Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
On-device detection continues protecting a device on hostile or no networks (e.g., a rogue Wi-Fi MITM scenario); look for explicit on-device capability, not detections that silently stop working when connectivity is compromised or absent.
Look for independent testing results (not just vendor-asserted detection rates) and specificity on what app-analysis techniques are actually used.
Detection without enforcement integration just produces an alert; look for real UEM/MDM integration with a stated enforcement latency.
iOS's sandboxing meaningfully limits what an MTD agent can actually see/do compared to Android — look for an honest per-platform capability and performance-impact breakdown, not a unified marketing claim.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Privacy-preserving BYOD risk assessment (work-profile/container-scoped visibility only) is essential for BYOD adoption — look for explicit technical boundaries, not vague privacy assurances.
Mobile phishing increasingly happens outside email entirely; look for explicit SMS/QR/in-app phishing detection, not a product that only extends email security to a mobile inbox.
Signature-only detection lags newly emerging mobile malware; look for behavioral detection with a real, referenced time-to-detection example.
Look for framework-mapped, exportable compliance evidence rather than a generic risk dashboard requiring manual interpretation for an audit.
Look for transparent, tier-differentiated pricing that's explicit about which capabilities (e.g., automated MDM response) are gated behind a premium tier rather than included in the base product.
Strong answers describe a real forensic-reconstruction capability with a customer example, not just confirmation that a threat was detected and blocked.
Trend-over-time reporting is a distinct capability from a real-time alert dashboard — confirm this exists as a maintained, exportable report.
Real-time SIEM-integrated export is materially more useful for a mature security team than data siloed in a separate mobile-specific console requiring manual cross-referencing.
A false positive with automated MDM response (conditional-access revocation) can block legitimate business use — ask for a real, customer-validated false-positive figure and a fast correction workflow.
A real-world device fleet always has some OS-version spread — a vendor should give an honest answer about detection consistency across supported versions, not just the newest release.
Ask for a real completion-rate figure from a customer reference, not just a provisioning capability — incomplete rollout leaves real coverage gaps.
Mobile threat campaigns vary significantly by region (e.g., SMS-fraud patterns common in specific markets) — ask for an honest answer on geographic threat-intelligence breadth for a genuinely global workforce.