Android host phone
The technician opens SecurePhone Device Utility on an authorized Android phone with USB host support. Downloads, image cache, prompts, and progress stay on this device.
Runs the appSP-UTILITY · NATIVE ANDROID FIELD TOOL
Run the app on an Android host phone, connect a target Google Pixel over USB-C, and install GrapheneOS without a laptop. Continue in the same guided flow to load the SecurePhone Device Manager DPC and enroll the new phone.
Device Utility lives on the technician's host phone. The connected Pixel is the target: it receives GrapheneOS, then the SecurePhone DPC and its enrollment assignment.
The technician opens SecurePhone Device Utility on an authorized Android phone with USB host support. Downloads, image cache, prompts, and progress stay on this device.
Runs the appA direct USB-C connection carries fastboot and ADB between the phones. The operator approves USB access and reconnects when the target changes boot modes.
Carries fastboot + ADBA supported Pixel can be erased and flashed with GrapheneOS. The same app can then push the SecurePhone DPC, set Device Owner, and apply the activation code for enrollment.
Receives OS + managementThe native app drives Android USB host mode, fastboot, the GrapheneOS factory-image sequence, and the final ADB enrollment handoff while the operator confirms security-sensitive actions on the target.
Confirm that the host phone is an approved SecurePhone provisioning device.
Put the target Pixel in fastboot and connect both phones over USB-C.
Download, verify, and flash the correct GrapheneOS factory image, then re-lock the bootloader.
Load the SecurePhone DPC over ADB, set Device Owner, and apply the activation code.
Verify policy and required apps, then deliver the managed phone to its user.
SecurePhone Device Utility makes the host, target, erase boundary, operating-system source, and management handoff explicit. Authorized operators can prepare phones without exposing a command line or an uncontrolled enrollment path.
The phone-to-phone path uses Android's USB host API directly. The browser installer remains a separate desktop option.
The target receives an official GrapheneOS factory release. GrapheneOS is an independent project and is not affiliated with SecurePhone.
Unlocking the Pixel bootloader and flashing GrapheneOS erases the target. The app calls this out before destructive actions and requires on-device confirmation.
GrapheneOS installation can end with a clean OS, or continue into SecurePhone DPC installation and enrollment. An enrollment-only path is available when the target is already prepared.
The app replaces the laptop, not the physical and security requirements of Pixel provisioning. Use supported hardware, enough power and storage, and a reliable data cable.
The app runs on the technician's Android host phone. The Google Pixel connected over USB-C is the target being flashed and enrolled.
No. The native app uses Android USB host mode to perform the phone-to-phone workflow. A Chromium desktop installer remains available as a separate option.
Yes. The enrollment-only path can load the SecurePhone DPC onto a compatible new or reset target and apply its activation code without flashing GrapheneOS again.
Yes. Bootloader unlock and GrapheneOS installation erase the target. Required data must be backed up before the workflow begins.
No. GrapheneOS is an independent project. Device Utility installs an official, unmodified release; SecurePhone DPC enrollment is a separate management step.
SecurePhone Device Utility is distributed to authorized Android host phones through the SecurePhone management environment. Contact us for access, or use the desktop WebUSB installer when a workstation is available.