Before you buy a single privacy tool, install a single app, or follow a single hardening guide, there is one question that decides whether any of it will actually help you: who are you protecting yourself from, and what are you protecting? That is your threat model, and it is the step almost everyone skips on the way to buying things. Skip it, and you will do one of two things. You will overspend and exhaust yourself defending against threats you do not face, or you will leave the threats you do face wide open while feeling secure. Both are common, and both come from never answering the question first.
“Secure” is not a thing. Secure against something is.
Here is the reframe that makes everything else click. There is no such thing as “secure” in the abstract. A phone is not secure or insecure on its own; it is secure against a particular adversary, protecting a particular thing. A setup that is bulletproof against a data broker might fold instantly against an abusive partner who knows your PIN. A device that defeats a street thief might be trivial for a forensic lab. “I want to be secure” is a wish. “I want to keep this specific thing safe from that specific person” is a plan.
So security is always relative to a threat, which means the honest first move is not shopping. It is defining the threat.
The questions that make up a threat model
A threat model is not a document or a product. It is a clear answer to a handful of questions, and you can do it on the back of a napkin.
What are you protecting? Be specific. Your location. Your messages. Your identity. Your money. Your photos. The identity of a source. Your physical safety. These are different assets, and they need different defenses. “My privacy” is too vague to act on; “where I sleep at night” is not.
Who are you protecting it from? This is the one people fumble, because they answer “hackers,” which is not an answer. Name the actual adversary. A snooping partner. A data broker. A scammer. A stalker. A business competitor. Local police. A foreign intelligence service. Each of these is a completely different opponent with completely different powers.
What can that adversary actually do? A stalker who has physical access to your unlocked phone is a different problem than a phisher on the other side of the world, who is different again from a forensic lab or a nation-state with zero-click exploits. Match your defenses to what your adversary can realistically bring to bear, not to the scariest thing you read about.
What happens if they succeed? A spammer getting your email address is an annoyance. An abuser getting your live location can be life-threatening. The consequence sets the stakes, and the stakes decide how much effort is justified.
How much cost and inconvenience will you accept? Security is never free. It costs money, convenience, and time to learn. Proportionality is the whole game: you should not spend two thousand dollars and daily friction to protect your lunch order, and you absolutely should invest real effort to protect something that could get you hurt.
Answer those five honestly and you have a threat model. Everything downstream, every tool, every setting, every purchase, becomes a straightforward question of “does this address my actual threat?”
The two ways people get it wrong
Almost every security mistake is a calibration error in one direction or the other.
The first is having no threat model at all. You feel uneasy, so you buy a “spy phone” or a VPN or a pile of apps, you get a hit of feeling protected, and you never notice that your actual adversary, say, an ex who knows your passcode, walked right around all of it. Effort spent in the wrong place is not just wasted; it is dangerous, because it feels like safety.
The second is an inflated threat model. You decide you are a target of the NSA, you exhaust yourself performing elaborate operational security, you burn out, and in the fatigue you drop the boring basics that would actually have protected you, like not reusing passwords. Pretending to be a spy is a great way to end up less safe than someone who calmly locked down the five things that mattered. As we have written, the most secure phone is the one you will actually use, and over-calibration is how people end up not using any of it.
The goal is neither paranoia nor complacency. It is calibration.
Most people’s real adversaries are mundane
Here is the honest truth for the large majority of people: your real adversaries are not glamorous. They are data brokers assembling and selling your profile, advertisers tracking you across apps, a partner or family member with access to your device, a thief who wants your unlocked phone, a scammer after your accounts, and apps quietly over-collecting because they can. Calibrating to those mundane, commercial, close-to-home threats will protect you enormously, and it looks nothing like the spy movie.
And a smaller group of people genuinely do face serious, capable adversaries: journalists protecting sources, activists, executives, domestic-violence survivors, dissidents. For them the calibration runs the other way, and getting it right is not a hobby, it is safety. The same framework serves both. It just produces very different answers, which is the entire point.
How the model chooses your tools
Once your threat model is clear, the shopping gets easy, because the tool follows the threat instead of the other way around. Worried about advertisers and brokers? A de-Googled phone and disciplined settings do most of the work. Worried about account takeover? Get off SMS two-factor. Worried about a coercive person with physical access? A strong passcode over biometrics and compartmentalized profiles matter more than any exotic feature. Worried about a nation-state? Now the exotic features and the operational discipline earn their keep. The threat picks the tool. This is exactly the logic behind choosing a device, which we walk through in our threat-model-first buyer’s guide, and it is why the wrong tool for the right threat is just expensive theater.
Why we ask this first
This is genuinely the first question we ask anyone, before any talk of which phone: what are you actually up against? Sometimes the honest answer is that you do not need our device at all, you need to change five settings and get a secondary number, and we will tell you that. Sometimes the answer is that your situation is serious and the full setup is warranted, and we will tell you that too. We would rather calibrate you correctly than sell you a device that misses your real problem, because a phone that does not match your threat model is not security. It is a costume.
“Secure” is not something you buy. It is a fit between what you are defending, who you are defending it from, and what you are willing to do about it. Answer those honestly, first, and every other decision, including whether you need us, gets simple.
If you want help figuring out your actual threat model before you spend a dime, that is a conversation we are glad to have. Email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.