Custom Android OS development: OS, app store, OTA and MDM

A bad update on phones already in users' hands cannot be rolled back like a website release. We build Android-based systems on AOSP with the app store, OTA updates and device management around them, as we did for RAW Cyber.

Book a free discovery workshop

Tell us about your device.

A few details about the hardware and the update path help us prepare the free discovery workshop.

RAW OS project
2018-2022

the RAW Secure Phone project ran from July 2018 to April 2022

OTA in production
Jan 2020

production RAW OS version with an OTA test delivered to the client

Move to Android 11
Sep 2021

RAW OS rebuilt on Android 11, with our features ported

Sideloading blocked
Nov 2021

from then on, apps came only from RAW Store

Mudita platform
Jul 2022

start of work on the App Store, Developer Portal and OTA platform

Custom Android OS development for device makers

Custom Android OS development means building your own operating system on the Android Open Source Project, together with the services that Google would otherwise provide. AOSP is the open code of Android, from which a device maker can build its own system for its own devices. Without Google services, the maker has to handle app distribution, updates and device management on its own. Our AOSP development services cover four layers: the operating system, app distribution, system updates and device management. This work is one part of our IoT and device software development.

We do it for CTOs and product owners at companies that make Android devices, such as phones, terminals or security devices, and that cannot or do not want to depend on Google Play.

Two projects show the scope:

  • For RAW Cyber we built RAW OS, a custom operating system based on Android and hardened with CopperheadOS. The project, called "RAW Secure Phone", ran from July 2018 to April 2022. The RAW Cyber case study describes it from the client's side.
  • For Mudita, starting in July 2022, we built the App Store, the Developer Portal and the OTA update platform for the Mudita Kompakt phone, which runs on AOSP. We did not build Mudita's operating system.
RAW Cyber mobile app showing the security level of an installed application

What we build around AOSP: OS, app store, OTA and device management

What a device maker gets with Google services, what it has to build on its own AOSP-based OS, and where we built it.
LayerWith Google servicesOn your own AOSP-based OSWhere we built it
Operating systemStock Android with Google servicesYour own build: hardening, security rules and features at system levelRAW OS for RAW Cyber, on CopperheadOS
App distributionGoogle PlayYour own app store, developer accounts and app reviewRAW Store; Mudita App Store and Developer Portal
System updatesDevice maker updates plus Google Play system updatesYour own OTA platform: packages, version checks, phased rolloutRAW OS OTA builds; Mudita OTA platform
Device managementAndroid Enterprise and MDM appsManagement built into the system, with an admin panelRAW OS admin panel for companies and user groups

Hardening the OS: RAW OS on Android

For RAW Cyber we hardened RAW OS at the system level, on top of CopperheadOS. We moved the CopperheadOS code to our own repository, and in the first sprint, in August 2018, we were already working on locking the bootloader of a Pixel phone with our own Android Verified Boot key. We prepared and tested the system on Pixel 2 / 2 XL and Pixel 3 / 3 XL phones.

RAW OS enforced these security rules:

  • Users had to set a screen lock, and the system detected a change of SIM card.
  • Connections used SSL pinning.
  • Bluetooth connections to devices that were not on a whitelist were blocked.

Network traffic inspection on the device

Traffic inspection in the system let a company block selected protocols and apps on its phones, for the whole company or for one user group. RAW OS inspected network traffic on the device, a form of deep packet inspection. A link classifier ran from 2020. In April 2021 we compiled the nDPI library for ARM and integrated it with the system. In August and September 2021 we added DNS detection, URL extraction and the blocking rules.

RAW Cyber web panel with a list of applications on a tablet

Your own app store and developer portal

RAW Store: approved apps only

RAW Store accepted only approved apps, and an admin panel let the client add them. From November 2021 the system blocked installing apps from outside the store, so sideloading was no longer possible. By April 2022 the store could also upgrade apps.

Mudita Developer Portal: accounts and review

For Mudita we built the Developer Portal and the App Store with developer accounts and a review of each app before it is published. A developer can change an app's description without uploading a new APK file.

Mudita App Store in 2026

The 2026 changes served both sides of the store. Users could open it from the phone itself (March) and read Android permissions in plain language (September). Developers got APK upload (April) and an APK scanner report (June).

OTA updates you can roll out in phases

Phased OTA updates let a device maker send a new system version to part of the fleet first and stop the rollout if something goes wrong. An OTA update installs new software on the device over the network.

For RAW OS we prepared the OTA procedures in September 2019 and delivered the production version, with an OTA test, to the client in January 2020. Further OTA builds were made at the client's request.

The second stage of Mudita's OTA platform, from May to July 2026, added:

  • incremental updates, with the full package kept as a fallback,
  • automatic generation of incremental packages,
  • checks of previous versions when a new version is configured,
  • a phased rollout in 1 to 10 phases, with each phase set from 0 to 720 hours.

During the migration to the new OTA panel in September 2026, tests found a bug that stopped the rollouts of all published versions. We fixed it on 9 September 2026 and finished the end-to-end tests on 29 September 2026.

RAW Cyber web dashboard on a laptop against an orange background

Keeping a custom Android OS current

A custom Android OS needs maintenance for as long as devices run it, because the code it is built on and the hardware both keep changing. For RAW OS, keeping up with changes in CopperheadOS and with new devices was a separate stream of work.

When Copperhead moved to Android 11, we aligned the repositories, rebuilt the system from scratch and ported our features to it. The move was complete in September 2021.

Android OS customization: device management built into the system

Android OS customization can put device management inside the system itself, with no separate MDM app to install. RAW OS had these management features:

  • an admin panel for companies and user groups, with the status of each device,
  • the list of Wi-Fi networks, managed in the admin panel,
  • a setup wizard for the first start of the phone.

A device that lost its connection was protected in three steps: a report, a warning and an automatic wipe of its data. In the panel these thresholds could be set to, for example, 5, 60 and 120 minutes. If the SIM card was removed from a locked phone, a 10-minute countdown to a reset started.

RAW OS also controlled access to the camera, microphone and location, data limits for apps, the allowed USB modes and device attestation.

Do you have questions?

Custom Android OS development - FAQ

Maciej Sułek
Maciej Sułek
Co-founder & CTO
Book a free discovery workshop
  • Order Group does. We build Android-based systems on AOSP together with the app store, OTA updates and device management around them. From 2018 to 2022 we built RAW OS for RAW Cyber, and starting in July 2022 we built the App Store, the Developer Portal and the OTA platform for the Mudita Kompakt phone, without building its operating system.

  • Yes. For RAW Cyber we built RAW OS, a custom system based on Android and hardened with CopperheadOS. Without Google services the device also needs its own app store, OTA updates and device management, and we built those for RAW OS as well.

  • We prepared and tested RAW OS on Google Pixel phones: Pixel 2 / 2 XL and Pixel 3 / 3 XL. In the first sprint, in August 2018, we were already working on locking the Pixel bootloader with our own Android Verified Boot key.

  • Through your own app store. RAW Store accepted only approved apps, and the system blocked installing apps from outside the store. The Mudita App Store and Developer Portal review each app before publication and show developers an APK scanner report.

  • A phased rollout sends the update to part of the fleet first, so a problem shows up before every device has it. On the Mudita platform this means a rollout in 1 to 10 phases, incremental updates that keep the full package as a fallback, checks of previous versions and end-to-end tests. In September 2026 those tests caught a bug that stopped rollouts, and we fixed it on 9 September.

  • Yes. In RAW OS it was built into the system, with an admin panel for companies and user groups and system-level control of the camera, microphone, location and USB modes. A device that stayed offline triggered a report, then a warning, then a data wipe, and removing the SIM card started a countdown to a reset.

  • Keeping the system current is a separate stream of maintenance work. When Copperhead moved to Android 11, we rebuilt RAW OS on the new base, ported our features and completed the move in September 2021.

  • No. We do not write microcontroller firmware in C/C++, embedded Linux or BLE code, and a hardware partner designs the PCBs. We build the Android system and the software around it.

  • Yes. In RAW OS we compiled the nDPI library for ARM and integrated it with the system, and in 2021 we added blocking of protocols and apps for a company or a user group.

  • With a free discovery workshop, where we describe the hardware, the update path and the security boundaries before any code is written. The code we create belongs to you by default, and we reply to a form message within 48 hours on working days.

Why work with us: how a custom Android OS project runs

A custom Android OS project with us starts with a free discovery workshop. Before any code is written, we describe the hardware and who makes it, the protocols, how the device behaves offline, the update path and the security boundaries.

We work on the Android system and on the software around it: the app store, the OTA platform, the admin panels and their backend. For RAW Cyber the backend and panels ran on Django and Celery, with Nginx and Gunicorn serving the traffic. We worked in Scrum, in a team of engineers, a tech lead, a tester, a PM and a UX/UI designer. Mudita's platform was built in Java, Kotlin, Python and Django. The Mudita work was billed on a time and materials basis.

We do not write microcontroller firmware in C/C++, embedded Linux or BLE code. A hardware partner designs the printed circuit boards (PCBs).

The code, designs and documentation we create for you belong to you by default. We reply to a message sent through the form within 48 hours on working days.

A secure phone with its own Android-based system

Custom Android OS case study

Contact image

An Android system for your device, from the discovery workshop to OTA updates after launch.

Your message goes to

Filip Szamborski

Filip Szamborski

Co-founder & CEO

SO FAR WE HAVE WORKED WITH BRANDS LIKE:

Thank you for your message.

We read every message ourselves and get back to you within 48 hrs on business days.

Something urgent? hello@ordergroup.co

Let's talk about your Android device

Tell us about your device and what it has to do without Google services, and we'll get back to you.

Fields marked with an asterisk (*) are required.

Order Group sp. z o.o. uses the information you provide only to reply to your enquiry and to keep a record of it (Art. 6(1)(b) and (f) GDPR). Details, including your rights, are in our Privacy Policy (opens in a new tab).

We reply within 48 hrs on business days - a person, not an autoresponder.

Using an AI assistant? It can send this inquiry for you or prepare a pre-filled form - instructions for it are in llms.txt.

Accessibility settings

Text size

100%