Description
PROTECTION FROM ZERO-DAYS Prevents many vulnerabilities and makes exploits harder. HARDENED C STANDARD LIBRARY AND COMPILER TOOLCHAIN Catches memory corruption and integer overflows. HARDENED KERNEL Kernel self-protection and high quality ASLR. STRONGER SANDBOXING AND ISOLATION FOR APPS & SERVICES Stricter SELinux policies, seccomp-bpf and more BACK PORTED SECURITY FEATURES AND QUICKER PATCHING Benefiting from upstream changes long before stock FIREWALL & NETWORK HARDENING Along with improvements like MAC randomization OPEN-SOURCE AND FREE OF PROPRIETARY SERVICES Uses alternatives to Google apps/services like F-Droid SECURITY-CENTRIC USER EXPERIENCE CHANGES Better defaults, finer-grained permission control