GrapheneOS vs LineageOS: which is right for you
"Which degoogled OS should I run?" is really two questions: how much security do you need, and how attached are you to your current phone? GrapheneOS and LineageOS are both excellent; they answer different briefs.
GrapheneOS: security-first, Pixel-only
GrapheneOS is a hardened Android build targeting Google Pixel devices exclusively. That's not brand loyalty — it's because Pixels expose the hardware and firmware hooks GrapheneOS relies on: a separate security co-processor with verified boot and attestation, timely firmware updates, and per-app sandboxing infrastructure that stock Android ships but doesn't fully use.
What you get:
- Sandboxed Google Play. The killer feature. Run Play Services and Play-dependent apps as ordinary, unprivileged sandboxed apps. Most apps work; they just lose their system-level access and background telemetry channels.
- Hardened memory allocator and exploit mitigations beyond AOSP defaults, with a documented history of blocking real-world exploit chains.
- Verified boot with remote attestation. You can cryptographically confirm the OS on the device is genuine GrapheneOS — this is what our attestation records for degoogled phones are built on.
- Automatic, fast security updates and a documented support lifetime.
The trade-offs: Pixel hardware only, and some stubborn apps (usually ones that check for Play certification at the system level) need the sandboxed Play route.
LineageOS: breadth and control
LineageOS is the community AOSP fork with support for well over a hundred devices. If your phone isn't a Pixel, this is usually your option — and that's the core value: keeping perfectly good hardware out of landfill and out of the upgrade treadmill.
What you get:
- Wide device support, including devices long abandoned by their manufacturers.
- AOSP-clean experience with no Google integration by default; add microG if you need it.
- Control and customisation — Lineage is closer to stock-you-configure than to a hardened platform.
The trade-offs are the inverse of GrapheneOS's strengths. Security depends heavily on the specific device and maintainer: official builds are regularly updated, but firmware (bootloader, modem) updates depend on the OEM, and on older devices those are stale. Verified boot is typically not re-signed, so attestation isn't available. Sandbox isolation of Play components is not part of the model.
A decision table
- You want maximum resistance to exploitation, remote attestation, and can use a Pixel → GrapheneOS, no contest.
- You own a non-Pixel you like and want it degoogled → LineageOS (check your device's official support status and update recency first).
- You need Play-dependent apps with minimal friction → GrapheneOS with sandboxed Play beats Lineage + microG for both functionality and security.
- You're a tinkerer who wants to read and modify the OS → both work; Lineage's broader community and device trees make it the more common research base.
One rule either way
Whatever you run, flash it through official channels. GrapheneOS's signed web installer exists precisely so you don't need to trust anyone — including us — for the OS image. For Lineage, use official builds for supported devices. Unofficial "helper" images are the single most common supply-chain failure in this space.
We sell degoogled phones with both OSes where support is solid, always flashed via official installers with attestation recorded per unit. If you're unsure which fits your threat model, the blog's first post covers the broader "why" — and we're happy to talk specifics before you buy.