# Device laboratory design

## Minimum equipment

- two matched Android devices still receiving security updates;
- one stock reality-lane device;
- one research-configured inspection-lane device;
- isolated Wi-Fi network and dedicated router or access point;
- encrypted workstation and restricted evidence volume;
- dedicated SIMs, research accounts and payment instruments;
- spare device or documented recovery plan.

## Configuration record

For every run preserve:

- hardware model and serial alias;
- OS version and build fingerprint;
- bootloader and root state;
- locale, timezone and accessibility settings;
- installed CA certificates;
- VPN, proxy, DNS and network path;
- installed non-system packages;
- Play Services and WebView versions;
- screen-recording and clock-synchronisation state.

## Isolation

- no personal accounts;
- no unrelated communication apps;
- no contact book or personal media;
- no cloud backups;
- per-project Wi-Fi credentials;
- raw evidence encrypted at rest;
- test accounts never reused for ordinary activity.

## Reset

Before each clean run:

1. confirm APK and policy hashes;
2. clear app data or factory-reset according to the protocol;
3. remove residual permissions and notification state;
4. confirm system time;
5. start screen, network and event recording;
6. document remote configuration uncertainty;
7. execute the script without exploratory taps;
8. stop capture before unrelated activity;
9. calculate hashes immediately.

## Romania-sensitive testing

For parking, transport, emergency or location services, prefer a device physically connected in Romania. A VPN can test region-dependent behaviour but must not be presented as equivalent to physical use.

## Emergency services

- never place a false call;
- never submit a fabricated incident;
- stop before any action that could dispatch resources;
- seek an institution-provided sandbox or supervised test;
- publish only non-operational information.
