Device trust

Work access.
Personal space.

Know the device that reaches your work apps. Leave personal files, messages and browsing history alone.

  • Your devices
  • Your policies
  • No browser extension

Personal devices

A work boundary, not a personal window.

Employees and contractors use computers that also hold private information. Device-based access can protect work sign-in with a limited, visible set of device facts.

What is checked

A smaller scope of trust.

The agent shows what it collects. Your organization gets the information needed to identify and approve the device.

For work access

  • Whether the device is registered and approved
  • A valid, fresh device signature
  • Phone confirmation when required by policy
  • The phone’s key storage class

Stays personal

  • Personal messages and notes
  • Private files and photos
  • Browsing history
  • Contents of personal applications

How it works

You can switch it off.

The organization sets the conditions for work access. Employees retain control of their computers.

Agent on

The device can prove its identity during work sign-in.

Device proof

Agent off

Protected sign-in is unavailable without device proof. Personal use remains unaffected.

Your choice

Policy in place

The organization decides which sign-in flows require the check.

Your boundary

Questions

A few things to know

Can my employer read my messages?

TrustFlare does not collect the contents of personal messages, files or applications.

Can I disable the agent?

Yes. Without its device proof, protected work sign-ins cannot proceed.

Does this include remote control?

No arbitrary remote shell or live query is provided through the admin console.

Try TrustFlare

Start with a few devices.

Your Keycloak, your team. We’ll help you test the fit.

How should we reach you *