Managing Work Devices

Everyone receives a new Mac when they join Anedot. We centrally manage and secure these devices with Apple Business Manager (ABM) which reduces our exposure to security incidents. APM applies a standard configuration to every device (e.g. enable disk encryption, firewall, password rules), and it will ensure the apps have the latest security updates applied. APM also allows us to remotely wipe devices should they be lost, or when an employee leaves the company.

This doesn’t mean you are being monitored or tracked! APM is a configuration management system, not a panopticon.

Access to code and secrets

Knowing our devices are safe and secure allows us to entrust our work computers with access to sensitive systems like Vault, and our internal VPN and remote servers. This means installing the VPN, checking out Anedot code, and storing secrets must only be done on a managed work device, not a personal device.

Please do not keep any personal data on your Anedot-issued laptop. You should maintain a separate, personally-owned machine if you need a home computer. The company reserves the right to and may be required to confiscate your laptop or its data at any point.

Mobile devices, Windows and Linux

Devices running Android, iOS/iPadOS, Windows or Linux are currently unmanaged. It’s fine to install our web apps on these devices to access work projects and email, but since they’re unmanaged – and therefore ‘untrusted’ – it’s not okay to store Anedot code or secrets on them. If you're coding or accessing secure systems, you should be doing so on a APM-managed Mac.