Features
Apostrophy curates a menu of enterprise options for business solutions, allowing flexibility to choose what works best for your organisation.
Apostrophy technical capabilities
Tech feature | Standard/Custom/Extraordinary | Device requirement | On-customer premises | Secure-hosted premises* | Third-party premises |
---|---|---|---|---|---|
Boot Integrity
Ensuring the integrity of the platform by demonstrating that the boot process starts from a trusted combination of hardware and software, and continues until the operating system has fully booted and applications are running.
Show more
|
S | Mandatory | NA | NA | NA |
Preloads
Giving the flexibility to pre-load specific Apps based upon project scope requirements.
Show more
|
SC | Optional* | Restricted | Mandatory | Restricted |
MDM
Allowing an Apostrophy MDM baked into the OS, allowing custom made secure features far beyond that of other commercially available MDM solutions in the market.
Show more
|
CE | Mandatory | Restricted | Mandatory | Restricted |
OTA (device)
OTA is available as a standard feature, and can be customised to local cloud or on-premises subject to project scope requirements.
Show more
|
SC | Mandatory | Allowed | Allowed | Restricted |
IMEI Ranging
Random IMEI makes it more difficult for hackers to predict the IMEI number due to auto-increment.
Show more
|
SC | Mandatory | Allowed | Restricted | Restricted |
Carrier Config
Ensuring the device is working seamlessly on local carriers networks.
Show more
|
CE | Mandatory | Allowed | Allowed | Allowed |
G-Lock Disabled (2G|3G|4G|5G)
Highly effective control mechanism to disable any of the GSM networks if required.
Show more
|
CE | Optional* | NA | NA | NA |
Mandatory App Permissions
Custom APK preload capabilities, allowing mandatory permissions for business-critical apps, and MDM enables the restricting of altering App Permissions.
Show more
|
CE | Mandatory | NA | NA | NA |
Privileged App Permissions
Allows system level permissions to be granted, in turn making sure only trusted applications are able to perform certain actions on the device.
Show more
|
CE | Mandatory | NA | NA | NA |
VPN
AphyOS comes with a built-in VPN framework; work required if not WireGuard -- also available for in-house/on-prem, typically most important as a Context-Based Access Control (VPN as a barrier to internal resources)
Show more
|
S | Mandatory | Allowed | Allowed | Allowed |
Location Service(s)
Apostrophy OS does not use Google Mobile Services, with no Google location services included on device. Installation of sandboxed Google Play is optional; if so, regular Apps are sandboxed, and therefore do not have access to location data or other standard permission by default, with nothing to turn off unless permissions explicitly granted as required by project scope.
Enabling location services in the OS only allows apps with granted permission to obtain location data. The OS location service is based on broadcasts from GNSS satellites and ground stations, and is a receive-only radio using downloaded static databases to expedite location detection (PSDS), also with the more dynamic SUPL to fetch databases tied to carriers. Both of these are provided through Apostrophy OS servers by default and PSDS databases are hosted directly on our servers.
Show more
|
CE | Mandatory | Allowed | Allowed | Allowed |
Email, Calendar, Contacts, etc.
Apostrophy Services can be customised to be Apostrophy on-cloud, local cloud or on-prem, based on customer requirement including Kolab Groupware and Cloud Storage.
Show more
|
S | Mandatory | Allowed | Allowed | Allowed |
Hardware PTT
An available Push-To-Talk feature.
Show more
|
SC | Optional* | NA | NA | NA |
Prohibit Screenshots
Capability to disable Screenshot on device.
Show more
|
SC | Mandatory | NA | NA | NA |
Prevent Developer Options
Capability to ensure the disabling of Developer Options in order to prohibit modifications on device.
Show more
|
SC | Mandatory | NA | NA | NA |
Engineering Mode Enabled
Engineering Mode is disabled by default, however can be enabled if a requirement within project scope mandates such.
Show more
|
SC | Mandatory | NA | NA | NA |
Custom Boot Animation / Startup Sound
Customisable boot animation and startup soundtrack available.
Show more
|
SC | Mandatory | NA | NA | NA |
Custom Sound Package
Customisable device sound package available.
Show more
|
SC | Optional* | NA | NA | NA |
Custom Iconography
Customisable device iconography available.
Show more
|
SC | Mandatory | NA | NA | NA |
GMS Wizard Removed
GMS Wizard is able to be removed from device if required.
Show more
|
SC | Optional* | NA | NA | NA |
Domus Lock to Enterprise | SC | Mandatory | Allowed | Allowed | Allowed |
Bluetooth Disabled (Verified OFF)
Capability to disable Bluetooth as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part).
Show more
|
CE | Optional* | NA | NA | NA |
Device Microphone Disabled (Verified OFF)
Capability to disable Microphone as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |
WIFI Disabled (Verified OFF)
Capability to disable WIFI as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |
WAN Disabled (Verified OFF)
Capability to disable WAN as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |
Tech feature | Standard/Custom/Extraordinary | Device requirement | On-customer premises | Secure-hosted premises* | Third-party premises |
---|---|---|---|---|---|
Threema
The messenger with rigorous data protection and rock-solid security. The Threema app comes pre-installed. Threema’s business apps Threema Work (SaaS) and Threema OnPrem (on-premises) can also be installed.
Find out more Show more
|
CE | Optional | Allowed | Restricted | NA |
Boot Integrity
Ensuring the integrity of the platform by demonstrating that the boot process starts from a trusted combination of hardware and software, and continues until the operating system has fully booted and applications are running.
Show more
|
S | Mandatory | NA | NA | NA |
Preloads
Giving the flexibility to pre-load specific Apps based upon project scope requirements.
Show more
|
SC | Optional* | Restricted | Mandatory | Restricted |
MDM
Allowing an Apostrophy MDM baked into the OS, allowing custom made secure features far beyond that of other commercially available MDM solutions in the market.
Show more
|
CE | Mandatory | Restricted | Mandatory | Restricted |
OTA (device)
OTA is available as a standard feature, and can be customised to local cloud or on-premises subject to project scope requirements.
Show more
|
SC | Mandatory | Allowed | Allowed | Restricted |
IMEI Ranging
Random IMEI makes it more difficult for hackers to predict the IMEI number due to auto-increment.
Show more
|
SC | Mandatory | Allowed | Restricted | Restricted |
Carrier Config
Ensuring the device is working seamlessly on local carriers networks.
Show more
|
CE | Mandatory | Allowed | Allowed | Allowed |
G-Lock Disabled (2G|3G|4G|5G)
Highly effective control mechanism to disable any of the GSM networks if required.
Show more
|
CE | Optional* | NA | NA | NA |
Mandatory App Permissions
Custom APK preload capabilities, allowing mandatory permissions for business-critical apps, and MDM enables the restricting of altering App Permissions.
Show more
|
CE | Mandatory | NA | NA | NA |
Privileged App Permissions
Allows system level permissions to be granted, in turn making sure only trusted applications are able to perform certain actions on the device.
Show more
|
CE | Mandatory | NA | NA | NA |
VPN
AphyOS comes with a built-in VPN framework; work required if not WireGuard -- also available for in-house/on-prem, typically most important as a Context-Based Access Control (VPN as a barrier to internal resources)
Show more
|
S | Mandatory | Allowed | Allowed | Allowed |
Location Service(s)
Apostrophy OS does not use Google Mobile Services, with no Google location services included on device. Installation of sandboxed Google Play is optional; if so, regular Apps are sandboxed, and therefore do not have access to location data or other standard permission by default, with nothing to turn off unless permissions explicitly granted as required by project scope.
Enabling location services in the OS only allows apps with granted permission to obtain location data. The OS location service is based on broadcasts from GNSS satellites and ground stations, and is a receive-only radio using downloaded static databases to expedite location detection (PSDS), also with the more dynamic SUPL to fetch databases tied to carriers. Both of these are provided through Apostrophy OS servers by default and PSDS databases are hosted directly on our servers.
Show more
|
CE | Mandatory | Allowed | Allowed | Allowed |
Email, Calendar, Contacts, etc.
Apostrophy Services can be customised to be Apostrophy on-cloud, local cloud or on-prem, based on customer requirement including Kolab Groupware and Cloud Storage.
Show more
|
S | Mandatory | Allowed | Allowed | Allowed |
Hardware PTT
An available Push-To-Talk feature.
Show more
|
SC | Optional* | NA | NA | NA |
Prohibit Screenshots
Capability to disable Screenshot on device.
Show more
|
SC | Mandatory | NA | NA | NA |
Prevent Developer Options
Capability to ensure the disabling of Developer Options in order to prohibit modifications on device.
Show more
|
SC | Mandatory | NA | NA | NA |
Engineering Mode Enabled
Engineering Mode is disabled by default, however can be enabled if a requirement within project scope mandates such.
Show more
|
SC | Mandatory | NA | NA | NA |
Custom Boot Animation / Startup Sound
Customisable boot animation and startup soundtrack available.
Show more
|
SC | Mandatory | NA | NA | NA |
Custom Sound Package
Customisable device sound package available.
Show more
|
SC | Optional* | NA | NA | NA |
Custom Iconography
Customisable device iconography available.
Show more
|
SC | Mandatory | NA | NA | NA |
GMS Wizard Removed
GMS Wizard is able to be removed from device if required.
Show more
|
SC | Optional* | NA | NA | NA |
Domus Lock to Enterprise | SC | Mandatory | Allowed | Allowed | Allowed |
Bluetooth Disabled (Verified OFF)
Capability to disable Bluetooth as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part).
Show more
|
CE | Optional* | NA | NA | NA |
Device Microphone Disabled (Verified OFF)
Capability to disable Microphone as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |
WIFI Disabled (Verified OFF)
Capability to disable WIFI as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |
WAN Disabled (Verified OFF)
Capability to disable WAN as close to hardware as possible, by removing the stack from the "vendor" part (as well as the "system" part)
Show more
|
CE | Optional* | NA | NA | NA |