XFA provides a privacy‑first, zero‑trust security layer that protects BYOD, freelancer, contractor and other unmanaged devices without the overhead of traditional mobile device management. It enables organizations to enforce device compliance, gain audit‑ready evidence for standards like ISO 27001 and SOC 2, and integrate compliance status with GRC platforms such as Vanta and Drata, all through a lightweight onboarding process.
Funding
Funding not disclosed

Founders
Product
Problem
Organizations struggle to secure unmanaged, BYOD, freelancer and contractor devices because traditional mobile device management (MDM) solutions require intrusive control, admin rights, and extensive IT overhead, leaving a security blind spot for devices that access corporate data.
Solution
XFA offers a privacy‑respecting, zero‑trust security layer that discovers every device used for work and verifies its compliance without taking ownership of the device. The solution integrates with identity providers (Microsoft 365, Google Workspace, Okta) to enforce device security policies at login, allowing only devices that meet defined risk criteria to access corporate resources. Compliance evidence is automatically generated for standards such as ISO 27001, SOC 2, Cyber Essentials, and NIS2, and can be exported to GRC platforms like Vanta, Drata, Trustcloud, and Thoropass. The lightweight agent runs without admin rights, preserving user privacy while providing administrators with dashboards, risk alerts, and automated reporting. Deployment is self‑service, with invite‑based verification and optional EU‑hosted deployment for regulated environments.
Target Audience
Primary customers are security and IT teams in enterprises that support BYOD, remote contractors, or mixed managed/unmanaged device environments, particularly in regulated sectors such as healthcare, finance, and education.
Features
- Automatic discovery of all work‑related devices by reading identity provider access logs
- Agent runs without admin privileges, ensuring minimal device control and user privacy
- Policy‑based enforcement at authentication (login) to block non‑compliant devices
- Risk‑based alerts and awareness emails with actionable remediation guidance
- Comprehensive dashboards and periodic admin reports on device security status
- Export of audit‑ready compliance data to GRC tools (Vanta, Drata, etc.) via automated feeds
- Support for Windows, macOS, Linux, iOS, iPadOS and major identity providers (SAML, OAuth2)
- Optional EU‑hosted deployment and custom integration options for large enterprises