GhostWire — downloads

Signed companion tools and Android test builds for the GhostWire / Pharoah Technology estate.

GhostWire the messenger is not here. It is a zero-identity field messenger that ships pre-installed to Pixel / GrapheneOS handsets — there is no app-store listing for it here. This page lists separate companion products and internal Android test builds below.

GhostArchive v0.1.0

Retention, legal-hold and WORM archival lifecycle. Mutating a sealed archive, deleting under legal hold, and retroactively shortening retention are structurally unrepresentable, not just runtime-checked; legal-hold release is gated on a trusted-signed policy ruleset evaluated for real by ghostcore_policy, never a typed-in decision.

GhostBackup v0.1.0

Client-side-encrypted backup, restore and retention. Every object is unrepresentable as plaintext at the type level, restore requires a signed and trusted policy ruleset evaluated for real (never a typed-in decision), and the master key is never stored anywhere restore reads from — lose it and the backups are gone, by design.

GhostBridge v0.1.0

Signed, policy-governed integration connectors. Fail-closed admission on signature, status, tenant, event type and data class; secrets only ever travel as references, never as values — refusals are recorded, not dropped.

GhostDeploy v0.1.0

Declarative, typed deployment orchestration. A deployment plan is a sequence of closed step kinds — no shell step, no script step, no generic "run" adapter. Signed release manifests, fail-closed promotion gates, and rollback as a planned, typed operation from the same engine.

GhostDeveloper v0.1.0

Third-party extension capability control for the GhostWire suite. A developer app can never exercise a capability it wasn't both declared in its signed manifest and explicitly granted — absence of a grant is never permission, and revocation takes effect on the very next check. Scope note: this release is the capability-control core and desktop console only, not the full developer platform (no HTTP API, SDK generation, sandboxes or webhook testing yet).

GhostDNS v0.1.0

Privacy-first encrypted DNS resolver, policy engine and local filter. Forwards only over encrypted DoT/DoH transports, fail-closed — never a silent plaintext fallback.

GhostFlow v0.1.0

Privacy-preserving workflow orchestration and approvals. Signed workflow templates, a deterministic state-machine engine, human approval gates on high-risk steps and GhostPolicy-enforced rules — no shell/script/eval step exists as a type.

GhostInsight v0.1.0

Privacy-preserving metadata analytics and risk insight for the GhostWire suite. A classification gate rejects secrets, content and unknown fields by default — rollups, risk indicators and alerts are built only from metadata that passed it.

GhostIntel v0.1.0

Privacy-preserving threat and research intelligence workspace. Protected-source identities that cannot exist unencrypted at the type level, a handling-sensitivity lattice that can only escalate, hash-verified evidence with a tamper-evident chain of custody, and policy-gated source reveal and export — fail-closed on every decision.

GhostKey v0.1.0

One place to generate, protect, use, rotate, back up and revoke your cryptographic keys — no escrow, no universal recovery key, no administrator who can open your vault.

GhostLabs v0.1.0

Gated experimental-feature and feature-flag platform for the GhostWire suite. Security-relevant flags and experiments cannot be built default-on or without an expiry — enabling one requires explicit, expiring consent evaluated for real by the shared GhostPolicy engine against a signed, trusted ruleset, never a typed-in decision. Scope note: this release is the experiment/flag/consent core only, not the full control-plane (no HTTP API, admin UI or multi-tenant enforcement yet).

GhostNode v0.1.0

Owner-controlled managed-node agent. Enrollment gated on local owner approval only, signed and version-checked service-bundle updates with fail-closed pre-check/post-check and automatic rollback, a tamper-evident local audit log — no generic command, shell or script execution exists anywhere in the wire format.

GhostOS v0.1.0

Image provenance and boot integrity for hardened golden images. Real operator commands sign, verify and promote images against a persisted, tamper-evident known-good registry with a monotonic rollback floor — no caller-suppliable "trust me" flag anywhere a cryptographic check belongs. Scope note: this release is the image-provenance/boot-integrity core only, not the full fleet-management platform (no control-plane API, admin UI or node orchestration yet).

GhostPulse v0.1.0

Privacy-preserving service health, incidents and alerting. Silence is never health — freshness-driven status, dependency propagation, one-way incident lifecycle, and alert routing with dedupe, cooldown and maintenance suppression.

GhostSecure v0.1.0

Defensive security posture evaluation for the GhostWire suite. A baseline of critical controls, deterministic severity-weighted risk scoring, and scoped expiring exceptions with mandatory approval trails — an unmeasured control is a violation, not a pass. Metadata only; no offensive tooling exists here.

GhostShield v0.1.0

Endpoint posture assessment and a tamper-evident local event log — real installed applications, real launchd startup items and real file integrity read off your own machine, assessed fail-closed (an unmeasured fact is always non-compliant, never a pass). Scope note: this release is assessment and visibility only — it does not block, isolate or quarantine anything; no enforcement executor exists yet.

GhostTraining v0.1.0

Operator training assessment and certification integrity. Create and publish assessments, assign them, grade attempts, and issue Ed25519-signed certificates from a completion record only — a certified state is unrepresentable without a passing assessment behind it, and any tampering with an issued certificate is caught as a signature failure at verify time. Scope note: this release is the assessment/certification core only, not the full enablement platform (no HTTP API, database, web UI, course/module hierarchy, or integration with the rest of the suite yet).

GhostTrust v0.1.0

Privacy-preserving identity verification and trust graph. No legal names, no phone numbers, no government IDs — safety-number ceremonies, signed key-change and device review, revocations and signed trust bundles, fail-closed on every decision.

Ghostwire Drive v0.1.0

Local-first encrypted cloud storage. Files, names and sharing keys are encrypted on-device before upload; providers store opaque ciphertext only. Provider-neutral: local folder, WebDAV or S3.

GhostWire LinkBond v0.3.0

GhostWire handset Wi-Fi companion: current-network checks, router-control handoff and dual-network research. Estate-signed release APK. Manual download; it is not a GhostWire messenger OTA.

GhostWire LinkBond Mac v0.1.0

macOS Apple Silicon scanner for stronger multi-network checks: Wi-Fi, Ethernet, tethering, VPN, DNS, default route and LinkBond tunnel readiness. Manual browser download, no automatic update service.

Ghostwire Mail v0.1.0

A private email client for your existing IMAP/SMTP mailbox — inbox, read and send, with on-device crypto. No telemetry, no server-side indexing.

GhostWire Router v0.2.6

GhostWire router companion for Android: current gateway checks, read-only router reachability, router-panel handoff, and VPN/DNS/security status notes. Estate-signed release APK. Manual download; it is not a GhostWire messenger OTA and does not write router configuration.

Ghostwire Vault v0.1.0

A local-first, end-to-end encrypted store for passwords, secrets, documents, identity records and files. No account, no email address, no telemetry — works fully offline.

Authenticity: none of these builds are Apple- or Windows-notarised yet, so your OS will warn on first launch ("unidentified developer" / SmartScreen). That warning is expected, not a red flag — the real trust anchor is independent of the OS: every release is signed with the product's Ed25519 release-signing key, and SHA256SUMS is the record of exactly what should be inside the artifact. Verify it yourself below before you trust the warning away.

Verify a download yourself

Every release directory publishes three trust files alongside the artifact: SHA256SUMS (the hash of every file in the release), SHA256SUMS.sig.json (an Ed25519 signature over the raw bytes of SHA256SUMS), and release-signing-key.pub.json (the public key — safe to publish; the private key never leaves the signer's machine).

1. Check the artifact you downloaded matches the manifest:

shasum -a 256 "<downloaded file>"
grep "<downloaded file>" SHA256SUMS   # hash must match

2. Check SHA256SUMS itself was signed by the release key (needs only openssl + xxd, both standard on macOS/Linux — download the script or run it inline):

PUBHEX=$(grep -o '"public_key_hex"[^,}]*' release-signing-key.pub.json | sed -E 's/.*"([0-9a-f]+)"/\1/')
SIGHEX=$(grep -o '"signature_hex"[^,}]*'   SHA256SUMS.sig.json         | sed -E 's/.*"([0-9a-f]+)"/\1/')
echo -n "302a300506032b6570032100${PUBHEX}" | xxd -r -p > pub.der
xxd -r -p <<< "$SIGHEX" > sig.bin
openssl pkey -pubin -inform DER -in pub.der -outform PEM -out pub.pem
openssl pkeyutl -verify -pubin -inkey pub.pem -rawin -in SHA256SUMS -sigfile sig.bin
# -> "Signature Verified Successfully" means the manifest is authentic

If both checks pass, the file you have is byte-for-byte what the release key signed off on — independent of anything your OS says about the publisher.