Vianordis
--:--:-- UTCVianordis / ED. 02 / 2026
§ 07 — App support

Enklave

Unified endpoint management for every device you need to trust.

Enklave gives IT and security teams a tenant-isolated UEM/MDM control plane for enrollment, inventory, policies, app and patch rollouts, telemetry, incident response, audit approvals, and on-device AI model distribution across iOS, iPadOS, macOS, Android, Windows, and Linux.

01Problem

Endpoint control breaks down when every platform is governed somewhere else.

Modern organizations need to manage corporate, shared, BYOD, kiosk, and specialized devices across multiple operating systems. Without one governed control plane, teams lose visibility, patching becomes inconsistent, exceptions live in tickets, and incident response depends on manual coordination.

  • Separate tools for Apple, Android, Windows, Linux, inventory, patching, and incident response
  • No consistent device posture model across ownership types and lifecycle stages
  • Policy drift that is discovered late or only during audits
  • Risky app and patch rollouts without rings, maintenance windows, or rollback evidence
  • Manual device isolation, wipe, certificate revocation, and user notification workflows
  • Limited governance for on-device AI models and edge runtime capabilities
02Solution

Enklave turns device management into a governed security control plane.

Enklave combines UEM inventory, MDM protocol services, intent-based policy, app deployment, patch management, telemetry, audit approvals, incident playbooks, and an AI model registry into one multi-tenant platform. It is built for teams that need operational control and defensible evidence across heterogeneous endpoint fleets.

  • Manage iOS, iPadOS, macOS, Android, Windows, and Linux devices from a shared backend model.
  • Compile high-level policy intent into platform-specific payloads and track drift against expected state.
  • Stage applications, packages, patches, and remediation actions through controlled rollout rings.
  • Record posture, telemetry, approvals, audit events, and remediation history in tenant-isolated data stores.
03Benefits

Operational outcomes for IT, security, and compliance teams

The value of Enklave is not just device enrollment. It is the ability to prove what is managed, what policy applies, what changed, who approved it, and how the platform responded when risk appeared.

Control every major endpoint family

Use one operating model for Apple, Android, Windows, and Linux fleets instead of splitting governance across disconnected consoles.

Reduce policy drift

Define intent once, compile it per platform, assign it by group and ring, and monitor actual state against expected state.

Deploy apps and patches safely

Coordinate packages, versions, rollout rings, patch definitions, and maintenance windows before changes reach production devices.

Automate incident response

Trigger auditable playbooks for isolation, wipe, lock, certificate revocation, quarantine, script execution, notification, restore, or escalation.

Govern edge AI usage

Track NPU capability, runtime status, model artifacts, model assignments, and deployment status for on-device AI workloads.

Keep tenant data separated

Enforce tenant isolation with PostgreSQL row-level security and tenant context applied before data access.

04How it works

How Enklave works

  1. 01

    Enroll and classify devices

    Register devices with enrollment tokens, certificates, groups, platform metadata, ownership type, lifecycle state, software inventory, and posture signals.

  2. 02

    Define policy, deployments, and response rules

    Create policy intents, compiled versions, group assignments, package rollouts, patch windows, incident playbooks, exceptions, and AI model assignments.

  3. 03

    Monitor, enforce, and prove control

    Ingest telemetry, process posture events, detect drift, launch remediation actions, require approvals where needed, and retain immutable audit evidence.

05Features

Core Enklave capabilities

Device inventory and enrollment

Track enrolled devices, serials, platform details, ownership model, lifecycle state, hardware, software, network interfaces, posture, and last-seen status.

Groups, tokens, and certificates

Organize devices into groups, issue enrollment tokens, and manage certificate records used for trusted device communication.

Intent-based policy engine

Define policy as intent, maintain versions, compile platform-specific payloads, assign them to groups, and track rollout status.

Drift detection and exceptions

Capture expected versus actual device state, classify severity, and handle approved break-glass or temporary exceptions with expiry.

Application deployment

Manage apps, app versions, packages, checksums, package types, platform support, and staged rollouts.

Patch management

Coordinate patch definitions, severity, reboot requirements, maintenance windows, rollout rings, and completion state.

Incident playbooks

Operate incidents with evidence, status, severity, assigned ownership, remediation actions, approvals, and execution results.

Audit and approval workflows

Record actor, action, resource, before/after state, evidence, rollback plans, request IDs, and approval decisions in immutable audit tables.

Telemetry and posture pipeline

Ingest device events and posture history, process them through NATS JetStream, and maintain aggregations for reporting and operational views.

On-device AI model registry

Store model artifacts, assign them to devices or groups, and track deployment status for edge AI runtimes.

06Architecture

Architecture and security model

Enklave is implemented as a Go microservices platform on Kubernetes, with explicit separation between inventory, policy, deployment, patching, incident, audit, model, telemetry, MDM, agent, and frontend-facing service boundaries.

  • Edge routing through Envoy, internal load balancing, and ingress-nginx before traffic reaches Enklave services.
  • API gateway and dedicated Go services for inventory, policy, deployment, patching, incident response, audit, model registry, telemetry ingest, and telemetry processing.
  • MDM protocol services for Apple, Android, and Windows, plus an agent gateway for device-side communication.
  • PostgreSQL high availability with seven domain schemas and row-level security enforced by tenant context.
  • NATS JetStream event bus for posture and telemetry processing across services.
  • Ceph RGW compatible object storage for deployable artifacts such as packages and model files.
  • Keycloak OIDC/JWKS identity, Kubernetes-native deployment, Istio Ambient security controls, Infisical secrets, and internal certificate infrastructure.
07Use cases

Where Enklave fits

Enterprise device fleet management

Operate mixed fleets across employee, shared, privileged, kiosk, dedicated, and BYOD scenarios.

Security posture and compliance

Maintain posture levels, compliance status, risk state, software inventory, CVE references, and audit-ready control evidence.

App and patch rollout governance

Use packages, versions, rings, maintenance windows, status tracking, and rollback evidence for safer change delivery.

Endpoint incident response

Coordinate isolation, wipe, lock, quarantine, notification, certificate revocation, script execution, restore, and escalation from tracked incidents.

Regulated multi-tenant environments

Separate tenant data with row-level security while preserving central operational workflows.

AI-capable endpoint operations

Track NPU capability, runtime health, and model deployment state where edge AI workloads are part of the endpoint strategy.

08Integrations

Integrations and platform connections

Enklave is designed to sit inside an enterprise infrastructure stack, connecting identity, device protocols, event processing, storage, certificates, and Kubernetes operations.

Keycloak OIDC and JWKS

Keeps access tied to organization accounts, roles, and sign-in policy.

PostgreSQL and Patroni high availability

Stores structured service records in a controlled tenant-aware backend.

NATS JetStream

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Ceph RGW S3-compatible artifact storage

Provides the governed place where service data and files are stored.

Kubernetes

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Istio Ambient and AuthorizationPolicy

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Infisical secrets

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Envoy edge routing

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Apple MDM and APNs workflows

Makes actions reviewable before work is executed or escalated.

Android Enterprise management

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Windows MDM, WNS, and SyncML workflows

Makes actions reviewable before work is executed or escalated.

Device agent gateway services

Shows how this service fits into the wider Vianordis environment instead of standing alone.

EJBCA internal certificates

Shows how this service fits into the wider Vianordis environment instead of standing alone.

Let's Encrypt edge TLS

Shows how this service fits into the wider Vianordis environment instead of standing alone.

09Trust

Controls built for enterprise assurance

Enklave’s trust model focuses on tenant isolation, auditable operations, controlled exceptions, and evidence-rich endpoint governance.

Tenant isolation

PostgreSQL row-level security using tenant session context

Identity

Keycloak OIDC with JWKS validation

Auditability

Immutable audit events with actor, action, resource, evidence, and rollback plan

Approvals

Tracked approval requests for sensitive operational actions

Exceptions

Break-glass exception records with expiry and justification

Drift evidence

Expected and actual state captured for policy drift records

Partitioning

Monthly partitions for high-volume audit and telemetry data

Secrets

Infisical-backed secret management

Traffic control

Envoy routing plus Kubernetes and Istio policy boundaries

Certificates

Device certificate tracking and internal certificate infrastructure

10 — Pricing

Plan around fleet size, modules, and deployment model

Enklave is scoped by device volume, operating systems, MDM protocol coverage, telemetry volume, selected modules, artifact storage, AI model registry requirements, and the deployment or support model.

11FAQ

Questions technical buyers usually ask.

Who is Enklave for?

Enklave is for IT, security, platform, and compliance teams that need one governed endpoint control plane across multiple operating systems and device ownership models.

Which platforms does Enklave support?

The platform model covers iOS, iPadOS, macOS, Android, Windows, and Linux, with dedicated MDM or agent service boundaries for the major managed-device families.

How are devices enrolled?

Devices are registered through enrollment tokens, grouped by policy target, associated with certificates, and tracked with platform, ownership, lifecycle, posture, and software inventory metadata.

What does intent-based policy mean?

Teams define the desired policy outcome once, then Enklave maintains compiled platform-specific versions, assignments, rollout state, exceptions, and drift records.

Can Enklave manage app and patch rollouts?

Yes. It models applications, app versions, packages, rollout rings, patch definitions, reboot requirements, and maintenance windows so changes can be staged and audited.

How does Enklave support incident response?

Incident records can collect evidence and drive remediation actions such as isolate, wipe, lock, notify user, revoke certificate, quarantine, restore, run script, or escalate.

Does Enklave support on-device AI governance?

Yes. The data model tracks NPU capability and runtime status, while the model registry stores artifacts, assignments, and deployment status for device-side AI workloads.

How is tenant isolation handled?

Core tables use PostgreSQL row-level security, with tenant context set before queries so tenant-specific records remain isolated at the database layer.

Does Enklave include an admin console?

The platform includes a backend-for-frontend service boundary for admin-console use. Current product positioning should be treated as API and control-plane centered unless a specific frontend deployment is included in the project scope.

12 — Next step

Bring endpoint governance into one controlled operating model.

Use Enklave to enroll devices, enforce policy, deploy changes, monitor posture, respond to incidents, and retain evidence across your endpoint fleet.