Devices that arrive already safe.
Most devices arrive empty, and making them safe — and capable enough to run a cyber lab — falls to you. These arrive the other way round: every protection on, the full app image installed, everything the manufacturer requires already licensed and configured, and a manifest telling you exactly what's inside before the box is opened.
Laptop, tablet, phone — take one, take two, or take all three. The same trusted image runs across every device you choose, and the apps are licensed to you, not to each piece of glass you own.
a household, a classroom, or a whole organization
runs the same trusted image.
Device manifest
Rev. 1 · draftThree things you can check before it ships
Not promises about the device. Facts about it you can verify against the manifest above.
Nothing hidden
Every application is listed before purchase. No trialware, no preinstalled software you didn't ask for, no app quietly reporting back.
Known origin
The hardware has a named manufacturer and a documented build. You know who made the machine and who provisioned it before it reached you.
Works locally
Devices in a package talk to each other directly. A classroom or an office runs as its own unit rather than routing everything through somewhere else.
Pick the glass. The image stays the same.
Each device does a different job, and each arrives fully provisioned — our apps, the safety core, and everything the manufacturer requires already licensed and set up. Nothing is left for you to install.
Laptop
The lab machine.
Runs the sanctioned range, virtual machines, and the full app portfolio. This is the one the Cyber Lab needs — 16 GB of memory, real virtualization, and Linux that actually works.
- Sanctioned range + VM host
- Full app image, all tiers
- Whiteboard, syllabus work, coursework
Tablet
The learning surface.
Where reading, note-taking, and coursework actually happen. Pen input, managed enrolment, and the same safety core locked on as everything else.
- The Whiteboard + BB2G University
- Fact Guides and civic build work
- Family Detective Lab for juniors
Phone
Where the risk lives.
The device a young person actually carries — and so the one where the safety layer matters most. If only one device in a household is managed, make it this one.
- ShieldScan doing its real work
- Project Exodus, locked on
- Local, device-to-device comms
And three ways off it.
The same worlds don't have to stay on a screen. Where a classroom or a household wants it, the image comes off the glass — onto a wall, into a headset, or floating on a desk. We ship what actually works today and say plainly what is still a roadmap. Try it live →
3-D projector
Fill a wall — available today.
Any provisioned device casts a world across a wall or three projectors edge to edge. Real, shipping, and part of the room mode in every learning app. No extra hardware from us — a projector you already have.
AR & MR glasses
In the room you're standing in.
On AR-capable phones and MR/passthrough headsets, the world and its guide appear in your actual space through WebXR — no app-store install. The software is built and live; the glasses are your device's, and the mode says so when a device can't do it. We do not sell the headset or pretend one is included.
Holograms
The desk pyramid — honestly.
Hologram mode is the Pepper's-ghost pyramid: set a small acrylic pyramid on the screen and the figure appears to float inside it. That is a real 19th-century optical effect, and it works now. Free-space holography — a figure standing in open air with nothing around it — is not something anyone can ship, and we will not say otherwise.
One, two, or all three
Take whichever devices fit. The apps are licensed per person — so a learner with all three doesn't pay for the same software three times over. Extra devices add a small provisioning charge, not another licence.
Laptop only
The lab machine on its own. The Cyber Lab's minimum.
Tablet only
Coursework and civic building. Strong for juniors.
Phone only
The safety layer where it matters most.
Laptop + Tablet
Build on one, learn and read on the other.
Laptop + Phone
Lab capability plus the carried device covered.
Tablet + Phone
A family set without the lab machine.
The full set
All three, one licence, one manifest, one safety core across every device.
Best value per devicePricing is built per person, not per device: hardware and provisioning scale with the number of devices, the app licence does not. Figures are in development and clear Olson before release.
What "cyber ready" actually requires The laptop spec
A lab machine has to do things an ordinary laptop never has to: run isolated environments, boot alternative operating systems, and survive a room full of learners. These are the specifications that follow from that — chosen for what the work needs, not for a spec-sheet number.
| Requirement | Floor | Why the labs need it |
|---|---|---|
| Virtualization | VT-x / AMD-V enabled, accessible in firmware | The sanctioned range runs as isolated virtual machines. Without it, there is no safe place to do hands-on work. |
| Memory | 16 GB minimum; 32 GB for the Pro tier | Running two or three VMs at once is normal lab work. 8 GB stalls the moment a range comes up.The one spec not to compromise on. |
| Storage | 512 GB NVMe SSD | VM images are large. Fast storage is the difference between a range that boots in a minute and one that eats the session. |
| Operating system | Linux-capable, with documented driver support | Most security tooling is Linux-first. A machine that fights Linux fights the curriculum. |
| Firmware controls | TPM 2.0; Secure Boot that can be turned off and back on | Learners need to boot lab images — and then restore the secure state. Locked-down firmware makes teaching impossible. |
| Serviceability | User-replaceable RAM, storage, and battery | A fleet takes damage. Parts availability decides whether a classroom set lasts three years or one.Also teachable: learners open the machine. |
| Provenance | Named manufacturer, documented build and supply chain | The program teaches provenance thinking. The hardware has to survive the same question the curriculum asks. |
Same machine, sized to the group
The image doesn't change between tiers — only how many devices, and which organization-level tools unlock.
Solo
One learner. Full app image, safety core locked on, Cyberlab junior track ready.
Family
A household set. Shared safety layer, parent visibility, devices talk locally.
Classroom / Team
A cohort set with the sanctioned range. The recommended first pilot.
Org / Campaign
Organization deployment. Harbor unlocks; controlled modules reviewed separately.
Locked on means locked on
"Cannot be removed" is a technical claim, so here is the technical answer — including where it is strongest and where it is honestly weaker.
| Device | Enforcement | What that means in practice |
|---|---|---|
| Phone | Android Enterprise fully managed + Samsung Knox | The safety core cannot be uninstalled, disabled, or force-stopped — and it survives a factory reset. The strongest enforcement of the three. |
| Tablet | Supervised enrolment (Apple) or fully managed (Android) | Apps cannot be removed while enrolled, and enrolment survives a reset. On iPad, apps arrive on first connection rather than preinstalled.Devices must be enrolled at purchase — retail units cannot be added later. |
| Laptop | Managed baseline image | Enforced at the account, network, and application layer. Strong — but not equivalent to phone-grade enforcement, and it does not survive a determined wipe.We say so rather than implying otherwise. |
The default. Full app image, safety core enforced, standard account, Secure Boot on, disk encrypted. Where a junior learner lives.
Entered deliberately for range work, inside virtual machines on a still-managed host. Apprentice and Pro tiers. Entering it is logged.
A machine can't be both fully locked and a place to learn cyber. Virtualization is what resolves it: learners get root inside a VM they can break freely, while the host stays managed and the safety core stays intact.
And what it never will
Management tooling can see far more than this program will ever collect. Where that line sits is our decision, so we publish it rather than leaving it in an admin console.
- Enrolment and compliance state — the proof the safety core is on
- App inventory, checked against the manifest
- OS version and patch level
- Safety alerts — sent to the parent or guardian, not to us
- Precise location history
- Message, call, or browsing content
- Keystrokes or screen captures
- Anything in the personal space of a shared device
A program that runs an Ethics Lab can't hand out managed devices without saying what those devices report. The restraint is part of the product — and leaving the program releases the device from management entirely. We don't hold hardware hostage to a subscription.
Child safety is not an upgrade.
ShieldScan and Project Exodus are locked on at every tier — including on a device nobody is paying for. They cannot be removed, disabled, or moved behind a paywall at any price point. That is a design floor written into the image, not a feature of the expensive package.
Who makes the machine
The app image is ours. The hardware comes from a manufacturer we name openly — because a program that teaches provenance can't be vague about its own.
logo — pending
agreement
Born Between 2 Generals owns and licenses the app image; partner organizations lease their deployments. The manufacturer is disclosed on every package, along with who provisioned the device before it shipped. No partner is named here until an agreement is signed.
Ask about a package.
Tell us the size of the group and where you'd start. We'll walk you through the image, the manifest, and what a pilot would look like.