Security model
This page is the one to read before you trust WraithLink with anything that matters. It describes what WraithLink actually defends against, how, and - just as important - where it stops.
Threats WraithLink is built for
- Theft of a powered-off or locked phone. Full-disk encryption keyed to your lock credential, enforced by the secure element with attempt throttling. Standard, and strong.
- Coercion to unlock. The decoy-duress PIN opens your everyday phone while silently destroying the hidden WraithVault. A coercer sees a real, working device with nothing sensitive on it.
- Seizure where you can act. A panic credential destroys the device's encryption keys outright. Because the keys are killed first, the data is unrecoverable even if the process is interrupted a second later.
- Network surveillance. Encrypted DNS, per-connection MAC randomization, optional Tor routing, and 2G disabled to resist fake-tower downgrade attacks.
- Opportunistic physical access. USB data blocked while locked, ADB off by default, auto-reboot back to a keys-evicted state after idle, auto-wipe after repeated wrong attempts.
- Remote exploitation. The upstream exploit mitigations and hardened memory allocator are preserved, the attack surface is trimmed, and heavy tooling is kept off the phone entirely (see X47 pairing).
The ceiling, stated plainly
There are also seams a determined examiner can find: the presence of a secondary profile is detectable over ADB or with physical acquisition even when it is hidden from the everyday UI. WraithLink hides WraithVault from casual view - the lock-screen switcher, quick settings, cross-profile notifications - but it does not claim to make the vault invisible to forensics. For state-level threats, the honest advice is: use the panic wipe, and don't rely on deniability you don't have.
What we deliberately did not change
WraithLink keeps verified boot, hardware attestation, and the upstream package identifiers intact. Renaming internal package IDs or defeating attestation to look "less like GrapheneOS" would break the WebView/browser wiring and, worse, weaken the very integrity guarantees that make the duress feature meaningful. The rebrand is user-facing only.
Trusting the build
WraithLink is signed with its own release key and relocks the bootloader against it, so the phone will refuse to boot a system image that isn't WraithLink's. Factory images published on this site carry a SHA-256 checksum, and the web installer verifies it in your browser before writing anything. Always check the checksum against the release.