Features

About

AXP.OS is a more private and more secure aftermarket mobile operating system based on AOSP & LineageOS.

The main goal of this project is to strive for a balance between a

privacy and
security-oriented
yet usable

Operating System - and last but not least … even for advanced* users.

*i.e. including full control over your own device - if desired

The Pro flavor of AXP.OS comes pre-rooted which is a major difference between many (if not all) other custom OS and requires to read the documentation properly and acting wisely (i.e. not installing APKs from random sources, open every link in mails you get, etc). While the OS comes pre-rooted it is not active at all and requires to actively install the Magisk companion app + run the requirements installer once to make it usable first. That means if you do not need root you can simply skip that step and there will be no su binary available at all.

The Slim flavor on the other site does not come pre-rooted while it has drawbacks regarding usability and is not that intensively tested as the Pro one.

If you are not sure which one to choose, ask in the support channel.

Divest Notice

Up to Dec 2024 AXP.OS was based on DivestOS, see the EOL notice for Divest and its impact on AXP.OS here.

Due to this AXP.OS started in 2025 offering different flavors.
The Pro one is still the main flavor and so default on new devices but users can request a slim variant which gives a “Divest-like” experience.

Flavor comparison

FeatureProSlim
Using Graphene’s hardened malloc (comparison)XX
OTA (Over The Air) updatesXX
Including ASB patches (see AXP.OS patch level for details)XX
Hardened and focusing on security and privacyXX
Hardened Browser & WebView by EXTENDROM_PACKAGESXX
Extra Privacy by extensive deblobbing and privacy-focused settings (config)X
Super Privacy by even more extensive deblobbing and privacy-focused settings (config)
(while reducing usability)
X
SELinux enforcedXX
Data encryption enforcedXX
Signed (by AXP.OS keys)XX
Increased key size + hash (8192 / sha512) for signing keys wherever possible
(incl. adjustments in recovery and OTA Updater)
XX
Advanced boot debug log (EXTENDROM_BOOT_DEBUG)XX
Advanced Signature spoofing support by EXTENDROM_SIGNATURE_SPOOFING
(must be explicitly enabled)
XX
Using the AOSmium System WebView by EXTENDROM_PACKAGESXX
Extra Apps included by EXTENDROM_PACKAGES
(F-Droid, AuroraStore, FossifyGallery)
XX
extended list of F-Droid repositories (1,2,3,4)
(must be explicitly enabled)
XX
eSIM support (A10 and later) for devices supporting euicc
(must be explicitly enabled)
XX
Internal DNS content blocker (blocklist)XX
Re-locking the bootloader on supported devicesXX
Reproducible builds - see the detailsXX
MicroG included
(requires to explicitly enable signature spoofing)
X¹
Current and MicroG compatible Google Play Store included
(must be explicitly enabled)
X¹
WireGuard VPN Kernel moduleX²
Pre-rooted (Magisk) by EXTENDROM_PREROOT_BOOT - Bootloader re-lock compatible
(must be explicitly enabled and activated first)
X
Basic (i.e. w/o SafetyNet) support for Widevine DRMX
Supporting a FULL(!) app & settings backup & restoreX
Advanced Usability Support by EXTENDROM_PACKAGES
(Magisk, MicrogGmsCore, GsfProxy, Phonesky, NeoLauncher)
X
On device* testing before release
(*for devices marked as “verified by the AXP Team”)
X
  • ¹ while not supported (and not possible on bootloader-locked devices) you can flash MicroG as in LineageOS.
    AXP.OS Phonesky can be installed manually (via a custom recovery: place it in /system/priv-app/Phonesky/).
    Regardless if using the MicroG FakeStore or AXP.OS Phonesky you need to follow the setup guide) as well.
  • ² some kernels have the wireguard patches already included - the Slim flavor will not remove them while you need root to activate it

Simplified OS comparison

The following is just a simplified comparison between some popular custom OS and is meant to give a short overview only (there are dozens of detailed comparisons available elsewhere).

Examples of more detailed comparisons (even though without AXP.OS) can be found:

  • here or
  • here (hint: AXP.OS was based on Divest until Dec 2024)

The Main(!) focus column is a bit vague or better said subjective as all OS claim to be all of these 3: user-friendly, secure and privacy-friendly.
Just some doing it more intensive than others.

OSMain(!) focusProContra
LineageOSUsabilitywide range of supported devices, very high usabilityno focus on privacy + security, only latest 3 major releases supported
CalyxOSUsability, Privacywide range of supported devices, high usabilityno focus on security
GrapheneOSSecurity, Privacybest in class focus on security, good usabilityGoogle Pixel devices only, usually does not support older Android versions
/e/ OSUsability, Privacywide range of supported devices, very high usabilityno focus on security, does not support devices with older Android versions, late ASB patches
AXP.OS - ProUsability, Security, Privacybest balance between Usability, Security, Privacy, supports devices with older Android versionsonly a subset of LineageOS devices currently supported
AXP.OS - SlimSecurity, PrivacySecurity, Privacy, supports devices with older Android versionsonly a subset of LineageOS devices currently supported, reduced usability compared to the Pro flavor

Privacy examples:

  • reducing/disabling Call-Home functions
  • reducing/removing Google dependencies
  • deblobbing of proprietary parts

Usability examples:

  • allow or even include custom extensions (e.g. MicroG)
  • pre-configurations
  • including certain Apps
  • support installing Apps from F-Droid

Security examples:

  • fast ASB patching
  • (CVE related) Kernel patching
  • intensive hardening (e.g. malloc replacement)
Last updated on