Device trust
Your sign-in.
Your rules.
Give your work apps a device boundary. Employees request access from their computers; you decide how devices are approved.
- Your devices
- Your policies
- No browser extension
How it works
Approval in your pocket.
The phone app lets an employee confirm a new computer and revoke a lost one.
Set up the phone
Register the mobile app as the controller for your devices.
EnrollConfirm the computer
A new device waits for approval. A password alone does not approve it.
ApproveRemove access
Revoke a computer from the phone if it is lost or no longer needed.
RevokeYour enrollment policy has the final say. Administrator-only approval keeps a request pending until an administrator accepts it.
Key protection
One identity. Two storage options.
Mobile devices retain the same Ed25519 identity when upgrading key protection. Your policy decides which storage classes are acceptable.
Protected local storage
On iOS, the key uses ThisDeviceOnly Keychain storage. Android uses a Keystore-backed AES wrapper without an attestation challenge.
Allowed or blocked by policyWith platform evidence
The core verifies attestation evidence linked to the device public key and a fresh challenge. Platform support must be validated for your deployment.
Verified by the coreAttestation adds evidence; it does not replace the Ed25519 signing identity with a P-256 key. Apple signing and physical-device acceptance are still in progress.
How it works
Upgrade first. Enforce when ready.
Ask phones to upgrade key protection before restricting the older storage class.
Request an upgrade
Start an attestation campaign for enrolled phones.
CampaignReview the results
See failures in the journal and check which devices need help.
VisibilityApply your policy
Block unattested storage when ready, with individual exceptions where needed.
Per-device exceptionsA failed upgrade does not silently become an accepted attestation. Downgrades from attested to unattested storage are rejected.
How it works
A small agent. A familiar sign-in.
The desktop agent sends signed device information directly to the core. The browser carries only a short-lived, one-use handle.
Install the agent
Use it on company or personal computers without a mandatory MDM rollout.
macOS, Windows, LinuxStart sign-in
The agent opens your normal SSO flow. No browser extension is needed.
Your existing browserKeep collection limited
Policy controls the information included. There is no arbitrary remote shell from the admin console.
Limited collectionThe agent can be switched off. Without device proof, protected sign-ins cannot proceed; personal use of the computer remains available.
Administration
A clear view of who belongs.
Manage enrollment, import users and devices, and review coverage from the console.
Changes apply without restarting the core. Individual exceptions do not change the policy for everyone.
Questions
A few things to know
Does this replace MDM?
No. TrustFlare controls sign-in from approved devices. It does not provide remote wipe or full device management.
Do I need a browser extension?
No. Sign-in starts in the desktop agent and continues in your browser.
Does device posture block access?
Not today. Device state is visible in the console, but posture checks do not currently determine sign-in decisions.
Are all mobile platforms release-ready?
Availability and attestation support must be verified during your pilot. Apple signing and physical iPhone acceptance are still in progress.
Try TrustFlare
Start with a few devices.
Your Keycloak, your team. We’ll help you test the fit.