I mean, some obvious things are there in the article, IMHO -
- App isolation and hidden profiles (up to 32 separate profiles)
- Verified Boot (tamper detection on every startup)
So you can do stuff on there that's not going to tip off someone who's controlling enough to demand to see your phone, and so you'll at least be tipped off if someone compromises it.
Indeed, whenever I reboot (which is very frequently, because Mastodon will only open, not reopen. If I close it, I need to reboot before using it again) I see the tamper detection. It warns me that I'm using GrapheneOS, not Android.
Yeah that's telling you that you are using custom signing keys (the ones of GrapheneOS, which should be compared once with those published on GrapheneOS' website).
Stock Android runs the tamper detection just the same; they just don't warn about the custom keys because the keys are not custom, they are the ones expected by the manufacturer :-).
- App isolation and hidden profiles (up to 32 separate profiles)
- Verified Boot (tamper detection on every startup)
So you can do stuff on there that's not going to tip off someone who's controlling enough to demand to see your phone, and so you'll at least be tipped off if someone compromises it.