Fowlguard

One identity, one rulebase.

Private access from one vendor, internet access from another, and nothing at all for the agents and scripts in between: three consoles that disagree about who a person is. Fowlguard answers all three from one identity.

01

Private Access

Device Granted Granted Unseen

Access is an entitlement, not a network.

A legacy VPN puts a device on the network and trusts it from then on. Fowlguard resolves what a person’s groups allow at the moment they connect and opens only that, so a compromised laptop reaches two subnets, not the estate.

  • Direct paths, not detours. The shortest route the network allows, with a relayed one where it refuses. A hostile network slows you down; it does not shut you out.
  • The device does not decide what it may reach. We do. A tampered client cannot widen its own access.
  • One machine, one entry. Devices are recognised across reconnects, so the fleet list stays a fleet list.

What Private Access costs →

02

Internet Access

Here arrives Via a cloud proxy still going

Filtered on the device. Straight out to the internet.

A cloud proxy puts itself in the path: every request goes to somebody else’s data centre to be judged and back again. You pay for that detour on every packet, in latency, in a dependency that fails with theirs, and in a third party watching your staff.

Fowlguard decides on the device, before the connection opens. Traffic then goes where it was always going. There is no proxy in the middle, because there is no middle.

  • No detour, no chokepoint. A laptop in Sydney reaches a Sydney server directly, not by way of a scrubbing centre in another hemisphere.
  • Nothing to be down. The rules are already on the device. If our control plane is unreachable, filtering carries on and so does the internet.
  • We do not see the traffic. Almost every decision needs no network at all, and the rare one that does never says where anyone was going.
  • Where you decrypt decides whom you trust. Inspection happens on your own machine, under your own certificate. A cloud proxy does it in its data centre.
  • Some destinations should see your address. Name the ones that must arrive from your network and only those route through, with one set at the office and another away from it.
  • Report before enforce. Any rule can run report-only, so you watch it in the logs before it cuts anyone off.
  • Your block page. Your wording and branding, or your own HTML, with a route to request the thing that was blocked.

Rules are categories, hostnames and keywords, scoped to a person or a group. Where two overlap there is one answer, the console shows which rule gave it, and you can reorder them.

What Internet Access costs →

03

Application Control

crawler CI runner not a browser

Not every caller is a person, and most organisations cannot name one of them.

Part of both of the above, not a third thing to buy. A caller reaching your systems and one leaving your devices are the same question in two directions.

Crawlers, scrapers, CI runners and AI agents are the fastest-growing share of what crosses a network and the least accounted for. A rulebase written for people has nothing to say about them.

Fowlguard names what is calling, gives you one row per agent, and lets you give each one an owner. An agent nobody will claim is the finding.

  • What it says, and what it is. What a caller calls itself is a claim it chose, so it is checked against evidence it does not get to choose.
  • Inbound and outbound are different problems. Somebody else’s crawler reading what you publish is not your own people sending work to a model, so they are never added together.
  • Callers, never conversations. No prompt or response content is read, stored or scored to identify a caller.

Included with both, see pricing →

04

Productivity Tools

In development

The everyday suite: mail, docs, sheets and meetings.

The tools a team spends its day in, built as one suite rather than assembled from four vendors.

Standing access is the thing you are trying to fix.

Most breaches do not start with a broken door. They start with a key somebody was given for one afternoon two years ago and nobody took back, because taking it back was a job and leaving it was not.

So access can be given for a stated length of time and expire on its own, and the way in to a server’s console is a brokered session rather than a port left open.

Just-in-time access

Just-in-time grants ask for how long, and the approver sets the duration. The approval is the change: the grant is written on approve and removed when the clock runs out. Nobody edits a rulebase, and nobody has to remember to close it.

Fowlguard Remote

Administrative protocols are the ones worth never exposing to the internet. Fowlguard Remote brokers them: a session tied to a person and a grant, opened from the console.

What a session may do

Being let in is not the same as being allowed to do anything. A session privilege policy governs what a brokered session may do, clipboard and screen recording included.

A record either way

Who asked, who approved, for how long, and what happened. “Who had access to that box in March” is a query, not an archaeology project.

The same product, at home.

Internet Access does not need an office to be useful. The same filtering, on the same device, on every network it joins, which is the part a home router cannot do.

It travels with the laptop

A router filters the house. A child on school wifi, a phone on mobile data, a laptop in a cafe is past it. These rules live on the device.

No family browsing in a vendor's logs

Consumer filtering usually means pointing your household DNS at a company that then sees every name anyone looks up. Your family’s browsing is not a dataset we hold.

It does not slow the house down

Nothing is routed through us, so streaming, games and calls take the path they always took.

A page that explains itself

When something is blocked, the block page says so in your own words and offers a way to ask for it. Personal covers up to 10 people and unlimited devices.

Your directory, actually read.

Every rule here resolves against a person’s groups, so the groups have to be right. Most products take whatever their provisioning feed sent and call it the directory.

SCIM, and then a question

SCIM pushes the users and groups your identity provider was configured to send. We query your directory as well, so a group outside provisioning scope is still one you can write policy against.

Distribution lists count

Provisioning covers users and security groups and never a mail-enabled distribution list. Asking returns it; waiting for a push never will.

Nested membership resolves

SCIM sends direct members only, so someone who belongs through another group is simply absent. An approver who does not resolve is an approval nobody can give.

Your directory, wherever it is

Microsoft Graph, PingOne, or an on-premises Active Directory or LDAP reached through a Router, without publishing it to anything.

The parts nobody demos, and everybody needs.

A security product is judged on its worst day, not its demo. These are the pieces that matter when something has gone wrong and somebody is asking you what happened.

Access logs

Every connection and every block, filterable by user, device and host.

Rollout visibility

The console shows which devices have picked up the current policy, so “saved” and “in force” stay distinguishable.

Groups, routes and limits

Entitlement and bandwidth defined once, applied per group or per person, stricter of the two winning.

See it against your own traffic.

Stand up the control plane, enrol a few devices, and have a rule in force the same hour. Report-only first is an option, not a phase you have to pass through.

© 2026 Fowlguard Platform Pricing Resources Company Security hello@fowlguard.com