Device trust

Your sign-in.
Your rules.

Give your work apps a device boundary. Employees request access from their computers; you decide how devices are approved.

  • Your devices
  • Your policies
  • No browser extension

How it works

Approval in your pocket.

The phone app lets an employee confirm a new computer and revoke a lost one.

Set up the phone

Register the mobile app as the controller for your devices.

Enroll

Confirm the computer

A new device waits for approval. A password alone does not approve it.

Approve

Remove access

Revoke a computer from the phone if it is lost or no longer needed.

Revoke

Your enrollment policy has the final say. Administrator-only approval keeps a request pending until an administrator accepts it.

Key protection

One identity. Two storage options.

Mobile devices retain the same Ed25519 identity when upgrading key protection. Your policy decides which storage classes are acceptable.

Unattested

Protected local storage

On iOS, the key uses ThisDeviceOnly Keychain storage. Android uses a Keystore-backed AES wrapper without an attestation challenge.

Allowed or blocked by policy
Identity stays the same

Attestation adds evidence; it does not replace the Ed25519 signing identity with a P-256 key. Apple signing and physical-device acceptance are still in progress.

How it works

Upgrade first. Enforce when ready.

Ask phones to upgrade key protection before restricting the older storage class.

Request an upgrade

Start an attestation campaign for enrolled phones.

Campaign

Review the results

See failures in the journal and check which devices need help.

Visibility

Apply your policy

Block unattested storage when ready, with individual exceptions where needed.

Per-device exceptions

A failed upgrade does not silently become an accepted attestation. Downgrades from attested to unattested storage are rejected.

How it works

A small agent. A familiar sign-in.

The desktop agent sends signed device information directly to the core. The browser carries only a short-lived, one-use handle.

Install the agent

Use it on company or personal computers without a mandatory MDM rollout.

macOS, Windows, Linux

Start sign-in

The agent opens your normal SSO flow. No browser extension is needed.

Your existing browser

Keep collection limited

Policy controls the information included. There is no arbitrary remote shell from the admin console.

Limited collection

The agent can be switched off. Without device proof, protected sign-ins cannot proceed; personal use of the computer remains available.

Administration

A clear view of who belongs.

Manage enrollment, import users and devices, and review coverage from the console.

ApprovalRequire an administrator to approve new devices. Phone confirmation alone need not grant access.
ImportRegister users and devices ahead of time with JSON or CSV.
CoverageSee enrolled phones, desktop agents, operating systems and mobile storage classes.

Changes apply without restarting the core. Individual exceptions do not change the policy for everyone.

Questions

A few things to know

Does this replace MDM?

No. TrustFlare controls sign-in from approved devices. It does not provide remote wipe or full device management.

Do I need a browser extension?

No. Sign-in starts in the desktop agent and continues in your browser.

Does device posture block access?

Not today. Device state is visible in the console, but posture checks do not currently determine sign-in decisions.

Are all mobile platforms release-ready?

Availability and attestation support must be verified during your pilot. Apple signing and physical iPhone acceptance are still in progress.

Try TrustFlare

Start with a few devices.

Your Keycloak, your team. We’ll help you test the fit.

How should we reach you *