Firmware integrity & SHA-256 verification
Every StealthOz unit ships a clean flash of upstream open-source firmware (Bruce / Marauder) built from pinned Git tags in a reproducible build pipeline. We do not disable ESP32 flash readout, so you can verify exactly what runs on your device.
How to verify your device
pip install esptool
esptool.py --port /dev/ttyUSB0 --baud 921600 read_flash 0x0 0x400000 dump.bin
sha256sum dump.bin # compare against the signed hash for your SKU
Per-SKU SHA-256 hashes and flash-offset manifests are GPG-signed with our release key and published on the docs site with each release note. Two independent build machines must produce byte-identical .bin files before a release is signed.
Phones
GrapheneOS devices are flashed only with the official signed GrapheneOS web installer — never custom images. You can independently re-verify via GrapheneOS's own attestable checks.