Forensic extraction software without exploits for locked device is common and not closely guarded. Users these tools only need to follow simple on-screen instructions. Developers of the tools are aware of alternative operating systems. GrapheneOS features have to work when known.
Cellebrite and other forensic data extraction companies included information on GrapheneOS in their documentation years ago. That includes it being covered in Cellebrite's tables documenting available capabilities:
https://androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-3611794/
The more recent tables are similar.
training.magnetforensics.com/w/courses/15-gk200-graykey-examinations
> An awareness module focused on anti-forensic operating systems and applications, with particular attention to GrapheneOS — its privacy and security features, supported devices, data-wipe behaviors, and the handling and seizure considerations these devices introduce.
reddit.com/r/embeddedlinux/comments/1josb0i/embedded_linux_jobs_monthly_thread_april_2025/ml3schx/
> Company: Magnet Forensics
>
> [...] experience in both embedded Linux, and also FPGA gateware. Deep understanding of the USB protocol and stack is a major differentiator - experience here sets you apart [...]
>
> Technologies: [...] #GrapheneOS, [...]
We make privacy and security tech. Privacy and security involve defending against adversaries actively adapting and improving. Companies developing offensive security tech including remote exploits and data extraction tools are aware of GrapheneOS. It's made with that in mind.
quotingIn response to recent suggestions mentioning it:
nevent1q…4tnh
> If you need plausible deniability, you must not use VeraCrypt to encrypt any part of (or create encrypted containers on) a device (or file system) that utilizes a wear-leveling mechanism.
https://veracrypt.io/en/Wear-Leveling.html
The decoy profile concept many have suggested for years is far more flawed than this. It wouldn't hide the presence of other profiles and would be trivially identified. Basic forensic software on a laptop would identify it without exploits. It would also make exploits far easier.
