Android phone-to-phone provisioning

SP-UTILITY · NATIVE ANDROID FIELD TOOL

SecurePhone
Device Utility.

Run the app on an Android host phone, connect a target Google Pixel over USB-C, and install GrapheneOS without a laptop. Continue in the same guided flow to load the SecurePhone Device Manager DPC and enroll the new phone.

ANDROID APPPHONE-TO-PHONEUSB-CNO LAPTOP
01No laptopnative Android USB host
02Phone → phoneUSB-C guided workflow
03PixelGrapheneOS target
04DPCSecurePhone enrollment handoff
The actual device topology

One Android app. Two phones. One USB-C cable.

Device Utility lives on the technician's host phone. The connected Pixel is the target: it receives GrapheneOS, then the SecurePhone DPC and its enrollment assignment.

01 / HOST

Android host phone

The technician opens SecurePhone Device Utility on an authorized Android phone with USB host support. Downloads, image cache, prompts, and progress stay on this device.

Runs the app
02 / LINK

USB-C data cable

A direct USB-C connection carries fastboot and ADB between the phones. The operator approves USB access and reconnects when the target changes boot modes.

Carries fastboot + ADB
03 / TARGET

New target phone

A supported Pixel can be erased and flashed with GrapheneOS. The same app can then push the SecurePhone DPC, set Device Owner, and apply the activation code for enrollment.

Receives OS + management
Guided field provisioning

From target Pixel to enrolled SecurePhone.

The native app drives Android USB host mode, fastboot, the GrapheneOS factory-image sequence, and the final ADB enrollment handoff while the operator confirms security-sensitive actions on the target.

01

Authorize

Confirm that the host phone is an approved SecurePhone provisioning device.

02

Connect

Put the target Pixel in fastboot and connect both phones over USB-C.

03

Flash

Download, verify, and flash the correct GrapheneOS factory image, then re-lock the bootloader.

04

Enroll

Load the SecurePhone DPC over ADB, set Device Owner, and apply the activation code.

05

Hand off

Verify policy and required apps, then deliver the managed phone to its user.

Designed for controlled deployment

A field tool, not a generic flashing app.

SecurePhone Device Utility makes the host, target, erase boundary, operating-system source, and management handoff explicit. Authorized operators can prepare phones without exposing a command line or an uncontrolled enrollment path.

01

Native Android, not a web page

The phone-to-phone path uses Android's USB host API directly. The browser installer remains a separate desktop option.

02

Unmodified GrapheneOS

The target receives an official GrapheneOS factory release. GrapheneOS is an independent project and is not affiliated with SecurePhone.

03

Explicit erase boundary

Unlocking the Pixel bootloader and flashing GrapheneOS erases the target. The app calls this out before destructive actions and requires on-device confirmation.

04

Optional enrollment handoff

GrapheneOS installation can end with a clean OS, or continue into SecurePhone DPC installation and enrollment. An enrollment-only path is available when the target is already prepared.

Pack the field kit

What the host and target need.

The app replaces the laptop, not the physical and security requirements of Pixel provisioning. Use supported hardware, enough power and storage, and a reliable data cable.

ANDROID / HOST

Provisioning phone

  • Android 9 or later
  • USB host / OTG support
  • Wi-Fi and space for the factory image
  • Authorized SecurePhone Device Manager
PIXEL / TARGET

Phone being prepared

  • A currently supported Google Pixel
  • OEM-unlockable bootloader
  • Backup completed before flashing
  • Fresh, account-free state for Device Owner
FIELD / LINK

Connection and enrollment

  • Reliable USB-C data cable
  • Both phones sufficiently charged
  • SecurePhone activation code
  • Time to confirm unlock and re-lock
Device Utility FAQ

Before you connect the phones.

01Which phone runs SecurePhone Device Utility?

The app runs on the technician's Android host phone. The Google Pixel connected over USB-C is the target being flashed and enrolled.

02Do I need a laptop?

No. The native app uses Android USB host mode to perform the phone-to-phone workflow. A Chromium desktop installer remains available as a separate option.

03Can it enroll a phone that already has its operating system?

Yes. The enrollment-only path can load the SecurePhone DPC onto a compatible new or reset target and apply its activation code without flashing GrapheneOS again.

04Does flashing GrapheneOS erase the target Pixel?

Yes. Bootloader unlock and GrapheneOS installation erase the target. Required data must be backed up before the workflow begins.

05Is GrapheneOS part of SecurePhone?

No. GrapheneOS is an independent project. Device Utility installs an official, unmodified release; SecurePhone DPC enrollment is a separate management step.

Provision without a laptop

Put the SecurePhone field kit in your pocket.

SecurePhone Device Utility is distributed to authorized Android host phones through the SecurePhone management environment. Contact us for access, or use the desktop WebUSB installer when a workstation is available.