Android app by GrapheneOS that uses hardware-backed attestation to verify the integrity and authenticity of a supported device and its operating system, confirming it has not been tampered with.
Auditor
attestation.appA hardened pick. Worth the effort once you have chosen to shrink your footprint on purpose. Enough for most people. Threat levels
Auditor does something most security tools cannot: it gives you a cryptographic proof, not just a software assertion, that a device is running the OS it claims to run. Using Android’s hardware-backed keystore and verified boot chain, it lets one Android device audit another over QR codes, or run scheduled remote checks with email alerts. The catch is narrow hardware support: it works best with Pixel devices running GrapheneOS or stock Android, and the value only lands if you understand what attestation failure actually means. For GrapheneOS users, it is a natural companion that rounds out the trust model.
Measures the security configuration of the tool's own website, not the privacy of the product itself. A strong tool can still score low here.
Auditor alternatives
Do almost anything: use, change, and ship it, even inside closed-source products. The only condition is keeping the copyright notice.
Permits
- Commercial use
- Modification
- Distribution
- Private use
Requires
- License and copyright notice
Does not provide
- Liability cover
- Warranty
Why it matters: Permissive licensing lets anyone reuse this, including inside closed products. That is freedom to build on, but no guarantee that downstream copies stay open.
Plain-language summary of the project's license, not legal advice. Read the full text for the exact terms.
* Average ratings will show on this page once the threshold of 5 ratings is reached.