Clear answers to the most common questions about how SpyPhone's hardware-level encryption works and how our devices may — and may not — be lawfully used.
Encryption runs beneath the OS in a secure enclave.
No software artifact for scans to detect.
Sold to vetted professionals under our Legal Notice.
The encryption and intelligence layer lives on a dedicated cyber-intelligence chipset embedded beneath the Android operating system, not as an Android app or kernel module. Keys are generated and held inside a secure element that the OS cannot read, so encryption runs independently of — and invisibly to — the operating system.
Consumer apps (Signal, WhatsApp) encrypt messages in software and depend on the OS to keep the key safe. Our operator-side encryption is hardware-isolated: session keys are bound to the device's secure enclave and never exposed to Android, meaning even a compromised OS or a forensic extraction of the Android file system cannot recover operator keys or decrypt stored intelligence.
Captured intelligence is written to an isolated, encrypted hardware partition that is inaccessible from the Android file system. Operator credentials and session keys live in the secure enclave. On command, the operator can perform a remote anti-forensic wipe of credentials and the secure storage.
Yes. Because the intelligence layer operates beneath the OS, a factory reset, OS update, or reboot does not remove it. Encryption state and the secure enclave persist across the device's entire lifecycle.
The implant communicates with the operator dashboard over an out-of-band encrypted transport using hardware-bound session keys with mutual authentication. The channel can remain active independently of the target's normal network — including in airplane mode or with the screen off.
No. Keys are generated and stored in the secure enclave, which is not accessible through the Android file system, physical extraction, or software forensic suites. There are no software artifacts, processes, or sockets for a forensic tool to target.
No. Because the layer is hardware-based and beneath the OS, antivirus products, mobile threat-detection apps, and OS security scans cannot detect the implant, its storage, or its encrypted channel.
Pegasus is software-only and relies on OS-level exploit chains that Apple and Google continuously patch; its persistence and key material are vulnerable to OS updates and forensic detection. Hardware isolation removes that dependency entirely — there is no exploit to patch and no software signature to detect. See our Pegasus spyware comparison.
Devices are sold exclusively to vetted corporate, investigative, and compliance professionals. Every request is reviewed before procurement. We do not sell to individuals for personal, recreational, or unlawful use.
Purchasers must confirm they have legal authority to monitor the target device under their applicable jurisdiction — for example, ownership of a corporate-issued device, written employee consent where required, a lawful court order, or a regulatory compliance mandate. Sale is conditional on acceptance of our Legal Notice.
Monitoring devices the employer owns and issues for business use is generally permitted in many jurisdictions, often subject to a proportionate, documented policy and — in several regions — prior notice to or consent from the employee. Applicable rules vary (e.g., UK ICO guidance, EU GDPR, US state law). Purchasers are responsible for obtaining their own legal advice.
No. We explicitly prohibit stalking, domestic surveillance without consent, unlawful interception, and any use that violates applicable law. Requests that indicate unlawful intent are refused. See our Legal Notice.
Each inquiry is reviewed to confirm the buyer's professional standing and stated lawful use case before a device is procured. We retain the right to refuse or cancel any request that does not meet our lawful-use criteria.
Purchasers are solely responsible for the lawful operation of the device in their jurisdiction, including obtaining required consents, giving required notices, and ensuring use stays within the scope of their legal authority. RedSec is not a party to the operator's monitoring activity.
Shipment is subject to applicable export controls and sanctions screening. Delivery is arranged via insured courier with encrypted, tamper-evident packaging after consultation confirms operational requirements and lawful authorization.
Our Legal Notice sets out the binding terms, prohibited uses, liability allocation, and export controls, and our Privacy Policy describes how client data is handled. Every page of this site also carries a lawful-use reminder.
These pages detail the hardware, capabilities, and communications referenced above.
SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.