FAQ

    Questions, answered.

    What you need to evaluate Smplify, whether you’re building it into a product or running your own fleet.

    General Questions

    Smplify is API-first device management infrastructure for Apple, Windows and Linux. You describe what should be true of your devices, and Smplify keeps it true. Build it into your product, or run your fleet from the tools you already use (the API, the CLI or AI agents), with people approving what matters.

    Traditional tools are built for a person clicking through a console. Smplify is built for automation: your product, scripts and AI agents drive it through one API, and Approval Gates decide what needs a person’s sign-off. There’s no endpoint agent on Apple and Windows, and your customers see your brand, not ours.

    On Apple and Windows, nothing of ours runs on the device. We use each platform’s own management protocol, so there’s no background app to deploy, update or troubleshoot, and nothing that conflicts with the endpoint security agent you already run. Linux is the exception: it runs a lightweight Smplify service (smplifyd).

    Open-source device management projects are great for experimentation, but you host, secure, scale and maintain everything yourself, from certificates to OS changes. Smplify gives you the same control on production-grade infrastructure: multi-tenancy, RBAC, automated certificates and APIs built for embedding, without the operational burden.

    Three kinds of teams:

    • Platform builders adding device management to their product (security, IT management, identity and vertical SaaS)
    • MSPs and MSSPs managing fleets for many clients
    • Enterprise IT and security teams automating their own fleet

    If you want a console to click through rather than an API or automation, a traditional tool is a better fit.

    Platform & Features

    • Full-spec Apple management: iOS, iPadOS, macOS, tvOS, watchOS, visionOS
    • Windows management through native CSPs
    • Linux management through a lightweight Smplify service
    • Android via AMAPI coming soon
    • Approval Gates on every action: automatic, notify, approve, two-person or deny
    • REST API, CLI and MCP server
    • Webhook events for real-time updates
    • Privilege-grade RBAC with a multi-tenant hierarchy
    • Automated Device Enrollment (ADE) for zero-touch provisioning
    • Certificate hosting and management
    • Hosted by us, or self-hosted in your own jurisdiction
    • Optional hosted UI (or build your own)
    • Usage-based pricing: pay only when devices enroll

    Yes. Smplify manages all required certificates for Apple device management, including APNS (Apple Push Notification Service), ADE (Automated Device Enrollment) tokens, and MDM identity certificates.

    We handle setup, renewal, and compliance so you don’t have to.

    Smplify supports global portability, devices can move between regions (e.g., EU to US) without re-enrollment.

    We use a global root Certificate Authority (CA) with per-cluster intermediate and issuing CAs. This enables seamless migration across clusters or regions while keeping private keys local and secure.

    The result: lower latency, simpler operations, and no compromise on security.

    Security & Compliance

    Yes. Security is built into every layer:

    • End-to-end encryption for all device communication
    • Multi-tenant RBAC with full data isolation
    • Secure API authentication
    • Regular security audits
    • SOC 2 Type II in progress

    Visit our Trust Center at trust.smplify.com for current security documentation.

    Wherever you choose. We can host in the region you pick, or you can self-host Smplify as a Kubernetes app in your own cloud, data center or sovereign provider, so device data stays in your jurisdiction. Data is encrypted in transit and at rest either way.

    Integration & Architecture

    Yes. Smplify is designed to embed into your platform via API. You control the UI, workflows, and user experience.

    We also provide an optional hosted UI you can use while you build your own integration, or as a fallback for advanced features.

    Smplify is built from the ground up for secure, scalable multi-tenant environments.

    You can serve multiple customers or teams from a single backend and segment access by customer, region, department, or any structure you need. Privilege-grade RBAC lets you define precisely who has access to what, across tenants, users, and device groups.

    Privilege-grade, multi-tenant RBAC: custom roles built from fine-grained privileges, scoped per asset, tag or tenant. A junior admin can request what a senior admin must confirm.

    Pricing & Implementation

    Usage-based. You pay only when devices enroll.

    No upfront costs. No per-seat licenses. Pricing scales with your business.

    Yes. Smplify is designed to support flexible billing models, including per-device billing, usage tracking, and partner markup.

    A working integration typically takes 2–4 weeks, depending on how deeply you integrate.

    We provide comprehensive APIs, documentation, and engineering support to accelerate development.

    Three approaches, depending on your goals:

    Option 1: Use the endpoint agent you already ship (low effort)

    If your product already includes an endpoint agent, it can deploy Smplify-managed profiles without an API integration. Your customers never see the Smplify name.

    Option 2: Selective API Integration (Moderate Effort)

    Integrate a focused set of APIs to display device data, patch status, and actions in your platform. Use Smplify’s optional hosted UI for full device management with minimal engineering effort.

    Option 3: Full Native Integration (Greater Effort)

    Build a fully embedded device management experience using Smplify’s comprehensive API. Support enrollment, policy management, patching, and reporting, all from within your existing portal.

    Every Smplify customer gets direct access to our engineering team.

    • Technical documentation and API references
    • Integration guides and SDKs
    • Professional services for custom integration, architecture reviews, and ongoing technical advisory

    Migration

    Yes. Apple supports seamless MDM migration with no device erasure required. The Smplify CLI includes migration workflows to make this straightforward.

    See Apple’s documentation: Migrate managed devices to another device management service

    The Smplify CLI includes step-by-step migration workflows that guide you through moving devices from an existing MDM platform to Smplify.

    We don’t believe in lock-in. Smplify follows open standards, and Apple’s migration support means devices can move to another service without being erased.

    Yes. Thanks to our RBAC model, you can transfer tenant ownership between accounts without re-enrolling devices, useful for acquisitions, partner handoffs, or internal restructuring.

    AI, MCP & Compliance

    Approval Gates. Every action, whether from a person, a script or an agent, meets the same gate. You set a tier per class of action: automatic, notify, approve, two-person or deny. Tiers tighten automatically for agent identities and large changes, and the requester can never approve their own request.

    Yes. The Smplify MCP server exposes real device data, real schemas, and real enforcement to AI agents. Every profile it generates is deployable, not theoretical.

    Your AI layer can query live device state, generate compliant configuration profiles, and enforce baselines, all through natural language or agentic workflows. No retrofitting required.

    Yes. The CLI has mSCP compliance workflows built in, and it works as a skill for AI coding agents. It caches payload schemas locally and filters results before they reach the model, so an agent looking for the 37 devices that match a condition out of 10,000 doesn’t send all 10,000 through the model. We support both the CLI and the MCP server; use whichever fits your workflow.

    The CLI supports all mSCP baselines: NIST 800-53, DISA STIG, CMMC, CIS, and CNSSI, or provide your own via an mSCP manifest. See the Compliance page for details.

    Still Have Questions?

    Whether you’re exploring Smplify or ready to integrate, we’d love to hear from you. Want to hear more about our philosophy? Listen to Episode 448 of the Mac Admins Podcast.