ClearScreen
Endpoint web blocks
without the black box.
Blocks risky domains locally, shows the reason on device, and logs it for admin review.
HIPAA-ready · NIST CSF 2.0 · CIS Controls v8 · SOC 2 TSC-aligned
Capabilities
Signed feeds, local enforcement, visible reasons
Capabilities
The policy loop is visible from device to admin.
-
Category policies
Block UT1 content categories per policy group — adult, gambling, malware, AI chat tools, and more.
-
Allow and block lists
Tenant-wide allowlists override category blocks; blocklists add domains on top of threat feeds.
-
Threat indicator feeds
URLhaus, OpenPhish, and PhishTank domains ship in an ed25519-signed bundle refreshed every 15 minutes.
-
Local block page
Blocked DNS queries sinkhole to 127.0.0.1 with the domain, category, source feed, and policy group on screen.
-
False-positive review
Users submit a review request from the block page; admins decide with the original policy reason attached.
-
Device reporting
Every block writes a JSONL audit record on the endpoint and posts to the admin block feed in managed mode.
In the product
The admin console, as shipped.
Real product screens — dashboard, policy, reviews, devices, audit, and sign-in.
How it works.
-
Deploy the agent
Install on Windows or Linux (macOS on demand). The agent binds 127.0.0.1:53 and sets system DNS so every app gets the same verdict.
-
Set policy per group
Choose blocked UT1 categories, add tenant allowlists and blocklists, and assign policy groups from the admin console.
-
Review on device and in admin
Blocked domains show a branded block page with the reason. False-positive reports land in the admin queue with device context.
Questions.
-
Where is tenant data stored?
Policy, block events, and enrollment records live in your Spot Suite Customer Environment on Cloudflare Workers and D1. Threat indicator bundles are signed at the edge and pulled by agents — no third-party DNS proxy in the path.
-
Does ClearScreen support SSO?
Yes. Admin sign-in uses Microsoft Entra ID through Spot Suite OIDC at spot-cloud.spot-suite.com. Device agents authenticate with per-device enrollment credentials, not user passwords.
-
Do you decrypt TLS traffic?
No. ClearScreen enforces at DNS only. Blocked domains resolve to a local sinkhole and show a block page — there is no TLS inspection, PAC file, or network gateway in the policy path.
-
How does the 30-day trial work?
Sign up without a credit card and run managed mode for up to 100 endpoints. Category policy, block reporting, and audit export are included. Convert to Team when you are ready.
Start with one policy group.
Deploy the agent to a pilot fleet, set UT1 categories, and review blocks on device before a wider rollout.