Straight answers about ArpokratOS, Arpokrat Messenger, the relay network, and what things actually cost.
Three tiers, one philosophy. Privacy shouldn’t require a threat model, but the tools that protect it can still be matched to one.
Hardened prioritizes isolation over integration. If you need the Google Play ecosystem, mainstream social apps, or cloud backups, Essential — or a different device entirely — may serve you better. Which tier fits which situation is set out on who Arpokrat is for
Arpokrat is a private company based in Zug, Switzerland. We are independently funded, take no money from Big Tech, and run no advertising business. Every product we release asks for the minimum information it can function on, because data we never collect is data we can never lose, sell, or be compelled to hand over.
The reasoning behind that is set out on our philosophy page
Geography is part of the security model. Switzerland offers:
What Switzerland is not is a country without law enforcement, and we do not claim otherwise: it has a lawful-interception regime like any other jurisdiction. That is precisely why we publish a signed warrant canary
Because the default internet runs on surveillance. Most “free” services are paid for with behavioral data — location, contacts, conversations, habits — collected in order to be profiled and resold.
We think privacy should be the default state of a device rather than a setting you have to go and find. Arpokrat exists so you can communicate without being profiled.
No — and you shouldn’t have to. “Trust us” is not a security property. Arpokrat is built as a zero-trust architecture: the system is designed so that we cannot read your messages or reach your keys, whatever we might want.
Where you don’t have to take our word for it, don’t. The protocol is public and documented on the protocol page
Our warrant canary is PGP-signed too, so you can check our operational integrity yourself
A service can be legally forbidden from telling you that it received a secret government order — but it cannot be forced to keep publishing a signed statement saying that it never did. So we publish one, PGP-signed and dated, and re-sign it inside a 60-day window.
That makes absence the signal. If the canary page is ever removed, not updated by the deadline, or if the PGP signature fails to verify, you must assume that Arpokrat has been compromised.
The current statement, the commands to check it and the key fingerprint are on the warrant canary page
Four things you can check without asking us for anything:
Compare the fingerprint against a source that is not this website. A fingerprint you only ever saw here proves nothing about us.
Yes. Arpokrat’s clients are fully open source and licensed under the AGPLv3. Anyone can inspect exactly what the app does — there are no black boxes, no hidden telemetry, and no backdoors to take on faith.
ArpokratOS is a fork of GrapheneOS, the hardened Android widely regarded as the gold standard for mobile privacy. We inherit its years of security review instead of starting from scratch, then add what it leaves out: a built-in messenger, system-wide Tor, and kernel-level radio lockdown. GrapheneOS is open source, and the Arpokrat-specific additions are open source too. We don’t claim to out-harden it — we credit it.
Arpokrat Messenger is built on an open messaging protocol whose specification and source code are public and independently reviewable: SimpleX
Our own repositories are at github.com/Arpokrat
No tracking cookies, no analytics, no ad tech, no third-party scripts. There is no cookie banner here because there is nothing to ask your consent for.
One functional exception, stated precisely rather than as an absolute: opening our contact page sets a strictly-necessary session cookie carrying the CSRF token that protects the form against forged submissions. It identifies nobody, it feeds no analytics, and it is exempt from consent requirements — which is why there is still no banner. The swap widget likewise keeps a small amount of state in your browser’s session storage so a quote survives a refresh; it never leaves your device.
No. We provide the software (ArpokratOS); you provide the hardware — a Google Pixel you buy yourself. That is deliberate.
If we mailed you a phone, it could be intercepted and tampered with in transit. Buying a sealed Pixel locally and flashing it yourself closes that gap on our side. That can’t vouch for Google’s own hardware supply chain; it only takes Arpokrat out of the chain of custody. The full reasoning is on the ArpokratOS page
It comes down to one sentence: we cannot leak what we do not collect.
Using our apps requires no personal information at all. Buying ArpokratOS requires a name, an email address and a country of residence, for payment processing only. Messages awaiting delivery live only in volatile RAM on our relays, never on disk, with swap disabled so the system can’t page that memory out to storage.
The full legal text is in our privacy policy
The infrastructure behind that claim is documented on the infrastructure page
Yes — Arpokrat Enterprise is available now. It covers bespoke deployment of hardened devices and self-hosted communication infrastructure for organizations with elevated security requirements, including coordinated update governance across a fleet and private relays. Engagements start at 10 devices.
Scope, engagement model and how to start are on the Enterprise page
Use a passphrase, not a PIN, and aim for at least 16 characters — the default length of our own password generator
A four-digit PIN has ten thousand possible values and is not a serious defense against someone holding the device. Length matters more than exotic symbols: a long passphrase of ordinary words is easier to remember and much harder to guess than a short mixed-character string.
That depends on whether you use a SIM card, and the distinction matters — so here it is in full.
So: with a SIM inserted for calls and SMS, you are locatable at the network level, exactly as you would be on any other phone. If that is part of your threat model, run the device without a SIM, over Wi-Fi only, and communicate through Arpokrat Messenger
Over the air. ArpokratOS receives over-the-air (OTA) updates on the device itself — you do not need a computer or a re-flash to stay current. Your one-time license includes lifetime updates for that device.
Release manifests for ArpokratOS are signed on a dedicated, air-gapped machine that has never touched the internet, as described on the infrastructure page
Technically yes, by installing an APK (Android Package Kit — Android’s installer format) directly. There is no Google Play Store on the device.
We advise against it: each third-party app widens the attack surface, and many carry exactly the trackers the rest of the system exists to remove.
Yes — standard GSM calls and SMS work if you insert a SIM card. Two things follow, and both are properties of cellular networks rather than of ArpokratOS:
For communication that avoids both, use Arpokrat Messenger
Not yet, natively. ArpokratOS doesn’t include a built-in email client — a secure, metadata-minimizing one is in development, and until then the device is focused on instant communication.
In the meantime, you can install an email app of your choice via APK, the same way as any other third-party app. The same caution applies: each third-party app widens the attack surface, and many carry exactly the trackers the rest of the system exists to remove.
On Android, yes. ArpokratOS is Pixel-only, but the Arpokrat Messenger app runs on any modern Android phone — install it from the Google Play Store, or download the APK directly.
iOS is coming soon, as are desktop builds for Windows, macOS and Linux. The current status of every platform is shown in the Download panel at the bottom of this page, and on the Messenger page
Today’s public-key cryptography relies on math that a large enough quantum computer could eventually break — and an adversary can record encrypted traffic now in order to decrypt it later, a threat known as “Harvest Now, Decrypt Later.”
Arpokrat Messenger’s key exchange adds a post-quantum layer alongside the classical encryption already in use, rather than replacing it. That key exchange uses Streamlined NTRU Prime — a deliberate choice over the NIST-standardized Kyber, which SimpleX’s engineers avoided due to specific cryptographic concerns raised during its standardization.
We’re deliberately measured about this: post-quantum cryptography is the current best-practice defense, not a permanent guarantee. It raises the bar significantly today, with a clear upgrade path as standards evolve. The full explanation is on the protocol page
As little as the protocol allows. Arpokrat Messenger is built on SimpleX, which has no user identifiers at all — no phone numbers, no email addresses, not even random user IDs.
A relay sees an encrypted payload arrive in an anonymous queue and later be collected, with nothing linking either event to a person. Each relay carries only one leg of an intentionally split path, so no single server holds both halves needed to connect two parties. How that works in detail is on the protocol page
Yes. Arpokrat Swap is a non-custodial aggregator: it surfaces live offers from independent providers, each scored A–D on how much identity verification it asks for, and the swap runs directly between you and the provider you choose. Your funds never touch our infrastructure.
It is built into the Messenger app and also runs in your browser at Arpokrat Swap
Not to Arpokrat. There is no account, no ID check, and nothing for us to verify.
Swap providers are independent businesses with their own policies, which is why every offer carries a KYC score from A (no KYC) to D (KYC required), shown before you commit. You choose the tradeoff between price and privacy on each trade.
Arpokrat charges 1.5% on swaps. That is the only fee we charge: there is no fee on wallet-to-wallet transfers, no account fee, and no subscription.
The amount quoted before you confirm a swap already has network and provider fees included, so the figure shown is the figure you get. The 1.5% is what funds the Arpokrat ecosystem — infrastructure, app development, and ArpokratOS — including the free Messenger app.
How offers are compared side by side: Arpokrat Swap
Instead of routing every conversation through one company’s servers, Arpokrat runs blind relays across five independent jurisdictions.
The relays are Arpokrat-operated, and we don’t claim otherwise. What is distributed is the legal exposure — no single jurisdiction’s process reaches the whole network. The map is on the infrastructure page
A blind relay is a dead drop. It receives a cryptographically sealed packet, puts it in a temporary anonymous queue, and hands it over when the queue’s owner collects it.
The architecture is documented in full on the protocol page
Each has a data-protection framework that applies to us and no blanket data-retention mandate for transit or relay services. Malaysia and Mauritius sit outside the “14 Eyes” intelligence alliances; Switzerland sits outside the EU and EEA and sets its own rules; Iceland’s IMMI framework is written to protect sources and free expression; Panama’s Law 81 is legally independent of both the US and EU frameworks.
The point of the spread is legal diversity: no single government’s process reaches every relay. The reasoning per country is on the infrastructure page
Our relays do not log connections. Daemon-level logging is disabled, and pending messages live in RAM and are cleared once delivered, so there is no routing history or connection record to retain, produce, or lose.
One precise exception on the website side, because an absolute that isn’t checkable is worth less than a scoped claim that is: the contact form and the swap widget use your IP address transiently, to enforce rate limits and block abuse. The counter lives in ephemeral, memory-backed storage, is never written to a log, and is purged on reboot. The address is used, not stored. The full statement is in our privacy policy
Yes, and there are two routes.
Arpokrat’s relay software is open source and free to self-host. If you’d rather not rely on ours, run your own — connect it to the network and route your own traffic through infrastructure only you control. A setup guide is coming to our blog.
Organizations that need dedicated, managed relays inside their own infrastructure can have them deployed as part of an Enterprise engagement instead. Scope and process are on the Enterprise page
Enterprise is a bespoke deployment rather than a product you buy off the page. Each engagement is scoped to your environment, your threat model, and your compliance obligations, and starts at 10 devices.
The full scope is on the Enterprise page
Yes. A smaller pilot or proof-of-concept can be arranged before any full commitment, available on request. Tell us about your organization’s requirements and we’ll scope a deployment to match; all inquiries are handled in confidence.
Start the conversation from the Enterprise page
Yes — white-label deployment is part of the Enterprise offering. You can apply your own visual identity, naming, and in-app language across both the operating system and the messenger, enable or restrict capabilities by role and environment, and deliver the app through your own managed channel rather than a public app store.
What can be rebranded and what stays fixed is set out on the Enterprise page
A response within 12 hours, 24/7/365 — shorter than the under-24-hour commitment that comes with a consumer ArpokratOS license, and included in every enterprise engagement.
A named team handles rollout, hardening, and onboarding, then stays on for the life of the deployment: coordinated, verified updates across your fleet on a schedule that fits your operations, and the same team available for security incidents throughout. The full description is on the Enterprise page
The license and what it includes are set out on the ArpokratOS page
To buy one: checkout
Today: Bitcoin (BTC) and Monero (XMR). Payments run through our own self-hosted infrastructure, with no financial intermediary between you and us.
Card and bank transfer are coming soon. They are not available yet, and we would rather say so than advertise a payment method you can’t actually use at checkout. If your organization needs to buy without cryptocurrency in the meantime, contact our team
If you are new to crypto, one regulated Swiss option is Mt Pelerin
It allows purchases by bank transfer without identity verification below a set daily threshold — around CHF 1,000 at the time of writing — and by card with minimal verification above that. Thresholds and rules change, so check their current terms before relying on them. This is a pointer, not financial advice.
A reply within 24 hours, 24/7/365. Commercial support is included with an ArpokratOS Hardened license — not a community forum. There is no ticket system and no account either: replies come by email, from a person.
Enterprise engagements carry a shorter commitment — a 12-hour response window — described on the Enterprise page
Yes — within 14 days, provided the license has never been used.
A license is refundable for 14 days after purchase, on one condition: it must never have been bound to a device. Binding happens the first time a license key is used to flash a phone — that is what makes the license valid for that device, and it cannot be undone.
So a key bought by mistake and never used can be refunded. A license that has already been used to flash a Pixel cannot.
To request one, contact us
If something here didn’t answer it, ask us directly. There is no ticket system and no account — replies come by email, from a person.
Contact SupportNot sure which product fits you? See who Arpokrat is for →
Checking our operational integrity? Read the Warrant Canary →