ClearScreen

EU endpoint web blocks
without the black box.

Blocks risky domains locally, shows the reason on device, and logs it for Console review.

GDPR · DORA · NIS2

Capabilities

The policy loop is visible from device to Console.

  • Category policies

    Block UT1 content categories per Environment — adult, gambling, malware, AI chat tools, and more.

  • Allow and block lists

    Tenant-wide allowlists override category blocks; blocklists add domains on top of threat feeds.

  • Threat indicator feeds

    URLhaus, OpenPhish, and PhishTank domains ship in an ed25519-signed bundle refreshed every 15 minutes.

  • Local block page

    Blocked DNS queries sinkhole to 127.0.0.1 with the domain, category, and source feed on screen.

  • False-positive review

    Users submit a review request from the block page; Console operators decide with the original policy reason attached.

  • Device reporting

    Every block writes a JSONL audit record on the endpoint and posts to the Console block feed in managed mode.

In the product

The Console, as shipped.

Real product screens — dashboard, policy, reviews, devices, audit, and sign-in.

ClearScreen dashboard
ClearScreen policy screen
ClearScreen reviews screen
ClearScreen devices screen
ClearScreen audit screen
ClearScreen sign-in screen

Dashboard — devices, blocks, and open reviews

How it works.

  1. Deploy the agent

    Install on Windows or Linux (macOS on request). The agent binds 127.0.0.1:53 and sets system DNS so every app gets the same verdict.

  2. Set your policy

    Choose blocked UT1 categories and add tenant allowlists and blocklists from the Console.

  3. Review on device and in the Console

    Blocked domains show a branded block page with the reason. False-positive reports land in the Console queue with device context.

Questions.

  • Where is tenant data stored?

    Policy, block events, and enrollment records live in your Spot Suite Customer Environment on Cloudflare Workers and D1. Threat indicator bundles are signed at the edge and pulled by agents — no third-party DNS proxy in the path.

  • Does ClearScreen support SSO?

    Yes. Console sign-in uses Microsoft Entra ID through Spot Suite OIDC at spot-cloud.spot-suite.com. Device agents authenticate with per-device enrollment credentials, not user passwords.

  • Do you decrypt TLS traffic?

    No. ClearScreen enforces at DNS only. Blocked domains resolve to a local sinkhole and show a block page — there is no TLS inspection, PAC file, or network gateway in the policy path.

  • How does the 30-day trial work?

    Card checkout includes a 30-day free trial per Environment. Invoice billing is available (paid from day one; no trial on invoice). Run managed mode for up to 100 endpoints. Category policy, block reporting, and audit export are included. Convert to Team when you are ready.

Start with one policy.

Deploy the agent to a pilot fleet, set UT1 categories, and review blocks on device before a wider rollout.