# The Army&#39;s Phone-as-a-Window Product Lists at $444.33 a Year. Here Is the Cheap Version.

The Army&#39;s answer to personal devices lists at $444.33 per user a year plus a $12,500 platform fee. A small business gets the same idea for $8 a user, free under 50.

Author: J.A. Watte
Published: August 21, 2026
Source: https://jwatte.com/blog/secure-workspace-on-any-unknown-device/

---

The US Army's answer to the problem of soldiers doing work on their own phones is a product called Hypori Halo, and the thing it does is refuse to send them any data at all.

The mobile operating system runs in a data centre. The phone in the soldier's hand runs a client that receives the pixels of whatever has changed on that remote screen, and sends touch and sensor input back up the wire. Hypori's own FedRAMP package describes it as hosting "a mobile operating system on a centralized server in a data center that is accessed by thin clients on the user's end point." The Army's own write-up puts the rationale in one line: "Risk to Army data is mitigated in case of a lost or stolen device since no information is ever stored on the user's device."

That is the whole idea, and it is not exotic. The device becomes a window instead of a container. Everything expensive about this category is downstream of that one decision, and so is everything cheap about it. A twelve-person company can buy the same principle for a small fraction of the price, and the licensing detail that makes it work is not the one most people reach for.

Prices below were read from vendor and government pages on 21 August 2026. This category reprices often. Check before you buy.

## The parts the brochure does not lead with

The marketing claim is "stream pixels, not data." The accreditation paperwork is more careful than the marketing, and it is the more interesting document.

**One thing is stored on the phone.** Hypori's FedRAMP record concedes it: "The data on the client is limited to the trust key chain. The mutual Transport Layer Security (TLS) tunnel certificate is stored with the operating system (OS) protected key store on the device, but no other data is on the end user mobile device." A certificate is not a spreadsheet, but "nothing lands on the device" is a claim with an asterisk on it.

**The traffic is not one directional.** The same record: "The client captures touch and sensor data from the end user physical device and routes it back to the Virtual Workspace through a secure and encrypted TLS tunnel." Camera, microphone and location are physical-device sensors that the user grants to the client. There is a "Hypori Camera" app inside the Army workspace. So everything the user sees and everything the user types crosses the handset in both directions.

**The workspace runs Android, whoever you are.** The FedRAMP text names the Android keystore as the key-protection mechanism inside the virtual workspace, and the Army workspace app inventory is an Android app set: Outlook, Teams, Office 365, OneDrive, Word, Excel, SharePoint, Power Apps, PowerBI, Adobe Acrobat, IPPS-A, Mobile Digital Signature, Chrome, Hypori Camera and Purebred. An iPhone user is holding an iPhone and driving an Android.

**There is no offline mode.** Hypori's own explainer of the category lists "Full network dependency; bandwidth and latency issues can hamper operational efficiency" first among the drawbacks. Session bandwidth runs, per Hypori, "typically ranging between 500 Kbs and 5 Mbps," with the top of that range for Teams and video feeds.

**There is no telephony.** The workspace cannot place a cellular call. Calls happen through Teams.

**And this is the detail that shows you how strict the rule is.** Push notifications are stored locally by the phone's operating system. That is a local write, so it violates the design. Hypori's answer: "Since notifications are stored locally on the physical device ... notifications must be sanitized to remove all Army-related data." A notification that tells you nothing is the price of a device that stores nothing. Once you see that, the rest of the architecture makes sense.

Two smaller notes. The client does inspect the phone a little: it detects root or jailbreak and refuses to connect, which is a limited exception to the "no agent on your device" framing. And there is deliberately no remote wipe, because in Hypori's words there is "no need (nor ability using Hypori) to remotely wipe the device." Hold that thought until the legal section, because remote wipe is where BYOD programmes get sued.

## What the certificates actually cover, and what they do not

This is where careful reading pays, because the scope of each certification is narrower than the logo implies.

**FedRAMP.** Package FR2333538201, "Hypori Government Cloud," High impact, SaaS, Government Community Cloud, agency authorization path, certified 20 March 2025 with Kratos as the assessor. It entered the process on 30 August 2024, so roughly seven months start to finish. The record shows one authorization and zero reuses. The sponsoring agency is recorded as the United States Army; the listed authorizing agency is DISA. Both appear in the same record.

Worth knowing if you are reading anyone's compliance page this year: FedRAMP has renamed the scheme. "FedRAMP Authorization" is now "FedRAMP Certification," Impact Levels have been replaced with Classes A to D, and Low, Moderate and High are being removed in January 2027. Every vendor page currently saying "FedRAMP Authorized" is on borrowed terminology.

**DISA IL5.** A provisional authorization granted in July 2023 against, per Hypori, an assessment of 390 security and privacy controls, extended in March 2025 through 2028 and raised from IL5 Moderate-Baseline to IL5 High-Baseline.

**Common Criteria covers the client app only.** The Hypori Halo clients for Android and iOS are certified against the Protection Profile for Application Software version 1.4, under the US scheme. Android 4.3 certified 20 February 2024 and running to 19 February 2027; iOS 4.3 certified 4 March 2024 and running to 4 March 2027; both received maintenance updates in February and March 2026 covering newer builds. That certificate says nothing about the cloud workspace or the backend. There is a conflict here worth naming: Hypori's own FAQ says its NIAP certifications are valid through 20 February 2026, which would mean they expired six months ago. The Common Criteria Portal says otherwise. The vendor's own page is the stale one.

**The NSA listing is narrower than it sounds.** Hypori Halo Client for Android 4.3 and iOS 4.3 appear on NSA's Commercial Solutions for Classified components list, under the category "TLS Software Applications." NSA attaches an explicit caveat to that category: components are "validated for their ability to establish a TLS connection as specified in the Capability Packages. Additional functionality not described within the Capability Packages ... are beyond the scope of CSfC approval." Hypori's FAQ describes the same listing as sitting under the Mobile Access Capability Package, which reads broader than the components list does.

**There is no FIPS certificate.** A search of the NIST validated-modules list for vendor "hypori" returns "No certificates match the search criteria." Hypori's own careful phrasing is that the app makes use of "FIPS 140-2 Certified components," which is a statement about its supply chain rather than a validation of its own. Note also that FIPS 140-2 has been superseded by 140-3.

**SOC 2 is a self-report.** Hypori announced SOC 2 Type 2 compliance dated 12 May 2026. SOC 2 reports are not published, so unlike FedRAMP or Common Criteria there is no public record anyone outside the engagement can check. Take it as a claim.

None of this means the product is weak. It means the accurate sentence is "an app certified against an application software protection profile, fronting a cloud service certified at FedRAMP High," and that is a different sentence from the one most write-ups produce.

## The published price, and why the deployment numbers are not a price signal

Hypori publishes no price. Its pricing page is a quote-request form with three unpriced tiers and the line "Contact us for a customized quote that fits your use case." It also holds no GSA Schedule contract of its own; on GSA eLibrary it appears only as a manufacturer, and every government purchase runs through a reseller.

The reseller catalogue is where the numbers live. All of the following are Carahsoft list prices on GSA Advantage under MAS SIN 518210C, contract 47QSWA18D008F, which ends 21 August 2028, read on 21 August 2026.

| Line item | List price |
|---|---|
| Hypori IL5 SaaS Licence, annual | $444.33 per year |
| Hypori FedRAMP SaaS Licence, annual | $444.33 per year |
| Hypori CMMC SaaS Licence, per user, 12 months | $444.33 per year |
| Hypori Cloud Licence (commercial, non-FedRAMP) | $296.22 per year |
| Hypori Private On-Premise, per user | $592.44 per year |
| Hypori Mobile Secure Messaging, per user | $142.19 per year |
| Halo Platform Fee (multi-tenant only) | $12,500 per year |
| CMMC Platform Fee | $25,000 per year |
| Dedicated cluster / CMMC dedicated instance | $148,110.83 per year each |
| On-premise product support agreement | $296,221.66 per year |
| Standard implementation | $24,685.14 one time |
| Ignite implementation | $19,748.11 one time |

So the sticker is roughly $444 per user per year for the accredited tiers, plus a platform fee of $12,500 or $25,000 a year, plus twenty to twenty-five thousand dollars of one-time implementation, plus $148,110.83 a year if you want a dedicated cluster instead of multi-tenant. Single-instance deployments cost more than the multi-tenant platform fee; the catalogue says so without saying how much more.

**What I am not going to do is multiply.** The obvious move is to take a published Army user count and multiply by $444.33. That number would not reconcile with what the government has actually obligated, volume discounting is plainly in play, and I could not verify any discount schedule. Treat $444.33 as a list price and nothing more.

The deployment story is genuinely large and genuinely not a market signal. Hypori began as an Army pilot in July 2022 and was approved as an enterprise capability in July 2023. As of 11 June 2024 it became the only way an Army.mil user can reach Army 365 from a personal device. The Department of the Air Force acquired the same capability, branded Workspace Anywhere, as an enterprise capability in July 2024, and in April 2026 raised its licence allocation from 10,000 to 17,000 with more than 15,000 users reported on a waitlist.

The user counts conflict, and the conflict is instructive. The Army's own article quotes Lt. Gen. John B. Morrison Jr. saying "almost 25,000 people" as of August 2023. Hypori's CEO was reported by C4ISRNET in July 2024 putting Army enrollment at 50,000. Eleven months apart, so growth explains most of it, but one figure is a government official's and one is a vendor's, and they should not be merged into a single number.

Here is the part that matters for anyone reading adoption as validation: the Army BYOD program is "centrally funded at the headquarters level and is available at no direct cost" to soldiers and units. When something is free at the point of use, uptake tells you about demand for free things. It does not tell you the product clears a purchasing bar.

The contract record is worth a sentence of its own, because three different dollar figures attach to one award. PIID W519TC24C0028, Army Contracting Command at Rock Island, signed 17 July 2024. The Defense Department's own contract announcement that day states $16,220,000 obligated at award. Hypori's press release four weeks later called it a $12 million renewal and expansion. USAspending now shows a total obligation of $28,785,780. All three are defensible readings of different moments, but anyone quoting the $12 million is quoting the smallest of the three. And the award was a service-disabled veteran-owned small business sole source with one offer received. It was never competed.

Across all time, direct federal prime-contract dollars to Hypori entities total $34,860,405 over six awards, including two Air Force SBIR Phase III follow-ons in 2025 at $4,099,920 and $1,200,000. Everything else runs through resellers, and the reseller trail names DISA, the IRS (300 licences for $450,347), the State Department, the FBI, the Navy, and a long-running US Special Operations Command deployment on classified networks.

One more thing about the category, because it explains why the cheap options matter. The first generation of this idea mostly died. Sierraware's domain is parked and for sale at $7,888. Avast's Virtual Mobile Platform, built on its 2015 Remotium acquisition, no longer exists as a product. Trend Micro's Safe Mobile Workforce is absent from the company's current mobile product page, though I found no formal end-of-life notice. Nubo Software is still going. And Cellcrypt, which gets swept into these comparisons, does not belong in them at all: it sells encrypted calling and messaging apps that run on the device, which is the opposite architecture.

## Why anyone bothers: what personal devices actually cost you

The strongest numbers here are telemetry, not surveys, and I have labelled which is which because it changes how much weight they carry.

**Measured, from Microsoft's endpoint telemetry.** In more than 90% of cases where a ransomware attack progressed to the ransom stage, the attacker used unmanaged devices in the network, either for initial access or to encrypt remotely. Microsoft observed remote encryption in 70% of successful attacks, with 92% of those originating from unmanaged devices.

**Measured, from credential logs.** In the infostealer logs analysed for Verizon's 2025 DBIR, 46% of compromised systems that carried corporate logins were non-managed devices hosting both personal and business credentials. Verizon's own reading: these are "most likely attributable to a BYOD program or are enterprise-owned devices being used outside of the permissible policy." Verizon separately estimated that around 30% of infostealer-compromised systems were enterprise-licensed devices, and flagged its own method as "a bit of a kludgy approach," which is unusually honest and worth respecting when you cite it.

Note that the 2026 DBIR does not rerun that BYOD analysis. It points back to 2025. If you see the 46% attributed to the newer report, someone has not opened it.

**Survey, with a disclosed sample.** Verizon's 2025 Mobile Security Index reports that 70% of mobile devices impacted by an attack are personal rather than corporate-issued. That is the headline BYOD statistic and it comes from a survey of 762 professionals, supplemented by data contributed by Check Point, Ivanti and Lookout. The same report puts BYOD prevalence at 25% of organisations allowing personal devices, 19% running a mix, 55% company-owned, and 1% not allowing mobile devices for work at all.

Inside that report is a figure I want to flag rather than quote flatly: among organisations that formally prohibit BYOD, only 22% say employees actually comply. That is Ivanti-contributed data appearing inside a Verizon publication, in a section arguing that mobile device management is essential, written by the company that sells mobile device management. It may well be true. It is not Verizon's own measurement, and the vendor supplying it sells the remedy its statistic implies.

**Device condition, measured across a fleet.** Zimperium's 2025 report found 61.2% of Android devices and 49.2% of iOS devices running an outdated operating system in any given twelve-month window, and 25.2% of devices classed as vulnerable and non-upgradeable, meaning they cannot be patched at all. Sideloaded apps were present on 23.5% of devices examined and on 25.3% of Android devices specifically, which are two different denominators and should not be reported as one number. Compromise rates are low but not zero: 1 in 400 Android devices rooted, 1 in 2,500 iOS devices jailbroken, 3 in 1,000 compromised, and 18.1% of Android devices encountering malware.

Jamf, examining over 1.7 million iOS and Android devices and over 150,000 Macs at the end of 2025, reports that 53% of organisations have at least one device with a critically out-of-date operating system. That is an organisation-level count and Zimperium's is a device-level count. They are not comparable and neither confirms the other.

**Phishing is moving to the phone.** Zimperium recorded voice phishing up 28% and text phishing up 22%, with the United States comprising 44% of mobile phishing targets in 2024. Verizon's 2026 DBIR found the median successful click rate in mobile-centric simulated campaigns runs 40% higher than email, and I would not build much on that one: Verizon flags the sample itself, 35 non-email campaigns against 8,395 email campaigns.

The 2026 DBIR also contains a trap. Credential abuse as an initial access vector appears to have fallen from 22% to 13%, which reads like a win. It is partly an artifact of Verizon newly tracking "Pretexting" as a separate vector, and Verizon states that on the prior-year basis the figure would have been 16%. Exploitation of vulnerabilities is now the most common vector at 31%.

And the visibility problem, in Verizon's words: SMS phishing detections "were only visible because those are managed devices ... If your employees are using purely unmanaged personal devices to perform organizational duties, this can represent a risky gap in your visibility." Separately, the 2025 Mobile Security Index puts the share of organisations that find shadow IT hard to detect, because of missing or incomplete data, at 45%.

**A named incident.** Uber, September 2022, from Uber's own report: "It is likely that the attacker purchased the contractor's Uber corporate password on the dark web, after the contractor's personal device had been infected with malware, exposing those credentials." Multi-factor fatigue got the attacker in, and the intrusion reached G Suite and Slack. One contractor's personal phone to a full corporate compromise, documented by the victim.

The LastPass breach is the other case everyone cites. LastPass's own post confirms only that the attacker "targeted a senior DevOps engineer by exploiting vulnerable third-party software" to deliver malware and reach cloud backups. The widely repeated detail that the machine was the engineer's home computer running an unpatched media server comes from LastPass statements quoted in press coverage, not from a LastPass document I could open. Use the confirmed version.

Finally, Verizon's blunt line, which I would put on a wall: "If you don't choose to have a BYOD policy and don't enforce what sorts of devices have access to corporate systems, the BYOD policy can wind up being chosen for you and you might not like the results."

## The exposure most owners have never priced: wages, reimbursement and discovery

The security case is the one people expect. The employment-law case is the one that actually generates invoices, and it does not care whether anything was breached.

**Reimbursement is a statutory duty in several states, and it is not about extra cost.** California Labor Code section 2802(a) requires an employer to "indemnify his or her employee for all necessary expenditures or losses incurred by the employee in direct consequence of the discharge of his or her duties." Subsection (c) folds the employee's attorney's fees into the recoverable amount, which is the provision that turns small per-person sums into viable litigation.

*Cochran v. Schwan's Home Service, Inc.* (228 Cal.App.4th 1137, No. B247160, filed 12 August 2014) settled the argument owners usually reach for. The court: "The answer is that reimbursement is always required. Otherwise, the employer would receive a windfall because it would be passing its operating expenses onto the employee. Thus, to be in compliance with section 2802, the employer must pay some reasonable percentage of the employee's cell phone bill." It does not matter that the plan was unlimited. It does not matter that the employee paid nothing extra. It does not matter if a family member paid the bill. Cochran was a class of 1,500.

Illinois is the better model to copy, because its statute tells you what you are allowed to do rather than only what you cannot. Section 9.5 of the Illinois Wage Payment and Collection Act (820 ILCS 115/9.5, added by P.A. 100-1094 effective 1 January 2019) requires reimbursement of necessary expenditures within the scope of employment that primarily benefit the employer, gives the employee 30 calendar days to submit unless a written policy extends it, and allows an employer to cap reimbursement by written policy "so long as the employer does not institute a policy that provides for no reimbursement or de minimis reimbursement." A written, capped, published stipend is compliant. Zero is not.

Montana (Mont. Code Ann. section 39-2-701) and South Dakota (S.D. Codified Laws section 60-2-1) use the same indemnify architecture as California. New Hampshire (RSA 275:57) requires reimbursement within 30 days of proof of payment and puts a civil penalty of up to $1,000 per violation on a willful breach. New York is different and should not be lumped in: Labor Law section 198-c treats "reimbursement for expenses" as a wage supplement, but it only bites where the employer is "party to an agreement" to provide it. New York enforces a promise you made. California creates a duty whether you promised or not.

Those are the six states I verified. Massachusetts and Pennsylvania get cited in these round-ups constantly and neither has a general freestanding reimbursement statute; the obligation there runs through other machinery. Check your own state rather than assuming.

**A policy against after-hours work is not a defence.** This is the most under-priced exposure in the whole subject. Under the Fair Labor Standards Act, work "not requested but suffered or permitted is work time" (29 C.F.R. 785.11), and that applies to work done away from the premises or at home if the employer knows or has reason to believe it is happening (785.12). Then 785.13, which is the line every owner should read twice: "It cannot sit back and accept the benefits without compensating for them. The mere promulgation of a rule against such work is not enough. Management has the power to enforce the rule and must make every effort to do so."

The escape hatch people reach for next is the de minimis doctrine, and it is narrower than they think. 29 C.F.R. 785.47 covers "uncertain and indefinite periods of time ... of a few seconds or minutes duration," and the authority cited in the regulation itself holds that 10 minutes a day is not de minimis. A non-exempt employee glancing at a work app on their own phone in the evening crosses that line trivially.

**And the "right to disconnect" articles are wrong.** There is a well-circulated claim that four US states have right-to-disconnect laws arriving in 2026. No US federal or state right-to-disconnect law is in force. California's AB-2751, which would have added Labor Code section 1198.2, is recorded by the California Legislature's own bill status page as "Inactive Bill - Died" in Assembly Appropriations. The pages asserting otherwise are search-bait.

The right does exist, in Australia. It applied from 26 August 2024 for employers with 15 or more employees, and from 26 August 2025 for small business employers with fewer than 15. It does not make out-of-hours contact unlawful. It gives employees a right to refuse to monitor, read or respond unless refusing would be unreasonable. If you employ anyone in Australia, that second date already passed.

**Discovery reaches the phone, and nobody can tell you exactly how far.** Federal Rule of Civil Procedure 34(a)(1) compels production of electronically stored information in the responding party's "possession, custody, or control." Whether a company controls what sits on an employee's personal handset is genuinely contested, courts are split, and I could not find a controlling primary authority I would be willing to cite. That uncertainty is itself the risk: you cannot plan around a rule nobody can state.

**Remote wipe is the one everyone gets backwards.** *Rajaee v. Design Tech Homes, Ltd.*, No. 4:13-cv-02517 in the Southern District of Texas, is the case people cite for "employer wiped a personal phone and lost." Per the docket, on 11 November 2014 the court dismissed the Electronic Communications Privacy Act and Computer Fraud and Abuse Act claims with prejudice, and dismissed the state-law claims for misappropriation, Texas Theft Liability Act, negligence and conversion without prejudice, meaning they survived to be refiled. The federal computer-crime statutes were a poor fit. Ordinary state tort law was where the exposure sat. I could not read the opinion itself, so I am not going to characterise the court's reasoning.

**If you are in healthcare, one requirement does the deciding for you.** The HIPAA Security Rule's device and media controls at 45 C.F.R. 164.310(d) make Disposal and Media re-use *required* implementation specifications: you must have procedures "for removal of electronic protected health information from electronic media before the media are made available for re-use." On a phone you do not own, cannot inventory and cannot inspect, no written policy satisfies that. Only an architecture where the data never arrives does.

**And if you are regulated in the way finance is regulated, there is a price tag.** In one action on 14 August 2024, the SEC fined 26 firms a combined $392.75 million over "pervasive and longstanding use of unapproved communication methods." Off-channel communication on personal devices is the sharpest regulatory precedent on the public record for what unmanaged-device work costs, and not one dollar of it involved a hacker.

## The affordable stack, with prices as observed on 21 August 2026

Everything below solves the same problem the government product solves. They differ in how much of the device they take over and how much of the work they move off it.

### Full cloud desktops

| Option | Published price | The catch |
|---|---|---|
| Windows 365 Business, 2 vCPU / 4 GB / 64 GB | $25.60 per user per month | 300-user tenant cap |
| Windows 365 Business, 2 vCPU / 8 GB / 128 GB | $36.00 per user per month | No policy management, no monitoring |
| Windows 365 Business, top of ladder | $255.20 per user per month | Thirteen sizes published |
| Windows 365 Enterprise | $28.00 to $765.00 per user per month | Every user also needs Windows Enterprise, Intune and Entra ID P1 |
| Windows 365 Flex, 2 vCPU / 8 GB / 128 GB | $62.00 per licence per month | Per licence, not per user |
| Amazon WorkSpaces Personal, Standard | $35.00 per month, always on | Plus $4.19 per user Microsoft licence fee |
| Amazon WorkSpaces Personal, Power | $78.00 per month, always on | Same |
| Azure Virtual Desktop | $0 access licence with M365 Business Premium or E3/E5/F3 | You pay compute; $10.00 per user per month for external users |

A few details that decide real deployments.

Windows 365 Business has a hidden ceiling: policy management is listed as not supported, monitoring is not supported, and device management is limited to assigning and unassigning licences in the admin centre. Application deployment works only if you separately hold an Intune licence. It also deletes all associated data when the subscription is cancelled, which matters if you were treating a contractor's Cloud PC as a filing cabinet. There is a 30-day free trial of the 2/8/128 size, one per version, credit card required, auto-converting to paid.

Windows 365 Frontline was renamed Windows 365 Flex, announced 4 May 2026, and Microsoft's own site has not finished the rename: the docs say Flex, the pricing table rows still read Frontline, and the pricing page still lives at the frontline path. The pricing is also easy to misread. One Flex licence in Dedicated mode provisions up to three Cloud PCs assigned to three named users but allows only one concurrent session. At three users per licence the 2/8/128 size works out to $20.67 per user per month, cheaper than the $36.00 Business equivalent, but only if those three people genuinely never need to be online at the same time. In Shared mode it is one Cloud PC per licence and all user data is deleted at sign-out.

Amazon WorkSpaces has a billing trap in the other direction. Hourly AutoStop billing for a Standard workspace is $9.75 a month plus $0.30 an hour, which at 160 hours a month is $57.75, well above the $35.00 always-on rate. Hourly only pays for genuinely light users. And AutoStop only stops when the user actually disconnects, with a default one-hour timer, so your cost model depends on behaviour you cannot enforce on a device you do not manage.

If you are reading an older comparison article, note that Amazon WorkSpaces Pools, the non-persistent shared-desktop option, is being withdrawn: no new customers from 31 July 2026 and end of service on 31 December 2027. The successor is Amazon WorkSpaces applications, billed per streaming hour (a general purpose Windows fleet instance is $0.268 an hour) plus $4.19 to $6.42 per user per month in Microsoft licence fees.

Azure Virtual Desktop looks free and is not. The access right is already covered if you hold Microsoft 365 Business Premium or E3/E5/F3, so there is no per-user fee for employees. You pay for the virtual machine. A 4 vCPU / 16 GB Standard_D4as_v5 in East US is $0.172 an hour at the base rate, which is $125.56 a month left running around the clock or $30.27 a month at eight hours across twenty-two working days. That base rate assumes the Windows multi-session right comes from a licence you already hold; running Windows Server instead puts you on the $0.356 rate. AVD is also the option that demands the most management labour, which does not appear on any price page.

### The browser layer, which is where most small businesses actually live

| Option | Published price |
|---|---|
| Cloudflare Zero Trust, free plan | $0 forever, up to 50 users |
| Chrome Enterprise Core | $0 |
| Chrome Enterprise Premium | $6.00 per user per month |
| Cloudflare Zero Trust pay-as-you-go | $7.00 per user per month |
| Amazon WorkSpaces Secure Browser | $7.00 per monthly active user |
| Kasm Workspaces Community Edition | $0, capped at 5 concurrent sessions |
| Kasm Cloud Personal (browser / desktop / OSINT) | $10 / $20 / $40 per month |
| Apache Guacamole | $0, Apache License 2.0 |

Cloudflare's free tier is the single most useful line in this article for a company under fifty people. Zero-trust network access, a secure web gateway, the device client, application connectors, experience monitoring, up to two read-only cloud app security integrations and limited data-loss-prevention profiles, at $0 forever, with 24-hour log retention and community-forum support. Above fifty users it is $7 per user per month with no cap. Remote browser isolation is *not* in any of those tiers; it is an add-on to the paid plans and Cloudflare publishes no price for it.

Cloudflare's device agent, formerly WARP and now the Cloudflare One Client, reports device posture including operating system version, disk encryption state and the presence of specific applications. That is exactly the visibility a BYOD user objects to, and you should expect to have that conversation.

Amazon's WorkSpaces Secure Browser at $7 per monthly active user is the cheapest published managed-isolation option that leaves nothing on the endpoint. Kasm Community Edition is free and self-hosted with a hard cap of five concurrent sessions, which covers a very small team completely; Kasm does not publish prices for its paid self-hosted tiers, and third-party aggregator numbers for it are not vendor sources. Apache Guacamole is free and genuinely useful, but be clear about what it is: a clientless gateway that brokers RDP, VNC and SSH into a browser. It does not provision or host anything. Everything behind it is yours to build and run. Its own FAQ documents real limits, including that RDP sessions cannot resize when the browser window changes and VNC sessions cannot be resized from the client at all.

Then there is the group that publishes nothing at all: Island, Palo Alto's Prisma Access Browser, Menlo Security, Zscaler, Citrix DaaS and Omnissa Horizon Cloud. Every one of them routes to a demo request or a quote. Citrix's own pricing URL does not resolve; its product page offers only the comparative claim that "Citrix customers save $98 per user, per year." For a twelve-person company, "call sales" is not a neutral fact. It is a cost, measured in weeks and in the certainty that you are the smallest account in the pipeline.

Cameyo, now "Cameyo by Google," delivers Windows applications as web apps through Chrome and is positioned as a replacement for full virtual desktops. The only price figure I could find for it, $132 per user per year, comes from trade coverage of the launch rather than from Google: it does not appear on cameyo.com, on Google's Chrome Enterprise pricing page, or in Google's own launch blog post. Treat it as a reported number, not a rate card.

### Manage the app, not the device. This is the answer for most readers.

Here is the licensing detail that does the real work, and it is not the one most people reach for.

Microsoft Intune app protection policies target the *user's identity*, not the device. Microsoft's documentation is explicit: "Because Intune app protection policies target a user's identity, the protection settings for a user can apply to both enrolled (MDM managed) and nonenrolled devices (no MDM)." You can write a strict policy for unmanaged personal hardware and a looser one for company-owned kit, from the same console, and the personal device is never enrolled in anything.

That capability sits in Intune Plan 1, which costs $8.00 per user per month standalone. It is also included in Microsoft 365 Business Premium at $22.00 per user per month paid yearly, or $26.40 monthly, alongside Office, business email and Defender for Business. Two pricing notes, because Microsoft's own pages will confuse you. The compare-all-plans page displays "Business Premium with Copilot" at $32.00 by default, which reads as a $10 price rise; plain Business Premium still exists at $22.00 and Microsoft's July 2026 commercial price list shows it unchanged while Business Basic went from $6.00 to $7.00 and Business Standard from $12.50 to $14.00.

The newer and much less known piece: Microsoft Edge for Business now supports Intune app protection on *Windows*, not just phones. Clipboard restrictions, protected downloads, watermarking and leak prevention applied to the Edge work profile, cross-tenant, without enrolling the machine. That covers a contractor's own laptop, which is the hardest case in most small companies. Conditional Access triggers the enrolment of the browser profile rather than the device.

There is one documented conflict to plan around, and it is a real one: if device-level Endpoint DLP is enabled on that Windows machine, your app protection policies cannot apply to Edge work profiles unless a bypass policy is set by the tenant that manages the device. On a device you do not own, that tenant is not you.

Two other Intune details worth knowing. Device-only licences exist for kiosks and shared hardware and are cheaper, but they explicitly do not support app protection policies or Conditional Access, so the cheap device SKU cannot solve this problem. And from July 2026 Microsoft is folding several paid add-ons into existing suites, so check what you already own before buying Remote Help, Advanced Analytics or Plan 2 separately.

### What the operating systems give you for nothing, and what your employees can actually see

This is the question employees ask and almost nobody answers accurately. Both major mobile platforms ship a free separation mechanism, and the boundaries are documented.

**Android Enterprise work profile, $0, built into the OS.** Google's own wording: "If your device has a Work Profile, your organization can view and manage your work apps and data. Your personal apps, data, and usage details aren't visible or accessible to your organization or Android Device Policy." On a personally owned device the employer can remotely lock and wipe *the work profile only*, not the phone. Work-profile apps cannot read SMS or MMS from the personal profile on Android 11 and later. Work apps carry a briefcase icon so the user can tell them apart, and the user can delete the work profile at will because they own the device.

The boundary weakens in one specific case, and it is worth being straight about: on devices flagged as company-owned during setup, some policies do reach the personal profile and overall device behaviour. That flag is set at enrolment. If you are asking someone to use their own phone, do not set it.

**Apple account-driven User Enrollment, $0, built into the OS.** Apple: "With account-driven User Enrollment, IT teams can manage only an organization's accounts, settings, and information provisioned with a device management service, never a user's personal account." The precise answer to "can they see what apps I have installed" is documented: the employer can query installed configurations and profiles and the status of managed apps, but explicitly not user-installed apps from the App Store. The operating system creates separate encryption keys for work data, and a Managed Apple Account coexists with the user's personal one. Crucially, the ability to erase the whole device belongs to Device Enrollment, not User Enrollment. Under the BYOD mode, you cannot wipe someone's phone. Which, per Rajaee, is a feature.

**Samsung Knox Suite Base Plan** is free with a Galaxy device purchase. The paid tiers are published, unusually for this market: Knox Suite Essentials at $30.00 per device per year and Knox Suite Enterprise at $52.50 per device per year, or $60.00 and $105.00 for two years.

**ChromeOS Enterprise Upgrade**, which is what makes a Chromebook centrally managed, is $4.17 per device per month MSRP as a standalone annual licence. **ChromeOS Flex** converts existing Windows or Mac hardware to ChromeOS for free, and Google is upfront about the trade: Flex machines lack the Google-designed security chip that enables verified boot and firmware integration, and cannot run managed Google Play apps.

### The hardware arithmetic, done honestly

I expected this to come out in favour of cheap hardware. It does not.

| Three-year path | Total | Per month |
|---|---|---|
| Existing PC converted with ChromeOS Flex plus management upgrade | $150.12 | $4.17 |
| Intune Plan 1 standalone, worker's own device | $288.00 | $8.00 |
| Amazon WorkSpaces Thin Client plus service fee | $411.00 | $11.42 |
| Lenovo Chromebook Duet 3 plus ChromeOS Enterprise Upgrade | $450.11 | $12.50 |
| Microsoft 365 Business Premium, worker's own device | $792.00 | $22.00 |
| Amazon WorkSpaces Standard, always on | $1,260.00 | $35.00 |
| Windows 365 Business 2/8/128 | $1,296.00 | $36.00 |

The $195 thin client looks like the cheapest secure endpoint and it is the most expensive total path, because it does nothing on its own. It needs a WorkSpace behind it at $25 to $78 a month, which adds $900 to $2,808 over three years. The $299.99 Chromebook plus management at $450.11 is genuinely self-sufficient and is a real answer.

But Intune Plan 1 at $288 over three years beats every piece of hardware, and Business Premium at $792 beats issuing a laptop while also covering Office, email and Defender. Managing the app on the worker's own device is cheaper than issuing any device. The honest reason to issue hardware is control and supportability, not price. Say that out loud when you make the decision, because if you tell yourself it is a cost decision you will make it badly.

For a browser-only workload the gap is not close: $0 on Cloudflare's free tier under fifty users, $216 over three years for Chrome Enterprise Premium, $252 for Cloudflare pay-as-you-go or WorkSpaces Secure Browser, against $1,296 for a Windows 365 Business 2/8/128 Cloud PC.

Two caveats on the hardware column. I could not verify a new sub-$250 Chromebook from a manufacturer's own page; the only Chromebook prices I could read directly were Lenovo's, where the Duet 3 lists at $299.99 and the Duet Gen 9 at $399.00, $499.99 and $629.99 depending on configuration. And Microsoft publishes no price at all for its Windows 365 Link thin client, routing buyers to an account team.

There is federal precedent for both halves of this, though it is old enough that I would use it only as a shape rather than a budget. The 2012 White House BYOD toolkit records the Alcohol and Tobacco Tax and Trade Bureau spending roughly $800,000 on a virtual desktop implementation, putting about 70% of its people on thin clients, avoiding a hardware refresh of roughly $2 million and netting $1.2 million. The same toolkit records Delaware replacing state-owned devices with a flat stipend of $10, $30 or $40 a month depending on voice and data, cutting per-participant device expense by 45% and departmental wireless costs by 15%. Fourteen-year-old numbers. The structure still holds; the dollars do not.

## The standards already agree, and one rule writes your endpoint out of scope entirely

NIST's practice guide for this is SP 1800-22, finalised in September 2023. Its recommended architecture is five components, none of which is "take ownership of the phone": enterprise mobility management, mobile threat defence, application vetting, a trusted execution environment supporting secure boot, and VPN. The example build rests on operating-system-level data separation, specifically Android Enterprise work profile or iOS User Enrollment, rather than full device management. That is the free tier of two consumer operating systems, sitting inside a federal reference architecture.

NIST SP 800-207, the zero trust architecture document, removes the premise the whole argument usually starts from: "Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location ... or based on asset ownership (enterprise or personally owned)." Buying the laptop does not make it trustworthy. It also requires that device authentication and authorization be a discrete function performed before a session, separate from authenticating the human.

CISA's Zero Trust Maturity Model version 2.0, April 2023, defines the worst state of the Devices pillar as an agency that "does not require visibility into devices or virtual assets used to access resources." OMB's federal zero trust strategy M-22-09, dated 26 January 2022, then makes the thin client argument in the government's own voice, carving such devices out of the endpoint-detection mandate because a device with a least-privilege design "may inhibit the use of common EDR tools but also poses less risk of malicious misuse and is consistent with zero trust principles."

And here is the strongest single sentence in any of this, from the CMMC rule at 32 C.F.R. 170.19: "An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset." The Defense Department's most demanding contractor security regime says it does not care whose laptop it is, provided nothing but keyboard, video and mouse crosses to it. Identical language covers both Level 1 and Level 2.

If you sell to defence, the dates are no longer prospective. The CMMC program rule was published on 15 October 2024 and took effect 16 December 2024. The acquisition rule that actually puts CMMC into contracts, DFARS Case 2019-D041, was published 10 September 2025 and took effect 10 November 2025, so contracting officers have been able to make it a condition of award for nine months. Level 1 is the 15 basic safeguarding requirements, requires an annual self-assessment plus an affirmation submitted to SPRS, and permits no plans of action: every requirement must be met. A false affirmation is a False Claims Act surface. Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, certified on a three-year cycle, with any conditional status closed out within 180 days or it expires.

## The new problem: AI puts data back on the endpoint you just cleaned

Everything above is about keeping data off the device. The last two years have produced a class of tools whose entire purpose is to put data on it.

**Windows Recall is the clearest case, and Microsoft shipped the problem and the mitigation on the same documentation page.** On a managed device, Recall is disabled and removed by default. On an unmanaged Copilot+ PC, which is what an employee's own laptop is, "Recall is available by default but a user has to opt in to save snapshots. Users can enable or disable Recall on their own." And then, flatly: "On unmanaged devices, currently, there aren't any built-in Conditional Access policies in Microsoft Intune or in Microsoft Entra for Recall."

You cannot condition access to your data on Recall being off, on a machine you do not manage.

The scale of what it retains is documented: 25 GB allocated at 256 GB of device storage, 75 GB at 512 GB, 150 GB at 1 TB or more, and snapshots retained indefinitely unless a retention duration is configured. Microsoft describes the mechanism without euphemism, noting that Recall uses general Windows screenshot APIs and that "it's a general security risk to allow screenshots of content that you want to prevent from being exfiltrated." The security architecture is real, with storage in a virtualization-based enclave, keys sealed to the TPM and the Recall user interface itself treated as untrusted. On a managed device two policies gate it, and disabling the first deletes any snapshots already on disk. Data-loss-prevention integration exists but enforces at the window level and does not retroactively clean snapshots already stored. Microsoft's documentation still labels the management surface as preview.

Now the part that closes the loop with the first half of this article: Recall filters remote desktop sessions from snapshots by default. Remote Desktop Connection, VMConnect, the Azure Virtual Desktop client and remote applications integrated locally are all excluded. Work done inside a streamed session does not get screenshotted. The same architecture that keeps files off the endpoint keeps the endpoint's own AI from photographing them.

**Apple's version of this problem has no employer-side answer at all on a personal device.** Apple's controls over Apple Intelligence and third-party "external intelligence" integrations require *supervised* devices. A personally owned phone under account-driven User Enrollment is not supervised, and Apple states that its BYOD enrolment mode "can apply only a limited set of payloads and restrictions" precisely because the user owns the device. Put those two documents together and the conclusion is unavoidable: an employer cannot disable Apple Intelligence or block a third-party AI integration on an employee-owned iPhone. Apple also deprecated the older restrictions-payload keys for Apple Intelligence, Siri and keyboard settings in the 26.4 releases and moved control to declarative configurations, so whatever control an admin did have carries a migration deadline.

**Local model runners create a data store nothing knows about.** LM Studio writes every conversation to disk as JSON in the user's home directory, under `.lmstudio/conversations`. That is an unencrypted record of whatever the employee discussed with a local model, sitting on a personal machine, invisible to every management tool, every data-loss-prevention product and every discovery process you have. Ollama documents where model weights land in the user profile; it does not document a conversation-history path, and I am not going to invent one.

**How common is this?** The only survey figure here with a disclosed sample is 1Password's, from October 2025: across 5,200 desk-based knowledge workers in six countries, 43% said they use AI apps to do work on personal devices and 25% use unapproved AI apps at work. The same survey reports 22% having shared company data with an AI tool to write a report or presentation, 24% sharing customer call notes, and 19% sharing employee data such as performance reviews. It is a vendor survey and should be read as one, but it discloses its methodology, which most numbers in this space do not.

Verizon's 2026 DBIR adds a measured angle from its data-loss-prevention corpus: 67% of users access AI services from non-corporate accounts on their corporate devices, and 45% of employees are now regular AI users on corporate devices, up from 15% the previous year. If that is what happens on hardware the company owns, assume worse on hardware it does not.

**The canonical leak incident is second-hand and I will label it that way.** The Samsung story, in which engineers reportedly pasted semiconductor source code, test sequences and a confidential meeting transcript into ChatGPT within about twenty days of the tool being permitted, leading to a company-wide ban on generative AI, traces to a Korean newspaper report relayed through Western coverage. Samsung published no incident report I could open. Use it as an illustration of a mechanism, not as an established set of facts.

**Browser agents are the newest version of this and both major vendors publish warnings against their own products.** That symmetry is the point.

Anthropic red-teamed Claude for Chrome across 123 test cases representing 29 attack scenarios and published the result: "Browser use without our safety mitigations showed a 23.6% attack success rate when deliberately targeted by malicious actors," reduced to 11.2% with mitigations in place. On a narrower challenge set of four browser-specific attack types, including hidden malicious form fields in a page's document object model that a human cannot see, malicious URL text and malicious tab titles, mitigations took attack success from 35.7% to 0%. Roughly one hijack in nine on the general set, published by the company selling the product. Since 18 December 2025 the extension has been available on paid plans with admin controls to enable or disable it organisation-wide and configure site allowlists and blocklists, which is the first real enterprise control surface for a browser agent.

OpenAI's warning about ChatGPT Atlas, launched 21 October 2025, is qualitative and just as blunt. Agents "are susceptible to hidden malicious instructions, which may be hidden in places such as a webpage or email," and "this could lead to stealing data from sites you're logged into or taking actions you didn't intend." OpenAI describes thousands of hours of red-teaming and then says plainly that "our safeguards will not stop every attack." Its user-side advice includes running the agent logged out. Atlas also introduces browser memories, which persist context from visited sites into the ChatGPT account, creating a second AI data store distinct from chat history, generated by ordinary browsing on whatever machine the browser runs on.

Read those two together. An agent operating inside the user's logged-in sessions inherits every session that browser holds. On a personal laptop, that includes the personal ones.

**On the assistants themselves, the contractual position is better than people assume, with one gap worth knowing.** Microsoft 365 Copilot stores the user's prompts and Copilot's responses, including citations, as tenant content, encrypted, discoverable and retention-governed through Purview, and states it is not used to train foundation models. So the AI conversation becomes a corporate record inside your boundary, which is good for discovery and bad if you had not planned for it. Copilot has been a covered workload in Microsoft's data residency commitments since 1 March 2024, but Microsoft discloses that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary. That is a real residency gap in a product sold partly on residency. OpenAI's business terms state that customer business data is not used for training by default, with AES-256 at rest and TLS 1.2 or better in transit. Anthropic's commercial terms, effective 17 June 2025, contain a flat prohibition: Anthropic may not train models on customer content from the services, and customer content is the customer's confidential information.

## The thing none of it fixes

A compromised host still sees the pixels and the keystrokes.

Every option in this article reduces where data comes to rest. Not one of them changes the fact that a streamed session is rendered on, and typed into, a machine you do not control. Hypori's own FedRAMP text says the client captures touch and sensor data and routes it upstream. If the phone is owned, the attacker is sitting between the user and everything the user sees and types, and it does not matter where the file lives.

I looked for a vendor claiming otherwise and did not find one. No documentation I read asserts protection against a compromised host. The closest thing to a mitigation on offer is device posture reporting, which asks the endpoint about its own operating system version, disk encryption state and installed applications. That is a signal from the machine under suspicion. On a host that is already owned, it is worth exactly what the attacker wants it to be worth.

That is not an argument against any of this. Reducing data at rest is worth doing, and the CMMC scoping rule shows a regulator agreeing. It is an argument against the sentence "the device does not matter." The device matters. It matters less.

## What I would actually do

In order, stopping at whichever line fits.

1. **Write the reimbursement policy this week, whatever else you do.** If you have anyone in California, Illinois, Montana, New Hampshire or South Dakota, this is a statutory duty and not a courtesy. Copy Illinois: a written, published, capped stipend with a 30-day submission window. Zero and token amounts are specifically not allowed there. It costs less than one hour of the lawyer you avoid.
2. **Fix the wage-and-hour exposure at the same time, because a policy alone is not a defence.** For non-exempt staff, either give them a way to record after-hours phone time or actually enforce the rule you wrote. The regulation says the mere promulgation of a rule against the work is not enough, and it says management must make every effort to enforce it.
3. **Under fifty people, browser-based work: start at $0.** Cloudflare Zero Trust free tier for zero-trust access and a web gateway, Chrome Enterprise Core at $0 for browser policy and extension control, plus the free work profile on Android and account-driven User Enrollment on iOS. That is a capable stack at zero software cost. Add Chrome Enterprise Premium at $6 per user per month when you need data-loss prevention and URL filtering.
4. **If you already pay for Microsoft, buy the app policy, not the device.** Intune Plan 1 at $8.00 per user per month, or Microsoft 365 Business Premium at $22.00 which includes it. Write one app protection policy for unmanaged devices and a looser one for company hardware. Use Edge for Business app protection on Windows for contractor laptops, and check whether the machine's own managing tenant runs Endpoint DLP, because that will silently block your policy.
5. **Only then consider a cloud desktop, and only for the workloads that need one.** Legacy Windows applications, a shared bookkeeping tool, anything you cannot put in a browser. Windows 365 Business at $25.60 to $36.00 per user per month is the least administrative work; Azure Virtual Desktop is cheaper on compute and more expensive in labour. Take the 30-day trial first and note that cancelling a Windows 365 Business subscription deletes the data.
6. **Buy hardware for control and supportability, not for price.** A managed Chromebook at about $450 over three years is a good device. It is not cheaper than managing the app on a device the worker already owns. If you convert existing machines, ChromeOS Flex costs nothing and gives up the hardware security chip and managed Play apps.
7. **Handle AI on the endpoint explicitly, now, in writing.** Assume you cannot turn off Recall on a personal Windows machine and cannot turn off Apple Intelligence on a personal iPhone, because you cannot. Decide which work is allowed to happen outside a streamed session at all. Ban local model runners on any machine touching regulated data, or accept an unencrypted conversation log you will never find. If anyone uses a browser agent, keep it out of the browser profile that holds your finance and administrative sessions.
8. **If you sell to defence, read 32 C.F.R. 170.19 before you spend anything.** A properly configured virtual desktop client puts the endpoint out of assessment scope. That single paragraph can be the difference between securing a fleet and not needing to.

The government's accredited tier lists at $444.33 per user per year, plus a platform fee, plus implementation, for the strongest version of an idea you can rent for $7 a month or run for nothing. The idea is the same in both cases. Make the device a window. Then be honest with yourself about the fact that someone may be standing behind it.

## Fact-check notes and sources

- **The architecture and its documented exceptions** come from Hypori's own pages and, more usefully, from the FedRAMP Marketplace product record for Hypori Government Cloud, which is written for the authorization package rather than for marketing. The client certificate in the device keystore, the upstream touch and sensor capture, and the Android keystore inside the workspace are all in that record: [FedRAMP Marketplace product data](https://www.fedramp.gov/marketplace/products.json), read 21 August 2026. The notification sanitisation, bandwidth range of 500 Kbps to 5 Mbps, absence of telephony, jailbreak detection and absence of remote wipe are from Hypori's [Department of Defense FAQ](https://www.hypori.com/resources/dod-faqs). Category drawbacks including full network dependency are Hypori's own, at [What is VMI?](https://www.hypori.com/resource-hub/what-is-vmi). No public source documents clipboard, copy-paste or file-transfer behaviour between the phone and the workspace, so I have not asserted anything about it.
- **Accreditation scope.** FedRAMP details, dates and the single agency authorization with zero reuses are from the marketplace data above; the renaming of Authorization to Certification and the January 2027 removal of Impact Levels is announced on the [FedRAMP Marketplace](https://www.fedramp.gov/marketplace/products/). Common Criteria dates are from the [Common Criteria Portal certified products list](https://www.commoncriteriaportal.org/products/index.cfm), which conflicts with Hypori's own FAQ claim that the certifications ran only to 20 February 2026; the portal shows 2027 expiries and 2026 maintenance updates, and I have used the portal. The CSfC scope caveat is NSA's own, on the [Components List](https://www.nsa.gov/Resources/Commercial-Solutions-for-Classified-Program/Components-List/). The absence of a FIPS certificate is a null result from the [NIST CMVP validated modules search](https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search) for vendor "hypori". The SOC 2 Type 2 claim is Hypori's own announcement dated 12 May 2026 and is not independently checkable, because SOC 2 reports are not public. I found no independent third-party evaluation, penetration test report or vulnerability history for the product; all "red team tested" language traces back to the vendor.
- **Prices for Hypori** are Carahsoft list prices on GSA Advantage under MAS SIN 518210C, contract 47QSWA18D008F, read 21 August 2026, one product page at a time on [GSA Advantage](https://www.gsaadvantage.gov/). Each price sits on its own catalogue entry, identified by GSIN: IL5 is 11000124783605, FedRAMP 11000124783603, CMMC 11000124783606, commercial cloud 11000124783604 and the platform fee 11000124783609. Search the catalogue for Hypori to reach them, since those detail pages are built by the site's own search and do not open from a cold link. These are list, not transaction, prices. Hypori publishes no price of its own and holds no GSA Schedule of its own; it appears on [GSA eLibrary](https://www.gsaelibrary.gsa.gov/ElibMain/searchResults.do?searchText=hypori) as a manufacturer only.
- **The three contract figures** are genuinely three different numbers for one award, PIID W519TC24C0028: $16,220,000 obligated at award per [the Defense Department's contract announcement of 17 July 2024](https://www.defense.gov/News/Contracts/Contract/Article/3841931/), "$12 million" in [Hypori's own release](https://www.hypori.com/news-and-media/army-renews-byod-program-with-hypori-for-12-million), and $28,785,780 total obligation on [USAspending](https://www.usaspending.gov/award/CONT_AWD_W519TC24C0028_9700_-NONE-_-NONE-), which also records the sole-source set-aside and the single offer received.
- **Deployment scale and funding.** "Almost 25,000" is Lt. Gen. John B. Morrison Jr., quoted in [the Army's own article](https://www.army.mil/article/273423/byod_brings_personal_devices_to_the_army_network); the 50,000 figure is Hypori's CEO as reported by [C4ISRNET, 9 July 2024](https://www.c4isrnet.com/cyber/2024/07/09/air-force-space-force-join-army-for-bring-your-own-device-enrollment/), which also carries the 11 June 2024 mandatory date. The Air Force expansion from 10,000 to 17,000 licences is [Hypori's April 2026 release](https://www.hypori.com/news-and-media/department-of-air-force-renewal-expansion-press-release). Central funding at no direct cost to units is stated in Hypori's DoD FAQ. I have deliberately not multiplied any user count by any list price.
- **Threat data, labelled by type.** Microsoft's ransomware figures are telemetry from Defender for Endpoint, in the [Microsoft Digital Defense Report 2024](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf). The 46% non-managed infostealer finding is from the [Verizon 2025 DBIR](https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf) and must be cited to the 2025 report, because the 2026 edition does not rerun that analysis. The 70% personal-device attack share is from the [Verizon 2025 Mobile Security Index](https://www.verizon.com/business/resources/T550/reports/2025-mobile-security-index.pdf), a survey of 762 professionals with data contributed by Check Point, Ivanti and Lookout; the 22% BYOD-policy compliance figure inside it is Ivanti-contributed, in a section arguing for mobile device management, and I have flagged it rather than treating it as Verizon's measurement. Device condition figures are from the [Zimperium 2025 Global Mobile Threat Report](https://zimperium.com/hubfs/Reports/2025%20Global%20Mobile%20Threat%20Report.pdf) and are device-level; Jamf's 53% is organisation-level, from [Jamf's own summary of Security 360](https://www.jamf.com/blog/jamf-360-security-report-insights/), and the two are not comparable. The [2026 DBIR](https://www.verizon.com/business/resources/Td15/reports/2026-dbir-data-breach-investigations-report.pdf) credential-abuse decline from 22% to 13% is partly an artifact of newly tracking Pretexting, and Verizon states the comparable figure would be 16%; the 40% mobile-phishing click difference rests on 35 non-email campaigns against 8,395 email ones.
- **Incidents.** The Uber quotation is from [Uber's own security update of 19 September 2022](https://www.uber.com/newsroom/security-update/). For LastPass, [the company's own post](https://blog.lastpass.com/posts/2022/12/security-incident-update-recommended-actions) confirms only that a senior DevOps engineer was targeted through vulnerable third-party software; the home-computer and media-server specifics circulating everywhere come from statements quoted in press coverage, not from a LastPass document, and I have not asserted them.
- **Employment law.** [California Labor Code section 2802](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=LAB&sectionNum=2802) including the attorney's fees provision; [Cochran v. Schwan's Home Service](https://law.justia.com/cases/california/court-of-appeal/2014/b247160.html), 228 Cal.App.4th 1137, filed 12 August 2014; [820 ILCS 115/9.5](https://www.ilga.gov/legislation/ilcs/fulltext.asp?DocName=082001150K9.5), effective 1 January 2019; [Mont. Code Ann. 39-2-701](https://archive.legmt.gov/bills/mca/title_0390/chapter_0020/part_0070/section_0010/0390-0020-0070-0010.html); [N.H. RSA 275:57](https://www.gencourt.state.nh.us/rsa/html/xxiii/275/275-57.htm); [S.D. Codified Laws 60-2-1](https://sdlegislature.gov/Statutes/60-2-1); [N.Y. Labor Law 198-c](https://www.nysenate.gov/legislation/laws/LAB/198-C), which only enforces an agreement the employer already made. Those six are the states I verified. FLSA: [29 C.F.R. 785.12](https://www.ecfr.gov/current/title-29/subtitle-B/chapter-V/subchapter-B/part-785/subpart-B/section-785.12), [785.13](https://www.ecfr.gov/current/title-29/subtitle-B/chapter-V/subchapter-B/part-785/subpart-B/section-785.13) and [785.47](https://www.ecfr.gov/current/title-29/subtitle-B/chapter-V/subchapter-B/part-785/subpart-B/section-785.47).
- **The right-to-disconnect correction.** The claim that four US states have such laws in 2026 is not supported. California's AB-2751 is recorded as "Inactive Bill - Died" on [the Legislature's own bill status page](https://leginfo.legislature.ca.gov/faces/billStatusClient.xhtml?bill_id=202320240AB2751). Australia's right is in force, per the [Fair Work Ombudsman](https://www.fairwork.gov.au/employment-conditions/hours-of-work-breaks-and-rosters/right-to-disconnect), from 26 August 2024 for employers with 15 or more employees and 26 August 2025 for smaller ones.
- **Discovery and remote wipe.** [FRCP 34(a)(1)](https://www.law.cornell.edu/rules/frcp/rule_34) supplies the "possession, custody, or control" standard, but I could not find a controlling primary authority applying it specifically to employee personal devices, and courts are split, so I have named the uncertainty rather than a rule. For [Rajaee v. Design Tech Homes](https://www.courtlistener.com/docket/5815982/rajaee-v-design-tech-homes-ltd/), No. 4:13-cv-02517 (S.D. Tex.), I verified the case, court, judge, date and disposition from the docket but could not read the opinion, so nothing here characterises the court's reasoning.
- **Regulatory hooks.** [45 C.F.R. 164.310(d)](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310) makes Disposal and Media re-use required specifications. The SEC's off-channel action of 14 August 2024, 26 firms and $392.75 million, is [SEC press release 2024-98](https://www.sec.gov/newsroom/press-releases/2024-98). I could not open the PCI DSS standard text, which sits behind a registration wall, so this piece cites no PCI requirement number.
- **Comparison prices** were read from vendor pages and official price files on 21 August 2026: [Windows 365 Business](https://www.microsoft.com/en-us/windows-365/business/all-pricing), [Windows 365 Enterprise](https://www.microsoft.com/en-us/windows-365/enterprise/all-pricing), [Windows 365 Flex](https://www.microsoft.com/en-us/windows-365/frontline/all-pricing), [the Business versus Enterprise comparison](https://learn.microsoft.com/en-us/windows-365/business-enterprise-comparison), [Windows 365 Flex mechanics](https://learn.microsoft.com/en-us/windows-365/enterprise/introduction-windows-365-flex), [Azure Virtual Desktop pricing](https://azure.microsoft.com/en-us/pricing/details/virtual-desktop/), [Amazon WorkSpaces pricing](https://aws.amazon.com/workspaces-family/workspaces/pricing/), [the WorkSpaces Thin Client](https://aws.amazon.com/workspaces-family/thin-client/pricing/), [Cloudflare Zero Trust plans](https://www.cloudflare.com/plans/zero-trust-services/), [Chrome Enterprise pricing](https://chromeenterprise.google/pricing/), [Kasm licensing](https://kasm.com/docs/latest/license.html), [Kasm Cloud Personal pricing](https://kasm.com/quote/deployment-options-small-teams), [Apache Guacamole](https://guacamole.apache.org/), [Intune pricing](https://www.microsoft.com/en-us/security/business/microsoft-intune-pricing), [Microsoft 365 Business Premium](https://www.microsoft.com/en-us/microsoft-365/business/microsoft-365-business-premium), [ChromeOS Enterprise Upgrade](https://chromeenterprise.google/os/upgrade/) and [ChromeOS Flex](https://chromeos.google/products/chromeos-flex/). AWS and Azure figures come from the providers' published price files and retail price service rather than from their marketing pages, which render prices only in a browser; I cross-checked the WorkSpaces numbers against the one worked example still visible on the live page and it matched exactly. The three-year totals in the table are arithmetic on those published rates and nothing else. Chromebook hardware prices are Lenovo's own list prices on the [Chromebook Duet 3 product page](https://www.lenovo.com/us/en/p/laptops/lenovo/lenovo-edu-chromebooks/ideapad-duet-3-chromebook-%2811-inch-qlc%29/82t6001hus) and the [Duet Gen 9 page](https://www.lenovo.com/us/en/p/laptops/lenovo/lenovo-edu-chromebooks/lenovo-chromebook-duet-gen-9-11-inch-mediatek/83hh0002us).
- **Vendors that publish no price** were each checked directly: Citrix, Omnissa, Island, Palo Alto's Prisma Access Browser, Menlo Security and Zscaler. Third-party blogs quote per-user figures for several of them. None of those figures is a vendor source and none is repeated here. Kasm's paid self-hosted tiers are likewise unpublished. The $132 per user per year figure for Cameyo by Google comes from [Computerworld's coverage of the launch](https://www.computerworld.com/article/4088825/cameyo-by-google-launches-with-chrome-enterprise-integration-gemini-ai-support.html) and appears on none of Google's own pages.
- **What the operating systems expose** is documented by their makers: [Android Device Policy](https://support.google.com/work/android/answer/12076837?hl=en), [Work Profile features](https://support.google.com/work/android/answer/9563584?hl=en) including the company-owned flag that weakens the boundary, [Apple User Enrollment](https://support.apple.com/guide/deployment/user-enrollment-and-device-management-dep23db2037d/web) and [what an employer can query under it](https://support.apple.com/guide/deployment/device-management-service-user-enrollment-dep6ae3f1d5a/web). Samsung Knox Suite prices are published one SKU at a time on [Samsung Business](https://www.samsung.com/us/business/software/knox/knox-manage/knox-suite-essentials-plan-1-year-mi-kxkmswwc210/) and [the Enterprise plan SKU](https://www.samsung.com/us/business/software/knox/knox-suite-enterprise-plan-1-year-sku-mi-kxksswwc211/).
- **Standards.** [NIST SP 1800-22](https://csrc.nist.gov/pubs/sp/1800/22/final), finalised September 2023, with the five-component architecture in [volume B](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-22.pdf); [NIST SP 800-207](https://csrc.nist.gov/pubs/sp/800/207/final); [CISA Zero Trust Maturity Model v2.0](https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf); [OMB M-22-09](https://bidenwhitehouse.archives.gov/wp-content/uploads/2022/01/M-22-09.pdf). The VDI scoping language is at [32 C.F.R. 170.19](https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170/subject-group-ECFR6d0b04c9c1e4f1a/section-170.19); the [CMMC program rule](https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program) took effect 16 December 2024 and the [acquisition rule](https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of) on 10 November 2025. The Level 1 and Level 2 requirement counts and assessment cycles are at [32 C.F.R. 170.14](https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170/subpart-C/section-170.14), [170.15](https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170/subpart-C/section-170.15) and [170.17](https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170/subpart-C/section-170.17). Several Defense Department issuance PDFs would not open for me, so no DoD instruction numbers are cited here.
- **AI on the endpoint.** Everything about Recall, including the unmanaged-device default, the absence of Conditional Access controls, the storage allocations and the remote desktop filtering, is from [Microsoft's Recall management documentation](https://learn.microsoft.com/en-us/windows/client-management/manage-recall), which still labels the feature preview; the enclave architecture is from [the Windows Experience blog of 27 September 2024](https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/). Apple's supervision requirement is in the [WWDC26 device management updates](https://support.apple.com/guide/deployment/device-management-updates-depd638aa061/web) and the User Enrollment limitation in [Apple's deployment guide](https://support.apple.com/guide/deployment/user-enrollment-and-mdm-dep23db2037d/web). LM Studio's conversation storage is documented in [its own docs](https://lmstudio.ai/docs/app/basics/chat); [Ollama's FAQ](https://docs.ollama.com/faq) documents model storage only, so no conversation path is claimed for it. The 43% and 25% figures are from [1Password's 2025 annual report](https://1password.com/press/2025/oct/annual-report-2025-the-access-trust-gap), a vendor survey of 5,200 knowledge workers with a disclosed sample. The Samsung leak account is press-sourced through [Forbes](https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/) relaying a Korean newspaper report, not a Samsung document.
- **Browser agents.** Anthropic's own attack-success numbers are published at [Piloting Claude in Chrome](https://www.anthropic.com/news/claude-for-chrome), which also carries the 18 December 2025 availability and admin controls; Anthropic notes its red-teaming was conducted in autonomous mode. OpenAI's warnings are in [Introducing ChatGPT Atlas](https://openai.com/index/introducing-chatgpt-atlas/), 21 October 2025. Assistant data handling is from [Microsoft's Copilot privacy documentation](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy), including the disclosure that Anthropic subprocessor models are currently excluded from the EU Data Boundary, [OpenAI's enterprise privacy page](https://openai.com/enterprise-privacy/) and [Anthropic's commercial terms](https://www.anthropic.com/legal/commercial-terms) effective 17 June 2025.
- **The historical federal cost cases** for thin clients and stipends come from the [2012 White House BYOD toolkit](https://obamawhitehouse.archives.gov/digitalgov/bring-your-own-device). They are primary government sources and they are fourteen years old. I have used them for structure, not for budgeting.
- **The closing point** is an absence of evidence rather than a cited denial. I found no vendor documentation claiming protection against a compromised host, and none of the products surveyed changes the fact that a streamed session is rendered and typed on the untrusted machine.

## Related reading

- [Build the guardrail before you mandate AI](/blog/ai-mandate-guardrails-small-business/): the policy half of the AI-on-the-endpoint problem, for teams about to roll something out.
- [Prompt injection when the data is the attack](/blog/ai-indirect-prompt-injection/): why a browser agent reading a hostile page is a different threat from a chatbot.
- [The three trust boundaries every AI system that acts has to draw](/blog/ai-security-three-trust-boundaries/): where to put the line when software starts taking actions on your behalf.
- [The connector permission cheat sheet](/blog/blog-connector-permissions-claude-smb/): minimum-permission sets for the tools that reach into your business data.
- [Six fraud reflexes worth building now](/blog/blog-ai-fraud-reflexes-smb-2026/): the human-side controls that catch what the technical ones miss.

*This post is informational and is not legal, security or financial advice. Statutes, case law and product prices are as published on the dates cited and change frequently. No affiliation with any vendor mentioned is implied, and mentions are nominative fair use.*


---

Canonical HTML: https://jwatte.com/blog/secure-workspace-on-any-unknown-device/
RSS: https://jwatte.com/feed.xml
JSON Feed: https://jwatte.com/feed.json
Hero image: https://jwatte.com/images/secure-workspace-on-any-unknown-device.webp
