Thank you all — this thread gave me more concrete answers in two days than two weeks of searching did. I want to thank each of you individually, and then summarise the results so this thread is useful to the next Ukrainian who searches for it.
@Kkeycap_puller — thank you for the most rigorous report here. Testing Rezerv+ in a secondary profile with no Play Services and no Play Store at all, with hardened malloc, memory tagging and secure app spawning all enabled, is exactly the worst-case configuration, and it still ran. That single data point removed the main blocker for me. Documenting the Diia crash sequence toggle by toggle was equally useful — it showed the failures were exploit-protection related rather than attestation related, which is a completely different problem to solve.
@kauyafrotrauci-4115 — thank you for the link to the older thread and for the detailed post-update behaviour report. Your diagnosis that Diia.Signature likely depends on Google ML Kit OCR for reading the passport number, distributed only as Play Store dynamite modules, is the most useful explanation I've seen anywhere. Nobody else had identified a specific mechanism. Your point about fingerprinting through "legitimate" Google domains even with RethinkDNS filtering is well taken too.
@Novaliss — thank you for the screenshots of the alternative activation paths, and for working out the actual recipe: disabling all exploit protection options except hardened malloc, allowing verified links, and granting Phone, Nearby devices, Network and Notifications. That's the difference between "it crashes" and "here's how to run it."
@elliasdev — thank you for the independent confirmation on Pixel 8a with Diia, Rezerv+, Privat24 and Mono all working. Two devices from two different people is what turns a single report into something I'm willing to spend money on.
@munch — thank you for the Pixel 10a data point and the Private Space approach, and for confirming that both Diia and Monobank refuse to launch when installed via Aurora. Creating a dedicated Google account for those apps is the pragmatic answer and I'll be doing the same.
Summary for future readers (Ukraine, GrapheneOS, July 2026)
- Rezerv+ (
ua.gov.reserveplus v2.3.2) — works. Confirmed on Pixel 9 and Pixel 8a. Notably runs even with no Play Services, no Play Store, installed via Aurora, with all exploit protections enabled. No Play Integrity dependency observed.
- Diia (
ua.gov.diia.app) — works, with two conditions: (1) must be installed from the Play Store, not Aurora — sandboxed Play with a signed-in Google account is required; (2) exploit protection needs to be relaxed for this app specifically. Confirmed on Pixel 8a, 9 and 10a.
- Diia.Signature (qualified electronic signature) — not yet confirmed working. Suspected dependency on Google ML Kit OCR modules from the official Play Store. Still open.
- Privat24, monobank — work.
- Contactless payments — Google Wallet does not work and won't. Ukrainian bank apps proxy their contactless through Google Pay, so no in-app workaround. Assume no tap-to-pay from the phone.
Two questions still open
@kauyafrotrauci-4115 — when Diia.Signature failed for you, were you running full sandboxed Play Store with a signed-in account, or only Aurora? If it was Aurora-only, then the ML Kit modules were simply unavailable, and the signature question may still be unanswered rather than answered negatively. That distinction matters a lot for anyone deciding whether to buy.
@munch — no pressure at all, but if you do get to test the signature feature, that result would close the last gap in this thread. Happy to wait.
I'll report back once I have my own device set up. Thanks again — this is the kind of thread that makes a community worth participating in.