NitroPhone 4 Pro - Most Secure Android on the Planet
The NitroPhone 4 Pro combines security, privacy and ease of use with modern hardware. Long-term software updates until 2030 guarantee sustainability and a low price per time. The NitroPhone 4 Pro is based on the high-quality Pixel 8 Pro hardware and GrapheneOS, the most hardened Android for professionals. Gain full control of your smartphone without Google and Apple!
New: Software updates for up to 7 years. Significantly improved protection against remote exploitation through hardware memory tagging.
Optional: Removed microphones, sensors and cameras make eavesdropping on the environment physically impossible. Phone calls are made with optional headset.
"If I were configuring a smartphone today, I'd use DanielMicay's GrapheneOS as the base operating system. I'd desolder the microphones." Edward Snowden, NSA whistleblower
"NitroPhone is a much better product than we did with Blackphone." Phil Zimmermann, inventor of PGP
Physical Tamper Protection
- Strong encryption and Titan M2 security chip protects your device and data against sophisticated physical attacks.
- Verified boot ensures that your operating system has not been modified.
- Automatic kill switch: Automatically shutdown after inactivity of configured time period.
- PIN layout scrambling, together with privacy screen (not included), allow entering PIN in public without being watched. Alternatively: integrated fingerprint sensor.
- The NitroPhone is delivered in a sealed box.
Protection From Spyware and Zero-Day Exploits
- Substantially hardened Android 14 for high security demands (e.g. hardened stock apps, libc, malloc, compiler toolchain, kernel, filesystem access, WebView).
- All apps are sandboxed to protect against exploitable and malicious apps.
- Hardened browser, WebView and PDF viewer.
- No waiting for months for updates but lightning-fast distribution of security updates until 2030.
- Protection against over-the-air exploits by isolating the baseband radio processor using IOMMU and optional LTE-only mode to significantly reduce cellular radio attack surface.
- Optional: For very high security requirements, all microphones and acceleration and rotation sensors can be removed. This is because acceleration and rotation sensors could be used as microphones. This physically prevents conversations in the environment from being recorded. Phone calls can still be made with an external headset.
Privacy Protection: No Tracking, No Google
- No cloud or Google Play Services integration by default, all under your control. If required, original Google Play Services can be installed as sandboxed apps without special privileges. This novel approach leads to much better compatibility than incomplete reimplementations like microG while providing higher security.
- Tracking protection: Apps can't access device IMEI and serial numbers, SIM card serial numbers, subscriber ID, MAC address etc.
- Per-connection MAC randomization prevents tracking by nearby WiFi scanners.
- Firewall: Granular network and sensors permissions (e.g. GPS) toggle for each app.
- Default Indicators for active camera, microphone, and location.
Inexpensive and Sustainable
- For industrialized smartphones, a long lifespan is the most effective way to reduce resource consumption per user. As with hardly any other Android smartphone, security updates are provided for the NitroPhone 4 Pro for up to 7 years, namely until October 2030. Calculated over this lifetime, the phone only costs from €0.60 per day.
- The NitroPhone can be opened relatively easily for repair and defective components can be replaced.
Easy Usability for Everybody
- No bloatware. Minimal secure system with few apps by default. Additional apps can be installed manually; updates have to be confirmed.
- End-to-end encrypted automatic backups to USB drive or to any cloud storage (e.g. Nextcloud).
Open Source and Attestation
- Open source allows checking for backdoors.
- Remote attestation: hardware-based verification of the authenticity and integrity of phone's software.
Secure Communication
For secure messages, voice and video calls use the free, end-to-end encrypted, and privacy-friendly Signal and NitroChat. Alternatively, we support you in operating your own Matrix server.
Enterprise-Ready MDM
To manage a larger number of devices and enforce policies and configurations on them, a powerful MDM is available as open source. Organizations can operate it themselves or obtain as a service.
Who Needs NitroPhone?
- People who want to use a privacy-friendly smartphone (without Google, without Apple).
- Executives, VIPs and professionals who need a secure smartphone for sensitive data and communication.
- Companies and authorities who want to provide their employees a secure smartphone.
- Journalists, activists and NGOs who need to protect themselves and their contacts.
Hardware
- Google Pixel 8 Pro
- Color: Obsidian
- RAM: 12 GB
- 170 mm (6.7"), 1344 x 2992 pixel, 489 ppi, LTPO-OLED full-screen display with punch-hole front camera
- Rear camera: 50 MP wide-angle camera, 48 MP ultra-wide-angle camera, 48 MP telephoto lens with 5x optical zoom
- Front camera: 10.5 MP
- Processor (CPU): Google Tensor G3 Nona-core, max. 2.45 GHz
- Titan M2 security chip
- Ports: USB-C 3.2 Gen
- Networks: GSM, LTE, 5G (sub-6 GHz, No complete frequency coverage in USA) NitroPhones work with all major carriers but not with all 5G networks. Check with your carrier to make sure your phone works on its 5G network.
- Wi-Fi 7 (802.11be), Bluetooth 5.3, NFC
- Fingerprint sensor under the display
- 1x Nano SIM card slot, 1x eSIM
- Protection class of the NPO4PxA "all inclusive": IP68. Other models with components removed: none
- Dimensions: 162.6 (height) x 76.5 (width) x 8.8 (depth) mm
- Weight: 213 g
- Removed sensors (optional): microphones, accelerometer, gyroscope, rotation sensor, device pickup sensor, tilt sensor, gravity sensor, compass, step counter
Scope of Delivery
- Google Pixel 8 Pro
- USB-C to USB-C cable
- USB-A (female) to USB-C (male) adapter
- SIM card needle
- Sealed box
Why Google Pixel Smartphone?
- Unlike most other devices, Pixel smartphones include a Titan M2 secure element that enables Verified Boot.
- Pixel smartphones are supported by Android by default, so security updates can be distributed quickly.
- Pixel smartphones allow installation of custom software such as GrapheneOS. Ironically, this makes them some of the best hardware for Google-free smartphones.
Comparison With e.g. LineageOS, CalyxOS, /e/
LineageOS, CalyxOS, /e/ and other Android distributions essentially rely on the standard Android which only comes with its own selection of apps. GrapheneOS, on the other hand, is an elaborately hardened Android and should therefore be seen as its own operating system. In addition, some of the distributions mentioned at the beginning provide security updates late.
Comparison With Linux Phones
Establishing Linux for smartphones as a third ecosystem alongside iOS and Android is a promising goal. In addition to thousands of existing applications, user freedom, transparency and security, the usability on both smartphones and large screens is compelling. Unfortunately, "Linux for Smartphones" is not yet mature enough for most users. In order to offer our customers a professionally usable, stable and secure smartphone, we have chosen GrapheneOS.
Therefore Nitrokey
We make security products, like the NitroPhone, accessible to technically inexperienced people. Enterprises and professionals appreciate that they do not have to deal with technical details. In addition, we bear the risk of technical defects during production and still sell the NitroPhone with standard warranty. In addition, we offer technical customer support. Optionally, we remove microphones, sensors and cameras from the NitroPhone.
Legal Notice
Nitrokey has modified this smartphone, originally manufactured by Google, without Google's consent. Any Google trademarks on this product merely indicate the original product and are not used by Nitrokey as trademarks.