Secure Phones – Who Really Needs Them and What Do?
A smartphone is now much more than a telephone. It stores our messages, documents, photos, location data, and access to banking, email and corporate systems.
Description
Secure Phones – Who Really Needs Them and What Do NitroPhone, Murena, HIROH, Volla and RAWCyber Offer?
A smartphone is now much more than a telephone. It stores our messages, documents, photos, location data, and access to banking, email and corporate systems. For many users, it is also an authentication tool without which they cannot log in to organisational services.
This means that losing a phone, having it compromised or installing malicious software may result in more than just the disclosure of private messages. It may also lead to access to business information, exposure of a contact network, eavesdropping on conversations or the use of the device as an entry point for a broader attack against a company or institution.
Against this background, a market is developing for phones designed with a stronger focus on security and privacy. Some of the most interesting brands include NitroPhone, Murena, HIROH, Volla and Poland-based RAWCyber. However, these are not identical solutions. Each of them addresses different risks and is intended for a slightly different group of users.
What Does a “Secure Phone” Actually Mean?
The term “secure phone” is often used too broadly. Devices that protect users from advertising tracking, phones with hardened operating systems and specialist solutions designed for high-risk organisations are frequently placed in the same category.
Privacy and security, however, are not the same thing.
Privacy primarily means limiting the collection, analysis and transfer of information about the user. A privacy-focused phone may reduce the number of tracking modules, restrict connections to advertising services and allow the device to be used without a Google account.
Technical security includes protection against malicious applications, exploitation of vulnerabilities, physical compromise of the device, unauthorised access to data and manipulation of the operating system.
Organisational security additionally requires centralised device management, application control, enforced configuration, update monitoring and the ability to remotely lock or wipe a device. The UK National Cyber Security Centre points out that hardware selection is only one part of the protection process. Configuration, updates and management throughout the device lifecycle are equally important.
There is therefore no single phone that is best for everyone. A soldier, a board member and a parent buying a child’s first smartphone all have different requirements.
NitroPhone – When System Resilience Is the Priority
NitroPhone uses Google Pixel hardware but runs GrapheneOS, an open-source operating system based on Android and developed with a strong focus on limiting the impact of vulnerabilities and isolating applications.
GrapheneOS extends standard Android protections with additional memory safety mechanisms, more restrictive permission management and measures designed to make exploitation of operating system and application flaws more difficult. NitroPhone also uses Verified Boot, which checks system integrity during startup, as well as the hardware security module available in Pixel devices.
One important advantage is the option to install original Google Play services as ordinary sandboxed applications. They do not automatically receive privileged system-level access, while still allowing a high degree of compatibility with applications that depend on the Google ecosystem.
NitroPhone is also available in specialist variants with microphones or cameras physically removed. This is not simply a software setting that disables a component, but an actual disconnection or removal of the hardware. Such an approach may be important in environments where a phone should not technically be capable of recording nearby conversations.
It is therefore primarily intended for users at risk of targeted attacks, including senior executives, security professionals, public administration employees, investigative journalists, activists and people processing particularly sensitive information.
Murena – Greater Privacy Without Giving Up the Smartphone Experience
Murena takes a different approach. Its primary goal is not maximum Android hardening, but reducing dependence on Google and limiting the volume of data transferred by the phone to external services.
Murena phones run /e/OS, an open-source operating system based on the Android Open Source Project. Google services are replaced or anonymised, and the system does not require the device to be linked to a Google account by default.
The built-in Advanced Privacy tool can detect trackers in applications, reduce advertising, hide the IP address and provide applications with an altered location. The App Lounge store also displays information about trackers and the permissions requested by individual applications.
Murena is therefore a more consumer-oriented solution than NitroPhone. It may appeal to users who are not targets of advanced attacks but do not want every action performed on their phone to contribute to advertising profiling.
Most popular Android applications should work, but key software should be checked before purchase, especially banking applications, contactless payments, public administration services, corporate authentication tools and applications relying on Google integrity mechanisms. The manufacturer itself refers to compatibility with “most” rather than all applications.
HIROH – Physical Control Over Cameras and Microphones
HIROH combines /e/OS with a physical security switch. When activated, the cameras and microphones are disconnected at the electrical circuit level rather than merely disabled through a software setting.
This distinction matters. A software switch depends on the assumption that the operating system is functioning correctly and has not been compromised. Physically interrupting the connection makes it much harder for an application or malicious software to reactivate the component.
HIROH may appeal to people conducting confidential meetings, lawyers, journalists, non-governmental organisation employees and senior managers. It offers a relatively convenient compromise between everyday usability and the ability to physically disconnect selected sensors.
It should be noted, however, that according to Murena, the device is still in production, with deliveries planned to begin in October 2026. There is therefore no long history of real-world use, software updates or independent testing of the final production model.
Volla – Application Control for Families and Small Businesses
Volla OS is also based on open-source Android and does not include Google applications, Google Play services or a mandatory user account by default. Applications requiring Google-related functionality can optionally use microG.
The most distinctive feature of Volla OS is Security Mode. It allows users to:
block selected applications completely,
prevent specific applications from accessing the internet,
block addresses associated with trackers, phishing and malicious software,
create an approved list of applications and websites available to the user.
The manufacturer explicitly identifies the protection of children’s phones and devices used by small businesses as potential use cases for this feature.
Volla also offers Mobile Device Management solutions for centralised administration of mobile devices. An organisation may use a service hosted by the provider or deploy it within its own infrastructure. Available capabilities include the management of applications, software versions, devices and selected communication interfaces.
Volla appears particularly relevant for families, schools, small businesses and users who want to control applications and network connections without moving to highly specialised solutions intended only for security professionals.
RAWCyber – Security as a Managed Service
RAW Secure Phone is developed by the Polish company RAWCyber. In this case, the focus is not only on the device and its operating system, but also on controlled applications, configuration and specialist support.
The manufacturer declares functions including application permission control, software-based disabling of the microphone and camera, protection against location tracking, safeguards against dangerous Wi-Fi networks and attacks involving the USB-C port, tamper detection and data deletion mechanisms.
Applications available in the RAW Secure Phone repository are intended to be reviewed in advance by the manufacturer’s specialists. Customers may also request a secure version of a specific application. The offering includes configuration, training, the installation of customised applications and technical support declared as available around the clock.
RAWCyber is therefore closer to a managed security service than to a typical consumer phone. It may appeal to companies and institutions that expect provider support and do not want to maintain the entire environment independently.
At the same time, some publicly available information remains based on the manufacturer’s own declarations. Before deployment in government, the military or critical infrastructure, these claims should be verified through technical documentation, independent audits, penetration tests, update policies and a clearly defined scope of supplier responsibility.
Military Use – Not Only Encryption, but Also Environmental Control
In military use, particularly important risks include loss of the device, capture by an adversary, disclosure of location and the use of microphones or cameras to monitor the surrounding environment.
NitroPhone variants without selected sensors, HIROH with a physical camera and microphone switch, and RAW Secure Phone as part of a managed communications environment may all be relevant options.
This does not mean, however, that any of these devices can automatically be approved for processing classified information. The terms “secure” or “military grade” do not replace a formal security assessment, organisational procedures, an approved communication system and the appropriate classification of information.
In a military environment, the phone must be assessed as one component of a broader system that includes the network, communication software, identity management, key distribution, device configuration and incident response procedures.
Public Administration – Data Sovereignty and Fleet Management
Public administration processes citizens’ data, financial information and documents requiring enhanced protection. In this context, user privacy alone is not enough.
Important capabilities include centralised device management, enforced updates, control of installed applications, separation of personal and professional data, and remote device blocking following loss. The NCSC recommends that business devices be centrally managed and that policies governing interfaces, applications and updates be enforced through Mobile Device Management. (ncsc.gov.uk)
NitroPhone may be suitable for selected employees who face a particularly high risk of targeted attacks. Volla offers options for managing larger numbers of devices and deploying MDM in an organisation’s own infrastructure. Murena may support initiatives aimed at reducing reliance on Google services, but compatibility with applications used by the public authority should be tested in advance.
RAWCyber may be considered where a service is needed that combines the phone, application preparation, training and ongoing support.
Business – Protecting Access to the Organisation
An employee’s phone often provides access to email, messaging platforms, customer relationship management systems, cloud documents and authentication applications. Compromising the phone may therefore become the starting point for a larger incident.
NitroPhone may be justified for board members, administrators and users with access to particularly valuable information. Volla may be a practical option for a small company requiring control over applications and websites. Murena may be suitable where the main objective is to reduce profiling and dependence on advertising and cloud service providers.
RAWCyber may appeal to organisations that need provider support and a controlled set of applications, but they should first understand the system architecture, the extent of monitoring and the way the provider’s staff may access devices and data.
Regardless of the selected model, a secure phone does not replace multi-factor authentication, identity management, encrypted backups, access segmentation or user training.
Journalists – Protecting Sources and Materials
An investigative journalist may face not only ordinary phishing but also targeted attempts to reveal information sources, contact networks or meeting locations.
NitroPhone provides a strongly hardened system environment and the option to physically remove selected sensors. HIROH allows microphones and cameras to be disconnected quickly during a confidential conversation. Murena may reduce advertising tracking and profiling, but it should not automatically be treated as equivalent to a system designed to resist the most advanced attacks.
The phone should nevertheless remain only one part of the protection strategy. Encrypted messaging applications, separate profiles or devices for different projects, regular updates and limiting the amount of material stored locally are also necessary.
Families – Less Profiling and Greater Awareness
For an average family, the main threat is usually not advanced spyware. More common problems include excessive application permissions, advertising profiling, fraudulent messages, account theft and uncontrolled sharing of location data.
Murena may help users identify which applications contain trackers and what permissions they require. Volla allows control over which applications can run and connect to the internet.
These solutions are more practical for most families than a specialist phone with physically removed microphones. Their greatest value may be not only the technical restrictions but also education. Users begin to understand what information applications collect and why an apparently free service requests access to contacts, location or the microphone.
Children – Control Without Continuous Profiling
A child’s first phone should allow parents to restrict dangerous content, random application installation, purchases and excessive internet use. At the same time, the parental control system should not itself build an extensive profile of the child.
Volla OS allows parents to define which applications can run, which websites can be accessed and which applications may connect to the internet. Security Mode is protected by a password, making it more difficult for the child to modify the agreed configuration. (volla.online)
Murena is also developing solutions aimed at children, combining parental controls with /e/OS and reduced profiling. (murena.com)
Technology cannot, however, replace a conversation with the child. A phone will not protect against manipulation by another person, peer pressure, the sharing of private images or revealing a password to someone impersonating a friend.
How Should the Right Solution Be Selected?
Before purchasing, it is worth answering several basic questions:
What data will be stored on the phone?
Who may try to obtain it?
Is protection from tracking or protection from advanced attacks more important?
Does the device need to be managed centrally?
Which applications must work on it?
Will the user accept functional limitations?
How long will the manufacturer provide updates?
Have the security claims been independently verified?
For a high-risk user, NitroPhone may be the most relevant option. For someone who wants to limit profiling, Murena may be more suitable. For users who need a physical camera and microphone cutoff, HIROH may be the better fit. For families or small businesses, Volla may be the most practical. For organisations seeking a comprehensive service with supplier support, RAWCyber may be appropriate.
This is not a ranking from best to worst. Each solution addresses a different threat model.
A Secure Phone Is the Beginning, Not the End, of Protection
NitroPhone, Murena, HIROH, Volla and RAWCyber demonstrate that users do not have to remain entirely dependent on standard Android with Google services or on the Apple ecosystem.
At the same time, purchasing a specialist phone does not automatically solve every security problem. It will not help if the user ignores updates, installs applications from random sources, opens every attachment received or shares passwords.
The best results come from combining the right device, a carefully selected operating system, regular updates, secure communication applications, access control and an informed user.
A secure phone is not a magic shield. It is one of the most important components of a well-designed information protection system.
13/07/2026
Source: NitroPhone, Murena, HIROH, Volla, RAWCyber
bezpieczne telefony, telefony zapewniające prywatność, szyfrowane smartfony, smartfony z cyberbezpieczeństwem, NitroPhone, Murena, telefon HIROH, Volla Phone, RAWCyber, RAW Secure Phone, GrapheneOS, /e/OS, Volla OS, bezpieczny Android, smartfon z naciskiem na prywatność, telefon z usuniętymi z Google informacjami, bezpieczeństwo mobilne, prywatność smartfona, wzmocniony smartfon, bezpieczna komunikacja, ochrona danych, zarządzanie urządzeniami mobilnymi, MDM, bezpieczeństwo smartfonów biznesowych, rządowe telefony z zabezpieczeniami, wojskowe telefony z zabezpieczeniami, telefony dla dziennikarzy, telefony dla dzieci, cyfrowe bezpieczeństwo rodziny, smartfon z kontrolą rodzicielską, telefon zapobiegający śledzeniu, bezpieczny mobilny system operacyjny, fizyczny przełącznik mikrofonu, fizyczny przełącznik kamery, suwerenność danych, ochrona przed zagrożeniami mobilnymi, bezpieczna mobilność przedsiębiorstwa, secure phones, privacy phones, encrypted smartphones, cybersecurity smartphones, NitroPhone, Murena, HIROH phone, Volla Phone, RAWCyber, RAW Secure Phone, GrapheneOS, /e/OS, Volla OS, secure Android, privacy-focused smartphone, de-Googled phone, mobile security, smartphone privacy, hardened smartphone, secure communication, data protection, mobile device management, MDM, business smartphone security, government secure phones, military secure phones, phones for journalists, phones for children, family digital safety, parental control smartphone, anti-tracking phone, secure mobile operating system, physical microphone switch, physical camera switch, data sovereignty, mobile threat protection, secure enterprise mobility