Loading

Secure & Private

Built for those who refuse to be tracked

Castrum OS is a secure mobile operating system built to protect your data at every layer. With hardened security, local-only controls, and strict sandboxing, your phone stays private, predictable, and fully under your control.

Built for security from the ground up, with advanced protections that safeguard your data.

Designed without backdoors. Engineered for absolute data control.

Absolutely secure communication between colleagues and friends, powered by end-to-end encryption.

Proactive defense that protects the device against both remote and physical attacks.

Privacy is your right

It’s not about hiding your data. It’s about feeling like it’s finally yours again.

Learn more

 Castrum goes further to keep your data safe

Hardened Kernel

A secure system core designed to resist attacks and exploits.

Android Verified Boot

Keeps your system protected from unauthorized modification.

OTA Updates

Fast, seamless security updates delivered directly to your phone.

No Google Services

No built-in tracking, profiling, or Google background activity.

No Forced Cloud Services

Your phone works fully without mandatory accounts and without unwanted syncing.

Multi-layer encryption

Castrum OS uses a multi-layer encryption architecture designed to protect your data at every level of the system.

Encryption is applied not only to files and storage, but also to system communication, application data, and sensitive device processes.

This layered approach ensures that even if one component is compromised, your data remains protected by additional security barriers.

Instead of relying on a single defensive mechanism, Castrum OS spreads protection across the entire operating system to making unauthorized access significantly harder and your personal information far more resilient.

Our main apps

Castrum OS is built with privacy in mind. No analytics, no silent data collection, and no background tracking. Each app runs in its own secure sandbox, so everything stays separate, simple, and exactly the way it should be. Built to work together. Build to protect.

Device control center (DCC)

Designed for device control

DCC goes beyond settings and enforces real security rules.

You decide what your phone can and cannot do. Rules are applied directly on the device, locally and offline.

Your phone follows your rules, not someone else’s.

12:30
  • Block Unknown Sources

    When enabled, installation of apps from unknown sources is blocked. This prevents the installation of potentially malicious apps. When disabled, apps can be installed from any source.

  • Block Location

    When enabled, location services are blocked. This restricts apps from accessing device location data, such as GPS coordinates. When disabled, apps can access location data as needed.

  • Block Bluetooth

    When enabled, Bluetooth connectivity is blocked, preventing the device from pairing with other Bluetooth devices. When disabled, Bluetooth can be used for pairing and data transfer.

  • Block Factory Reset

    When enabled, users cannot initiate a factory reset on the device. This prevents accidental or malicious data erasure. When disabled, users can perform a factory reset.

  • Block USB Storage

    When enabled, USB storage access is blocked. This prevents users from transferring files between the device and a computer or USB device. When disabled, USB storage can be used for file transfer.

  • Wipe Data

    When enabled, the device will automatically wipe all data after 10 consecutive incorrect password attempts. This protects sensitive information from unauthorized access.

  • Password complexity

    When enabled, users must set a complex screen lock password that meets minimum security requirements (e.g., including letters, numbers, or symbols). This enhances device protection against unauthorized access. When disabled, users can set simpler PINs or passwords.

  • Always on VPN

    When enabled, the device must maintain an active VPN connection at all times. If the VPN disconnects, internet traffic is blocked until the connection is restored. This ensures all data is securely tunneled.

  • App encryption

    When enabled, app data is encrypted at rest, protecting sensitive information even if the device is compromised. This ensures that only authorized users and processes can access the stored app data.

  • Block developer options

    When enabled, access to Developer Options is blocked. This prevents users from enabling debugging features, modifying system settings, or activating OEM unlocking — which would allow the bootloader to be unlocked.

  • Restrict users

    When enabled, adding new users or guest profiles on the device is blocked. This ensures that only the primary, managed user can access the device, preventing unauthorized or unmanaged usage. When disabled, users can add secondary accounts or guest profiles.

  • Restrict backup

    When enabled, device and app data cannot be backed up to cloud services. This prevents potential data leakage through third-party backup systems and ensures sensitive information remains on the device. When disabled, users can back up data to supported cloud services.

  • Block SMS

    When enabled, sending SMS messages is blocked. This ensures that no outgoing communication occurs over SMS, a protocol that is unencrypted. When disabled, apps are allowed to send SMS messages.

  • Block Dialer

    When enabled, the device cannot initiate outgoing phone calls through the dialer. This prevents unencrypted voice communication over the cellular network. When disabled, users can make phone calls using the default dialer app.

  • Block Uninstall of System VPN

    When enabled, the system VPN app cannot be uninstalled or disabled by the user. This ensures that the secure VPN connection remains enforced at all times. When disabled, users can uninstall the VPN app.

  • Block fingerprint unlock

    When enabled, fingerprint unlock is disabled. This prevents the use of biometric authentication and enforces screen unlock using a PIN or password only. It ensures greater control over access, especially in high-security environments. When disabled, users can unlock the device using their registered fingerprint.

  • Block hotspot

    When enabled, the device cannot be used as a Wi-Fi hotspot. This blocks internet sharing over mobile data to other nearby devices, reducing the risk of unauthorized network access or data misuse. When disabled, users can enable and use hotspot normally.

  • block screen capture

    When enabled, screenshots and screen recordings are blocked across the system. This prevents apps and users from capturing sensitive information displayed on the screen. When disabled, screen capture functions normally.

  • block USB debugging

    When enabled, USB debugging is blocked. This prevents the device from communicating with development tools like ADB (Android Debug Bridge), reducing the risk of unauthorized access or system tampering via USB. When disabled, USB debugging can be enabled from Developer Options if available.

  • Block Camera

    When enabled, all camera access is blocked. Apps and system functions will not be able to use the front or rear cameras, preventing image or video capture. This helps protect against surveillance and unauthorized recordings. When disabled, camera functionality is fully available.

  • Hide Camera

    When enabled, the Camera app is hidden from the home screen, app drawer, and recent apps list. This prevents users from launching the camera directly, while system-level camera access (e.g., for QR scanning) may still remain available. When disabled, the Camera app is visible and accessible.

  • Hide Gallery

    When enabled, the Gallery app is hidden from the home screen, app drawer, and recent apps. This prevents users from directly browsing stored photos and videos through the default gallery interface. When disabled, the Gallery app is visible and accessible as usual.

  • Hide File Manager

    When enabled, the File Manager app is hidden from the home screen, app drawer, and recent apps. This prevents users from directly accessing or browsing local storage through the system file explorer. When disabled, the File Manager app is visible and accessible.

  • Hide SMS App

    When enabled, the default SMS app is hidden from the home screen, app drawer, and recent apps. This prevents users from accessing or sending SMS messages through the standard messaging interface. When disabled, the SMS app is visible and accessible as usual.

  • Hide Phone App

    When enabled, the Phone (dialer) app is hidden from the home screen, app drawer, and recent apps. This prevents users from making or managing phone calls through the default interface. When disabled, the Phone app is visible and accessible as usual.

SECURITY THAT FEELS EFFORTLESS

Seamless Design

A secure phone doesn’t need to look boring

Castrum OS combines strong security with a clean, modern design.
Every detail is crafted with consistency, clarity, comfort, and ease of use in mind, because a secure phone should feel natural, not complicated.

More than OS

Calculator

Calculator

Fast, clean calculations with no tracking. Includes advanced tools like Date Calculator for everyday planning and productivity.

Calendar

Calendar

Secure scheduling without cloud dependency. All events stay where they belong - on your device.

Clock

Clock

Alarms, timers, and world time tools that work fully offline.

Camera

Camera

Capture photos and videos without background uploads or silent data sharing.

Gallery

Gallery

Your photos stay always on your device - always. Includes Tresor for keeping private photos hidden and protected.

File Manager

File Manager

Full control without hidden transfers. Includes Tresor for securing sensitive files.

Contacts

Contacts

Private address book with no sync leaks and no data harvesting.

Phone App

Phone App

Complete calling functionality is included for compatibility and everyday use. Access can be restricted or disabled through DCC for users who want maximum privacy control.

Messages

Messages

SMS messaging is available when needed, but can be fully blocked or hidden using DCC to reduce exposure to unencrypted communication.

Secure Chat

Secure Chat

Encrypted communication by design, built for privacy-first conversations.

Notes

Notes

Private notes & tasks stored locally and protected by encryption. Simple, clean, reliable.

Secure Store

Secure Store

Castrum-curated apps without surveillance, ads, or hidden permissions. No analytics and no account needed.

Freedom to choose your apps

Castrum OS is not a closed system. Install vetted third-party apps from our secure store, no account required.

Learn more

Smooth on every device

  • Google Pixel 6
  • Google Pixel 6a
  • Google Pixel 6 Pro
  • Google Pixel 7
  • Google Pixel 7a
  • Google Pixel 7 Pro
  • Google Pixel 8
  • Google Pixel 8a
  • Google Pixel 8 Pro
  • Google Pixel 9
  • Google Pixel 9a
  • Google Pixel 9 Pro
  • Google Pixel 9 Pro XL
  • Google Pixel 10
  • Google Pixel 10a
  • Google Pixel 10 Pro
  • Google Pixel 10 Pro XL
Key reasons:
  • Unlockable bootloader — install custom OS and re-lock securely
  • Titan M2 security chip — hardware-backed encryption and verified boot
  • Long-term updates — reliable firmware and documentation
  • Built-in eSIM support — ready for global connectivity
  • Full hardware control — modem, Wi-Fi, and system partitions

Pixel is the only Android platform that allows deep system hardening, secure re-locking, and full hardware-level encryption.

Comparison overview

  • Features
  • Encryption
  • Auto Wipe
  • Secure Log Deletion
  • Enforced Security Protocols
  • Automatic Threat Blocking
  • Advanced Data Security
  • Full-System Hardening
  • Device Owner / Policy Control
  • OTA Update Delivery
  • App Distribution
  • Update Frequency
  • Update Integrity Checks
  • Verified Boot
  • Secure Development Environment
  • Stable Releases Only
  • Device Board Optimization
  • Lightweight & Minimal System
  • Optimized Frameworks
  • Custom Compiler Filters
  • Stock Android
  • Graphene OS
  • Castrum OS
  • Military-grade AES-256
  • Automatic emergency wipe
  • Automatic sensitive log deletion
  • Strict zero-trust & integrity
  • Real-time behavioral blocker
  • Encrypted & isolated data
  • Full-stack hardening
  • DCC pre-installed as system app
  • Encrypted VPS delivery
  • Secure Store with signature verification
  • Independent OTA cycle
  • Signed updates via encrypted VPS
  • Enhanced with strict key algorithms
  • Encrypted ephemeral workstations
  • In-house tested stable releases
  • Optimized for performance & efficiency
  • Bloat-free, no unwanted apps/services
  • Custom frameworks for smoother system performance
  • Less Background JIT, Better Battery under Heavy Loads
  • Features
  • Encryption
  • Auto Wipe
  • Secure Log Deletion
  • Enforced Security Protocols
  • Automatic Threat Blocking
  • Advanced Data Security
  • Full-System Hardening
  • Device Owner / Policy Control
  • OTA Update Delivery
  • App Distribution
  • Update Frequency
  • Update Integrity Checks
  • Verified Boot
  • Secure Development Environment
  • Stable Releases Only
  • Device Board Optimization
  • Lightweight & Minimal System
  • Optimized Frameworks
  • Custom Compiler Filters
      • Castrum OS
      • Military-grade AES-256
      • Automatic emergency wipe
      • Automatic sensitive log deletion
      • Strict zero-trust & integrity
      • Real-time behavioral blocker
      • Encrypted & isolated data
      • Full-stack hardening
      • DCC pre-installed as system app
      • Encrypted VPS delivery
      • Secure Store with signature verification
      • Independent OTA cycle
      • Signed updates via encrypted VPS
      • Enhanced with strict key algorithms
      • Encrypted ephemeral workstations
      • In-house tested stable releases
      • Optimized for performance & efficiency
      • Bloat-free, no unwanted apps/services
      • Custom frameworks for smoother system performance
      • Less Background JIT, Better Battery under Heavy Loads
      • Features
      • Encryption
      • Auto Wipe
      • Secure Log Deletion
      • Enforced Security Protocols
      • Automatic Threat Blocking
      • Advanced Data Security
      • Full-System Hardening
      • Device Owner / Policy Control
      • OTA Update Delivery
      • App Distribution
      • Update Frequency
      • Update Integrity Checks
      • Verified Boot
      • Secure Development Environment
      • Stable Releases Only
      • Device Board Optimization
      • Lightweight & Minimal System
      • Optimized Frameworks
      • Custom Compiler Filters
      • Stock Android
          • Features
          • Encryption
          • Auto Wipe
          • Secure Log Deletion
          • Enforced Security Protocols
          • Automatic Threat Blocking
          • Advanced Data Security
          • Full-System Hardening
          • Device Owner / Policy Control
          • OTA Update Delivery
          • App Distribution
          • Update Frequency
          • Update Integrity Checks
          • Verified Boot
          • Secure Development Environment
          • Stable Releases Only
          • Device Board Optimization
          • Lightweight & Minimal System
          • Optimized Frameworks
          • Custom Compiler Filters
            • Graphene OS

              How to get Castrum OS

              Whether you want a complete ready-made solution or prefer to get Castrum OS on your Pixel yourself, you can choose the option that best fits your needs.

              Conectum Portal

              Flash It Yourself

              Flash Castrum OS on your own Pixel device using the Conectum portal. Built for advanced users who prefer full control and manual setup.

              • Flash Castrum OS yourself
              • Global access
              • Anonymous purchases
              • Optional eSIM and VPN
              Go to Conectum Portal

              Spectre Solutions

              Ready-made Secure Phone

              Get a fully prepared Google Pixel with Castrum OS pre-installed and professionally configured. Designed for users who want a secure phone without any technical setup.

              • Castrum OS with eSIM and VPN
              • Security and privacy preconfigured
              • Ready to use out of the box
              • Optional consulting and support
              Go to Spectre Solutions

              Both options deliver the same hardened operating system. The choice depends only on how you want to get it.