Leadership, Open Source & Governance

Engineered in Norway.
Rooted in open source.

Kalidroid bridges desktop-class offensive and defensive Linux capabilities with modern, unrooted Android hardware. Founded and led by seasoned security researcher and Linux wireless kernel engineer Christian Bremvåg (kimocoder), Kalidroid combines decades of upstream wireless engineering with strict Norwegian corporate and legal sovereignty.

Founder & Lead Architect

Christian Bremvåg (kimocoder)

Official Kali NetHunter Team · Aircrack-ng Core Maintainer · Linux RF Kernel Engineer

  • Kali NetHunter Team
  • Aircrack-ng Core Maintainer
  • Linux RF Driver Author
  • Norwegian Tech Founder
“If you give me a toy, the first thing I'd do is take it apart to figure out how it works.”— Christian Bremvåg (kimocoder)

Christian Bremvåg (widely recognized in the international cybersecurity and Linux kernel communities as kimocoder) is an open-source security software engineer, firmware reverse engineer, and core developer within both the official Kali NetHunter Teamat Offensive Security (OffSec) and the Aircrack-ng project (christian@aircrack-ng.org).

CoreKali NetHunter Team

As an official member of the Kali NetHunter development team at OffSec, Christian contributes to advancing mobile penetration testing, developing custom Android kernel patches, HID attack vectors, and wireless packet injection on portable hardware.

MaintainerAircrack-ng Project

Longstanding core maintainer within the premier 802.11 wireless auditing suite. Leads protocol compatibility testing, packet injection validation, WPA/WPA2/WPA3 cryptographic handshake verification, and cross-architecture RF engine stability.

KernelLinux Wi-Fi Drivers & Nexmon

Author and primary maintainer of the industry-standard Realtek Linux wireless drivers (rtl8812au, rtl88x2bu, rtl8188eus) utilized globally for monitor mode and frame injection, alongside low-level Nexmon ARM assembly patches for internal mobile Broadcom silicon.

InnovationThe Kalidroid Vision

Engineered to solve a longstanding operational dilemma: field operators should not have to sacrifice device integrity, void OEM warranties, or bypass Samsung Knox and Google Play Integrity with root exploits just to run a dependable, fully authenticated Kali Linux deployment.

Corporate Structure

Registered in the Kingdom of Norway

Kalidroid is an independent commercial and open-source software venture registered in Norway (Kongeriket Norge). Operating under the jurisdiction of the Norwegian Companies Act (Aksjeloven) and registered in the Central Coordinating Register for Legal Entities (Enhetsregisteret) and the Register of Business Enterprises (Foretaksregisteret) in Brønnøysund:

  • Sovereign Jurisdiction: All software engineering, release compilation, and cryptographic signing keys originate from and are maintained in Norway.
  • Tax & Fiscal Compliance: Subject to the Norwegian Tax Administration (Skatteetaten). Value Added Tax (VAT / MVA - Merverdiavgift) registration is maintained in compliance with Norwegian commerce laws.
  • Privacy & GDPR: Strict enforcement of the Norwegian Data Protection Act (Personopplysningsloven), incorporating European Union General Data Protection Regulation (GDPR) standards supervised by the Norwegian Data Protection Authority (Datatilsynet).

Legal Framework

Norwegian Laws & Cyber Legislation

Security testing tools, dual-use software, and penetration testing methodologies in Norway are governed by clear, predictable statutory legislation. Understanding these provisions is vital for every operator deploying Kalidroid in professional, academic, or research settings:

Straffeloven § 204 — Data Trespass (Innbrudd i datasystem)

Unauthorized Access

The Statute: Norwegian Penal Code § 204 criminalizes intentionally and unlawfully obtaining access to a computer system, stored digital data, or electronic communication channels ("den som uberettiget skaffer seg adgang til datasystem...").

Application to Kalidroid: Operators must possess explicit, verified authorization (such as a signed Rules of Engagement contract or formal penetration testing agreement) prior to conducting assessments against any network, infrastructure, or device they do not directly own.

Straffeloven § 201 & § 202 — Security Tools & Passwords

Dual-Use Legality

The Statute: § 201 and § 202 penalize the acquisition, production, or distribution of access codes, passwords, or computer programs designed primarily for committing cybercrimes.

Dual-Use Recognition: Under Norwegian jurisprudence, software tools with legitimate diagnostic, defensive, and research utilities (such as packet sniffers, port scanners, and wireless auditing suites like Aircrack-ng and Kalidroid) are recognized as dual-use technology. Possession and lawful use for authorized auditing, vulnerability analysis, and network defense are entirely legal.

Straffeloven § 205 — Interception of Communications

Radio Telecommunications

The Statute: § 205 protects the confidentiality of communications, prohibiting unauthorized wiretapping, radio surveillance, or eavesdropping on closed electronic and wireless transmissions.

Application to Wi-Fi Auditing: Capturing payload data from non-consenting third parties is strictly unlawful. Monitor mode in Kalidroid is designed for auditing your own beacon frames, testing handshake resilience, or conducting authorized red-team engagements where client consent is formally documented.

Electronic Communications Act (Ekomloven)

Spectrum & Hardware

The Statute: Regulated by the Norwegian Communications Authority (Nasjonal kommunikasjonsmyndighet - Nkom), the Electronic Communications Act establishes parameters for radio frequency (RF) transmissions, EIRP power levels, and spectrum allocation.

Hardware Compliance: External USB wireless adapters and directional antennas paired with Kalidroid must adhere to national power output limits (e.g., 100 mW EIRP for 2.4 GHz and 200 mW EIRP for 5 GHz indoor/outdoor bands in Norway and CE jurisdictions).

Ethical Practice

Rules of Engagement (RoE)

Every user of Kalidroid is expected to adhere to the core principles established by the Norwegian National Security Authority (Nasjonal sikkerhetsmyndighet - NSM) and international ethical standards:

  1. Defined Scope: Always operate within written boundaries agreed upon with the system or network owner.
  2. Non-Destructive Testing: Avoid disruption to critical infrastructure, availability, or operational services.
  3. Responsible Disclosure: Report any discovered vulnerabilities promptly, privately, and constructively to the affected organization before public disclosure.
  4. Data Minimization: Secure and delete packet capture files (PCAPs), handshakes, and credentials immediately following verification and debriefing.

Responsible Security

Reporting Vulnerabilities

Kalidroid maintains a formal RFC 9116 security contact point for security disclosures, bug bounty questions, and responsible reporting.