SOVEREIGN
← All guides/

Platform comparisons

GrapheneOS vs CalyxOS

Both are genuinely privacy-respecting, open-source alternatives to stock Android. They make different trade-offs. Here's the honest breakdown.

GrapheneOS and CalyxOS are both non-profit, open-source projects that replace stock Android on Pixel phones with something that doesn't send your data to Google by default. Neither is a scam or a lesser alternative to the other — they're built by different teams with different priorities, and those priorities show up in real, practical differences.

The short version: GrapheneOS prioritises security hardening and ships with nothing Google-related by default. CalyxOS prioritises out-of-the-box app compatibility and ships microG — a privacy-respecting reimplementation of some Google APIs — enabled from the first boot.

Where they agree

Both are non-profit projects with no commercial data-collection incentive. Both are fully open-source and auditable. Both support re-locking the Pixel bootloader so Verified Boot stays active, meaning both can prove — via a boot fingerprint — exactly what software is running. Both are meaningfully more private than stock Android out of the box, and both are legitimate, credible choices for a privacy-conscious Pixel owner.

Where they differ

Exploit hardening. This is the largest practical gap. GrapheneOS implements hardened_malloc (a hardened memory allocator that closes off entire classes of memory-corruption exploits), an expanded kernel attack-surface reduction, and finer per-app permission controls — including network and individual sensor access. CalyxOS's baseline sits meaningfully above stock Android, but doesn't implement hardening to the same depth.

Default Google exposure. CalyxOS ships microG active by default, which is Google-adjacent by design — it approximates Google's APIs closely enough for many apps to work without real Google Play Services installed. GrapheneOS ships with nothing Google-related until you explicitly install Sandboxed Google Play, which then runs Google's actual, unmodified code in an isolated sandbox with no elevated privileges.

Duress and physical-security features. GrapheneOS includes a duress password (wipes the device instead of unlocking it) and configurable auto-reboot (returns the phone to its most secure, encrypted state on a timer). CalyxOS doesn't currently offer equivalents to either.

App compatibility, in practice. Because microG isn't Google's real code, some apps — particularly banking apps that run stricter Play Integrity checks — detect the difference and refuse to run on CalyxOS. GrapheneOS's Sandboxed Google Play uses Google's genuine Play Services binaries, so it passes these checks far more consistently.

Side by side

Default configurations on both platforms. Both can be configured differently from the defaults shown here.

FeatureGrapheneOSCalyxOS
DeveloperGrapheneOS Project (independent, non-profit)Calyx Institute (non-profit)
Supported devicesGoogle Pixel only (Motorola support announced for 2027)Google Pixel, plus some other devices (e.g. Fairphone, select Sony Xperia)
Google Play ServicesNot installed by default; optional Sandboxed Google Play installmicroG (a reimplementation of Google APIs) included and enabled by default
Default app storeApps repository (GrapheneOS first-party apps) plus optional Aurora Store/Sandboxed PlayF-Droid preinstalled; microG enables some Play Store functionality
Exploit hardeningExtensive — hardened_malloc, hardened kernel, expanded exploit mitigationsStandard AOSP hardening plus some additions; less extensive than GrapheneOS
Per-app network permissionYesNo
Per-app sensor permissionYes (including camera, mic, location, USB, network)Partial (standard Android permission model)
Duress passwordYesNo
Auto-rebootYes (configurable)No
Verified Boot / re-lockable bootloaderYesYes (on supported Pixel devices)
Signal preinstalledNo (install from Apps repository)Yes, by default
Banking app compatibilityMost major apps via Sandboxed Google PlayVariable — some apps reject microG's Play Integrity responses
Update frequencyFast — typically within days of AOSP/Pixel security releasesRegular, typically slightly behind GrapheneOS
PhilosophySecurity-first; privacy as a consequence of hardeningPrivacy-first with more permissive Google compatibility by default

Comparison reflects default configurations as of July 2026. Both projects update regularly — verify specifics before making a decision.

Who should choose which

Choose GrapheneOS if security hardening is a priority, if you want a duress password or auto-reboot, if you rely on banking or other apps with strict integrity checks, or if you want the strongest available baseline and are comfortable installing Sandboxed Google Play yourself when you need it.

Choose CalyxOS if you want broader out-of-the-box app compatibility without an extra install step, you value having Signal preinstalled, or your device isn't a Pixel and CalyxOS's wider hardware support matters to you. It's a genuinely solid choice — just a different set of trade-offs.

Frequently asked questions

Is CalyxOS as secure as GrapheneOS?
CalyxOS is a genuinely privacy-respecting, well-maintained project, and its baseline is well above stock Android. But GrapheneOS goes considerably further on exploit hardening specifically — hardened_malloc, an expanded set of kernel and userspace mitigations, and finer-grained permission controls that CalyxOS doesn't implement to the same degree. If security hardening is your primary concern, GrapheneOS is the stronger choice on the evidence.
Why does CalyxOS include microG by default and GrapheneOS doesn't?
It's a philosophical difference. CalyxOS ships microG — a reimplementation of some Google Play APIs — enabled out of the box, prioritising out-of-the-box app compatibility. GrapheneOS ships with nothing Google-related installed by default, and makes Sandboxed Google Play an explicit, opt-in install. Neither approach is wrong; they reflect different defaults for the same underlying trade-off between convenience and minimal footprint.
Will my banking apps work on CalyxOS?
It depends on the app. microG attempts to satisfy Play Integrity checks that many banking apps run, but because microG isn't Google's actual implementation, some apps detect the difference and refuse to run. GrapheneOS's Sandboxed Google Play uses Google's real, unmodified Play Services code running in a sandbox, which is why it passes these checks more consistently. If banking app compatibility matters to you, this is a material difference.
Does CalyxOS support the same phones as GrapheneOS?
CalyxOS supports a slightly broader hardware list, including some non-Pixel devices. But GrapheneOS's Pixel-only scope is deliberate — Pixel is the only line offering the specific hardware security guarantees GrapheneOS's threat model depends on, including a re-lockable bootloader with full Verified Boot support.
Can I switch between GrapheneOS and CalyxOS later?
Yes, on a supported device. Both are separate OS images you flash to the phone, and switching means a clean reinstall — you'll lose data on the device unless backed up separately beforehand. Neither GrapheneOS nor CalyxOS supports an in-place migration from the other.

Chosen GrapheneOS?

Every SOVEREIGN device ships with official, unmodified GrapheneOS, hardened and attested before it leaves us.

Last updated: July 2026. GrapheneOS is a trademark of the GrapheneOS Project. CalyxOS is a trademark of the Calyx Institute. SOVEREIGN is not affiliated with or endorsed by either project.