Basic Security Pixel 9a with GrapheneOS

Last updated
Aug 16, 2026
Mobile brand
Google Pixel
Mobile model
Pixel 9a
Phone OS
Custom Android ROM
Phone OS version
Android 17
Phone OS Support status
Supported - Able to receive updates for OS and security
Phone OS Updates status
Automatic updates
App store(s)
    • Other APT/APK sources
App updates
Auto-update on any connection
Phone unlock
PIN (medium-high security)
Biometric security
    • None
SIM PIN and Card Lock
    • Not protected
Stolen Device Protection
Off
Tracker Protection
    • Off
Find my Phone
    • Off
Security & Privacy Apps
GrapheneOS built-in security with Android security preview releases, usually a couple each month.

All GrapheneOS built-in exploit protections enabled:
  • Hardened memory allocator
  • Memory tagging
  • Secure app spawning
  • Native code debugging
  • WebView JIT
  • Dynamic code loading via memory
  • Dynamic code loading via storage
GrapheneOS features overview

App updates via GOS App Store, Accrescent and Obtainium.
Quad9 DNS
Firewall & VPN Apps
None
Browser
Built-in Vanadium with ad blocking and hardened WebView
Password manager
None
Authenticator
None
Phone & Caller ID
Fossify Phone
Messaging
Fossify Messages
Music & Podcasts
Auxio
Photo & Video
Fossify Gallery
Entertainment
Via Vanadium
Note-taking
Fossify Notes
Cloud storage
None
Games
None
Android launcher
GrapheneOS Launcher with Android themed icons.
File and Photo backup
Automatic built-in Seedvault system backup
Manual file backup
Subscriptions
    • None
Notable changes
GrapheneOS with lean and mean configuration. All GOS-specific security features enabled. Almost all Fossify apps. App updates via GOS App Store, Accrescent and Obtainium. No bloat. No Google. No AI. No BS.

Moving to GOS was hands-down the best move I've made in tech. (y)(y):cool:
What I'm looking for?

Looking for minimum feedback.

I've also played and able to install Debian using Termux and Termux:boot to install self hosted searxng + nginx + local https, it works well but lot's of works for maintening up-to-date and run all maintenance scripts like upgrade/check/clean, and android keyboard for doing that are a total mess, i've to connect a usb keyboard, so i'am done with that, i 've IVPN and it suit my needs. I preferer by far using searxng +nginx + https locale on my Debian distro, work like a charm with alls maintenance scripts :

==============================================================
King-One SearXNG Health Check v4.6
==============================================================
Vérification d'une installation SearXNG native
MODE COMPLET
==============================================================

[INFO] Démarrage de King-One SearXNG Health Check v4.6

==============================================================
Audit système
==============================================================
[ OK ] 001 Distribution compatible
[ OK ] 002 Codename distribution — debian
[ OK ] 003 Architecture système — x86_64
[ OK ] 004 Kernel Linux — 6.12.101+deb13-amd64
[ OK ] 005 Hostname — ROOTS
[ OK ] 006 Exécution en root
[ OK ] 007 Commande bash
[ OK ] 008 Commande python3
[ OK ] 009 Commande git
[ OK ] 010 Commande curl
[ OK ] 011 Commande openssl
[ OK ] 012 Commande nginx
[ OK ] 013 Commande systemctl
[ OK ] 014 Commande ss
[ OK ] 015 Commande awk
[ OK ] 016 Commande grep
[ OK ] 017 Commande sed
[ OK ] 018 Commande stat
[ OK ] 019 Commande journalctl
[ OK ] 020 Commande getent
[ OK ] 021 Commande id
[ OK ] 022 Commande free
[ OK ] 023 Commande df
[ OK ] 024 Commande ps
[ OK ] 025 Commande pgrep
[ OK ] 026 Commande timedatectl
[ OK ] 027 Répertoire principal — /usr/local/searxng
[ OK ] 028 Sources SearXNG
[ OK ] 029 Virtualenv
[ OK ] 030 Configuration SearXNG
[ OK ] 031 settings.yml
[ OK ] 032 limiter.toml
[ OK ] 033 Service systemd
[ OK ] 034 Python virtuel exécutable
[ OK ] 035 pip virtuel exécutable
[ OK ] 036 Utilisateur searxng
[ OK ] 037 Home searxng — /usr/local/searxng
[ OK ] 038 Shell searxng — /bin/bash
[ OK ] 039 Groupe searxng — searxng
[ OK ] 040 Configuration Nginx
[ OK ] 041 Sites disponibles Nginx
[ OK ] 042 Sites activés Nginx
[ OK ] 043 Configuration Nginx valide
[ OK ] 044 settings.yml YAML valide
[ OK ] 045 use_default_settings présent
[ OK ] 046 secret_key présente
[ OK ] 047 secret_key non par défaut
[ OK ] 048 secret_key longueur correcte — 64 caractères

==============================================================
Audit TLS
==============================================================
[ OK ] 049 Certificat présent
[ OK ] 050 Clé privée présente
[ OK ] 051 Certificat lisible
[ OK ] 052 Clé privée lisible
[ OK ] 053 Certificat / clé correspondants
[ OK ] 054 Certificat non expiré
[ OK ] 055 Expiration > 30 jours — 822 jours
[ OK ] 056 Subject Alternative Name
[ OK ] 057 Émetteur certificat — C=FR, ST=France, L=Maison, O=Maison-CA, CN=Maison-CA
[ OK ] 058 CA présente
[ OK ] 059 Chaîne de confiance
[ OK ] 060 Résolution searx.local
[ OK ] 061 HTTPS disponible
[ OK ] 062 HTTPS HTTP 200

==============================================================
Audit Nginx
==============================================================
[INFO] VirtualHost détecté : /etc/nginx/sites-available/searxng
[ OK ] 063 VirtualHost détecté
[ OK ] 064 Service Nginx actif
[ OK ] 065 Service Nginx activé
[ OK ] 066 Processus Nginx
[ OK ] 067 Configuration Nginx valide
[ OK ] 068 server_name correct
[ OK ] 069 Port HTTPS 443
[ OK ] 070 Directive ssl_certificate
[ OK ] 071 Directive ssl_certificate_key
[ OK ] 072 Proxy HTTPS configuré
[ OK ] 073 Proxy vers backend 8888
[ OK ] 074 Configuration SSL complète

==============================================================
Audit Valkey
==============================================================
[ OK ] 075 Service Valkey actif
[ OK ] 076 Service Valkey activé
[ OK ] 077 Client Valkey/Redis — valkey-cli
[ OK ] 078 Endpoint Valkey — TCP 6379
[ OK ] 079 Port TCP 6379
[ OK ] 080 PING Valkey/Redis
[ OK ] 081 Version serveur KV — 7.2.4
[ OK ] 082 Configuration Valkey

==============================================================
Audit SearXNG
==============================================================
[ OK ] 083 Service SearXNG actif
[ OK ] 084 Service SearXNG activé
[ OK ] 085 Version SearXNG — 2026.8.14+094c33d40
[ OK ] 086 Import Python searx
[ OK ] 087 settings.yml
[ OK ] 088 limiter.toml
[ OK ] 089 Propriétaire SearXNG
[ OK ] 090 Permissions SearXNG — 755
[ OK ] 091 Réponse HTTPS SearXNG — 200
[ OK ] 092 API JSON valide
[ OK ] 093 robots.txt

==============================================================
Audit Python
==============================================================
[ OK ] 094 Python virtuel
[ OK ] 095 Version Python — 3.13.5
[ OK ] 096 Version pip — 26.2.1
[ OK ] 097 pip check
[ OK ] 098 Import Python searx
[ OK ] 099 Import Python yaml
[ OK ] 100 Import Python msgspec
[ OK ] 101 Virtualenv propriétaire

==============================================================
Audit Git
==============================================================
[ OK ] 102 Dépôt Git
[ OK ] 103 Branche Git — master
[ OK ] 104 Commit Git — 094c33d40
[ OK ] 105 Remote Git — origin
[ OK ] 106 URL remote — GitHub - searxng/searxng: SearXNG is a free internet metasearch engine which aggregates results from various search services and databases. Users are neither tracked nor profiled.
[ OK ] 107 Dépôt propre
[ OK ] 108 Worktree valide
[ OK ] 109 Version Git — 2.47.3
[ OK ] 110 Dépôt à jour

==============================================================
Audit sécurité
==============================================================
[ OK ] 111 Propriétaire SearXNG
[ OK ] 112 Permissions SearXNG — 755
[ OK ] 113 Propriétaire settings.yml — searxng
[ OK ] 114 settings.yml non lisible par others — 600
[ OK ] 115 Propriétaire limiter.toml — root
[ OK ] 116 Permissions limiter.toml — 644
[ OK ] 117 Propriétaire certificat
[ OK ] 118 Permissions certificat — 644
[ OK ] 119 Propriétaire clé privée
[ OK ] 120 Permissions clé privée — 600
[ OK ] 121 Validation systemd
[ OK ] 122 Configuration server_name
[ OK ] 123 Configuration SSL
[ OK ] 124 Dépendances Python

==============================================================
Audit des moteurs
==============================================================
[ OK ] 125 Détection dynamique des moteurs — 5 moteur(s) configuré(s)
[ OK ] 126 Moteurs actifs détectés — 5
[ OK ] 127 Moteurs désactivés — aucun
[ OK ] 128 Moteurs inactifs — aucun
[ OK ] 129 Moteur wikipedia — résultat confirmé
[ OK ] 130 Moteur google cse — résultat confirmé
[ OK ] 131 Moteur google cse images — résultat confirmé
[ OK ] 132 Moteur youtube — résultat confirmé
[ OK ] 133 Moteur brave — résultat confirmé

==============================================================
Audit performances
==============================================================
[ OK ] 134 Temps HTTPS — 0.005940 s
[ OK ] 135 Temps backend SearXNG — 0.002097 s
[ OK ] 136 Temps TLS — 0.003539 s
[ OK ] 137 Temps recherche JSON — 0.410018 s

==============================================================
Audit ressources système
==============================================================
[ OK ] 138 Uptime système — up 1 hour, 34 minutes
[ OK ] 139 Charge CPU — 0.54
[ OK ] 140 Mémoire — 7% utilisée
[ OK ] 141 Swap — aucune swap
[ OK ] 142 Espace disque — 2% utilisé
[ OK ] 143 Inodes — 1% utilisés
[ OK ] 144 Horloge synchronisée
[ OK ] 145 Entropie — 256
[ OK ] 146 File-max — 9223372036854775807
[ OK ] 147 Processus actifs — 301

==============================================================
Audit des journaux
==============================================================
[ OK ] 148 Journal SearXNG — 0 erreur critique
[ OK ] 149 Journal Nginx — 0 erreur critique
[ OK ] 150 Journal Valkey/Redis — 0 erreur critique
[ OK ] 151 error.log Nginx — 0 anomalie
[ OK ] 152 Journal Incus — Incus non installé
[ OK ] 153 Journal Kernel — 0 anomalie
[ OK ] 154 Services échoués — aucun
[ OK ] 155 Événements critiques système récents — aucun
[ OK ] 156 Journal systemd accessible

Temps d'exécution : 5s

==============================================================
RAPPORT FINAL
==============================================================

Contrôles exécutés : 156

Succès : 156
Avertissements : 0
Échecs : 0
Échecs critiques: 0

Score indicatif : 100 %

Installation conforme — aucun problème détecté

Journal : /tmp/searxng-healthcheck-0.log


Appuyez sur Entrée pour quitter...
 
BTW LineageOS is available for your device [unofficial]
I know. I refuse to install something that is maintained by some random user with unknown intentions. Too big security risk for me. If it was developed by some kind of foundation like GrapheneOS I'd trust it and install it.
 
  • Like
Reactions: Khushal
Here are exploit protections available in GOS. Please let me know of any other Android or other phone OS that has these protections.
  • Hardened memory allocator
  • Memory tagging
  • Secure app spawning
  • Native code debugging
  • WebView JIT
  • Dynamic code loading via memory
  • Dynamic code loading via storage
 
Last edited:
Here are exploit protections available in GOS. Please ket me know of any other Android or other phone OS that has these protections.
  • Hardened memory allocator
  • Memory tagging
  • Secure app spawning
  • Native code debugging
  • WebView JIT
  • Dynamic code loading via memory
  • Dynamic code loading via storage
I did a quick research and it seems those protection modules are GOS-exclusive