# Hardening the Endpoint: Implementing OS-Native Data Containerization

In a global enterprise environment, the challenge is to secure corporate intelligence without infringing on user privacy. Hexnode addresses this by utilizing **OS-native containerization** to create a secure, encrypted “fence” around sensitive data.

By automating document distribution through **Mobile Content Management (MCM)** and enforcing strict **Data Loss Prevention (DLP)** rules, Hexnode ensures that corporate files are accessible only within managed environments—effectively preventing data leaks across the entire fleet.

Logical Architecture: The Secure Data Plane
-------------------------------------------

Hexnode’s content security model functions as a virtual fenced environment, isolating corporate data from personal user space.

- **The Repository Layer**: The [Hexnode Content Repository](https://www.hexnode.com/mobile-device-management/help/how-to-set-up-file-repository-for-content-management/) acts as the central **Source of Truth**. Files are encrypted at rest and associated with dynamic **Policies** or **Device/User Groups**.
- **The Delivery Path**: Content delivery is coordinated using **Platform Notification Services** (APNs, FCM, WNS), with secure downloads over HTTPS optimized for global availability.
- **The Sandbox Layer**: 
    - **Apple**: Enforces **Managed Open-In** to prevent document movement to unmanaged apps.
    - **Android**: Utilizes [Android Enterprise (Work Profile)](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-in-android-in-the-enterprise-as-profile-owner-using-hexnode-mdm/) to house corporate data in an encrypted, briefcase-badged work container.
- **The DLP Enforcement Layer**: Uses OS-level restrictions to intercept the clipboard, block screen capture, and disable unauthorized sharing (AirDrop, Bluetooth).

The Secure Content Container
----------------------------

Hexnode utilizes platform-native containerization to silo corporate data without infringing on personal privacy.

**Apple Managed Open-In (iOS/macOS)**

Hexnode governs data flow between applications:

- **Intra-App Isolation**: Work documents can only be opened by “Managed” apps.
- **Unmanaged App Blocking**: Prevents users from moving work attachments to personal social media or unmanaged cloud storage (e.g., personal iCloud/Dropbox).

**Android Enterprise Work Profile**

- **Encrypted Container**: Corporate files reside inside a secure, encrypted work profile.
- **App Separation**: Personal apps cannot “see” or access files within the Work Profile partition.

**Managed Content Access**

Hexnode enforces secure access to distributed content through managed apps and policy controls:

- **Restricted Actions**: Limits actions such as copy/paste, sharing, and file export where supported.
- **Content Removal**: Corporate files are removed when a device is disenrolled or a **Selective Wipe** is triggered due to non-compliance.

Managed Content Distribution at Scale
-------------------------------------

Hexnode supports automated content lifecycles for large-scale deployments.

- **Policy-Driven Sync**: Documents are distributed automatically based on [User Groups](https://www.hexnode.com/mobile-device-management/help/user-groups/) or [Dynamic Device Groups](https://www.hexnode.com/mobile-device-management/help/dynamic-device-groups/).
- **Version Control**: When a document is updated, devices receive the latest approved version and outdated copies are replaced or removed.
- **Selective Wipe**: Admins can remove only corporate content while preserving personal apps and data—critical for **BYOD** environments.

Data Loss Prevention (DLP) Matrix
---------------------------------

ConstraintPolicy ControlImplementation OutcomeClipboard ControlCopy/Paste restrictionsPrevents data movement between work and personal apps.Screen CaptureScreenshot and recording restrictions Disables screenshots and screen recordings in managed apps.Managed DomainsWeb and domain restrictionsForces work documents to stay within corporate-approved URLs.Sharing RestrictionsManaged Open-In / Work Profile controlsDisables AirPlay, AirDrop, and Bluetooth sharing for work files.Content Governance Metrics
--------------------------

CapabilityStandard MDMHexnode UEMFile DeliveryManual/App-basedPolicy-driven auto-sync Containerization Third-party wrapper **OS-native** (High Performance) Wipe Control Full device wipe **Selective content wipe** Compliance Manual enforcement Policy-based enforcement Implementation Checklist 
-------------------------

1. Upload corporate files to the **Hexnode Content Repositor**y.
2. Configure **Managed Open-In** rules for iOS/macOS devices.
3. Enroll Android devices in **Work Profile mode**.
4. Apply DLP policies for clipboard, sharing, and screen capture restrictions via [Device Restrictions](https://www.hexnode.com/mobile-device-management/help/how-to-configure-restrictions-on-devices-enrolled-in-android-enterprise-using-hexnode-mdm/).
5. Assign content using **Dynamic Device Groups** or **User Groups** for automated distribution.