What's included

One disciplined standard, applied as far across your world as you need.

Every engagement applies the same government-grade hardening standard, in person, in your presence. What changes between tiers is reach — never the quality of the work. Here is exactly what that standard covers.

In person only · No remote access · No cloud · No logs · No app

The principle

The Standard doesn't change between tiers. Only its reach does.

A smaller engagement is not a lighter touch. Your phone is hardened to the same standard whether it stands alone or sits inside a household of devices. The tier you choose decides how far that standard extends — to more people, more devices, your home, your vehicle — not how thoroughly each is done.

The Standard, measure by measure

What we harden.

The named measures of the hardening standard, each mapped to recognised public baselines. The detailed settings stay internal — so they can't become a map for anyone working against you, and so the standard stays current as platforms change.

Diagnose

  1. 01

    Threat model & risk assessment

    We map your assets, who could realistically reach them, and how — then build the plan that follows from it.

  2. 02

    Exposure triagein every tier

    We check what may already be wrong: live sessions and unfamiliar logins, silent mail-forwarding rules, hidden tracking and stalkerware, and whether your credentials have leaked. We find how you're exposed and close it.

Lock your identity

  1. 03

    Identity & authentication

    Unique passphrases held in a password manager; multi-factor moved off SMS to passkeys and hardware security keys; account recovery closed — a private layer that decides who can reach your accounts.

Harden your devices

  1. 04

    Device & operating-system hardening

    Your devices brought to the current government baselines: encryption, lock and auto-erase policy, remote wipe, encrypted backups, and a check for tampering.

  2. 05

    App, cloud & privacy configuration

    Per-app permissions, location and family sharing, shared albums and backups, cloud-account security, browser and social-media privacy — reviewed one by one and closed. We also reduce your data-broker footprint.

Extend to your world

  1. 06

    Home network & connected environmentHome tier and above

    Your router, network, and smart-home accounts brought back under your sole command: current firmware and WPA3, segmentation into trusted, guest, and device networks, and connected devices contained behind it.

  2. 07

    Vehicleadd-on

    Your connected-car account, paired devices, and location data brought under your control.

  3. 08

    Physical & travel

    The habits that protect your devices away from home — public-Wi-Fi and charging discipline — and, where your situation warrants, the high-risk modes (Apple Lockdown Mode, Google Advanced Protection) and a physical counter-surveillance sweep (Sovereign / by arrangement).

Make it hold

  1. 09

    Coaching & habits

    We train you on recognising phishing and social engineering, using your secure channel, and the routines that keep the hardening durable.

The record

  1. 10

    Certificate of Hardening

    A signed, dated record of every measure applied — for your file and your attorney's.

Mapped to public baselines

The same standards used to defend governments.

The hardening standard is mapped to recognised public baselines, for both phone platforms. The device steps follow EFF's Surveillance Self-Defense (Android) and the DISA Apple iOS / iPadOS STIG; the exposure-triage and high-risk-mode measures follow the guidance Amnesty International's Security Lab gives high-risk users. Specific settings are applied to the then-current published baseline for each platform — and kept internal, by design, so they can't serve as a map for anyone working against you.

  • NSA endpoint guidance
  • NIST — incl. SP 800-213 (connected home)
  • CIS Benchmarks & CIS Controls v8
  • DISA Apple iOS / iPadOS STIG
  • EFF Surveillance Self-Defense (iOS & Android)
  • UK & NZ NCSC device security
  • Amnesty International Security Lab
  • Coalition Against Stalkerware
Reach by tier

How far the standard extends.

The same measures, a wider reach as you move up. Prices for each tier are on the pricing page.

Reach of the hardening standard across the four tiers
The measure Personal Home Inner Circle Sovereign
Applied to everyone in scope
Threat modelIncluded×up to 3Bespoke
Exposure triageIncluded×up to 3Bespoke
Identity & authenticationIncluded×up to 3Bespoke
Device & OS hardening+ up to 2 devices×up to 3 peopleBespoke
App, cloud & privacyIncluded×up to 3Bespoke
Coaching & habitsIncluded×up to 3Bespoke
Certificate of HardeningIncludedIncludedIncluded
Your environment
Home network & connected environmentIncludedAdd-onIncluded
VehicleAdd-onAdd-onIncluded
Physical & travelHabitsHabits+ Sweep
Ongoing protection
Annual Watch / Priority RetainerOptionalOptionalIncluded

✓ included · — not included · ×N = applied to each of up to N people · Bespoke = scoped to you in Sovereign. High-risk modes (Apple Lockdown Mode, Google Advanced Protection) are applied in any tier where your threat model warrants.

People beyond three, devices beyond a tier's cap, and the vehicle are priced add-ons, agreed before any extra work. See tiers & pricing →

What you keep

The Certificate of Hardening.

Every engagement ends with a signed, dated certificate — a record of every measure applied and every standard referenced, suitable for your own records and your attorney's file. It records what was done, never the content of your data or your accounts.

  • Performed in person, in your presence — recorded as fact.
  • Every measure applied and every standard referenced.
  • No client data, credentials, or device images retained.
  • Signed and dated — for your records and your attorney's file.
How we work

Five commitments, every engagement.

  • In person only — all work is done physically, in your presence.
  • No remote access — we never connect to or control your devices remotely.
  • No cloud — we never upload or process your data in any cloud service.
  • No logs — we keep no logs of your data, credentials, or device contents.
  • No app — nothing of ours is installed on, or left on, your devices.
Where to start

Start with a Threat Assessment.

An in-person diagnostic and written report that confirms the right tier before you commit — and carries the same Promise and confidentiality as every engagement.

Threat Assessment
3 hours

In person, with a written report — credited in full toward any tier booked within 14 days. The fee is shown on the pricing page.

Book the assessment See tiers & pricing →