Enterprise-grade controls without sacrificing zero-knowledge privacy guarantees.
The relay never sees plaintext. End-to-end encryption is enforced at the device level using Kyber-1024 + AES-256.
Push enterprise relay URLs, enforce Shoulder Shield, and block screenshots via Intune, Jamf, or any EMM that supports AppConfig.
Encrypted ciphertexts are blindly forwarded to your private AWS S3 vault with KMS encryption and 7-year WORM Object Lock.
RSA blind signatures let your Identity Server prove employee identity to the relay without the relay ever touching credentials.
Mandatory screenshot blocking, clipboard restrictions, and permanent Shoulder Shield โ enforced by your MDM policy.
Deploy the relay on your own Swiss or on-premises VPS. Your data never transits Cordon infrastructure.
From public App Store + deep-link activation to fully air-gapped binary delivery.
Requires an active enterprise contract. Contact sales@cordon-hq.com to get started.
ANDROID (APK)
Cryptographically SHA-256 signed. Compatible with Android 10+. Supports direct install (allow unknown sources) or push via your MDM/EMM.
IOS (APPLE BUSINESS MANAGER)
Distributed as an unlisted Apple Custom App via Managed App Configuration. Your ABM admin redeems the link and pushes it to managed devices.