Phone management for businesses
Your company phones.
Manage all your company phones conveniently in your browser. Your data stays on your own , with no Google at all.
- Runs on your own server
- Phones need no Google
- All features in every plan
- From €199 a month
- GrapheneOS
- Google Pixel
- Samsung
- OnePlus
- Android 15 and later
Tested with Google Pixel, Samsung and OnePlus. Works with all common Android phones running Android 15 or later.
With most providers, your company data sits in someone else's cloud. Not with us.
An is the remote control for your company phones: deploy apps, define settings, lock a lost phone. Most solutions run on the provider's servers and depend on Google. ShadowZ MDM runs on your own server.
ShadowZ MDM
On your server- All device data stays on your server
- The phones need neither Google services nor a Google account
- Commands come straight from your server over a permanent connection, without a detour through Google
- Made for the particularly secure , runs on all common Android phones from Android 15 (tested with Samsung and OnePlus)
- One price for all features, no surcharges for add-on modules
- Every change is recorded in an activity log that cannot be altered afterwards
- Your phones keep running even if our servers are ever unreachable
Typical cloud MDM
- Device data is stored on the provider's servers
- The connection to the phones usually runs through Google
- Phones without Google services only with limitations, such as setup by cable and delayed commands
- Important features cost extra
- Billing per device and month
- If the provider's service is disrupted, your admin portal is unreachable too
Plug in a Pixel phone, click in your browser, and it is fully managed.
is one of the most secure operating systems for phones. For an MDM to fully control a GrapheneOS phone, the management app has to be set up once over a USB cable. Normally that means typing commands on a computer, phone by phone. ShadowZ MDM does this for you, right in the admin portal in your browser.
- 01
Connect
Connect the phone to your computer with a USB-C cable and confirm “Allow ” once on the phone.
- 02
Activate
In the admin portal, choose the configuration, group and runtime, then click “Activate”.
- 03
Done
The phone is fully managed. You can unplug the cable.
What happens automatically:
- The ShadowZ app is installed and receives full for the phone.
- The phone enrolls with your server, with the configuration, group and runtime you selected.
- Your company logo, company name and color are applied to the phone.
- The recommended GrapheneOS security settings are applied and checked, for example extended memory protection for all apps and an automatic restart if the phone has not been unlocked for four hours.
- Finally, USB debugging and the developer options are turned off again.
No GrapheneOS on the phone yet?
You can do that in the admin portal too. It installs GrapheneOS on your Google Pixel phone over a USB cable. You do not need any extra software. On Windows you need at most the USB driver from Google.
Works with Google Pixel phones and, on the computer, in Chrome, Edge or another Chromium browser. On GrapheneOS, two settings can only be changed by hand. The admin portal shows you which ones.
View live demoShadowZ MDM and other solutions at a glance.
We evaluated the public information on 25 MDM products. The table shows what is common among most providers. Individual providers may differ.
| Topic | ShadowZ MDM | Typical cloud MDM | Typical self-hosted MDM |
|---|---|---|---|
| Where your device data is stored | On your own server | On the provider's servers | On your own server |
| Phones without Google services | Full feature set | Usually only with a Google connection, severely limited without Google | Partly possible, often with limitations |
| GrapheneOS | Made for it | Hardly supported | Rarely supported explicitly |
| Setting up a GrapheneOS phone | Over a USB cable from the browser, with one click | Usually not provided for | Where supported, usually with commands on a computer, phone by phone |
| Installing GrapheneOS | Directly in the admin portal | As a rule not included | As a rule not included |
| Commands to the phones | Straight from your server over a permanent connection | Usually via Google, without Google sometimes only hourly or every few hours | Varies, sometimes only at fixed intervals |
| Apps from F-Droid and GitHub | Yes, with a daily check for new versions | Usually Google Play and your own app files | Usually your own app files |
| Messages to the phones | End-to-end encrypted, not even your server can read them | Where offered, end-to-end encryption is rarely described | Where offered, end-to-end encryption is rarely described |
| Kiosk mode, remote wipe, messages to the phones, activity log | All included in every plan | Sometimes only in more expensive plans | Sometimes only in higher tiers or as an add-on module |
| Billing | Fixed price per plan | Per device and month | Usually per device, prices often only on request |
| When the provider's service is disrupted | Phones and admin portal keep running | Admin portal unreachable | Phones and admin portal keep running |
Where your device data is stored
- ShadowZ MDM
- On your own server
- Typical cloud MDM
- On the provider's servers
- Typical self-hosted MDM
- On your own server
Phones without Google services
- ShadowZ MDM
- Full feature set
- Typical cloud MDM
- Usually only with a Google connection, severely limited without Google
- Typical self-hosted MDM
- Partly possible, often with limitations
GrapheneOS
- ShadowZ MDM
- Made for it
- Typical cloud MDM
- Hardly supported
- Typical self-hosted MDM
- Rarely supported explicitly
Setting up a GrapheneOS phone
- ShadowZ MDM
- Over a USB cable from the browser, with one click
- Typical cloud MDM
- Usually not provided for
- Typical self-hosted MDM
- Where supported, usually with commands on a computer, phone by phone
Installing GrapheneOS
- ShadowZ MDM
- Directly in the admin portal
- Typical cloud MDM
- As a rule not included
- Typical self-hosted MDM
- As a rule not included
Commands to the phones
- ShadowZ MDM
- Straight from your server over a permanent connection
- Typical cloud MDM
- Usually via Google, without Google sometimes only hourly or every few hours
- Typical self-hosted MDM
- Varies, sometimes only at fixed intervals
Apps from F-Droid and GitHub
- ShadowZ MDM
- Yes, with a daily check for new versions
- Typical cloud MDM
- Usually Google Play and your own app files
- Typical self-hosted MDM
- Usually your own app files
Messages to the phones
- ShadowZ MDM
- End-to-end encrypted, not even your server can read them
- Typical cloud MDM
- Where offered, end-to-end encryption is rarely described
- Typical self-hosted MDM
- Where offered, end-to-end encryption is rarely described
Kiosk mode, remote wipe, messages to the phones, activity log
- ShadowZ MDM
- All included in every plan
- Typical cloud MDM
- Sometimes only in more expensive plans
- Typical self-hosted MDM
- Sometimes only in higher tiers or as an add-on module
Billing
- ShadowZ MDM
- Fixed price per plan
- Typical cloud MDM
- Per device and month
- Typical self-hosted MDM
- Usually per device, prices often only on request
When the provider's service is disrupted
- ShadowZ MDM
- Phones and admin portal keep running
- Typical cloud MDM
- Admin portal unreachable
- Typical self-hosted MDM
- Phones and admin portal keep running
As of October 2026. Summarized from public vendor information (websites, documentation, price lists).
Also in every plan
- Encrypted contact backup that only the employee can open
- A warning when someone tries to intercept a phone's connection
- Runtime per phone that locks the phone even without internet
- Your logo and your colors on every phone
Everything you need for your company phones. In one place.
From setting up a new phone to locking a lost device: you do everything in the , conveniently in your browser.
Setup
- Enrollment
Set up phones in minutes
Samsung, OnePlus and other Android phones: switch on a new or reset phone, scan a QR code, done. Google Pixel phones with GrapheneOS: activate them over a USB cable straight from the browser, including the installation of GrapheneOS if you wish. A Google account is not needed.
- Enrollment
Many phones at once
A single QR code enrolls up to 1,000 phones. In the code, you define beforehand which configuration, which groups and which runtime each new phone gets. The phones are named automatically, for example “Warehouse 1”, “Warehouse 2” and so on. You print the code or save it as an image, and you can revoke it at any time.
- Enrollment
Reset, and still recognized
If a phone is reset to factory settings and set up again, ShadowZ MDM recognizes it. The old entry is replaced and the existing runtime is kept.
Apps
- Apps
Deploy apps automatically
For each app, decide whether it is required and always installed, or only allowed so that employees may install it themselves. Required apps reach the phone without any action by your employees and stay up to date. You simply upload your own apps as a file. WhatsApp is already prepared and comes directly from the vendor.
- App sources
Apps from F-Droid and GitHub
Add apps directly from F-Droid or from GitHub. You only enter the name of the app, and your server fetches it itself. Every day it checks whether there is a new version and distributes it to your phones. Before each update it checks that the new version really comes from the same developer. You can also add the F-Droid sources that vendors such as Threema run themselves.
- Apps
Updates at the right time
App updates install only within the time window you set, for example at night. If you wish, the phones download apps only over Wi-Fi to save mobile data.
- Updates
Test new versions of the phone app first
Roll out an update of the ShadowZ app to a test group first, then to all phones. You see how many phones still have an older version. If an update fails on a phone, it is not offered again endlessly.
Rules and security
- Policies
Settings nobody can get around
More than 30 settings, from camera and screenshots to factory reset. What you set applies on the phone and cannot be reversed there. For each phone you see whether everything is in effect.
- Groups
Groups instead of one phone at a time
Combine phones into groups, such as warehouse, drivers and administration. A configuration for the group applies to all phones in it. If a single phone needs something different, it gets its own configuration, and the admin portal shows you for every phone whether it uses its group's configuration or its own.
- Kiosk
for individual phones
Turn a phone into a device for exactly one app, for example as a checkout or warehouse device. The phone stays in this app, even after a restart.
- Runtime
Runtime per phone
Give each phone a runtime. When it expires, the phone locks automatically, even without an internet connection. Reminders appear on the phone beforehand. Extend it with one click in the admin portal.
In an emergency
- Remote access
Lost a phone? Act immediately.
Lock it, restart it, force a new password or wipe the phone completely. You can always see the status of the wipe: delivered, confirmed or canceled. If the phone is offline at the moment, the wipe waits and is carried out as soon as the phone checks in.
- Remote access
Colleagues can wipe a lost phone
Allow selected phones, for example the shift supervisor's, to wipe a lost phone, even when nobody is at the admin portal. You decide which groups this phone may wipe. By default, a 30-second countdown runs before the wipe, during which you can cancel it in the admin portal. Every wipe is recorded in the activity log.
Everyday use
- Messages
Encrypted messages to your phones
Write to your employees directly from the admin portal. The messages are , not even your server can read them. You decide whether and how often a phone may reply. When a reply arrives, the admin portal notifies you. On the phone, messages can delete themselves after a time you choose.
- Contacts
Contacts kept safe
On the company phone, your employees keep their messenger contacts and open the chat in Signal, WhatsApp or Threema with one tap. There is also a separate phone book for calling and texting. Everything is backed up, encrypted, on your server once a day. If a phone is lost, you restore the contacts to the new phone. Only the employee knows the password for this.
- Branding
Your logo, your colors
The app on the phones shows your company logo, your company name and your color. Plus your own lock screen text and your wallpaper.
- Overview
See at a glance what needs doing
The overview shows which phones need attention: runtime expiring soon, offline for days, a setting not in effect, a new reply. In the device list you find any phone by name, model or serial number and filter by group, configuration or status. If there are problems, you read a phone's crash reports or fetch a current log snapshot from the phone without having it in your hands.
- Access
Accounts with clear permissions
Four roles, from read-only access to full management. Anyone allowed to make changes always signs in using with an app. If the app is ever lost, you get back in with recovery codes. After a configurable period of inactivity, the admin portal signs you out automatically. Every change is recorded in the activity log, which you can search by area, time period and name. The admin portal is available in six languages.
This is what it looks like on your employees' phones.
The app runs in the background and keeps the phone in the state you define. Your employees see a tidy overview with your logo.


Security settings for your phones
Languages in the admin portal
User roles with clear permissions
Google services needed on your phones
Settings that apply on the phone. Not just in the admin portal.
ShadowZ MDM enforces every setting directly on the phone. Your employees cannot turn them off. All settings work from Android 15.
- BlockProtection against fake cell towers that eavesdrop on calls
- NFC offNo contactless reading
- Ultra-wideband offNo locating via short-range radio
- Thread offNo connection to smart home devices (Android 16 and later)
- Bluetooth contact sharing offContacts do not leave the phone via Bluetooth
- Location offThe phone does not reveal its location
- Block 2G network
- NFC off
- Ultra-wideband off
- Thread off
- Bluetooth contact sharing off
If a phone notices someone listening in, you know immediately.
Your phones talk only to your server, over their own encrypted line. If someone tries to get in between, for example through a manipulated Wi-Fi network, the phone refuses the connection, warns the user and reports the incident in the admin portal.
A line of its own
Each phone has its own digital ID and talks only to your server.
Key in the phone's chip
The phone's key is kept in the security chip and never leaves the device. In the admin portal you see how well each phone is protected.
Alarm on interception attempts
The phone detects fake counterparts, warns immediately and reports the incident with all details.
Your phones talk to your server. To nobody else.
Commands, settings and status reports travel directly between your phones and your server. We see none of it.
The only connection to us is the license check, once a day. It transmits only:
- Your license key
- the ID of your installation
- the address of your server
- the version number of ShadowZ MDM
No device data, no user data, no settings. Your server fetches new app versions itself from F-Droid, GitHub or the vendor. Your phones download apps only from your server.
Your own MDM in four steps.
You do not need a server room of your own. A small rented server on the internet is enough. Two commands do the rest.
▶ Check tour✓ System ubuntu 24.04✓ Docker Engine 29.8.2 running, Compose 5.6.0✓ Firewall ufw active: 22/tcp, 80/tcp, 443/tcp, 443/udp, 8443/tcp open✓ fail2ban sshd jail active✓ Updates automatic security updates on (no automatic reboot)Result: ready for install.sh- STEP 01
Rent a server
A small rented server from a provider of your choice is enough. Choose Ubuntu or Debian, 4 GB of RAM and 40 GB of storage. Plus an internet address for your admin portal, for example mdm.your-company.com.
- STEP 02
Prepare the server
One command sets up everything ShadowZ MDM needs: Docker, a , protection against password attacks and automatic security updates. It then checks everything and shows you whether your server is ready.
- STEP 03
Install ShadowZ MDM
A second command with your license key installs ShadowZ MDM. The security certificate for your internet address is set up automatically.
- STEP 04
Set up phones
Samsung, OnePlus and others: create a QR code in the admin portal and scan it with the new phone. Google Pixel with GrapheneOS: connect it with a USB cable and click “Activate” in the admin portal.
One license. All features. You only choose the term and the number of devices.
There are no feature packages and no surcharges. Every plan includes everything ShadowZ MDM can do.
Monthly
up to 50 devices
No minimum term
- All features: admin portal and the app for the phones
- Any number of accounts for your administrators
- Ongoing updates for the admin portal and the phone app
- Personal support via Signal
Yearly
up to 250 devices
You pay for ten months and use twelve
- All features: admin portal and the app for the phones
- Any number of accounts for your administrators
- Ongoing updates for the admin portal and the phone app
- Personal support via Signal
Lifetime
regular price €5,990
unlimited devices (Lifetime)
Pay once, use it permanently, including all future updates
- All features: admin portal and the app for the phones
- Any number of accounts for your administrators
- Ongoing updates for the admin portal and the phone app
- Personal support via Signal
Payment in cryptocurrency (Bitcoin, Monero, Ethereum). After payment you receive your license key.
Frequently asked questions
Take back control of your company phones.
Your own server, no Google services, all features in one plan.
Choose a plan