ClearScreen
UK endpoint web blocks
without the black box.
Blocks risky domains locally, shows the reason on device, and logs it for Console review.
UK GDPR · NIS Regulations
Capabilities
The policy loop is visible from device to Console.
-
Category policies
Block UT1 content categories per Environment — adult, gambling, malware, AI chat tools, and more.
-
Allow and block lists
Tenant-wide allowlists override category blocks; blocklists add domains on top of threat feeds.
-
Threat indicator feeds
URLhaus, OpenPhish, and PhishTank domains ship in an ed25519-signed bundle refreshed every 15 minutes.
-
Local block page
Blocked DNS queries sinkhole to 127.0.0.1 with the domain, category, and source feed on screen.
-
False-positive review
Users submit a review request from the block page; Console operators decide with the original policy reason attached.
-
Device reporting
Every block writes a JSONL audit record on the endpoint and posts to the Console block feed in managed mode.
In the product
The Console, as shipped.
Real product screens — dashboard, policy, reviews, devices, audit, and sign-in.
How it works.
-
Deploy the agent
Install on Windows or Linux (macOS on request). The agent binds 127.0.0.1:53 and sets system DNS so every app gets the same verdict.
-
Set your policy
Choose blocked UT1 categories and add tenant allowlists and blocklists from the Console.
-
Review on device and in the Console
Blocked domains show a branded block page with the reason. False-positive reports land in the Console queue with device context.
Questions.
-
Where is tenant data stored?
Policy, block events, and enrollment records live in your Spot Suite Customer Environment on Cloudflare Workers and D1. Threat indicator bundles are signed at the edge and pulled by agents — no third-party DNS proxy in the path.
-
Does ClearScreen support SSO?
Yes. Console sign-in uses Microsoft Entra ID through Spot Suite OIDC at spot-cloud.spot-suite.com. Device agents authenticate with per-device enrollment credentials, not user passwords.
-
Do you decrypt TLS traffic?
No. ClearScreen enforces at DNS only. Blocked domains resolve to a local sinkhole and show a block page — there is no TLS inspection, PAC file, or network gateway in the policy path.
-
How does the 30-day trial work?
Card checkout includes a 30-day free trial per Environment. Invoice billing is available (paid from day one; no trial on invoice). Run managed mode for up to 100 endpoints. Category policy, block reporting, and audit export are included. Convert to Team when you are ready.
Spot Suite
The rest of the suite.
Seven products, one sign-in, one invoice. Each runs on its own dedicated infrastructure and is sold separately. Four you can trial today, three you can reserve a place for.
-
Secure file exchange Move files over SFTP, S3, Azure Blob and more, with a custody record per transfer. xevolve.io Open
-
Cloud cost and forecasts Daily spend from AWS, Azure, GCP and StackIT, with anomalies flagged before the close. cloud-horizons.com Open
-
TLS certificate lifecycle Find every certificate, renew it through ACME, and deploy it where it runs. automate-certificates.com Open
-
IP address management Plan CIDR blocks across Azure tenants and catch conflicts before they ship. Join waitlist
-
Joiner, mover, leaver Onboard, move and offboard staff in Microsoft 365 or Google Workspace, with a log. Join waitlist
-
UBO and sanctions screening Screen owners and counterparties against UBO and sanctions lists. Join waitlist
Start with one policy.
Deploy the agent to a pilot fleet, set UT1 categories, and review blocks on device before a wider rollout.