Operator-owned Android

Bring the handset
under your roof.

Choose a configured compact appliance or a larger managed server deployment. Every option works with the same runtime-selectable control plane.

Compact appliance

Ephemeral Box

A ready-to-run private Android server for an individual, family, or small team. We choose and validate the internal platform as part of fulfilment, so customers buy a supported capability rather than a particular board or chipset.

  • Control plane and runtime agent installed
  • Android profile prepared for the delivered runtime
  • Verified phone capacity recorded before shipping
  • Remote updates and recovery documentation
  • Branded Android access app prepared during fulfilment
Founding hardware programme
Delivery
Preconfigured
Capacity
Verified per order
Android
Selected profile
Support
Founding onboarding

Checking founding availability…

Join the hardware programme

Programme interest is recorded in a public GitHub issue, so do not include an address or other private information. A real order opens Stripe Checkout, where price, taxes, and delivery are shown before payment. Delivered systems are not certified security appliances.

Multi-phone deployment

Mission Server

For diplomatic missions, consular teams, NGOs, newsrooms, and organisations that need more than two isolated handset slots. Capacity, failover, networking, physical access, Android images, and support are designed around the deployment rather than promised as a generic “embassy-grade” label.

  • Multiple Linux runtime nodes selectable from one console
  • Capacity advertised by each node and enforced before start
  • Private network, audit, backup, and recovery design review
  • Optional warm spare and site-to-site runtime failover plan
  • Operator branding and managed client signing plan
Designed per site

Architecture review first.

There is no safe one-size-fits-all capacity number. The proposal records the exact hardware, concurrent handset target, isolation boundary, Android image, recovery objective, and acceptance test.

Request a deployment review

Android images

Choose only what the runtime can honestly support.

The console now reads image capabilities from each runtime node. It rejects a phone request when that image has not been configured and verified on the selected host.

Reference profile

AOSP

The default profile for virtual Android runtimes and the reference deployment.

Compatibility checked

LineageOS

Available when the selected deployment has a built and verified compatible image.

Supported devices only

GrapheneOS

Available only through a deployment built around devices officially supported by GrapheneOS.

Accepted before delivery

Buy a working capacity, not a parts list.

Every delivered deployment is tested for Android boot, authenticated streaming, input, lifecycle operations, and account isolation before it is handed over.