Layered encryption, with keys under the organisation's control
Encryption protects what policy cannot prevent: a lost device, an intercepted network, a retired disk. Blindium configures encryption at rest and in transit from the EMM, with validated cryptographic modules and key and certificate management integrated with the agency's PKI.

Device encryption and Knox DualDAR
Every managed device applies file-based disk encryption, with hardware-protected keys bound to the user's credential. The EMM makes it mandatory and checks its status in every compliance cycle.
Knox DualDAR adds a second, independent layer over the work container: separate keys, its own lock policy and a cryptographic module that can be Samsung's or an approved third-party module. The inner layer remains encrypted while the container is locked, even when the device is in use. This is the mechanism Samsung documents for military communications scenarios with dual encryption.
Keys, certificates and validated modules
Encryption in transit
IPsec/IKEv2 VPN or TLS with approved cipher suites and mutual TLS between the device and the EMM server. No cleartext channels.
Key and certificate management
Issuance, renewal and revocation of device and user certificates from the corporate PKI through the EMM. Hardware-backed key store.
Validated cryptographic modules
The manufacturer states that its cryptographic module is FIPS 140-2 validated; on Galaxy devices, Samsung maintains FIPS 140-2 and 140-3 validated modules. The applicable CMVP certificate is verified in each project.
CPSTIC, ENS and qualified products
The CPSTIC catalogue (Catálogo de Productos y Servicios de Seguridad TIC) of the Spanish National Cryptologic Centre (CCN) lists the products qualified and approved for use in public administration and in systems handling classified information. Whether a product is listed in the catalogue, and in which category, is an objective purchasing criterion.
The Esquema Nacional de Seguridad (ENS) requires, in the High category, encryption of information on portable devices and in communications, using accredited algorithms and products. The CCN-STIC guides for mobile devices set out specific configurations.
In each proposal Blindium indicates which component is qualified in CPSTIC, which holds Common Criteria or FIPS certification and which is presented as aligned without certification. No qualification is claimed that does not appear in the catalogue.
- CPSTIC The CCN catalogue. The category and the qualified version of the product are checked.
- ENS High-category controls op.exp, mp.eq and mp.com as the configuration reference.
- CCN-STIC Secure configuration guides for mobile devices and fleet management.
Secure wipe and device lifecycle
Onboarding
Mandatory encryption enabled before any data is loaded. Certificates issued by the PKI. Verification of the cryptographic module and firmware version.
Operation
Automatic certificate renewal, compliance checks and rotation of container keys according to policy.
Loss or compromise
Immediate cryptographic erasure (key destruction), certificate revocation and lock. The command and its confirmation are logged.
Retirement
Verified secure wipe, removal from Knox and from the inventory, retirement certificate for the file.
Free MDM/EMM continuity assessment (45 minutes)
A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.
- Current architecture and number of devices
- Data criticality and network or cloud constraints
- Integration with Samsung Knox and mixed fleets
- Transition options and deployment model (on-prem, hybrid or cloud)


