Breaking / The app is the endpoint
Blue Cedar turns mobile security into a release step ◆ From Mocana spinout to no-code protection ◆ A bank planned a 1,200-branch rollout

01 / Company profile Cybersecurity · Enterprise software

The Phone Wasn't the Problem. The App Was.

Blue Cedar made a bet that companies cannot control every phone carrying their data. Its answer is to put the guardrails inside the mobile app - then make the release process repeatable.

A branch employee needs to approve a loan. The information sits behind a bank firewall; the employee's phone belongs to the employee. Asking for a company-managed device sounds tidy until the bank's own mobile program runs on bring-your-own-device rules. Asking for a laptop sends the work back to the slow process the app was meant to replace. This was the bind described in a Canadian bank case study published by Blue Cedar: the workflow mattered, the phone could not be commandeered, and security had become the bottleneck.

The short version

  • Blue Cedar puts encryption, runtime checks and network controls inside Android and iOS apps.
  • Its no-code service can enhance a compiled app, then repeat that work when the app changes.
  • Its cloud platform ties security to import, signing and distribution workflows.
  • The most useful case is an organization with sensitive apps on phones it does not manage.

The bank said it piloted Blue Cedar against other vendors and selected its app-level controls. The mobile app could reach backend systems through an in-app secure connection without a device agent or a phone-wide VPN. By 2020, the bank was planning adoption across 1,200 Canadian branches. That is a planned rollout reported in a vendor case study, not a measured count of finished installations. The distinction matters. So does the practical point: an ordinary phone could do a job once reserved for a desktop without giving the bank control over everything else on it.

1,200

Canadian branches in the bank's planned rollout after its pilot.

Blue Cedar customer case study · 2020

Move the lock, keep the key

Blue Cedar's central idea is almost annoyingly simple. A company may not own the phone, but it can still set rules for the app that handles its data. Its software can encrypt information stored by that app, check device posture, restrict copying or screenshots, detect tampering and run a private connection from the app to protected services. The controls travel with the application. Personal apps on the same device need not enter the company's security arrangement.

The alternative was familiar in 2016, when Blue Cedar spun out of security firm Mocana: manage the device, install an agent, and build a perimeter around the phone. That works when the organization owns the hardware and users accept enrollment. It grows awkward with contractors, customers, suppliers and employees who carry their own devices. Blue Cedar inherited Mocana's Atlas technology and called the app the endpoint. Its launch announcement said Atlas already served more than 150 customers and over a million users of secured apps. Those figures belong to the platform at the time of the spinout; they are not a current Blue Cedar census.

Kevin Fox, co-founder and CEO of Blue Cedar
The person behind the perimeterKevin Fox, Blue Cedar's co-founder and current CEO, worked on Atlas at Mocana before the spinout. The security team took its old idea into a new company.

Fox, now chief executive after serving as CTO, had been Mocana's vice president of engineering. His background also includes network and endpoint security work at Cisco. That pedigree explains the product's unusual emphasis: Blue Cedar talks about a mobile app as if it were a small network with its own boundary, traffic rules and incident reporting. The app does not merely hold a login screen. It becomes a place where policy can be enforced.

“We believe that mobile communications security starts by securing the app.”John Aisien, Blue Cedar CEO at the time, 2017

A shortcut with moving parts

The second act was to take security integration out of the developer's queue. Blue Cedar's Enhance service works on compiled app binaries. A team uploads an app, selects supported controls, and produces an enhanced version. That is the promise behind its no-code pitch: the app developer does not have to hand-wire a security SDK into every release. Blue Cedar has said a manually secured app could take up to five weeks; that is the company's own estimate, rather than a universal industry price tag. The actual software subscription price is not published on its editions page.

The repeatable release sequence described in Blue Cedar's platform materials.

That workflow became a product in its own right. The Blue Cedar Platform can import builds from GitHub or GitLab, add Blue Cedar or partner controls, manage signing steps and move apps toward endpoint managers or stores. A compliance team gets an activity trail. A developer gets fewer handoffs. A security team gets another chance to apply policy when the app changes. This is where the company fits in the market: between mobile app builders, mobile device management systems and the people responsible for releasing software that handles sensitive information.

Blue Cedar illustration showing a many-armed character connecting app development and deployment tools
The product, as an octopusBlue Cedar's own drawing gives its platform eight arms. Mobile releases have enough handoffs to keep all of them occupied.

The company offers several kinds of protection under Blue Cedar App Security. Code obfuscation and encryption aim to make reverse engineering harder. Runtime application self-protection watches for tampering, debugging, rooted or jailbroken devices, emulators and network interception. Data controls cover local storage, authentication and loss prevention. In-app connectivity can give a single app access to a protected service without opening a phone-wide tunnel. Some policies can run on-device when the app is offline. The newer company pitch adds a distributed sensor mesh, with incident data from protected apps feeding cloud analysis and AI-assisted threat intelligence; the public material describes capabilities, not independently verified detection rates.

The customer who could not own the phone

Lockheed Martin offered an early proof of fit. In 2017 it selected Blue Cedar security for UCP Communicator, a mobile app meant to connect iOS and Android devices with secure radio and cellular communications used by defense and first-responder teams. The point was not to make every ordinary phone a military radio. It was to extend a communications system to people carrying commercial smartphones, while putting encryption and connection controls in the app they downloaded. Lockheed Martin also said it would distribute Blue Cedar technology to customers and prospects.

Blue Cedar later worked with Microsoft on an accelerator for Intune controls and built one for BlackBerry Dynamics. The BlackBerry work won the company's 2019 ISV Innovation Award. These partnerships reveal another part of the business model: Blue Cedar can sell its own controls and also automate the insertion of someone else's. For an enterprise already committed to Intune or BlackBerry, the nuisance is often the manual integration and maintenance of the security libraries, not the lack of a security vendor.

The bill, in public view: Blue Cedar raised $10 million in a 2016 Series A and $17 million in a 2019 Series B. Those are the company's financing costs, not customer prices. Its public editions page compares features but shows no list price.

The company sells enterprise software to corporations, governments and independent software vendors. Its site displays a broad list of customer logos, though a logo wall says little about contract size or present usage. The Canadian bank case gives more texture. Before the pilot, compliance workflows lived on laptops and desktops and completion was too low, according to Blue Cedar. The bank could not require device management for employees' personal phones. After the pilot, it reported a sharp improvement in workflow completion and planned national branch adoption. That story explains the purchase more clearly than any promise of “military-grade” protection: the work could move to mobile because the security rules no longer needed to own the device.

What travels, and what does not

A reader can copy the decision pattern without copying the vendor. Start with one mobile workflow blocked by device ownership or repeated security integration. Identify the data inside the app, the backend services it reaches and the controls that must work offline. Run a pilot on real personal devices. Compare the release effort and user friction with a managed-device approach. Then repeat the integration on a new app version, because an elegant first release is little use if the next update restores the bottleneck.

The shortcut does have edges. Blue Cedar's documentation says some enhancement flows strip iOS app extensions. Android apps already minified or obfuscated need special handling; without it, an enhanced app may not run properly. Adding code for multiple Android architectures can also enlarge the binary. These are engineering facts, not an indictment. They are the reason a pilot needs the actual app, its build settings and its signing process. A no-code button cannot repeal the structure of the binary it modifies.

That is Blue Cedar's most interesting lesson. The company began by questioning ownership of the phone. It ended up doing much of its work in the unromantic last mile of software delivery: import, enhance, sign, distribute, do it again. Mobile security tends to be sold as a wall. Blue Cedar makes a better case when it looks like a well-rehearsed door.