven) Pixel 6 (oriole) The release tags for these devices have official builds and updates available. These devices meet the stringent privacy and security standards and have substantial upstream and downstream hardening specific to the devices. We provide extended support releases as a stopgap for users to transition to the far more secure current generation devices. Many other devices are supported by GrapheneOS at a source level, and it can be built for them without modifications to the existing GrapheneOS source tree. Device support repositories for the Android Open Source Project can simply be dropped into the source tree, with at most minor modifications within them to support GrapheneOS. In most cases, substantial work beyond that will be needed to bring the support up to the same standards. For most devices, the hardware and firmware will prevent providing a reasonably secure device, regardless of the work put into device support. GrapheneOS does not support being used as a Generic System Image, which only exists for development/testing purposes and isn't usable for GrapheneOS since we require kernel changes and the userspace part of the OS cannot run on top of a kernel without the required functionality. The generic targets simply run on top of the underlying device support code (firmware, kernel, device trees, vendor code) rather than shipping it and keeping it updated. It would be possible to ship generic system images with separate updates for the device support code. However, it would be drastically more complicated to maintain and support due to combinations of different versions and it would cause complications for the hardening done by GrapheneOS. The motivation doesn't exist for GrapheneOS, since full updates with deltas to minimize bandwidth can be shipped for every device and GrapheneOS is the only party involved in providing the updates. For the same reason, it has little use for the ability to provide out-of-band updates to system image components including all the apps and many other components. Some of the GrapheneOS sub-projects support other operating systems on a broader range of devices. Device support for Auditor and AttestationServer is documented in the overview of those projects . The hardened_malloc project supports nearly any Linux-based environment due to official support for musl, glibc and Bionic along with easily added support for other environments. It can easily run on non-Linux-based operating systems too, and supporting some like HardenedBSD is planned but depends on contributors from those communities.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4b88c9d8d2f07794c5f5b4d0d4a231ea654f6c9ca375af07d2d1cfb7cbe1e123",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": null,
      "fetch_event_id": "1ffaf5a7-90dc-5d3f-93b9-1814502a2411",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "GrapheneOS has two officially supported installation methods.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4b88c9d8d2f07794c5f5b4d0d4a231ea654f6c9ca375af07d2d1cfb7cbe1e123",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
      "fetch_event_id": "460ae391-0b1c-5471-a933-7678ba6dfde8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "GrapheneOS now has multiple full-time and part-time developers supported by donations and multiple companies collaborating with the project. GrapheneOS Foundation was created as a non-profit organization in Canada in March 2023 to handle the intake and distribution of donations.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "6a483338ee32251e6519ac2dca3307963b31520855673dca0014f3c1f44f9d94",
      "source_url": "https://grapheneos.org/history/",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "GrapheneOS says it is not able to comply with a government order to build, sign, and ship a malicious update to a specific device based on information such as an IMEI or serial number, and it rejects updates constrained to a serial number.",
      "fetch_event_id": "e6b3defc-8594-595b-b49a-8af54227e36a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Security The update server isn't a trusted party since updates are signed and verified along with downgrade attacks being prevented. The update protocol doesn't send identifiable information to the update server and works well over a VPN or Tor. GrapheneOS isn't able to comply with a government order to build, sign and ship a malicious update to a specific user's device based on information like the IMEI, serial number, etc. The update server only ends up knowing the IP address used to connect to it and the version being upgraded from based on the requested incremental. Android updates can support serialno constraints to make them validate only on a certain device but GrapheneOS rejects any update with a serialno constraint for both over-the-air updates (Updater app) and sideloaded updates (recovery).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "215f8a50c227aceb9aa9f2ee808b0c9ac2043e3d7bc7302e21e1a9566acecfda",
      "source_url": "https://grapheneos.org/usage#updates",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "GrapheneOS says its public-service servers retain logs for at most 10 days, with a lower limit or no persistent logs for some services.",
      "fetch_event_id": "80cb240c-dba3-591f-93de-36297050e980",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "What is the privacy policy for GrapheneOS services? GrapheneOS services follow the EFF's privacy-friendly Do Not Track (DNT) policy for all users of our publicly available services, not just those opting out of tracking via Do Not Track. Our policy is the same with \"DNT User\" redefined as \"user\" to cover any user. This serves as a standard privacy policy across all of our public services: attestation.app grapheneos.network grapheneos.online grapheneos.org grapheneos.social apps.grapheneos.org broadcom.psds.grapheneos.org samsung.psds.grapheneos.org qualcomm.psds.grapheneos.org discuss.grapheneos.org element.grapheneos.org mail.grapheneos.org matrix.grapheneos.org releases.grapheneos.org remoteprovisioning.grapheneos.org widevineprovisioning.grapheneos.org supl.grapheneos.org time.grapheneos.org gs-loc.apple.grapheneos.org update.vanadium.app dl.vanadium.app Our implementation of the policy primarily consists of making sure our servers only retain logs for at most 10 days with a lower limit or no persistent logs for certain services. In practice, we follow much stricter privacy guidelines than the rules laid out in the EFF policy. However, we don't want to define our own complex, ad-hoc privacy policy rather than reusing a sensible one with serious thought put into it by experts. Our mail server (mail.grapheneos.org), Matrix server (matrix.grapheneos.org), Element instance (element.grapheneos.org) and Mastodon server (grapheneos.social) only provide accounts for GrapheneOS project members so most functionality is outside the scope of what's relevant to a public privacy policy.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a5cf1229f0d09e52d310e573ebfbd39eea980520d0213e21505291daaddda538",
      "source_url": "https://grapheneos.org/faq",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says it hardens the app sandbox through SELinux and seccomp-bpf policy and also improves other sandboxes, including the browser-renderer sandbox.",
      "fetch_event_id": "fc9ecfa5-fbe3-58aa-a247-0b374f06595b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Improved sandboxing GrapheneOS improves the app sandbox through hardening SELinux policy and seccomp-bpf policy along with all the hardening to components like kernel implementing the app sandbox and providing a path for the attacker to escape it if they can exploit those components. We primarily focus on the app sandbox, but we also improve the other sandboxes including making direct improvements to the web browser renderer sandbox used for both the default browser and WebView rendering engine provided by the OS and used by a huge number of other apps from dedicated browsers to messaging apps.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "a112c3b243c904c6e6136c6eafe80a3a854c485004a18b4dc6b299f374b25fe3",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/features.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says it does not provide Factory Reset Protection because the standard implementation depends on tying a device to an online-service account.",
      "fetch_event_id": "fcffa230-9f91-52b5-940a-eef491a75090",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Does GrapheneOS provide Factory Reset Protection? No, since this is strictly a theft deterrence feature, not a security feature, and the standard implementation depends on having the device tied to an account on an online service. The only advantage would be encouraging thieves to return a stolen device for a potential reward after realizing that it has no value beyond scrapping it for parts. Google's Factory Reset Protection ties devices to a Google account using a tiny, special region of persistent state not wiped by a factory reset. It prevents a thief from wiping the device to a fresh state for resale without being stuck at a screen for authenticating with the Google account persisted on the device after wiping. Google's approach works well because if users forget their Google password, there are account recovery methods available to avoid a bricked phone. It would be possible to make an implementation not reliant upon an online service where the user has the option to enable Factory Reset Protection and is given a seed phrase required to use the device after wiping data from recovery. However, since this has no security value and the ability to deter theft is questionable, implementing this is an extremely low priority. Users will end up with a bricked phone if they lose the seed phrase and need to wipe the phone after forgetting their passphrase or something else causing them to need to wipe such as breaking the OS via the Android Debug Bridge shell. Bricked phones would be a far bigger problem than any theft deterrence this could provide. This approach may be implemented by GrapheneOS in some form in the future but it's a low priority and we don't want to cause people to brick their phones. We won't be able to offer any help if people brick their phones with this. Providing the option to disable wiping from recovery would be simpler, but would be incompatible with features designed to wipe data automatically in certain cases. It would also result in far more bricked phones than the seed phrase approach describe above since setting a new lock method and forgetting it which is a relatively common occurrence would mean a bricked phone. This will not be implemented by GrapheneOS since it isn't a good approach and it conflicts with other planned features.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4b88c9d8d2f07794c5f5b4d0d4a231ea654f6c9ca375af07d2d1cfb7cbe1e123",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says it is an open-source project with an open development process and many source repositories.",
      "fetch_event_id": "3d25f30a-53e5-570b-8612-e1abb39d0bfe",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Source code GrapheneOS is an open source project with an open development process. The GrapheneOS sources are hosted in the GrapheneOS organization on GitHub . Since there are many repositories, this page aims to provide a guide for it. See the reporting issues section on the contact page for an comparable overview of where issues should be filed. Table of contents GrapheneOS Standalone apps Services Utilities Archive",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4552bbe656ba237c651764114cc0e3ea41164f10ebf4215bd9a00f9adce7ef9b",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/source.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says it has no analytics or telemetry and makes default remote connections only to GrapheneOS services and network-provided DNS resolvers.",
      "fetch_event_id": "3d98ddea-6def-5341-8b3b-546570e59f23",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "What kind of connections do the OS and bundled apps make by default? By default, GrapheneOS only makes remote connections to GrapheneOS services and the network provided DNS resolvers. There aren't any analytics/telemetry in GrapheneOS. The only information revealed to the GrapheneOS servers are the generic device model (such as Pixel 7 Pro) and OS version which are necessary for obtaining updates. The default connections provide the OS and apps with updates, set the system clock, check each network connection for internet connectivity, download a global database (does not vary based on location) with predicted satellite locations when using Location and obtain attestation chain signing keys for the hardware keystore needed for the hardware-based attestation feature. Make sure to read the other connections section below this one too which covers non-default connections triggered by having a certain carrier, having apps installed, etc. The expected default connections by GrapheneOS (including all base system apps) are the following: The GrapheneOS System Updater app fetches update metadata from https://releases.grapheneos.org/ DEVICE - CHANNEL approximately once every six hours when connected to a permitted network for updates. Once an update is available, it tries to download https://releases.grapheneos.org/ DEVICE -incremental- OLD_VERSION - NEW_VERSION .zip for a delta update, and then falls back to https://releases.grapheneos.org/ DEVICE -ota_update- NEW_VERSION .zip. No query or data is sent to the server, so the only information given to it are the variables in these 3 URLs (device, channel, current version) which is necessary to obtain the update. Users are in control of which types of networks the Updater app will use and can disable the Updater app in extreme cases.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "4b88c9d8d2f07794c5f5b4d0d4a231ea654f6c9ca375af07d2d1cfb7cbe1e123",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says its updater checks approximately every six hours when network connectivity is available, then downloads and installs updates in the background.",
      "fetch_event_id": "95bbed68-2263-5581-9379-da0d4c4e18df",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Updates The update system implements automatic background updates. It checks for updates approximately once every six hours when there's network connectivity and then downloads and installs updates in the background. It will pick up where it left off if downloads are interrupted, so you don't need to worry about interrupting it. Similarly, interrupting the installation isn't a risk because updates are installed to a secondary installation of GrapheneOS which only becomes the active installation after the update is complete. Once the update is complete, you'll be informed with a notification and simply need to reboot with the button in the notification or via a normal reboot. If the new version fails to boot, the OS will be rolled back to the past version and the updater will attempt to download and install the update again. The updater will use incremental (delta) updates to download only changes rather than the whole OS when one is available to go directly from the installed version to the latest version. As long as you have working network connectivity on a regular basis and reboot when asked, you'll almost always be on one of the past couple versions of the OS which will minimize bandwidth usage since incrementals will always be available. The updater works while the device is locked and idle, including before the first unlock since it's explicitly designed to be able to run before decryption of user data. Release changelogs are available in a section on the releases page . Settings The settings are available in the Settings app in System > System update . The \"Check for updates\" option will manually trigger an update check as soon as possible. It will still wait for the configuration conditions listed below to be satisfied, such as being connected to the internet via one of the permitted network types. The \"Release channel\" setting can be changed from the default Stable channel to the Beta channel if you want to help with testing. The Beta channel will usually simply follow the Stable channel, but the Beta channel may be used to experiment with new features. The \"Permitted networks\" setting controls which networks will be used to perform updates. It defaults to using any network connection. It can be set to \"Non-roaming\" to disable it when the cellular service is marked as roaming or \"Unmetered\" to disable it on cellular networks and also Wi-Fi networks marked as metered. The \"Require battery above warning level\" setting controls whether updates will only be performed when the battery is above the level where the warning message is shown. The standard value is at 15% capacity. The \"Require device to be charging\" setting controls whether updates will only be performed when the device is charging. Enabling the opt-in \"Automatic reboot\" setting allows the updater to reboot the device after an update once it has been idle for a long time. When this setting is enabled, a device can take care of any number of updates completely automatically even if it's left completely idle. The \"Notification settings\" option is a shortcut to the System Updater notification settings which allows you to control notification settings from System Updater such as notification dot, lock screen, and noisy or silent notifications. These notifications include updater errors, progress, already up to date, and reboot prompts. By default all notifications are enabled. Security The update server isn't a trusted party since updates are signed and verified along with downgrade attacks being prevented. The update protocol doesn't send identifiable information to the update server and works well over a VPN or Tor. GrapheneOS isn't able to comply with a government order to build, sign and ship a malicious update to a specific user's device based on information like the IMEI, serial number, etc. The update server only ends up knowing the IP address used to connect to it and the version being upgraded from based on the requested incremental. Android updates can support serialno constraints to make them validate only on a certain device but GrapheneOS rejects any update with a serialno constraint for both over-the-air updates (Updater app) and sideloaded updates (recovery).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "ef8d3db60406e7892f93784c706610a546388c0a63c8e02e62a636c1f8921e44",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/usage.html",
      "table": "vendor"
    },
    "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "public_record",
      "display": "GrapheneOS says locking the bootloader enables full verified boot, which detects OS-partition modifications and prevents reading modified or corrupted data.",
      "fetch_event_id": "1efcbef6-9213-567f-a032-c84914c9354e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Locking the bootloader Locking the bootloader is important as it enables full verified boot. It also prevents using fastboot to flash, format or erase partitions. Verified boot will detect modifications to any of the OS partitions and it will prevent reading any modified or corrupted data. If changes are detected, error correction data is used to attempt to obtain the original data at which point it's verified again which makes verified boot robust to non-malicious corruption. In the bootloader interface, set it to locked: fastboot flashing lock The command needs to be confirmed on the device and will wipe all data. Use one of the volume buttons to switch the selection to accepting it and the power button to confirm.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "b07931fd9440fcf527eea0edcadf71044216ad9127cb7d9dfa5eb2cac281976b",
      "source_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/install/cli.html",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says the design principle for iPhone and iPad focuses on centralized distribution, code signing, and strict sandboxing, while European Union users can also install apps from alternative marketplaces or authorized developer websites.",
      "fetch_event_id": "ac1afadf-9a35-5848-b8c5-8c8d57651b69",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "On iPad and iPhone, the design principle focuses on centralized distribution, code signing, and strict sandboxing to provide the tightest controls. To reflect the Digital Market Act’s requirements, users in the European Union (EU) can install apps from alternative app marketplaces and directly from an authorized developer’s website, which introduces additional risks. Apple introduced protections, including (but not limited to): • Notarization for apps • An authorization for marketplace developers • Disclosures on alternative payments • Install confirmations that provide the user Apple-verified information about the app These help to reduce risks and deliver the best, most secure experience possible for users in the EU. Even with these safeguards in place, many risks remain including a greater prevalence of malware, fraud and scams, illicit and harmful content, and other privacy and security threats. For more information, see Update on apps distributed in the European Union on the Apple Developer website.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "ff133ee2-8473-5898-8730-1d368020c9f2",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats such as targeted mercenary spyware.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says exercising privacy rights requires account sign-in and identity verification, and some deletion requests may be denied, for example when Apple is legally obligated to keep a record of a transaction or when granting the request would undermine Apple's legitimate use of data for anti-fraud and security purposes.",
      "fetch_event_id": "d8288419-357e-5543-b315-4767190b74c8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "At Apple, we respect your ability to know, access, correct, transfer, restrict the processing of, and delete your personal data. We have provided these rights to our global customer base and if you choose to exercise these privacy rights, you have the right not to be treated in a discriminatory way nor to receive a lesser degree of service from Apple. Where you are requested to consent to the processing of your personal data by Apple, you have the right to withdraw your consent at any time. To exercise your privacy rights and choices, including where a third-party service provider is acting on Apple’s behalf, visit the Apple Data and Privacy page at privacy.apple.com for Apple or shazam.com/privacy for Shazam. To help protect the security of your personal data, you must sign in to your account and your identity will be verified. If you want to obtain a copy of personal data that is not currently available from privacy.apple.com , you can make a request at apple.com/legal/privacy/contact . You also have the right to lodge a complaint with the applicable regulator. There may be situations where we cannot grant your request — for example, if you ask us to delete your transaction data and Apple is legally obligated to keep a record of that transaction to comply with law. We may also decline to grant a request where doing so would undermine our legitimate use of data for anti-fraud and security purposes, such as when you request deletion of an account that is being investigated for security concerns. Other reasons your privacy request may be denied are if it jeopardizes the privacy of others, is frivolous or vexatious, or would be extremely impractical or unreasonable. If you live in California and you cannot access Apple’s Data and Privacy page, you or your authorized agent can make a request at apple.com/legal/privacy/contact or by calling 1-800-275-2273. For more information on exercising your rights, visit support.apple.com/102283 .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dbbad8a02adb6060887d387b0bb0dc85ba1220f813fddb84ab20eb78cb56c8b0",
      "source_url": "https://www.apple.com/legal/privacy/en-ww/",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.device_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says Lockdown Mode is available in iOS 16, iPadOS 16, macOS 13, watchOS 10, or later, with additional protections in iOS 17, iPadOS 17, macOS 14, and watchOS 10.1 or later.",
      "fetch_event_id": "24b7af98-268f-5cd6-99d3-9128364303b5",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Lockdown Mode is available in iOS 16, iPadOS 16, macOS 13, watchOS 10, or later. Additional protections are available in iOS 17, iPadOS 17, macOS 14, and updates to watchOS 10.1, or later. To take advantage of additional features of Lockdown Mode, devices should be updated to the latest operating system. For more information, see the Apple Support article About Lockdown Mode.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "958324d9-3639-55e5-8b59-9d0f02cb36c0",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats such as targeted mercenary spyware.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
      "fetch_event_id": "fce6319c-541c-5dac-b5bf-5d81ab0e6563",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Personal data relating to individuals in the European Economic Area, the United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland. Apple’s international transfer of personal data collected in the European Economic Area, the United Kingdom, and Switzerland is governed by Standard Contractual Clauses . If you have questions or would like a copy of Apple’s Standard Contractual Clauses, you can contact us at apple.com/legal/privacy/contact . Personal data collected by Apple or an Apple-affiliated company worldwide is generally stored by Apple Inc. in the United States. Regardless of where your personal data is stored, Apple maintains the same high level of protection and safeguarding measures.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dbbad8a02adb6060887d387b0bb0dc85ba1220f813fddb84ab20eb78cb56c8b0",
      "source_url": "https://www.apple.com/legal/privacy/en-ww/",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says its transparency report provides information on government requests for customer data received globally.",
      "fetch_event_id": "50756baf-a38d-5c85-8870-fbc812da13f8",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Apple is committed to your privacy and being transparent about government requests for customer data globally. This report provides information on government requests received.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "36fbce99d74106d6029ed7fb9f665950a3f4bf9829e84e88ed6ecdac5648c68f",
      "source_url": "https://www.apple.com/legal/transparency/",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says it retains personal data only as long as necessary for the purposes for which it was collected or as required by law, seeking the shortest period permitted by law when retention is required.",
      "fetch_event_id": "14a0fca3-cab6-5a78-a0b3-0e18756271b1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Apple retains personal data only for so long as necessary to fulfill the purposes for which it was collected, including as described in this Privacy Policy or in our service-specific privacy notices, or as required by law. We will retain your personal data for the period necessary to fulfill the purposes outlined in this Privacy Policy and our service-specific privacy notices. When assessing retention periods, we first carefully examine whether it is necessary to retain the personal data collected and, if retention is required, work to retain the personal data for the shortest possible period permissible under law.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dbbad8a02adb6060887d387b0bb0dc85ba1220f813fddb84ab20eb78cb56c8b0",
      "source_url": "https://www.apple.com/legal/privacy/en-ww/",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple's guide says all third-party apps are sandboxed and can access information outside their own unique home directory only through services explicitly provided by iOS, iPadOS, and visionOS.",
      "fetch_event_id": "2e841738-9884-50ca-89df-a7da57bf0b95",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All third-party apps are sandboxed. Sandboxing is designed to prevent apps from gathering or modifying information stored by other apps or from making changes to the device. Each app has a unique home directory for its files, which is randomly assigned when the app is installed. If a third-party app needs to access information other than its own, it does so only by using services explicitly provided by iOS, iPadOS, and visionOS.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "83aa7c61-8608-5ecf-a82f-870a7cbbfe3e",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats such as targeted mercenary spyware.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says source code for its operating systems and developer tools is available through downloadable releases and Git repositories.",
      "fetch_event_id": "c77a4fe6-e65e-5079-ac55-7841b4546077",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can access the source code for our operating systems and developer tools by downloading releases or browsing Git repositories.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "ea1e26b0f878268f19dcb4c535c611f6d5d82b5266915ae6c9e58680f4faaad7",
      "source_url": "https://opensource.apple.com/",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says analytics about removal recommendations are sent only if the user agrees to share them through the specified Analytics & Improvements settings on iPad, iPhone, or Mac.",
      "fetch_event_id": "97e17794-0d26-56c1-a678-af75846f7152",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Analytics related to removal recommendations (for example, the app that triggered the recommendation or the fact that the recommendation was displayed) are sent to Apple only if the user has agreed to share this information using the following settings: • iPad: Settings > Privacy & Security > Analytics & Improvements > Share iPad Analytics • iPhone: Settings > Privacy & Security > Analytics & Improvements > Share iPhone & Watch Analytics • Mac: Settings > Privacy & Security > Analytics & Improvements > Share Mac Analytics",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple says it regularly releases software updates for emerging security concerns and delivers updates wirelessly, with iPhone and iPad users receiving notifications on their devices.",
      "fetch_event_id": "bbc42c4c-2eb5-5103-8671-c9515d9a2f3a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Security is a process and isn’t enough to reliably boot the operating system version installed at the factory—there needs to also exist a mechanism to quickly and securely obtain the latest security updates. Apple regularly releases software updates to address emerging security concerns. Users of iPad and iPhone devices receive update notifications on the device. Mac users find available updates in System Settings (macOS 13 or later), or System Preferences (macOS 12 or earlier). Updates are delivered wirelessly, for rapid adoption of the latest security fixes.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "For iOS with Lockdown Mode, Apple's guide says startup components are cryptographically signed by Apple and boot proceeds only after verifying the chain of trust, including bootloaders, the kernel, kernel extensions, and cellular baseband firmware.",
      "fetch_event_id": "15dd682a-4509-5ad7-8c95-c5900f1ffb5d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Each step of the startup process contains components that are cryptographically signed by Apple to enable integrity checking so that boot proceeds only after verifying the chain of trust. These components include the bootloaders, the kernel, kernel extensions (kext), and cellular baseband firmware. This secure boot chain is designed to verify that the lowest levels of software aren’t tampered with. Apple Platform Security 30",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b52f68820c1ea891c34bba5b9f54ded6f1160fc72561d75fdf5c230c64f83e67",
      "source_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Stock Android documentation says Android apps may be distributed through app marketplaces, websites, or email, with users opting in before installing unknown apps.",
      "fetch_event_id": "142b9e85-d037-53be-836e-4edac04e0709",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "As an open platform, Android offers choice. You can distribute your Android apps to users in any way you want, using any distribution approach or combination of approaches that meets your needs. From publishing in an app marketplace to serving your apps from a website or emailing them directly to users, you’re never locked into any particular distribution platform. The process for building and packaging your apps for distribution is the same, regardless of how you distribute them. This saves you time and lets you automate parts of the process as needed. You can read Preparing for Release for more information. The sections below highlight some of the alternatives for distributing your apps. Distributing through an app marketplace Usually, to reach the broadest possible audience, you’d distribute your apps through a marketplace, such as Google Play. Google Play is the premier marketplace for Android apps and is particularly useful if you want to distribute your apps to a large global audience. However, you can distribute your apps through any app marketplace you want or use multiple marketplaces. Unlike other forms of distribution, Google Play allows you to use the In-app Billing service and Licensing service. The In-app Billing service makes it easy to sell in-app products like game jewels or app feature upgrades. The Licensing service helps prevent unauthorized installation and use of your apps. Distributing your apps by email A quick and easy way to release your apps is to send them to users by email. To do this, you prepare the app for release, attach it to an email, and send it to a user. When the user opens your email on their Android-powered device, the Android system recognizes the APK and displays an Install Now button in the email message. Users can install your app by touching the button. Users need to opt in for installing unknown apps if they haven't already to proceed with the installation. Distributing apps through email is convenient if you’re sending them to a few trusted users, as it provides few protections from piracy and unauthorized distribution; that is, anyone you send your apps to can simply forward them to others.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "40150682d4b117f311f4c812fae4d0ca186c550c402a08e1287b571870d23a80",
      "source_url": "https://developer.android.com/distribute/marketing-tools/alternative-distribution",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "30887dc1-b79c-59af-a794-a37c67b155c9",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": null,
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "01a41484ee30d081de3c52acb20c583df28ddf9dfe9ca26d9fc22cfe8b11deb4",
      "source_url": "https://source.android.com/docs/setup/about",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Google says users can delete content or individual items from specific services, delete specific Google products and their associated information, or delete an entire Google Account.",
      "fetch_event_id": "2c8e24bc-1b5d-5b87-a937-4d78744951ad",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "To delete your information, you can: Delete your content from specific Google services Search for and then delete specific items from your account using My Activity Delete specific Google products , including your information associated with those products Delete your entire Google Account Delete your information",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7f5ea3d5b6d5cbc334d8660257022a68829e0b67a9ea7384f398d6566ce5c1fd",
      "source_url": "https://policies.google.com/privacy?hl=en-US",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.device_support": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Android documentation says an Android-compatible device can run third-party apps built with the Android SDK and NDK, must meet the Compatibility Definition Document requirements and pass the Compatibility Test Suite, and is eligible to participate in the Android ecosystem.",
      "fetch_event_id": "f42693c2-da79-539d-8033-95a1999d1da7",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "An Android-compatible device is any device that can run any third-party app written by third-party developers using the Android SDK and NDK. An Android-compatible device must adhere to the requirements of the compatibility definition document (CDD), and pass the compatibility test suite (CTS). Android-compatible devices are eligible to participate in the Android ecosystem which includes potential licensure of the Android Play Store and the Google Mobile Services (GMS) suite of applications, and use of the Android trademark. Anyone is welcome to use the Android source code, but to be considered part of the Android ecosystem, your device must be Android-compatible. This document provides an overview of the Android Compatibility program which represents the processes, requirements, and tests used to ensure that your device is Android-compatible.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "d1775d80d1481b260490a528c22df5131bc5a6917195e9258c1d10b534605717",
      "source_url": "https://source.android.com/docs/compatibility/overview",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "d1d43409-d0ac-5a3a-9d92-0ff3b877b756",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Android is an operating system for a wide array of devices with different form factors. The documentation and source code for Android is available to anyone as the Android Open Source Project (AOSP) . You can use AOSP to create custom variants of the Android OS for your own devices.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "01a41484ee30d081de3c52acb20c583df28ddf9dfe9ca26d9fc22cfe8b11deb4",
      "source_url": "https://source.android.com/docs/setup/about",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
      "fetch_event_id": "ee20f88a-20a1-5259-ad2f-52f5f34a2481",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Android is an operating system for a wide array of devices with different form factors. The documentation and source code for Android is available to anyone as the Android Open Source Project (AOSP) . You can use AOSP to create custom variants of the Android OS for your own devices.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "01a41484ee30d081de3c52acb20c583df28ddf9dfe9ca26d9fc22cfe8b11deb4",
      "source_url": "https://source.android.com/docs/setup/about",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Google says it receives government and court requests for user data worldwide, reviews every request, and frequently pushes back when a request appears overly broad or does not follow the correct process.",
      "fetch_event_id": "1c9d34df-09d4-5232-b7de-b4dec0793e1c",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Like other technology and communications companies, Google regularly receives requests from governments and courts around the world to disclose user data. Respect for the privacy and security of data you store with Google underpins our approach to complying with these legal requests. Our legal team reviews each and every request, regardless of type, and we frequently push back when a request appears to be overly broad or doesn’t follow the correct process. Learn more in our Transparency Report .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7f5ea3d5b6d5cbc334d8660257022a68829e0b67a9ea7384f398d6566ce5c1fd",
      "source_url": "https://policies.google.com/privacy?hl=en-US",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Google says retention varies by data type, use, and settings: some data is user-deletable, some is automatically deleted or anonymized, some remains until account deletion, and some is kept longer for business or legal purposes.",
      "fetch_event_id": "81cce9d9-e593-5ecb-b1eb-beddd0983ca1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We retain the data we collect for different periods of time depending on what it is, how we use it, and how you configure your settings: Some data you can delete whenever you like, such as your personal info or the content you create or upload, like photos and documents . You can also delete activity information saved in your account, or choose to have it deleted automatically after a set period of time. We’ll keep this data in your Google Account until you remove it or choose to have it removed. Other data is deleted or anonymized automatically after a set period of time, such as advertising data in server logs. We keep some data until you delete your Google Account, such as information about how often you use our services. And some data we retain for longer periods of time when necessary for legitimate business or legal purposes, such as security, fraud and abuse prevention, or financial record-keeping.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7f5ea3d5b6d5cbc334d8660257022a68829e0b67a9ea7384f398d6566ce5c1fd",
      "source_url": "https://policies.google.com/privacy?hl=en-US",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Android documentation says each app receives a unique user ID and runs in its own process, with a kernel-level Application Sandbox isolating apps and limiting their default access to the operating system and other apps.",
      "fetch_event_id": "5a771c46-3dde-5e3a-9405-9bbd2ce81728",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Android platform takes advantage of the Linux user-based protection to identify and isolate app resources. This isolates apps from each other and protects apps and the system from malicious apps. To do this, Android assigns a unique user ID (UID) to each Android app and runs it in its own process. Android uses the UID to set up a kernel-level Application Sandbox. The kernel enforces security between apps and the system at the process level through standard Linux facilities such as user and group IDs that are assigned to apps. By default, apps can't interact with each other and have limited access to the OS. If app A tries to do something malicious, such as read app B's data or dial the phone without permission, it's prevented from doing so because it doesn't have the appropriate default user privileges. The sandbox is simple, auditable, and based on decades-old UNIX-style user separation of processes and file permissions. Because the Application Sandbox is in the kernel, this security model extends to both native code and OS apps. All of the software above the kernel, such as OS libraries, app framework, app runtime, and all apps, run within the Application Sandbox. On some platforms, developers are constrained to a specific development framework, set of APIs, or language. On Android, there are no restrictions on how an app can be written that are required to enforce security; in this respect, native code is as sandboxed as interpreted code.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b7f76d2b73c819b69576e44160b5f3791304526d4df96bee7a41bf2749ccb2ee",
      "source_url": "https://source.android.com/docs/security/app-sandbox",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": null,
      "fetch_event_id": "ff170833-ce4e-5e8c-adaa-b6575af7ac30",
      "pinpoint": null,
      "public_reason": "Not disclosed in the captured primary source.",
      "publish_status": "typed_unknown",
      "quote": "Android is an operating system for a wide array of devices with different form factors. The documentation and source code for Android is available to anyone as the Android Open Source Project (AOSP) . You can use AOSP to create custom variants of the Android OS for your own devices.",
      "readiness": "verified_absence",
      "reason_code": "not_disclosed",
      "rendered": "badge",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "01a41484ee30d081de3c52acb20c583df28ddf9dfe9ca26d9fc22cfe8b11deb4",
      "source_url": "https://source.android.com/docs/setup/about",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Android documentation says the Android source and its full change history are hosted by Google across a collection of Git repositories.",
      "fetch_event_id": "d54858c3-4ee4-5e16-9764-474b23d29fb1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Android source is located in a collection of Git repositories hosted by Google. The Git repository includes the entire history of the Android source, including changes to the source and when the changes were made. This page describes how to download the source. Note: All commands on this page are preceded by a dollar sign ($) to differentiate them from output or entries within files. To omit the dollar sign when copying the command, click the Copy code sample icon in the top right of each command box. Note: To obtain the source code for third-party components where the open source license grants you the right to receive the source, see Obtain Android source .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "5b811f06e06a2a22dfbb1c1f1faee79e9d0eb4685b59df9f867181d461b0991a",
      "source_url": "https://source.android.com/docs/setup/download",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Stock Android support documentation says enabling Usage & diagnostics sends Google information such as battery level, app-use frequency, and network-connection quality and duration, and the setting can be turned off.",
      "fetch_event_id": "3fa1eeaf-71d8-50f9-8d89-a5fcc466fdb3",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "If you turn on usage and diagnostics, your device sends info to Google about what’s working and not working. For example, your device can send info like: Battery level How often you use your apps Quality and length of your network connections (like mobile, Wi-Fi, and Bluetooth) Turn usage & diagnostics on or off Important: If you turn off usage and diagnostics, your device can still get essential services, like a new version of Android. Turning off usage and diagnostics won’t affect info that apps might collect. To choose whether to send usage and diagnostics info to Google: Open your device's Settings app. Tap Google More Usage & diagnostics . Turn Usage & diagnostics on or off. Tip: If you use a shared device, other user profiles may change this setting . How Google uses this information Google uses usage and diagnostics info to improve products and services, like Google apps and Android devices. All info is used in accordance with Google’s Privacy Policy . For example, Google can use usage and diagnostics info to improve: Battery life: Google can use info about what's using the most battery on your device to help make common features use less battery. Crashing or freezing on devices: Google can use info about when apps crash and freeze on your device to help make the Android operating system more reliable. Some aggregated info can help partners, like Android developers, make their apps and products better, too.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "39fd0cb0cc6745e6a39aa09d1dab0b980b2d9fea2f208b460ab9f3fe9cb12b09",
      "source_url": "https://support.google.com/android/answer/6078260?hl=en",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Android documentation says devices can receive over-the-air updates to system and app software and time-zone rules, with Android 11 and later using Virtual A/B updates on modern devices.",
      "fetch_event_id": "e3fa9797-1128-50da-99e0-25f9400254c1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Android devices in the field can receive and install over-the-air (OTA) updates to the system, app software, and time zone rules. This section describes the structure of update packages and the tools provided to build them. It is intended for developers who want to make OTA updates work on new Android devices and those who want to build update packages for released devices. OTA updates are designed to upgrade the underlying operating system, the read-only apps installed on the system partition, and time zone rules; these updates do not affect apps installed by the user from Google Play. Note: Upgrade Party and Upgrade Invite are deprecated and no longer supported. The documentation for these features has been removed and no feature replaces them. Virtual A/B (seamless) system updates Modern Android devices (Android 11 and after) maintain two copies of each partition (A and B) during an update. This update mechanism is called Virtual A/B with compression. While legacy A/B updates (Android 10 and earlier) kept two copies for every single partition, Virtual A/B only keeps two physical slots for boot critical partitions. The unused slot is written to directly for bootcritical partitions. Dynamic partitions have new operating system data written as compressed snapshots since their image size tends to be much larger. Compressed snapshots allows a device to simulate the experience of having two slots, while reducing space requirements. For more information about Virtual A/B OTA updates, see Virtual A/B (seamless) system updates . For a sample app that provides examples on using Android system update APIs (that is, update_engine ) to install A/B updates, refer to SystemUpdaterSample (app details available in updater_sample/README.md ). Legacy A/B updates and Non-A/B system updates Legacy A/B updates were the first version of A/B updates in Android. This update mechanism kept two slots of every single partition, but had the drawback of needing twice the storage for each partition. For more information see, A/B system updates . As of Android 15, non A/B updates are deprecated. For more information, see Non-A/B system updates .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "ee116ea2d15f9920c55059685e7e4db1adb4a62671dbfe56540e5f2070e36c32",
      "source_url": "https://source.android.com/docs/core/ota",
      "table": "vendor"
    },
    "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot": {
      "additional_sources": null,
      "capture_date": "2026-10-07",
      "claim_type": "vendor_stated",
      "display": "Android documentation says Verified Boot establishes a chain of trust from a hardware-protected root through the bootloader and verified partitions, while rollback protection ensures devices update only to newer Android versions.",
      "fetch_event_id": "7bccabf0-59a6-5f65-9d66-1beb7c0c6961",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verified Boot strives to ensure all executed code comes from a trusted source (usually device OEMs), rather than from an attacker or corruption. It establishes a full chain of trust, starting from a hardware-protected root of trust to the bootloader, to the boot partition and other verified partitions including system , vendor , and optionally oem partitions. During device boot up, each stage verifies the integrity and authenticity of the next stage before handing over execution. In addition to ensuring that devices are running a safe version of Android, Verified Boot checks for the correct version of Android with rollback protection . Rollback protection helps to prevent a possible exploit from becoming persistent by ensuring devices only update to newer versions of Android. In addition to verifying the OS, Verified Boot also allows Android devices to communicate their state of integrity to the user. Background Android 4.4 added support for Verified Boot and the dm-verity kernel feature. This combination of verifying features served as Verified Boot 1. Where previous versions of Android warned users about device corruption, but still allowed them to boot their devices, Android 7.0 started strictly enforcing Verified Boot to prevent compromised devices from booting. Android 7.0 also added support for forward error correction to improve reliability against non-malicious data corruption. Android 8.0 and higher includes Android Verified Boot (AVB), a reference implementation of Verified Boot that works with Project Treble. In addition to working with Treble, AVB standardized partition footer format and added rollback protection features.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2b497ae9b6b0a7656c2c5c57e011ce6eed3c38584ee72f8b627239414e333a04",
      "source_url": "https://source.android.com/docs/security/features/verifiedboot",
      "table": "vendor"
    }
  },
  "class": "MAGNET",
  "content_file_sha256": "4557de43e90bee1333e301d262ae013fc6d2247706ff8abf2bd8bf652fd3cfb9",
  "figure_slots": [],
  "generator": "page-generator/1",
  "held": {
    "cells": [],
    "counts": {
      "gap": 0,
      "no_quote": 0,
      "unconfirmed": 0,
      "unresolved": 0
    },
    "is_held": false
  },
  "last_updated": "2026-10-07",
  "route": "/privacy-tools/mobile-operating-system-comparison/",
  "schema": "pp-page-sources.v1",
  "tables": {
    "devices-and-updates": {
      "field_definitions": {
        "device_support": "Device families, models, hardware requirements, availability boundaries, release or feature scope, and exceptions stated by the current cell.",
        "update_cadence_and_source": "Update source, publisher or signing actor, release channel, cadence statement, rollout model, support window, device scope, and release locator stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-mobile-os:devices-and-updates",
      "rows": [
        {
          "cells": {
            "device_support": {
              "cell_citation_url": "https://source.android.com/docs/compatibility/overview",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.device_support",
              "publish_status": "publish_ready",
              "source_field": "device_support",
              "value": "Android documentation says an Android-compatible device can run third-party apps built with the Android SDK and NDK, must meet the Compatibility Definition Document requirements and pass the Compatibility Test Suite, and is eligible to participate in the Android ecosystem."
            },
            "update_cadence_and_source": {
              "cell_citation_url": "https://source.android.com/docs/core/ota",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source",
              "publish_status": "publish_ready",
              "source_field": "update_cadence_and_source",
              "value": "Android documentation says devices can receive over-the-air updates to system and app software and time-zone rules, with Android 11 and later using Virtual A/B updates on modern devices."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://source.android.com/docs/setup/about",
          "operating_entity_citation_url": "https://source.android.com/docs/setup/about",
          "operating_entity_subline": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
          "row_anchor": "devices-and-updates-stock-android",
          "row_id": "stock-android",
          "state": "Android Open Source Project (AOSP)"
        },
        {
          "cells": {
            "device_support": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.device_support",
              "publish_status": "publish_ready",
              "source_field": "device_support",
              "value": "For iOS with Lockdown Mode, Apple says Lockdown Mode is available in iOS 16, iPadOS 16, macOS 13, watchOS 10, or later, with additional protections in iOS 17, iPadOS 17, macOS 14, and watchOS 10.1 or later."
            },
            "update_cadence_and_source": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source",
              "publish_status": "publish_ready",
              "source_field": "update_cadence_and_source",
              "value": "For iOS with Lockdown Mode, Apple says it regularly releases software updates for emerging security concerns and delivers updates wirelessly, with iPhone and iPad users receiving notifications on their devices."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_subline": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
          "row_anchor": "devices-and-updates-ios-lockdown-mode",
          "row_id": "ios-lockdown-mode",
          "state": "Lockdown Mode"
        },
        {
          "cells": {
            "device_support": {
              "cell_citation_url": "https://calyxos.org/docs/guide/device-support/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.device_support",
              "publish_status": "publish_ready",
              "source_field": "device_support",
              "value": "CalyxOS says it tries to support devices as long as possible and publishes estimated operating-system-upgrade and security-update dates by device."
            },
            "update_cadence_and_source": {
              "cell_citation_url": "https://calyxos.org/docs/guide/updates/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source",
              "publish_status": "publish_ready",
              "source_field": "update_cadence_and_source",
              "value": "CalyxOS says installed devices automatically check for, download, and install frequent over-the-air updates from its servers, typically monthly after Android Open Source Project security releases."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_citation_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_subline": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
          "row_anchor": "devices-and-updates-calyxos",
          "row_id": "calyxos",
          "state": "CalyxOS"
        },
        {
          "cells": {
            "device_support": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.device_support",
              "publish_status": "publish_ready",
              "source_field": "device_support",
              "value": "GrapheneOS says devices sold through some carriers may be locked and prevent installation, while officially supported devices have builds and updates available from release tags."
            },
            "update_cadence_and_source": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/usage.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.update_cadence_and_source",
              "publish_status": "publish_ready",
              "source_field": "update_cadence_and_source",
              "value": "GrapheneOS says its updater checks approximately every six hours when network connectivity is available, then downloads and installs updates in the background."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://grapheneos.org/history/",
          "operating_entity_citation_url": "https://grapheneos.org/history/",
          "operating_entity_subline": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
          "row_anchor": "devices-and-updates-grapheneos",
          "row_id": "grapheneos",
          "state": "GrapheneOS"
        }
      ],
      "scope_label": "4 products"
    },
    "distribution-and-identity": {
      "field_definitions": {
        "app_store_model": "Bundled stores, alternative-store support, direct-installation support, privileged integration, account-requirement statement, region, device scope, release or channel, and limitations stated by the current cell.",
        "later_verification_triggers": "Trigger, requested identifier, collecting actor, retained-by value, plan, and region stated by the current cell, preserving nested verified absences.",
        "signup_identifiers": "Identifier type, requiredness, collecting actor, plan, region, and platform stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-mobile-os:distribution-and-identity",
      "rows": [
        {
          "cells": {
            "app_store_model": {
              "cell_citation_url": "https://developer.android.com/distribute/marketing-tools/alternative-distribution",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model",
              "publish_status": "publish_ready",
              "source_field": "app_store_model",
              "value": "Stock Android documentation says Android apps may be distributed through app marketplaces, websites, or email, with users opting in before installing unknown apps."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://source.android.com/docs/setup/about",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "later_verification_triggers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://source.android.com/docs/setup/about",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "signup_identifiers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://source.android.com/docs/setup/about",
          "operating_entity_citation_url": "https://source.android.com/docs/setup/about",
          "operating_entity_subline": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
          "row_anchor": "distribution-and-identity-stock-android",
          "row_id": "stock-android",
          "state": "Android Open Source Project (AOSP)"
        },
        {
          "cells": {
            "app_store_model": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model",
              "publish_status": "publish_ready",
              "source_field": "app_store_model",
              "value": "For iOS with Lockdown Mode, Apple says the design principle for iPhone and iPad focuses on centralized distribution, code signing, and strict sandboxing, while European Union users can also install apps from alternative marketplaces or authorized developer websites."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "later_verification_triggers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "signup_identifiers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_subline": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
          "row_anchor": "distribution-and-identity-ios-lockdown-mode",
          "row_id": "ios-lockdown-mode",
          "state": "Lockdown Mode"
        },
        {
          "cells": {
            "app_store_model": {
              "cell_citation_url": "https://calyxos.org/docs/guide/apps/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model",
              "publish_status": "publish_ready",
              "source_field": "app_store_model",
              "value": "CalyxOS says F-Droid Basic is its preferred app store and that its default F-Droid store installs during setup, while Aurora Store provides the option to install apps without a Google account and, for paid apps or if anonymous mode is not working, lets the user additionally enter Google account credentials in its settings (some paid apps may not work)."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://calyxos.org/docs/guide/faq/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "later_verification_triggers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://calyxos.org/docs/guide/microg/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "CalyxOS offers microG modes without a Google Account and a mode with a Google Account."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_citation_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_subline": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
          "row_anchor": "distribution-and-identity-calyxos",
          "row_id": "calyxos",
          "state": "CalyxOS"
        },
        {
          "cells": {
            "app_store_model": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/source.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.app_store_model",
              "publish_status": "publish_ready",
              "source_field": "app_store_model",
              "value": "GrapheneOS says its standalone apps are developed by GrapheneOS and included in the OS; the list excludes apps with no GrapheneOS modifications or only minor ones."
            },
            "later_verification_triggers": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.later_verification_triggers",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "later_verification_triggers",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "GrapheneOS says it does not provide Factory Reset Protection because the standard implementation depends on tying a device to an online-service account."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://grapheneos.org/history/",
          "operating_entity_citation_url": "https://grapheneos.org/history/",
          "operating_entity_subline": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
          "row_anchor": "distribution-and-identity-grapheneos",
          "row_id": "grapheneos",
          "state": "GrapheneOS"
        }
      ],
      "scope_label": "4 products"
    },
    "isolation-and-boot": {
      "field_definitions": {
        "sandboxing_model": "Sandbox unit, isolation boundaries, permission model, interprocess-access statement, privileged exceptions, release or channel, device scope, and documentation locator stated by the current cell.",
        "verified_boot": "Mechanism name, trust root or signing actor, verified components, boot-state requirements, relock or recovery behavior, update-verification statement, device scope, release or channel, and limitations stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-mobile-os:isolation-and-boot",
      "rows": [
        {
          "cells": {
            "sandboxing_model": {
              "cell_citation_url": "https://source.android.com/docs/security/app-sandbox",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model",
              "publish_status": "publish_ready",
              "source_field": "sandboxing_model",
              "value": "Android documentation says each app receives a unique user ID and runs in its own process, with a kernel-level Application Sandbox isolating apps and limiting their default access to the operating system and other apps."
            },
            "verified_boot": {
              "cell_citation_url": "https://source.android.com/docs/security/features/verifiedboot",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot",
              "publish_status": "publish_ready",
              "source_field": "verified_boot",
              "value": "Android documentation says Verified Boot establishes a chain of trust from a hardware-protected root through the bootloader and verified partitions, while rollback protection ensures devices update only to newer Android versions."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://source.android.com/docs/setup/about",
          "operating_entity_citation_url": "https://source.android.com/docs/setup/about",
          "operating_entity_subline": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
          "row_anchor": "isolation-and-boot-stock-android",
          "row_id": "stock-android",
          "state": "Android Open Source Project (AOSP)"
        },
        {
          "cells": {
            "sandboxing_model": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model",
              "publish_status": "publish_ready",
              "source_field": "sandboxing_model",
              "value": "For iOS with Lockdown Mode, Apple's guide says all third-party apps are sandboxed and can access information outside their own unique home directory only through services explicitly provided by iOS, iPadOS, and visionOS."
            },
            "verified_boot": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot",
              "publish_status": "publish_ready",
              "source_field": "verified_boot",
              "value": "For iOS with Lockdown Mode, Apple's guide says startup components are cryptographically signed by Apple and boot proceeds only after verifying the chain of trust, including bootloaders, the kernel, kernel extensions, and cellular baseband firmware."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_subline": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
          "row_anchor": "isolation-and-boot-ios-lockdown-mode",
          "row_id": "ios-lockdown-mode",
          "state": "Lockdown Mode"
        },
        {
          "cells": {
            "sandboxing_model": {
              "cell_citation_url": "https://calyxos.org/docs/guide/getting-started/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model",
              "publish_status": "publish_ready",
              "source_field": "sandboxing_model",
              "value": "CalyxOS provides a work profile and says its apps will not access data from the main profile, even if they are duplicates."
            },
            "verified_boot": {
              "cell_citation_url": "https://calyxos.org/features/list/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot",
              "publish_status": "publish_ready",
              "source_field": "verified_boot",
              "value": "CalyxOS says it supports fully verified boot and bootloader re-locking to ensure the operating system has not been modified and maintain physical security equivalent to stock Android."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_citation_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_subline": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
          "row_anchor": "isolation-and-boot-calyxos",
          "row_id": "calyxos",
          "state": "CalyxOS"
        },
        {
          "cells": {
            "sandboxing_model": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/features.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.sandboxing_model",
              "publish_status": "publish_ready",
              "source_field": "sandboxing_model",
              "value": "GrapheneOS says it hardens the app sandbox through SELinux and seccomp-bpf policy and also improves other sandboxes, including the browser-renderer sandbox."
            },
            "verified_boot": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/install/cli.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.verified_boot",
              "publish_status": "publish_ready",
              "source_field": "verified_boot",
              "value": "GrapheneOS says locking the bootloader enables full verified boot, which detects OS-partition modifications and prevents reading modified or corrupted data."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://grapheneos.org/history/",
          "operating_entity_citation_url": "https://grapheneos.org/history/",
          "operating_entity_subline": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
          "row_anchor": "isolation-and-boot-grapheneos",
          "row_id": "grapheneos",
          "state": "GrapheneOS"
        }
      ],
      "scope_label": "4 products"
    },
    "responsibility-and-evidence": {
      "field_definitions": {
        "audit_report": "Assessment date, assessor, scope, access, and report locator, preserving row-level and nested verified absences.",
        "operating_entity": "Company, project, platform owner, publisher, or controller and jurisdictional details supported by the current cell.",
        "request_reporting": "Period, jurisdiction, unit, scope, count, and absence reason, preserving typed unknowns rather than printing zero.",
        "source_availability": "Repository URL, license, component, version, and release locator stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-mobile-os:responsibility-and-evidence",
      "rows": [
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://source.android.com/docs/setup/about",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "audit_report",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "operating_entity": {
              "cell_citation_url": "https://source.android.com/docs/setup/about",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available."
            },
            "request_reporting": {
              "cell_citation_url": "https://policies.google.com/privacy?hl=en-US",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Google says it receives government and court requests for user data worldwide, reviews every request, and frequently pushes back when a request appears overly broad or does not follow the correct process."
            },
            "source_availability": {
              "cell_citation_url": "https://source.android.com/docs/setup/download",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Android documentation says the Android source and its full change history are hosted by Google across a collection of Git repositories."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://source.android.com/docs/setup/about",
          "operating_entity_citation_url": "https://source.android.com/docs/setup/about",
          "operating_entity_subline": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
          "row_anchor": "responsibility-and-evidence-stock-android",
          "row_id": "stock-android",
          "state": "Android Open Source Project (AOSP)"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "note": "Not disclosed in the captured primary source.",
              "publish_status": "typed_unknown",
              "source_field": "audit_report",
              "value": "unknown",
              "visible_subline": "Not disclosed in the captured primary source."
            },
            "operating_entity": {
              "cell_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States."
            },
            "request_reporting": {
              "cell_citation_url": "https://www.apple.com/legal/transparency/",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "For iOS with Lockdown Mode, Apple says its transparency report provides information on government requests for customer data received globally."
            },
            "source_availability": {
              "cell_citation_url": "https://opensource.apple.com/",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "For iOS with Lockdown Mode, Apple says source code for its operating systems and developer tools is available through downloadable releases and Git repositories."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_subline": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
          "row_anchor": "responsibility-and-evidence-ios-lockdown-mode",
          "row_id": "ios-lockdown-mode",
          "state": "Lockdown Mode"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://raw.githubusercontent.com/trailofbits/publications/master/reviews/2026-01-calyx-hsm-provisioning-ceremony-scripts-securityreview.pdf",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "CalyxOS identifies a security assessment titled Calyx Institute HSM Provisioning Ceremony Scripts Security Assessment, dated January 23, 2026."
            },
            "operating_entity": {
              "cell_citation_url": "https://calyx.org/legal/terms-of-service",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites."
            },
            "request_reporting": {
              "cell_citation_url": "https://calyx.org/legal/privacy-policy",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "CalyxOS says it shares available personal information with law enforcement or government agencies with the user's written consent, under apparently valid legal process, or when applicable law requires disclosure."
            },
            "source_availability": {
              "cell_citation_url": "https://calyxos.org/docs/development/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "CalyxOS says its development occurs in public source-code repositories, with source available on GitLab and mirrored to GitHub."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_citation_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_subline": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
          "row_anchor": "responsibility-and-evidence-calyxos",
          "row_id": "calyxos",
          "state": "CalyxOS"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://grapheneos.org/faq",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "GrapheneOS says its code is continuously reviewed by external security researchers, companies, and organizations, with most review and audit results visible through public pull requests and issue trackers."
            },
            "operating_entity": {
              "cell_citation_url": "https://grapheneos.org/history/",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations."
            },
            "request_reporting": {
              "cell_citation_url": "https://grapheneos.org/usage#updates",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "GrapheneOS says it is not able to comply with a government order to build, sign, and ship a malicious update to a specific device based on information such as an IMEI or serial number, and it rejects updates constrained to a serial number."
            },
            "source_availability": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/source.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "GrapheneOS says it is an open-source project with an open development process and many source repositories."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://grapheneos.org/history/",
          "operating_entity_citation_url": "https://grapheneos.org/history/",
          "operating_entity_subline": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
          "row_anchor": "responsibility-and-evidence-grapheneos",
          "row_id": "grapheneos",
          "state": "GrapheneOS"
        }
      ],
      "scope_label": "4 products"
    },
    "telemetry-and-lifecycle": {
      "field_definitions": {
        "deletion": "Initiation path, completed-erasure statement, exceptions, timeframe, and controller stated by the current cell.",
        "retention": "Data category, trigger, duration, exceptions, and controller stated by the current cell.",
        "telemetry_defaults": "Telemetry or diagnostics category, documented default, controller or recipient, configuration path, and device, release, feature, application, or account scope stated by the current cell."
      },
      "last_updated": "2026-10-07",
      "matrix_id": "vendor-mobile-os:telemetry-and-lifecycle",
      "rows": [
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://policies.google.com/privacy?hl=en-US",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Google says users can delete content or individual items from specific services, delete specific Google products and their associated information, or delete an entire Google Account."
            },
            "retention": {
              "cell_citation_url": "https://policies.google.com/privacy?hl=en-US",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Google says retention varies by data type, use, and settings: some data is user-deletable, some is automatically deleted or anonymized, some remains until account deletion, and some is kept longer for business or legal purposes."
            },
            "telemetry_defaults": {
              "cell_citation_url": "https://support.google.com/android/answer/6078260?hl=en",
              "cell_locator": "stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults",
              "publish_status": "publish_ready",
              "source_field": "telemetry_defaults",
              "value": "Stock Android support documentation says enabling Usage & diagnostics sends Google information such as battery level, app-use frequency, and network-connection quality and duration, and the setting can be turned off."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#stock-android.stock-android.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://source.android.com/docs/setup/about",
          "operating_entity_citation_url": "https://source.android.com/docs/setup/about",
          "operating_entity_subline": "Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.",
          "row_anchor": "telemetry-and-lifecycle-stock-android",
          "row_id": "stock-android",
          "state": "Android Open Source Project (AOSP)"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "For iOS with Lockdown Mode, Apple says exercising privacy rights requires account sign-in and identity verification, and some deletion requests may be denied, for example when Apple is legally obligated to keep a record of a transaction or when granting the request would undermine Apple's legitimate use of data for anti-fraud and security purposes."
            },
            "retention": {
              "cell_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "For iOS with Lockdown Mode, Apple says it retains personal data only as long as necessary for the purposes for which it was collected or as required by law, seeking the shortest period permitted by law when retention is required."
            },
            "telemetry_defaults": {
              "cell_citation_url": "https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf",
              "cell_locator": "ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults",
              "publish_status": "publish_ready",
              "source_field": "telemetry_defaults",
              "value": "For iOS with Lockdown Mode, Apple says analytics about removal recommendations are sent only if the user agrees to share them through the specified Analytics & Improvements settings on iPad, iPhone, or Mac."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#ios-lockdown-mode.ios-lockdown-mode.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_citation_url": "https://www.apple.com/legal/privacy/en-ww/",
          "operating_entity_subline": "For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.",
          "row_anchor": "telemetry-and-lifecycle-ios-lockdown-mode",
          "row_id": "ios-lockdown-mode",
          "state": "Lockdown Mode"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://calyx.org/legal/privacy-policy",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "CalyxOS says personal information is kept on an encrypted basis while a person remains a Calyx member or registered user, then deleted promptly once retention is no longer required by policy or law."
            },
            "retention": {
              "cell_citation_url": "https://calyxos.org/docs/guide/security/network-activity/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "CalyxOS says release.calyxos.org per-request logs are retained briefly before aggregation and destruction, while long-term aggregate data contains request totals by country and device model."
            },
            "telemetry_defaults": {
              "cell_citation_url": "https://calyxos.org/docs/guide/security/network-activity/",
              "cell_locator": "calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults",
              "publish_status": "publish_ready",
              "source_field": "telemetry_defaults",
              "value": "CalyxOS says the operating system or microG initiates connections for system updates, anti-tracking-filter updates, optional online location services, and GPS-assistance data."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#calyxos.calyxos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_citation_url": "https://calyx.org/legal/terms-of-service",
          "operating_entity_subline": "CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.",
          "row_anchor": "telemetry-and-lifecycle-calyxos",
          "row_id": "calyxos",
          "state": "CalyxOS"
        },
        {
          "cells": {
            "deletion": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "GrapheneOS says deleting a profile wipes its corresponding Weaver slot, while a factory reset wipes all Weaver slots."
            },
            "retention": {
              "cell_citation_url": "https://grapheneos.org/faq",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "GrapheneOS says its public-service servers retain logs for at most 10 days, with a lower limit or no persistent logs for some services."
            },
            "telemetry_defaults": {
              "cell_citation_url": "https://raw.githubusercontent.com/GrapheneOS/grapheneos.org/05be4e5c6e41e25e7578a7c5b9968488ea6df336/static/faq.html",
              "cell_locator": "grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.telemetry_defaults",
              "publish_status": "publish_ready",
              "source_field": "telemetry_defaults",
              "value": "GrapheneOS says it has no analytics or telemetry and makes default remote connections only to GrapheneOS services and network-provided DNS resolvers."
            }
          },
          "last_checked": "2026-10-07",
          "name_cell": "vendor#grapheneos.grapheneos.all-documented-plans.vendor-documented.all-documented-platforms.operating_entity",
          "official_source_url": "https://grapheneos.org/history/",
          "operating_entity_citation_url": "https://grapheneos.org/history/",
          "operating_entity_subline": "GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.",
          "row_anchor": "telemetry-and-lifecycle-grapheneos",
          "row_id": "grapheneos",
          "state": "GrapheneOS"
        }
      ],
      "scope_label": "4 products"
    }
  },
  "template": "matrix",
  "tier": "T1",
  "warnings": [
    "sideways label \"Device Lock Screens and Theft Protection\" differs from the known title \"Device Lock-Screen Exposure and Theft Protection\" of /exposure/device-lock-screen-and-theft-protection/",
    "sideways label \"Hardened Mobile Operating Systems\" differs from the known title \"Hardened Mobile Operating Systems: Isolation, Boot, and Updates\" of /exposure/hardened-mobile-operating-systems/"
  ]
}
