Uncontrolled application telemetry
Vault applies deny, redact or app-scoped policy values instead of exposing unrestricted device identifiers.
Device-validated prototype · September 2026
A privacy-controlled mobile operating system prototype that places a policy boundary between applications and the device's network, identity, sensors and cryptographic services.
Architecture
The prototype is evaluated by observable controls and bounded test evidence—not by an unqualified “zero telemetry” claim.
Vault applies deny, redact or app-scoped policy values instead of exposing unrestricted device identifiers.
A controlled network boundary blocks direct DNS, NTP and public egress in the measured test windows.
Camera, microphone, location, motion sensors and hardware interfaces are default-denied unless policy permits access.
Vault brokers isolated, non-exportable keys and rejects unrestricted hardware attestation paths.
The tested installation contains no GMS, Google Play Services or Google-owned application payloads.
Boot + unlock demonstration
This short evidence composite uses the installed boot-animation frames and live locked/unlocked device captures.
Test evidence
The 13-page report records packet, sensor, package and key-broker evidence from the current Nothing Phone (1) prototype.
Open the PDF report ↗