Home Business Solutions Buy FAQ Contact Book a Discovery Call
Frequently Asked Questions

Everything you need to know

Honest answers about the device, GrapheneOS, security, the pilot process and what this service can and cannot do.

About the Device

The device is a Google Pixel smartphone configured with GrapheneOS, a security and privacy-focused mobile operating system.

Optimise Privacy supplies and configures the device so it is ready for business use, with agreed apps, security settings, onboarding and support.

No. The device uses normal mobile networks, Wi-Fi and standard connectivity.

It is not a satellite phone and does not require a private network to operate. The security focus is on protecting the device itself, controlling app access, reducing unnecessary data exposure and helping the organisation manage mobile risk more effectively.

No. Optimise Privacy does not provide a private encrypted communications network.

The device can use normal apps such as email, messaging and business applications, depending on the client's requirements and app compatibility. The aim is to provide a more secure and controlled mobile environment, not a closed or hidden network.

Google Pixel devices are used because they are the supported hardware platform for GrapheneOS and provide a strong base for secure mobile deployment.

Using a consistent device type also helps with configuration, support, replacement and onboarding across an organisation.

GrapheneOS is a security and privacy-focused operating system for Google Pixel devices. It is designed to improve device security, strengthen app isolation, reduce unnecessary exposure and give users greater control over permissions and data access.

For business users, the value is not just GrapheneOS itself. The value is the managed deployment, configuration, app setup, onboarding and support around it.

No. No responsible provider should claim any device is unhackable.

The purpose of the device is to reduce risk, improve control and make compromise more difficult. It does not remove all risk. Optimise Privacy focuses on practical mobile risk reduction rather than unrealistic security claims.

No. The device is not a magic anonymity tool.

Privacy and anonymity depend on many factors, including apps used, accounts signed into, network activity, user behaviour and operational practices. The device helps reduce unnecessary data exposure and gives stronger control over apps and permissions, but it does not guarantee anonymity.

Many standard Android apps can work, but app compatibility depends on the specific app. Before a pilot begins, Optimise Privacy asks the client to complete an app compatibility checklist to identify required apps before the device is configured.

Compatibility is assessed on a best-effort basis and should be tested before wider rollout.

Some banking apps may work and some may not. It depends on the bank, the app and the checks used by the app provider. Optimise Privacy does not guarantee banking app compatibility without testing.

If a banking app is business-critical, this should be raised before the pilot begins.

Many common business and communication apps may work, but they should still be tested as part of the pilot process. Optimise Privacy helps install and configure agreed apps, supports user sign-in and checks that the core workflow is practical before recommending wider rollout.

GrapheneOS can support Google services in a sandboxed way where needed. This means Google services can be installed like normal apps rather than having the same deep system-level access found on standard Android devices.

Whether Google services should be installed depends on the client's app requirements and risk preferences.

Not always. The device is often most suitable for users who handle sensitive information — directors, partners, executives, senior staff, travelling staff or employees accessing confidential business data on mobile.

Many organisations start with one or two key users before considering wider deployment.

Security and Privacy

The service is designed to help reduce mobile-related risks such as:

  • Sensitive information being exposed from a lost or stolen phone
  • Apps collecting more data than necessary
  • Weak or inconsistent device configuration
  • Poor control over permissions
  • Unclear lost-device procedures
  • Lack of support for users handling sensitive information
  • Mobile devices being overlooked in the wider security strategy

GrapheneOS provides stronger control over app permissions and access. Apps can be restricted from accessing unnecessary data such as contacts, files, sensors, camera, microphone, location and network access, depending on the configuration.

The goal is to limit what apps can access unless that access is genuinely needed.

App sandboxing means apps are isolated from each other and from parts of the system unless permission is granted. This helps reduce the amount of data one app can access from another app or from the wider device.

The simple explanation: apps should only access what they need, not everything on the phone.

USB protection helps reduce risks from physical connection attempts. Certain settings can restrict USB data access, especially when the device is locked. This can help reduce the risk from untrusted cables, accessories or physical access attempts.

Auto-reboot can restart the device after a period of inactivity. After a reboot, the device returns to a more protected state before the first unlock. This can help reduce risk if a device is lost, stolen or left unattended.

Auto-reboot can be enabled where appropriate, but it may affect user experience and should be discussed before activation.

Remote wipe and mobile device management are not included by default unless separately agreed. Remote wipe also depends on the device being reachable, powered on and connected — it should not be relied on as the only protection.

Optimise Privacy focuses on reducing exposure before something goes wrong through strong device configuration, clear procedures and account/session response steps.

If any phone is stolen while unlocked, risk increases. This applies to all smartphones. Risk can be reduced through strong lock settings, short lock timers, app controls, account/session revocation procedures, profile separation and clear lost-device reporting.

No device can completely remove the risk of a phone being taken while unlocked.

The Pilot Process

The pilot allows the organisation to evaluate whether the device and configuration are practical before considering wider rollout. It helps test required app compatibility, user workflow, device usability, security settings, onboarding requirements, support needs and whether the solution fits the organisation.

No. Optimise Privacy does not request or store user passwords.

A temporary setup PIN/password may be used during configuration. The user changes this during onboarding before live use. Account sign-in should be completed by the authorised user wherever possible.

The service is designed to minimise access to client data. Optimise Privacy does not intentionally access emails, documents, case files or confidential client information unless specifically authorised and necessary for an agreed task.

The preferred process is for users to sign in to their own accounts during onboarding.

Yes. Configuration depends on the client's needs, app requirements and risk preferences.

For example, a law firm, financial adviser, consultant or executive team may each require different apps, permissions and security settings. The aim is not to make the device difficult to use — the aim is to make it practical and better controlled.

Yes. Optimise Privacy can work alongside an existing IT provider where needed. The service is not designed to replace the client's IT provider — it is focused specifically on secure mobile deployment, configuration and support.

Lost, Stolen or Compromised Devices

Report it immediately using the agreed support channel. Provide the time and location of loss, whether the device was locked or unlocked, whether the SIM is still active, what apps and accounts may be accessible, and whether the device contains or can access sensitive information.

Depending on the support plan and scope, Optimise Privacy can help guide the response. This may include advising on SIM blocking, account and session revocation, password changes, messaging and authentication app exposure, replacement and rebuild process, and documenting the incident.

Optimise Privacy does not guarantee device recovery, tracking or remote wipe unless separately agreed and technically available.

The client remains responsible for legal, regulatory, insurance and client notification decisions. Optimise Privacy can support the technical response process, but does not provide legal or regulatory advice.

Yes, replacement rebuild support can be provided depending on the support plan or agreed scope. This may include setting up a replacement Pixel device, installing GrapheneOS, applying agreed configuration and supporting user onboarding again. Hardware cost and availability are separate unless specifically agreed.

Support and Ongoing Use

Support may be available by WhatsApp, email and phone depending on the support plan. Different plans include different response targets and levels of support. Details are available on the Business Solutions page.

Yes, but the training is practical and simple. Users need to understand how to use the device, how permissions work, what to do if something looks suspicious, what to do if the phone is lost or stolen, how to contact support and which apps are approved for business use.

In many cases, separation can be supported through profiles and configuration choices. This can help keep work-related apps and data more controlled. The best approach depends on the client's risk appetite, app requirements and user workflow.

Suitability and Limitations

No. It may be suitable for any organisation handling sensitive information, including law firms, financial advisers, consultants, real estate businesses, security-conscious SMEs, executive teams, professional services firms, organisations with travelling staff and businesses handling client or financial data.

No. The service does not replace cyber insurance. It is a technical and operational measure designed to help reduce mobile risk. Cyber insurance, legal advice, compliance advice and wider cyber governance remain separate matters.

No. Optimise Privacy does not guarantee GDPR, SRA, FCA or other regulatory compliance. The service can support stronger mobile security and data protection practices, but legal and regulatory responsibility remains with the client and their advisers.

No. Optimise Privacy can complement existing IT support by focusing specifically on secure mobile device deployment and support. Your IT provider may still manage email systems, cloud platforms, networks, laptops, backups and wider infrastructure.

The main benefit is control. Optimise Privacy helps organisations take a more deliberate approach to the mobile devices carrying sensitive information every day.

The service combines secure hardware, GrapheneOS configuration, app setup, onboarding, support and clear procedures — so mobile security is no longer an afterthought.

Still have a question?

Message us on WhatsApp or send an enquiry and we will get back to you within one hour during support hours.

Send an Enquiry