Nitrokey · Berlin, Germany · open hardware
Nitrokey makes the most trusted open-source hardware security devices in the world — GrapheneOS-hardened phones, Qubes-certified laptops, and EAL 6+ security keys. We're the authorized US channel. Same hardware, US inventory, faster delivery.
Why Nitrokey
The case for open hardware over commercial alternatives.
Open-source firmware
All firmware is publicly auditable. No hidden backdoors, no vendor trust required. Verified by the security community.
EAL 6+ certified secure element
The Nitrokey 3 stores OpenPGP key material in an NXP SE050 secure element certified to Common Criteria EAL 6+ — the assurance class used for government smart cards and payment chips.
EU jurisdiction
German company, German law. No FISA court orders, no NSL gag orders. For principals with cross-border exposure, this matters.
GrapheneOS hardened phones
NitroPhone runs GrapheneOS on certified Pixel hardware — the most secure Android available. No Google services unless you choose them.
Product categories
Every product category Nitrokey makes, available in the US.
Hardened phones
NitroPhone 5a, 10 Pro, 10 Pro XL
Secure laptops
NitroPad V54, V56 — Qubes certified
Secure desktops
NitroPC Pro 2, NitroPC X
Security keys & HSMs
Nitrokey 3 series, Nitrokey HSM 2
Network & firewalls
NitroWall V1410
Secure storage
NextBox NAS, encrypted drives
All products
Every Nitrokey device we carry, in US inventory.
Hardened phones

NitroPhone 10 Pro
GrapheneOS hardened Pixel 10 Pro. Verified boot, sensor controls, no Google services unless you opt in. Built in Berlin on open hardware and firmware, fulfilled from a US 3PL with 2-day shipping.
$1,235 $1,435
View product
NitroPhone 10 Pro XL
GrapheneOS hardened Pixel 10 Pro XL. Larger 6.9-inch display for executives who need their secure phone to double as a primary productivity device. Same GrapheneOS stack as the 10 Pro.
$1,750 $1,780
View product
NitroPhone 5a
Entry-tier hardened Android on the Google Pixel 9a. Same GrapheneOS protections as the flagship NitroPhone at a lower price point — ideal for wider team deployment or as a dedicated travel device.
$965
View product
NitroPhone 10
A hardened Google Pixel 10 running GrapheneOS with a Titan M2 security chip, verified boot, and optional physical removal of microphones, sensors, and cameras for high-threat mobile users.
$1,035
View product
NitroPhone 10 Pro Fold
Hardened foldable Android built on the Google Pixel 10 Pro Fold running GrapheneOS: de-Googled, telemetry-free, with verified boot, Titan M2 secure element, and a duress PIN in a large-screen form factor.
$2,000 $2,365
View product
NitroPhone 5 Pro
Hardened Google Pixel 9 Pro running GrapheneOS on Android 16, de-Googled with Titan M2 secure element and optional physical microphone/camera removal for high-threat operators.
$1,000 $1,020
View product
NitroPhone 5 Pro XL
Hardened large-format Android built on the Google Pixel 9 Pro XL, shipping with GrapheneOS, Verified Boot and the Titan M2 secure element — with optional physical removal of microphones, sensors and cameras for the highest threat models.
$1,380
View product
NitroPhone 10a
GrapheneOS on the Google Pixel 10a — the most affordable way into a de-Googled, hardened Android with the Titan M2 security chip. Same hardening as the flagship NitroPhones at the mid-range price.
$810
View productSecure laptops

NitroPad V54 (14")
High-assurance 14-inch workstation on Dasharo (coreboot) open firmware — Intel ME neutralized, optional HEADS measured boot, and Qubes OS for VM compartmentalization. Intel Core Ultra, DDR5, NVMe.
$2,285
View product
NitroPad V56 (16")
16-inch high-assurance workstation — same Dasharo (coreboot) open firmware, Intel ME neutralization, and optional HEADS measured boot as the V54, with a larger 165 Hz display. Runs Ubuntu or Qubes OS.
$2,330
View product
NitroPad T480
A tamper-evident Lenovo ThinkPad T480 hardened with Coreboot/Heads measured boot and a bundled Nitrokey, with Intel ME deactivated. Detects evil-maid and supply-chain firmware tampering.
$740
View product
NitroPad T480s
Tamper-evident hardened ThinkPad T480s with HEADS firmware, neutralized Intel ME, and TPM-based measured boot, verified at every power-on by a paired Nitrokey for evil-maid resistance.
$690
View productSecure desktops

NitroPC Pro 2
A high-assurance desktop workstation with open-source Dasharo coreboot firmware, Heads measured boot anchored to a Nitrokey, and a deactivatable Intel Management Engine to resist firmware tampering and evil-maid attacks.
$2,230
View product
NitroPC 2
Compact coreboot mini PC with Dasharo open-source firmware — a small, quiet desktop for Qubes OS or hardened Linux where the boot chain is auditable rather than a vendor black box.
$1,085
View productSecurity keys & HSMs

Nitrokey 3C NFC
EAL 6+ certified secure element, open-source firmware. FIDO2/WebAuthn, OpenPGP, OTP, PIV smart card. USB-C + NFC. The open-source alternative to YubiKey.
$80
View product
Nitrokey 3A NFC
USB-A variant of the Nitrokey 3 with NFC. Same EAL 6+ secure element and open-source firmware as the 3C. For legacy hardware without USB-C or as a backup key.
$75
View product
Nitrokey HSM 2
Hardware security module for PKI, code signing, CA operations, and SSH host key storage. Open-source firmware, USB-A interface. The affordable HSM for teams that need hardware-bound keys but can't justify an enterprise rack appliance.
$135
View product
Nitrokey 3A Mini
Compact USB-A hardware security key with an NXP SE050 EAL 6+ secure element and Rust open-source firmware, delivering phishing-resistant FIDO2/WebAuthn MFA plus OpenPGP, OTP, and X.509 key storage.
$65
View product
Nitrokey Pro 2
OpenPGP smart-card key with a tamper-resistant smart card, one-time passwords, and a 16-entry password manager. For email/file encryption, SSH, and X.509 — OpenPGP Card 3.4, no FIDO2.
$135
View product
Nitrokey 3A NFC Hacker
NOT A READY-TO-USE SECURITY KEY. This is the bare Nitrokey 3A NFC electronics shipped WITHOUT firmware, in an unprinted case, for developers building their own firmware on the LPC55S69. If you want a working key, buy the Nitrokey 3A NFC instead.
$100
View product
Nitrokey Start
The entry-level Nitrokey: an OpenPGP smart-card key for encrypting email, files, and SSH/server access. Open-source hardware (OSHwA certified), made in Germany. OpenPGP only — no FIDO2, no NFC.
$60
View product
Nitrokey Passkey
FIDO2/WebAuthn and U2F hardware key for phishing-resistant passwordless login and 2FA. Rust-based open-source firmware on an nRF52 secure element, made in Germany, priced for fleet-wide rollout.
$60
View product
Nitrokey 3A (No NFC)
USB-A hardware token built on an SE050 secure element certified to Common Criteria EAL 6+, with Rust-based open-source firmware. Consolidates FIDO2, OTP, and OpenPGP/PIV in one tamper-resistant device.
$90
View product
Nitrokey 3C (No NFC)
USB-C hardware security key built on an EAL 6+ certified SE050 secure element and Rust firmware. Delivers FIDO2, U2F, OpenPGP and OTP for phishing-resistant authentication and key protection.
$90
View productNetwork & firewalls

NitroWall V1410
OPNsense firewall on open hardware with IPS and VPN gateway. Four 2.5-Gigabit Ethernet ports, Suricata intrusion prevention, WireGuard/OpenVPN/IPsec. Replaces your ISP-provided router with something auditable.
$835
View product
NitroWall NW750
Battery-powered travel privacy router on OpenWrt with Tor, VPN, and 4G LTE. Randomises IMEI and MAC via blue-merle to break device-level tracking — a pocket network you carry into untrusted places.
$375
View product
NitroWall VP4670
Six-port 2.5 GbE OPNsense firewall appliance on an i7 with AES-NI — the high-throughput NitroWall for an office perimeter, segmented VLANs, or a small datacentre rack shelf.
$1,540
View productSecure storage

NextBox NAS
Self-hosted Nextcloud NAS on open-source hardware. Replace Google Drive, Dropbox, and iCloud with an encrypted, on-premise file server you fully control.
$450
View product
Nitrokey Storage 2 (64 GB)
64 GB of AES-256 hardware-encrypted storage with a hidden-volume mode, plus the full OpenPGP smart card, OTP slots, and password manager of the Pro line — encrypted drive and security key in one device.
$250
View productNot sure where to start?
Use the Nitrokey Stack Builder — answer 6 questions about your role, threat model, and budget, and get a personalized Nitrokey hardware recommendation with NIST control coverage.
Buying from us
US inventory
In stock
Ships from US warehouse within 2 business days. No international customs delays.
Authorized reseller
Verified
Official Nitrokey authorized channel. Full manufacturer warranty applies.
PO & net-30
Available
Purchase orders accepted. Net-30 terms for approved organizations. W-9 on file.
Common questions
Is this the same hardware as buying directly from Nitrokey?
Yes. We are an authorized reseller. The hardware, firmware, and warranty are identical to buying direct. You get faster US shipping and local support.
Why buy through SecurityGadgets.shop instead of nitrokey.com?
US fulfillment (2-day shipping vs. 7–14 days from Germany), NIST control mapping per product, PO/net-30 procurement support, and a security-practitioner buyer experience tuned for your use case.
Do you support enterprise volume purchases?
Yes. Contact us for volume pricing on orders of 5+ units. We also support PO-based procurement and can provide W-9 documentation for your procurement team.
What is GrapheneOS and why does it matter?
GrapheneOS is an open-source, hardened Android OS built for privacy and security. It runs on certified Pixel hardware, provides per-app permission controls, verified boot chain, and significantly reduces the attack surface compared to stock Android or iOS.