European-built device management for defence and government. Run it on your own hardware, air-gapped, or dark behind our Firefly Core network. No foreign cloud in the control plane, no public attack surface, no vendor kill switch.
Most MDM platforms are run from US clouds and subject to US law. A data processing agreement does not change that: under the CLOUD Act and FISA 702 a foreign authority can compel access, and a foreign vendor can switch off your fleet. DELTΔ MDM removes that dependency. It is designed, built, and operated in the Netherlands by AKASEC, and the control plane runs where you decide: in your own data centre, in an air-gapped enclave, or in our Dutch facility.
The result is strategic autonomy over the devices your people carry into the field. Ministries, police forces, defence organisations, and the defence industrial base use DELTΔ MDM to enrol, harden, monitor, and wipe Android fleets without handing keys, telemetry, or metadata to a third country.
AKASEC is a Dutch offensive security firm specialised in advanced red teaming and secure software development, working for government and the defence industry. We build DELTΔ MDM the way we attack networks: assume breach, minimise exposure, trust nothing by default.
Built for operators, not administrators. Fleet posture, compliance drift, and device location in one view, so a small team can run thousands of devices. Push a hardened policy baseline, deploy a signed APK, or wipe a lost handset in seconds, with every action written to a tamper-evident audit trail.
Device management that assumes the network is hostile and the adversary is capable.
Every device, operator, and request is authenticated and authorised. No implicit trust, no flat network, no standing admin access.
Private app distribution with signature pinning. Only APKs you approved reach the fleet, with no public app store in the supply chain.
Lock, locate, or cryptographically wipe a compromised or lost device the moment it checks in.
Policy baselines and audit logging that map to NIS2, BIO2, GDPR, and ABDO requirements for the defence industry.
Root, tamper, and policy-drift detection with alerts you can forward to your own SOC or SIEM.
Designed for rapid decisions under pressure. New operators are productive within an hour.
Three deployment models. Same platform, same feature set. You choose where the control plane lives and who can reach it.
01 / On-prem
Install DELTΔ MDM on your own hardware or private cloud. Runs fully air-gapped for classified networks. No licence server, no phone-home, no outbound dependency.
For: ministries, defence, classified enclaves
02 / Sovereign hosted
We run it for you in the Netherlands, on EU-owned infrastructure, operated by screened Dutch staff. Operational within hours, with no foreign parent company in the chain.
For: agencies and suppliers that want speed without giving up jurisdiction
03 / Dark
Either model above, with the MDM removed from the internet entirely. It only answers inside the Firefly Core network. Devices connect from anywhere in the world; attackers have nothing to scan.
For: deployed personnel, travelling staff, high-threat profiles
Firefly Core network
Your people are deployed, travelling, or stationed abroad. Your MDM should not be exposed to the internet to reach them.
Firefly Core is AKASEC's private VPN backbone. Devices connect to the nearest edge point, wherever they are. From there, traffic is carried over multiple encrypted hops into the EU and, if you require it, into the Netherlands, where DELTΔ MDM is reachable only from inside the network.
Anywhere
Device
Always-on tunnel, enforced by policy
Nearest edge
Global ingress
Anycast entry point close to the user, on every continent
Multi-hop
EU core
Layered encryption across Firefly Core nodes inside the EU
Optional: NL
DELTΔ MDM
No public IP. Reachable only through Firefly Core
The management plane has no internet-facing endpoint. Nothing to scan, fingerprint, or exploit, including the next zero-day in a web stack.
The tunnel is provisioned at enrolment and enforced by policy. No configuration, no choosing servers, low latency from anywhere.
Terminate in the EU, or pin the exit to the Netherlands. Management traffic never exits in a third country.
Multi-hop routing separates where a device is from where it is managed. Observers at the edge see an encrypted tunnel, not your organisation.
Sovereignty, deployment, and security, answered.
Talk to an engineer, not a sales team. We will walk you through deployment options and a live demo.