During its two years of existence, GuardDo Pixel has undergone many independent tests in specialist laboratories and in private laboratories operated by our clients, including closed facilities that outsiders cannot access.
Those results, however, remained private. In some cases, the reports belonged to clients; in others, they were provided only to interested parties. For understandable reasons, we could publish neither the documents nor details of those studies.
At the same time, we kept hearing the same request from the GuardDo community and customers: “Show us an independent audit whose results can be checked and published.”
We therefore approached the European company MicroTech BG to conduct an independent information-security audit of GuardDo Pixel, with one essential goal: to obtain a result that could be made public for the first time.
The assessment is complete.
Today, for the first time, we are publicly presenting an independent audit of GuardDo Pixel’s key claims regarding anonymity, data protection, and the features of GuardDoOS, the operating system used by GuardDo Pixel.
The independent audit took place from May 10 to September 20, 2026. MicroTech BG issued its final report on September 27, 2026, under report number 58690-38598. The assessment covered six new GuardDo Pixel 10 devices with identical configurations and firmware versions #1580–#1601.
What Was Tested
We deliberately did not ask the auditor to perform an abstract “security check” of the phone. That wording says very little: a single test cannot prove that a device is absolutely secure against every existing and future attack.
Instead, MicroTech tested four specific claims made by GuardDo about GuardDoOS mechanisms:
- Can the hidden space be accessed without its password?
- Can the existence of the hidden space, or traces of its contents, be detected?
- Can data be recovered after the emergency-deletion function is triggered?
- Is there a master password, hidden recovery mechanism, or other undocumented way to access data without the user’s password?
These four claims were the subject of the independent assessment.
The threat actor was far from an ordinary user
The audit considered a scenario in which the device comes into the hands of a specialist with serious technical capabilities.
Under the agreed threat model, the adversary could have physical access to a powered-off smartphone or to a powered-on but locked device. The adversary would not know the hidden-space password.
The model also included industrial forensic suites such as Cellebrite, MSAB, and GrayKey; JTAG/EDL and chip-off equipment and programmers; and the ability to intercept the smartphone’s outbound network traffic. A separate scenario examined whether hidden capabilities could allow a GuardDo developer to access the device’s contents.
In other words, the question was not whether an ordinary person could open the hidden space. The test examined whether protected data could be extracted or detected with physical access to the device and specialist digital-forensics tools.
How the Assessment Was Conducted
MicroTech used elements of the recognized OWASP MASTG and NIST SP 800-101 methodologies.
Every action was documented with its date, the tool used and its version, and the result, while maintaining chain of custody.
Before testing began, an agreed test dataset with unique identifying markers was placed in the hidden space of each device. This meant the outcome could not be interpreted subjectively: if any of the test data had been obtained or recovered by the specified methods, that would have been recorded in the results.
That is why the audit result matters so much to us.
4 out of 4 — PASSED
GuardDo Pixel received a “PASSED” result for all four claims under review.
1. The hidden space could not be extracted
MicroTech attempted to obtain the hidden-space contents using both logical and physical methods.
The assessment covered ADB and debugging interfaces, backups, chip-off, sector-by-sector analysis of a NAND dump, JTAG/EDL, and analysis of a RAM dump.
Result: PASSED. The hidden-space contents could not be obtained.
2. No traces of the hidden space could be detected
The protected space must not only be inaccessible; under the mechanism being claimed, it should not reveal itself through traces in the phone’s ordinary environment or network traffic.
Specialists therefore analyzed system and application logs, cache, crash reports, service directories, and telemetry. Outbound traffic was intercepted through a MITM proxy.
Result: PASSED. No signs of the hidden space’s existence or contents were found in the tests conducted.
3. Deleted data could not be recovered
The next test concerned one of GuardDoOS’s most critical functions: emergency deletion.
After the emergency-deletion function was triggered normally, the specialists obtained a NAND dump and attempted to recover data through forensic analysis and standard file-carving tools. They also assessed the effects of TRIM and wear leveling.
Result: PASSED. Data from the hidden space could not be recovered after the emergency-deletion function was triggered.
4. No master password or hidden access-recovery method was found
This point is fundamental to us. Security loses its meaning if a second key exists somewhere: a master password, hidden recovery, hardcoded credentials, or another mechanism that can bypass the owner’s password.
MicroTech examined UART/JTAG and recovery mode, and specifically checked the authentication module for hardcoded credentials.
Result: PASSED. No methods of access that bypass the normal password-entry process were identified within the scope of the assessment.
What This Means
MicroTech’s final conclusion is specific: within the agreed threat model, task list, tools, and allotted time, the independent auditor did not defeat the GuardDo Pixel protection mechanisms under review.
The assessment found that:
- the hidden-space contents were not extracted by logical or physical methods;
- no signs of the hidden space were found in the ordinary profile or network traffic;
- data could not be recovered after emergency deletion;
- no master password or hidden recovery mechanism for bypassing normal authentication was identified.
For GuardDo, this is more than another internal test. It is the first independent test result for GuardDo Pixel that we can show publicly.
No Marketing Claim of “Absolute Invulnerability”
There is one more point we believe is important to state openly.
Neither GuardDo nor MicroTech claims that an “absolutely invulnerable” device exists. The report makes no such conclusion.
MicroTech specifically emphasizes that the result applies to a particular firmware version, device configuration, agreed threat model, tools used, and scope of work. A change to the firmware, hardware platform, or threat model requires a new assessment.
Social engineering and phishing, supply-chain attacks, attacks through cellular infrastructure, searches for zero-day vulnerabilities in the underlying Android/Pixel platform outside GuardDo customizations, and a full code review of the entire firmware were outside this audit’s scope.
This is how security claims should be presented, in our view: not “trust us,” but a specific threat model, specific testing methods, and a specific result.
For Two Years We Have Talked About the Technology. Now There Is Public Confirmation
Since GuardDo Pixel became a product, we have built it around a simple idea: users should control their own data.
Not GuardDo. Not the smartphone manufacturer. Not a third party. The user.
Until today, much of the evidence about how GuardDoOS behaves under real forensic examination remained inside closed laboratories and private studies conducted for our customers.
Now one of those results is being made public for the first time.
Six devices. Nearly four and a half months of testing. Physical and logical extraction. NAND. JTAG/EDL. Chip-off. RAM analysis. Network-traffic interception. Examination of logs, telemetry, recovery, and authentication mechanisms.
Four claims under review. Four results: PASSED.
This does not mean the work is finished. On the contrary, GuardDoOS continues to evolve, and the methods used to assess it independently should evolve too.
But we now have a public answer to the question, “Has anyone checked this independently?” Yes.
And to the question, “Did the audit obtain hidden data, detect the hidden space, recover data after emergency deletion, or find a master password?” the answer recorded in MicroTech’s report is: No.
The audit took place from May 10 to September 20, 2026. MicroTech BG issued the report on September 27, 2026; its report number is 58690-38598.
GuardDo Pixel. Protect your secrets.
Audit firm website: MicroTech BG