Policy filtering

Policy filtering before traffic leaves the browser path

Set policy over categories and domains and enforce it before traffic leaves the browser path — clear control you configure, not a black box.

Baseline categories

The gateway blocks known high-risk and prohibited-use categories using a curated, versioned category list and operational deny rules.

  • Malware and phishing
  • Fraud and abuse
  • Adult content by policy
  • Weapons and drugs marketplaces

Technical boundary

HTTPS page content is not inspected on the browser path. Filtering is based on domains, network metadata and a versioned category list.

  • No TLS interception on the browser path
  • Domain / category controls
  • Allow and deny overrides

US egress for controlled web testing