Databricks Secures Personal Devices for AI Workflows
Databricks IT has implemented a four-layer mobile security strategy to protect corporate data on personal devices, enabling employees to safely run AI tools like Genie on the go.

Databricks has detailed its internal mobile security framework designed to protect corporate data on personal devices without compromising employee privacy. As modern workflows shift from desktop environments to mobile phones, employees increasingly rely on communication platforms and generative AI tools such as Genie, Omnigent, and Claude Code. To support this transition safely, the company's IT division developed a layered security model that treats its own workforce as the initial testing ground for secure mobile operations.
The security architecture relies on four distinct layers: device management, authentication, zero trust network access, and application management. For device management, Databricks utilizes Account-Driven User Enrollment on iOS and Work Profile on Android. These methods isolate corporate data in an encrypted workspace without granting the company control over personal files or the ability to wipe the entire device. Access is governed by context-aware authentication that requires phishing-resistant, passwordless multi-factor authentication, alongside verification of the device's management status and network path.
To enforce continuous security, Databricks implements Zero Trust Network Access, which routes work-related traffic through a per-app virtual private network. This system constantly evaluates device health, allowing the network to automatically block compromised operating systems. At the application level, the company uses managed configurations and tenant-level controls to restrict data movement, such as preventing users from copying and pasting corporate information outside of approved applications.
Databricks IT served as the internal testing partner, or what the company calls "customer zero," to deploy the Genie mobile app under this new framework. Because the foundational security layers were already active, Genie did not require a bespoke security solution. Instead, it was deployed as a managed app that routes traffic through the secure tunnel and enforces identity controls. This collaborative effort has helped refine the security models for both Genie and Omnigent, paving the way for future secure, mobile-first enterprise applications.
This is our own summary of reporting by Databricks AI


