Mission-Loaded
Ships with ATAK, licensed plugins, encrypted comms, and every mission-critical application pre-installed. Power on and operate.
The Pixel Tablet is delivered fully de-googled and configured with GrapheneOS for maximum privacy, hardened security, and full control over your software environment.
Unlike standard consumer tablets, this configuration is intentionally air-gapped:
No cellular modem
No GPS modem
Wi-Fi only (user-controlled)
No background carrier services or baseband communications
This dramatically reduces the attack surface compared to conventional mobile devices.
GrapheneOS is a security-focused, open-source operating system designed to provide strong isolation, hardened memory protection, and advanced permission controls — without sacrificing usability.
User Privacy
GrapheneOS minimizes data collection and removes proprietary Google services by default. Users maintain strict control over permissions and network access.
Hardened Security
Includes enhanced exploit mitigations, sandboxed Google Play compatibility (optional), and robust app isolation — reducing exposure to malware and privilege escalation attacks.
Transparency
As an open-source project, the codebase is publicly auditable, improving trust and verifiability.
Granular Control
Users can tightly manage:
Network access per app
Sensor access (camera, mic, etc.)
Background activity
Storage permissions
Exploit protection compatibility mode
Closed-source applications can run inside secure sandboxes without compromising system integrity.
This Pixel Tablet configuration does not contain:
A cellular baseband radio
A GPS modem
Removing these components eliminates entire categories of remote attack vectors associated with carrier infrastructure and GNSS tracking.
For users requiring controlled, compartmentalized, or offline operational environments, this makes the device well-suited for:
Field deployments
Secure briefing environments
Sensitive document handling
Tactical or research use cases
While GrapheneOS significantly enhances security and privacy, no system can guarantee absolute protection. Digital security remains dependent on:
Regular OS updates
Strong, unique passphrases
Careful application vetting
Strict permission management
Proper OPSEC discipline
The device ships with no additional applications installed by GoTAK, unless explicitly selected.
We do not retain or store any PII, IMEI, serial numbers, or identifying device information related to your purchase.
In-person purchase arrangements are available at our office upon special request.
We do not sell VPN services, cloud backup, data protection subscriptions, or monitoring solutions. These services should be independently vetted and selected by the end user according to their own threat model and operational requirements.
Please conduct proper due diligence for any OPSEC-related matter.
Why not a stock tablet?
A consumer device shares everything by default. The EUD V3 is built to share nothing — unless you decide otherwise.
| FEATURE | STOCK PHONE | PIXEL TABLET |
|---|---|---|
| Google Telemetry | Active by default | Zero Google dependency |
| Modem Access | Direct memory access | Hardware-isolated from OS |
| Under Duress | No safe exit | Duress PIN wipes all keys |
| App Permissions | Broad defaults | Per-app network & sensor control |
| Forensic Resistance | Expanded attack window after unlock | Auto-reboot to locked state |
| Mission Software | Manual install required | ATAK + plugins pre-loaded |
Your threat model is your baseline.
Consumer phones defend against opportunistic malware. The EUD V3 defends against targeted exploitation, post-compromise persistence, and physical coercion.
THE THREAT
Zero-click exploits. Silent network signaling. Baseband-level attacks. Every app you install widens the attack surface.
GRAPHENEOS RESPONSE
GrapheneOS enforces strict application sandboxing — each app operates in its own isolated environment, restricted from interacting with other apps or accessing sensitive system resources without explicit user consent.
THE THREAT
Cellular modems operate outside the OS using closed-source firmware blobs, independent execution environments, and persistent network exposure when enabled.
GRAPHENEOS RESPONSE
The EUD V3 treats the modem as untrusted hardware. On most phones, the modem is inherently trusted with direct memory access.
THE THREAT
Security often fails under physical pressure. Users may be coerced to unlock devices. Biometric access can be forced. Standard locks offer no safe exit.
GRAPHENEOS RESPONSE
GrapheneOS is designed for real-world hostile scenarios — both digital and physical. A pre-configured duress PIN triggers an irreversible process that destroys all hardware keystore keys, disk encryption keys, and eSIMs, then shuts down the device.
THE THREAT
Once unlocked, most phones become significantly easier to extract data from. Commercial forensic tools can access active memory, capture running services, and exploit the expanded post-unlock attack window.
GRAPHENEOS RESPONSE
The EUD V3 reduces After-First-Unlock (AFU) exposure — the window where decryption keys live in memory.
THE THREAT
Default smartphone permissions grant apps broad access to microphones, cameras, GPS, and network connectivity. Most users never audit these permissions. Apps routinely collect and transmit data beyond their stated function.
GRAPHENEOS RESPONSE
GrapheneOS provides per-app control over network connectivity, file access, and every device sensor. Disable an app's ability to connect to the internet or access sensors like the microphone and accelerometer entirely.
Hardened from chip to app.
The Pixel Tablet ships with the Titan M2 security chip — hardware-backed key storage, verified boot chain, and a tamper-resistant secure element. All cryptographic operations are isolated from the main processor.
Operational on first boot.
Power on and operate. Every device ships with the mission stack already loaded — no configuration, no licenses to chase, no setup time.
Ships with ATAK, licensed plugins, encrypted comms, and every mission-critical application pre-installed. Power on and operate.
Interfaces with any mesh radio — TrellisWare, Silvus, goTenna, and Beartooth. One device, every network.
Any global carrier. Dual SIM and eSIM support. No MVNO restrictions.
Single QR-code enrollment for full device management. Push policies, deploy apps, and lock devices fleet-wide from one console.
Utilized by tier 1 operators, military personnel, law enforcement, public safety officials, search and rescue teams, and forward-thinking civilians worldwide.
One console. Every device. In ~3 seconds.
Stock MDMs were built for office workers. WARDEN was built for operators — deployed on GrapheneOS EUDs where a misconfigured device is a mission liability. Push policy, issue commands, lock or wipe any device in the fleet from a single console. Pre-loaded on every EUD V3. Included with every TAK OS subscription.
Core Capabilities
Drag a policy onto a device or group. Every enrolled device picks up the new config — apps, certs, restrictions, VPN — on next heartbeat. No USB cable. No IT ticket.
Lock any device to a single app for mission deployment. One app, no exit without an admin password. The EUD becomes a dedicated tool — ATAK only, nothing else.
Push ATAK, plugins, certs, and mission configs to every device in the fleet — no user prompts, no app store, no physical access. Upload an APK once, assign to thousands.
Organize devices into nested groups — All Devices → Field Teams → Alpha Team. Each level inherits or overrides policy. One change at the top propagates down through the entire structure.
Policy presets engineered for the EUD V3 GrapheneOS stack. Knox-safe debloat removes unwanted vendor apps without breaking attestation. Pre-loaded and pre-licensed on every EUD V3.
Every enrollment, command, policy change, and token generation logged in chronological order. Filterable by device or action type. The compliance-grade chain of custody government procurement requires.
Enrollment Modes
Full MDM. Factory-reset the device, scan a QR on the welcome screen. The launcher installs as Android Device Owner — you get everything.
Lite MDM. Install the WARDEN launcher APK on an existing device — no factory reset required. Right for BYOD scenarios or when resetting isn't an option.
Remote Commands
Locks the screen immediately. Device requires auth to re-enter.
ReversibleRestarts the device. Returns to locked BFU state on startup.
ReversiblePlays a loud alarm to locate a misplaced or lost device.
ReversibleForces the device to push its current GPS position immediately.
One-ShotExits kiosk mode or unlocks the device screen remotely.
ReversibleFactory-reset. Destroys all keys, certs, and case files. Confirmation required.
IrreversibleCORTEX, the TAK OS cognitive layer, pulls live device state from the Redis heartbeat feed. Battery, location, network, app status — available to the AI in real time. No other MDM product ships this.
Enable Push-to-TAK in policy and device positions stream into TAK Server as CoT contacts — visible on Overwatch alongside human EUDs. Your WARDEN fleet and your ATAK operators share the same common operating picture.
Built to operate.
Hardware, software, procurement, and lifecycle — the field-ready details.
Boot, log in, operate. Every unit ships fully provisioned: ATAK, plugins, encrypted comms, VPN, SDR, and mesh stacks ready on first power-on.
No Google account. No setup wizard. No configuration required.
Hardened Android — open-source, maintained on an accelerated patch cycle independent of Google.
Private TAK server provisioned at the factory and pre-paired with each device. Admin credentials are issued before the kit ships.
Five-unit field kits include three months of TAKOS at no charge. Federate, scale, or self-host on request — no infrastructure standup required.
NDAA Section 889 compliant. No banned-vendor components in the chip set, modem, or RF chain.
Factory-direct from Virginia Beach. Two-business-day standard ship. Expedited military procurement available.
Volume pricing at 10+ units. Custom kits scoped, sourced, and shipped to spec.
sales@getgotak.com · (757) 910-0259
Need 10+ units?
Contact our sales team for volume pricing, NDAA-compliant configurations, and custom deployment packages.
Deploy with confidence.
NDAA compliant. Ships in 2 business days. For bulk orders and military quotes, contact sales directly.