Wyrd
EN RU

Device fleet management on GrapheneOS

Personal stays private. Work stays under control

A fleet of corporate phones on GrapheneOS, managed by your own server. Nothing stands between the phones and that server: no app store, no vendor cloud.

Pricing Documentation

The foundation

GrapheneOS is an independent open source project. It is Android without Google services, hardened against exploits. Wyrd adds corporate management of work profiles on top of that foundation.

GrapheneOSWyrd

Features

Work profile

A work profile is created on the employee's phone, and the system touches nothing else. The personal half of the device is out of its reach. The phone states plainly that the profile is managed by the organisation, and that cannot be hidden.

Applications

You upload an application file to the panel and push it to the devices you choose. No app store and no Google services are involved. Applications can be configured in advance, and installing anything else into the work profile can be blocked.

Policies

Moving work data into the personal half is closed off. The clipboard shared between the work and personal halves is turned on or off from the management panel. Policies are enforced continuously and cannot be removed on the phone itself.

Visibility

Model, system version, patch level and bootloader state for every device. You see the fact that USB debugging is on, a SIM change, failed unlocks and the network calls applications make.

Vulnerabilities

The server matches the patch level of every device against the Android vulnerability catalogue. The catalogue refreshes itself automatically.

Alerts

You define the rules: failed unlock attempts, a device that stopped reporting, vulnerabilities above a severity you pick, an entry in the security log. An alert clears itself once its cause is gone.

Lost phone

From the panel the work profile is locked, and wiped if the device is not coming back. If the phone is offline, it gets the command the moment it comes back online.

Finding a device

Coordinates are collected only after the phone's owner grants explicit permission. That permission can be withdrawn.

Updates

The server is updated by installing a newer Debian package over the old one. It picks up the latest version of the mobile application itself and distributes it to the devices.

Limits

Architectural limits and commitments.

Personal is off limits

Personal applications, messages, photos and accounts are invisible to the administrator. They are never collected and never wiped.

Wiping the whole device

Only the work profile is wiped. The product has no command that erases the phone itself.

Phones and connectivity

Phones and mobile service are not part of the product.

Protection from the owner

No fleet management system stops a person from showing their screen, reading a message aloud or handing over an unlocked phone. The system reduces the risk of loss, theft and infection. It does not replace your rules for handling information.

What you need on your side

Server

  • A Debian server, physical or virtual: 2 cores, 2 GB of memory, 20 GB of disk, 40 GB recommended for logs and the map cache.
  • A domain name. The TLS certificate is set up automatically.
  • Network access from the phones to the server.
  • Backups of the server database on your side.

Phones

  • Google Pixel 8 or newer. The eighth generation brought hardware memory protection, and update support grew from five years to seven.
  • No carrier-locked devices. Their bootloader is locked for good, so no other system can be installed on them.
  • Foldables are not recommended. Unfolding is known to cause faults – from uneven screen backlight to loss of mobile service.
  • Second-hand devices are suitable and reduce the cost of the fleet.

How a rollout goes

  1. Server

    You install the package on your server and open the management panel.

  2. Licence

    Without a key the server handles up to two phones. The key raises that limit.

  3. Phones

    Each device is connected to a computer by cable. The flashing tool installs GrapheneOS, creates the work profile and connects the phone to your server. If GrapheneOS is already installed, the data on the phone is kept.

  4. Operation

    From then on you work in the management panel: policies, the set of applications, the state of the fleet, commands to devices.

Pricing

The plan sets the number of devices and the way support works.

Free

$0

Permanent

Up to 2 devices

  • Every capability of the system.
  • No account and no contract needed.
  • Documentation is open to everyone. Portal support answers with no promised time.
Installation guide

Minimal

$15per 30 days

$160 per year, which is $13.3 a month

Up to 10 devices

  • Everything in the free plan.
  • Support through the portal for the whole licence term: a reply within 2 hours, weekdays 07:00–15:00 UTC.
  • Video courses on Wyrd.
  • Renewal at any moment.
Buy

Enterprise

On request

Device count, term and price by agreement

Any number of devices

  • Everything in the Minimal plan.
  • A dedicated support channel: a direct chat in the messenger of your choice.
  • Hosting the server on our capacity is a separate agreement.
Discuss terms

When a licence expires the fleet is not blocked. The panel and the list of devices stay in place, and the server stops accepting new data from the phones.

Where to start

Rent a virtual server, install the package by the guide and connect the first phone. Two devices need no licence.

Documentation Demo Support