New — Aegis AI: ask your fleet a question, get a one-click fix See it →

Aegis AI · Android Enterprise · Apple MDM

Every company phone and tablet under one policy.

Aegis UEM enrolls, locks down and monitors your Android and iOS fleet from a single console. Write the policy once — we translate it to Android Management API and Apple configuration profiles for you.

New · Aegis AIHow many devices have developer options enabled?

Ask your fleet in plain language — answers come with the devices and a one-click fix.

Built on
Android Management API

Policy, enrollment and device commands

Managed Google Play

App approval and delivery

Apple MDM protocol

Signed configuration profiles

Apple Business Manager

Automated Device Enrollment and app licences

APNs

Push wake-ups that trigger device check-in

SCEP

Device identity certificates issued at enrollment

Aegis AIIn development

Ask your fleet a question. Get the devices, not a dashboard.

Aegis already collects every device's hardware, software, policy state and command history. AI turns that into plain-language answers — and the remediation is one click away, because it's the same bulk action the console already runs.

Grounded in tenant data only. No fleet data leaves your tenant for model training.

How many devices have developer options enabled?Ask
23of 1,284 devices have developerSettings enabled
17
Android GMS
6
Non-GMS / AOSP
0
iOS / iPadOS
DeviceGroupSeen
Rugged T80 · AEG-DPC-00412Route 73h ago
SM-A146 · R9WT402KXYBField staff12m ago
Galaxy Tab A9 · R5CX236LPNAWarehouse2m ago
+ 20 more
Add “block developer options” to Field-Staff-Baseline→ pushes to 23 devices
Other questions admins actually ask
Which devices haven't checked in for 30 days?
Where did the camera restriction fail to apply?
Which iPads are unsupervised, so kiosk won't work?
List apps installed outside the allowlist this week
Which tablets are below 20% battery health?
Policy drafting

Describe the lockdown in words; review the generated policy field by field before it pushes.

Anomaly watch

Flags the device that suddenly left kiosk, changed SIM, or stopped reporting.

Platforms we manage today

Two platforms. Three enrollment paths.

Windows, macOS and ChromeOS are on the roadmap — we'd rather tell you that now than in month three of a rollout.

Android · GMS

Android Management API

Fully managed, work profile and dedicated (kiosk) modes. Apps distributed through Managed Google Play, zero-touch or QR enrollment.

Device ownerWork profileKiosk
Our differentiator
Android · non-GMS

Our own device-owner app

The budget tablets and rugged handhelds that ship without Google services — managed by our DPC agent, with the same policy model. Most MDM vendors simply can't touch these.

AOSP tabletsRugged handheldsSide-loaded APKs
iOS · iPadOS

Apple MDM protocol

Signed configuration profiles over APNs. Supervised via Apple Business Manager for Single App Mode, Lost Mode, locate and full restriction control.

ADE / ABMSingle App ModeLost Mode
One policy model

Write it once. We speak both dialects.

You configure a normalized policy. Aegis translates it into an Android Management API policy and an Apple configuration profile, then reconciles what each device actually reports back.

POLICY · FIELD-STAFF-BASELINE
CameraBlocked
ScreenshotsBlocked
Passcode6+ / alphanumeric
App accessAllowlist · 7 apps
KioskSingle app
Wi-FiNW-CORP · WPA2
Android output
{
  "cameraDisabled": true,
  "screenCaptureDisabled": true,
  "passwordPolicies": [{
    "passwordQuality": "ALPHANUMERIC",
    "passwordMinimumLength": 6 }],
  "kioskCustomLauncherEnabled": true,
  "applications": [ … 7 allowed ]
}
iOS output
com.apple.applicationaccess
  allowCamera         = false
  allowScreenShot     = false
com.apple.mobiledevice.passwordpolicy
  minLength           = 6
  requireAlphanumeric = true
com.apple.app.lock  (supervised)
com.apple.wifi.managed

Supervision matters: on iOS most block-and-force controls require an ABM-supervised device. The console tells you which of your devices qualify before you push.

Capabilities

Everything below is shipping today.

Kiosk & lockdown

Single-app or multi-app kiosk on Android and supervised iOS. Lock the device to the job, not the whole OS.

App allow / block lists

Push from Managed Play or upload your own APK. Approve, force-install, or silently remove.

Hardware controls

Camera, microphone, screenshots, USB, Bluetooth, tethering, factory reset — on or off per group.

Time-bound access

Grant an app or a policy exception that expires by itself. No sticky “temporary” unlocks.

Dynamic groups & bulk actions

Group by site, model or role, then lock, reboot or repush policy to the whole group at once.

Compliance auto-remediation

Define the rule once — a drifted device gets flagged and corrected without a ticket.

Lock, wipe, locate, Lost Mode

Remote commands with a full command history — who ran what, when, and whether the device acked.

Enrollment that scales

QR and token enrollment, 1:1 or shared-device assignment, ADE for Apple hardware.

Inventory & audit log

Hardware, OS, storage, battery, last-seen and every admin action, retained per tenant.

Fleet visibility

Know what every device is doing — or when it stopped.

Search 1,200 devices by serial, IMEI or UDID. Filter by platform, enrollment state, compliance and management mode. Select rows and act in bulk.

Per-device hardware, software, policy and command history
Effective-policy view: group policy, overrides and expiry in one place
Last-seen tracking that surfaces the device nobody has touched in 30 days

Where teams put it to work

Logistics & field

Shared rugged handhelds locked to the scanning app.

Retail & POS

Store tablets in kiosk mode, updated after hours.

Schools & EdTech

1:1 tablets, exam lockdown, time-bound app access.

Healthcare

Shift-shared iPads with enforced passcode and wipe.

Security & architecture

Built multi-tenant, encrypted, and auditable.

Every tenant is isolated at the data layer. Credentials — Google service accounts, APNs push certificates, VPP tokens — are encrypted at rest with rotatable keys.

Tenant isolation

One console, many organizations — sell to a group, not one site.

Encrypted secrets

Envelope encryption with documented key rotation.

Role-based access

Owner, admin and member scopes; 2FA and passkeys.

Full audit trail

Every push, command and login recorded per tenant.

An honest roadmap

— because month three is a bad time to find out
Shipping today
  • Android GMS + non-GMS + iOS
  • Kiosk & exam lockdown
  • App allow / block lists
  • Hardware restriction controls
  • Time-bound app access
  • Temporary policy unlocks
  • Dynamic groups, bulk actions
  • Lock / wipe / locate / Lost Mode
  • Compliance auto-remediation
  • Audit log & command history
  • Multi-tenant + encryption
  • QR, token & ADE enrollment
Next on the roadmap
  • Recurring schedules (9am–3pm)
  • Per-app usage analytics
  • Web / URL content filtering
  • Email & push alerting
  • CSV & report exports
  • VPN and per-app VPN
  • Aegis AI fleet queries
  • AI policy drafting
  • Windows & macOS
  • Onboarding wizard

See it against your own fleet.

Bring two devices — one Android, one iPhone or iPad. In 30 minutes we'll enroll them live, push a policy and lock one into kiosk mode while you watch.

30 minutesNo self-signupPilot fleet within a week
Book a demo
Devices to manage

We reply within one business day. No newsletter, no drip sequence.