Soldiers checking a mobile device during a field exercise
defence-grade EMM

Mobile device management and hardening for units that cannot afford to fail

Blindium deploys and operates Samsung SDS EMM, the NIAP-certified mobility management platform with a DISA STIG, for the Armed Forces, police forces, intelligence services and critical entities. Samsung SDS EMM On-Prem within your isolated network: the console and the data never leave your organisation.

On-premConsole and data on your infrastructure
Air-gapManagement without an Internet connection
NIAP CCMDM-PP v4.0, first in the sector
KnoxKME, DualDAR, E-FOTA, Tactical Edition

We sell an EMM. And we deploy it the way defence demands.

Our product is an Enterprise Mobility Management platform: inventory, policies, applications, compliance and the lifecycle of every device from a console under your control. What changes is the level of demand: closed networks, hardened hardware, two-layer encryption and evidence that withstands an audit.

Learn about the platform
Three layers, one platform

The EMM is the core. VPN and encryption complete the hardening.

The entire operation revolves around device management. Secure communications and encryption are configured, distributed and audited from the same console.

Main pillar70%

Device management and hardening

Samsung SDS EMM: a single console for Samsung, Android Enterprise and iOS/iPadOS. Policies, applications, compliance, remote support and the complete lifecycle. On-prem with air-gap or in a private cloud under your control.

  • Isolated networks with SDS Private Push
  • Knox Mobile Enrollment and NFC provisioning
  • Kiosk mode, shared device and remote support
  • Remote wipe and lock, controlled geolocation
Pillar 215%

VPN and secure communications

Always-on and per-app VPN managed from the EMM, Knox VPN framework, IPsec/IKEv2 and TLS, and dual-tunnel architectures for classified networks.

  • Access to internal resources without exposing them
  • Segmentation by application and profile
Pillar 315%

Data and device encryption

Encryption at rest with Knox DualDAR (two layers), encryption in transit, key and certificate management and validated cryptographic modules.

  • FIPS 140-2/140-3 cryptographic modules (as stated by the manufacturer)
  • Galaxy devices qualified in CPSTIC by model and current catalogue
  • Secure wipe and lifecycle
Silhouetted personnel during a night operation
Continuous operation

No coverage, and control still stays inside your network

Devices operate on the last policy received and synchronise when the link returns. No external service decides when a unit can work.

See the defence proposal

Priority sector

Designed for the Armed Forces and deployed units

Tactical mobility with local control: the EMM server is installed on the network of the unit or agency and continues to manage the devices with no Internet access. Samsung Galaxy Tactical Edition devices, DualDAR dual encryption and mission-based policies.

  • Isolated network or intermittent connectivity
  • Profiles by unit, mission and classification level
  • Remote wipe and emergency mode
  • Integration with radio, PTT and third-party secure messaging

View the proposal for defence

Command post with an operator monitoring the situation on screen
Deployment model

On-prem or hybrid: control stays within the organisation

The proposal is based on Samsung SDS EMM (On-Prem) and SDS Private Push: console, data and notifications on the organisation's own infrastructure or in a private or government cloud under its control. Blindium does not propose public-cloud EMM for these environments. The architecture and licences are selected according to the client's requirements and the manufacturer's current documentation.

On-prem

Own infrastructure and isolated network

EMM server, database and policy services in the organisation's data centre or in a classified enclave, with no Internet access. SDS Private Push replaces public push services and firmware is distributed from inside. This is the reference model for defence, police and intelligence.

Hybrid

Private or government cloud

Console and data on your own infrastructure, with the Knox support services consumed from the cloud through a controlled gateway: firmware distribution with Knox E-FOTA and Knox Asset Intelligence. Clear segmentation of what leaves the organisation and what does not.

The initial assessment determines the model. In defence, police and intelligence the usual pattern is an isolated network for operational units and, where appropriate, hybrid mode for the rest of the organisation: different configurations, a single console and the data always inside.

Verifiable security

Credentials that can be presented to a security committee

Each credential links to its official source on the credentials page. References that appear only in the manufacturer's documentation are marked as such.

NIAP Common Criteria
MDM-PP v4.0
NIAP certification under the MDM Protection Profile v4.0 (February 2020) of the product "Samsung SDS EMM and EMM Agent for Android", version 2.2.5. First EMM solution to obtain it.
DISA
Samsung SDS EMM STIG
DISA Security Technical Implementation Guide for Samsung SDS EMM, version V1R3 (June 2022), applicable to the product version stated in the guide itself.
Android Enterprise
Gold Partner
Recognition by Google of a small group of EMM providers (May 2025).
NSA
CSfC programme
The manufacturer states that it was the first EMM provider in the Commercial Solutions for Classified programme (2015).
Cryptography
FIPS 140-2
FIPS 140-2 validated cryptographic module, as stated by the manufacturer. The applicable CMVP certificate and module version are identified in each project.
Spain
ENS and CCN-STIC
Architecture and policies aligned with the Esquema Nacional de Seguridad (ENS) and the CCN-STIC guides for mobile devices.
Alignment, not certification.
Isolated network
Air-gap with Private Push
Device management without an Internet connection through a private notification server.
Samsung Knox
Native integration
Knox Mobile Enrollment, DualDAR, E-FOTA and Galaxy Tactical Edition.

* Reference stated by the manufacturer in its public documentation; it does not replace the documentary evidence provided in each project. All certifications and validations cited refer to specific products, versions and modules, which are identified in each proposal.

View credentials and sources

Sectors

Where local control is non-negotiable

Defence and police are the priority sectors. The same platform, with different reference architectures depending on each organisation's risk.

View all sectors

Cover frame of the Samsung SDS EMM video
The platform on video

Samsung SDS EMM in three minutes, told by the manufacturer

Official Samsung SDS video on its on-premise EMM solution for the highest level of security: architecture, Knox and operation on closed networks.

Video · YouTube · Samsung SDS Global

Watch the video on YouTube

Opens on YouTube in a new tab. This website loads no third-party content and embeds no players.

Reference use cases
Scenarios

Reference use cases

Military communications with dual encryption, disconnected platforms, integration with PTT and secure messaging, forces in the field and multi-tenant operation.

View use cases

Decision matrix

When is Blindium the right fit?

Five needs commonly raised by security committees and procurement boards, and how well the solution fits each.

NeedWhy it mattersFit
Remain on-prem SaaS cannot be relied upon for reasons of security, sovereignty or closed networks. High
Samsung + Android + iOS fleet Samsung and Knox carry strategic weight, but the fleet is mixed. Very high
Sensitive data Security evidence is required, not promises. Very high
Users in the field Security without slowing down operations: patrols, units, technicians. High
Justifying the project The security committee, procurement or management need a clear rationale. Very high
Estimated fit based on secure mobility projects in defence, security and critical entities. Confirmed during the assessment.
Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, private cloud or hybrid)

The assessment is a preliminary guidance session and does not constitute an audit, certification, accreditation, expert report or guarantee of compliance. Its conclusions depend on the information provided and must be technically validated within the scope of each project.