Device Agent-to-Platform communication: confirming mTLS and TLS encryption for security review
Android
Title: Esper Agent–platform encryption — confirming mTLS for security reviewsWhen a security team asks for confirmation of encryption standards between managed devices and the Esper platform, Esper uses mutual TLS (mTLS) for all control plane communications between the Esper Agent and the Esper platform.
Why this matters
mTLS requires both the Esper Agent on the device and the Esper platform to authenticate each other using certificates before any management command, configuration, or policy data is exchanged. This is stronger than standard TLS, which only verifies the server. Without mutual authentication, a compromised network could allow an unauthorized party to intercept or spoof management traffic.
What Esper confirms about Agent–platform encryption
The following statements apply to all Esper Agent–to–platform control plane communications on Android and are suitable for use in security questionnaires, audit responses, and compliance documentation:
- TLS version: All communications between the Esper Agent and the Esper platform are encrypted using TLS 1.2 or higher.
- Mutual authentication (mTLS): All control plane communications use mutual TLS. Both the Esper Agent and the Esper platform verify each other's identity using certificates before any data is exchanged.
- Network coverage: TLS and mTLS protections apply to all IP network transports, including Wi-Fi, cellular, and any other IP-based network. They are not limited to Wi-Fi.
- Threat protection: mTLS protects against interception, tampering, and man-in-the-middle (MITM) attacks by verifying the identity of both endpoints.
- Scope — control plane: In Esper's architecture, control plane communications include all management commands, device configuration, and policy enforcement traffic between the Esper Agent and the Esper platform.
Using this information in a security review
The statements above can be cited directly in security questionnaires, internal audit responses, and compliance documentation to confirm Esper's control plane security architecture.
If a formal written artifact is required — such as a security attestation letter, SOC 2 Type II report, or third-party audit summary — contact Esper Support to request the appropriate document from Esper's security and compliance team.
Scope note for Linux devices
The encryption details in this article apply specifically to the Esper Agent on Android. If your security review covers Linux-managed devices, contact Esper Support to confirm the applicable encryption standards for that environment before including those devices in your documentation.
If this doesn't resolve it
If your security team requires technical details beyond what is listed here — such as specific cipher suites, certificate issuance and rotation procedures, mTLS implementation details at the infrastructure layer, or signed attestation documents — contact Esper Support with the following information:
- The specific questions or requirements from your security team or auditor
- The type of documentation needed (for example, attestation letter, completed questionnaire, audit report)
- Any deadline imposed by your compliance or audit process
Esper's security and compliance team will provide a detailed technical response appropriate for your review.
Still need help?
If you have questions about mTLS or TLS encryption configurations for your Device Agent-to-Platform communication, please submit a support ticket and include your Device Agent version, platform environment details, and any certificate or encryption-related errors you're encountering.
Please sign in to leave a comment.
Comments
0 comments