Skip to content
CShark MDM
Menu

Security and privacy

Built for IT teams that answer to security reviews

CShark MDM keeps device data on your servers, treats every credential as a secret, and gives device users a clear view of what is managed.

Self-hosted by design

  • The CShark MDM server and its database run in your own infrastructure.
  • Devices connect only to your server over HTTPS. There is no third-party relay for device data.
  • Each organization’s devices, policies and users are kept separate.

Credentials handled carefully

  • Each device gets its own token; the server keeps only a hash of it.
  • Passcode resets and new account passwords are encrypted at rest, shown once to the admin, delivered once to the device and then erased.
  • Windows kiosk passwords are generated on the PC and never sent to the server.
  • Credentials never appear in command history, events, logs or exports.

Least privilege in the console

  • Admins manage policies, enrollment, local accounts and wipes.
  • Operators manage devices and send everyday commands.
  • Viewers can look but not change anything, and don’t see device location.

Remote support with consent

  • A policy decides whether the user approves each session, sessions run unattended, or remote access is off.
  • The device shows when a session is active.
  • Sessions are recorded on the device’s timeline.

Location with limits

  • Location history is deleted after 30 days by default; you can shorten or lengthen it.
  • Only operators and admins can see location, and it never appears in exports, events or the device list.
  • Retiring a device deletes its location history.
  • The agent tells the device’s user that their location is shared.

An audit trail for every device

  • Policy changes, commands, remote sessions and enrollment are logged with who did what and when.
  • Command results are reduced to safe, typed fields; raw device output is not kept.
  • Exports escape spreadsheet formulas, so a hostile device name can’t run code in Excel.

Questions from your security team?

Email hello@csharkmdm.com and we’ll walk through the architecture with them.