Security

Controls you can defend in an audit.

Escrow, tamper protect, trust, dual control, evidence — residual risk written up front.

BitLocker escrow

Recovery passwords to the control plane. Full reveal requires hostname type-to-confirm and is audited. Drive inventory shows encryption state per volume.

Infrastructure encryption

Uninstall / tamper key

CrowdStrike-style allow-uninstall token. Live Actions issue key; MSI / --allow-uninstall validates hashed token. Tamper emails admins. Safe Mode residual risk documented.

Verify integrity
Trust
Trust

Device TrustScore

Posture, encryption, agent health, Lost Mode factors.

Dual control
Access

Dual control

Two reviewers for risky grants / Lost Mode.

Alerts
Alerts

Admin email

Lost Mode, tamper, encryption drop.

Evidence
Evidence

Audit trail

MDM events + Verify actions.

What we will not claim

Enterprise buyers deserve residual risk in plain language.

Security review pack

Ask SecureGen for the IBES architecture brief for Ireland-region deployment.

Request pack