Device Security Across All Platforms
Device Hardening
We lock down your devices using the same hardening checklists we use on our own machines. From full-disk encryption and firewall configuration on desktops to VPN, biometric locks, and authenticator hardening on mobile — every setting verified and documented with a before/after report.
How It Works
Pre-Session Snapshot
We document your device's current security state — what's enabled, what's missing, what's misconfigured. This becomes the "before" baseline in your report.
Guided Implementation
We walk through each setting together via screen share. You see exactly what we're changing and why. Every change is explained and reversible. We don't install anything without your understanding and approval.
Full 15-Point Checklist
Every device gets the same thorough treatment — encryption, firewall, update policy, user separation, DNS security, recovery keys, and more. The same checklist we use on every engagement, every time.
Verification & Report
After implementation, we verify every setting is active. You receive a hardening report showing all 15 points checked with before/after status, your recovery key location, and any recommendations for follow-up.
Platforms We Harden
macOS
- FileVault full-disk encryption
- Application Firewall + Stealth Mode
- Gatekeeper & XProtect verification
- Admin/Standard user separation
- Login items & Launch Agents audit
- DNS-level ad/malware blocking
- Find My Mac + Activation Lock
- Software updates enforced
Windows
- BitLocker full-disk encryption
- Windows Defender Firewall config
- SMBv1 disabled
- Standard account for daily use
- Startup program audit
- Automatic updates enforced
- Screen lock & timeout settings
- Remote desktop disabled
Linux
- LUKS full-disk encryption
- UFW/iptables firewall configuration
- SSH hardening (key-only, non-standard port)
- Sudo access audit & separation
- Unnecessary services disabled
- Automatic security updates
- AppArmor/SELinux enforcement
- DNS-level ad/malware blocking
Mobile Hardening
We lock down what matters most on mobile — authentication, network security, and data protection.
iPhone / iPad
- Lockdown Mode evaluation & setup
- VPN always-on configuration
- Password manager + authenticator app
- Advanced Data Protection enabled
- Find My + Stolen Device Protection
- App permissions audit
- Notification previews hidden when locked
Android
- VPN always-on configuration
- Password manager + authenticator app
- PCAPdroid / NetGuard firewall
- Google Advanced Protection enrollment
- App permissions audit & cleanup
- 2G network disabled
- Notification previews hidden when locked
All Mobile — Core
- Strong PIN/biometric lock
- Signal Messenger installed
- Bluetooth off when not in use
- Auto-join WiFi disabled
- SIM PIN lock enabled
- Emergency contacts configured
- Cloud backup encryption verified
Our 15-Point Hardening Checklist
The same checklist we use on every device, every time. Consistent, thorough, documented.
Preview: Mac Hardening Checklist
Sample Hardening Report
Every engagement includes a completion report documenting what was changed and verified.
macOS Device Hardening
15-point security checklist applied to MacBook Pro (Apple M2, macOS Sonoma 14.5)
Overview
Full device hardening session covering disk encryption, firewall configuration, user account separation, login item audit, DNS security, and recovery configuration. All changes verified post-implementation. Device remained fully functional throughout.
| Control | Before | After | Status | |
|---|---|---|---|---|
| FileVault | Off | → | On (encrypting) | Fixed |
| Firewall | Off | → | On + Stealth Mode | Fixed |
| User Account | Admin (daily use) | → | Standard + separate Admin | Fixed |
| Auto-Lock | Never | → | 2 minutes | Fixed |
| DNS | ISP default | → | NextDNS (encrypted) | Fixed |
| Gatekeeper | App Store + ID'd devs | → | App Store + ID'd devs | Pass |
What You Get
- Full 15-point hardening applied to your device
- Full-disk encryption enabled and verified (FileVault, BitLocker, or LUKS)
- Firewall configured and tested (stealth mode where supported)
- Admin/Standard user separation implemented
- Login items & startup programs audited and cleaned
- DNS-level ad and malware blocking configured
- Recovery key generated and securely stored
- Before/after documentation proving every change
- Written hardening report for your records