GrapheneOS
Security and privacy hardened Android forms the upstream operating system foundation for Obris SecureOS.
Obris SecureOS builds on open source foundations. We publish the material people need to understand what they are trusting, meet applicable source and attribution obligations, and verify authentic releases without publishing every Obris developed commercial implementation.
Our trust model combines open upstream foundations, documented security architecture, release verification and independent review of proprietary Obris security components.
Obris SecureOS is derived from GrapheneOS and the Android Open Source Project. Those projects remain the upstream foundation. Obris maintains its own modifications and product integration on top.
Security and privacy hardened Android forms the upstream operating system foundation for Obris SecureOS.
AOSP provides the underlying Android platform and the open source components on which the operating system is built.
Obris tracks component licences and publishes source, notices and attribution where an applicable licence requires it.
References to GrapheneOS describe the upstream technical foundation and do not imply that Obris SecureOS is an official GrapheneOS product.
Trust should come from concrete artefacts, not a broad claim that everything is open source.
Source code, licence notices and attribution are made available where the applicable component licence requires distribution.
Document the security boundaries, supported devices, Security User model, YubiKey workflow and the responsibilities of each Obris layer.
Publish release identifiers, supported device information, security patch information and the public material needed to identify an authentic release.
Provide cryptographic hashes and public verification information so downloaded release artefacts can be checked independently.
Describe security relevant changes and fixes without exposing credentials, private infrastructure or anti abuse controls.
Build toward a maintained component and dependency inventory, including an SBOM where it provides meaningful verification value.
Some Obris developed technology is commercial intellectual property. We can protect that implementation while still giving qualified independent reviewers controlled access to evaluate its security properties.
Proprietary components can remain outside public repositories. That includes technology where publication would disclose Obris implementation details without materially improving a customer's ability to verify an installed release.
The intended model is to let an independent security firm inspect selected proprietary security critical components under appropriate confidentiality terms, then publish the audit scope, reviewed version, findings and remediation status.
For each production release, the goal is to publish a compact verification record that ties the documented release to its downloadable artefacts.
Private signing material and operational credentials are not source transparency. Publishing them would reduce security rather than increase trust.
We will distinguish between what is available now, what is being prepared and what remains a future security assurance milestone.
Maintain access to upstream source and satisfy applicable source and notice obligations for distributed components.
Standardise release identifiers, hashes, signature information and source references for production SecureOS releases.
Commission qualified third party review of selected proprietary security critical components and publish meaningful results.
That model gives customers evidence about the security of Obris products while preserving the commercial implementation that differentiates them.