Private access from one vendor, internet access from another, and nothing at all for the agents and scripts in between: three consoles that disagree about who a person is. Fowlguard answers all three from one identity.
Access is an entitlement, not a network.
A legacy VPN puts a device on the network and trusts it from then on. Fowlguard resolves what a person’s groups allow at the moment they connect and opens only that, so a compromised laptop reaches two subnets, not the estate.
Filtered on the device. Straight out to the internet.
A cloud proxy puts itself in the path: every request goes to somebody else’s data centre to be judged and back again. You pay for that detour on every packet, in latency, in a dependency that fails with theirs, and in a third party watching your staff.
Fowlguard decides on the device, before the connection opens. Traffic then goes where it was always going. There is no proxy in the middle, because there is no middle.
Rules are categories, hostnames and keywords, scoped to a person or a group. Where two overlap there is one answer, the console shows which rule gave it, and you can reorder them.
Not every caller is a person, and most organisations cannot name one of them.
Part of both of the above, not a third thing to buy. A caller reaching your systems and one leaving your devices are the same question in two directions.
Crawlers, scrapers, CI runners and AI agents are the fastest-growing share of what crosses a network and the least accounted for. A rulebase written for people has nothing to say about them.
Fowlguard names what is calling, gives you one row per agent, and lets you give each one an owner. An agent nobody will claim is the finding.
The everyday suite: mail, docs, sheets and meetings.
The tools a team spends its day in, built as one suite rather than assembled from four vendors.
Most breaches do not start with a broken door. They start with a key somebody was given for one afternoon two years ago and nobody took back, because taking it back was a job and leaving it was not.
So access can be given for a stated length of time and expire on its own, and the way in to a server’s console is a brokered session rather than a port left open.
Just-in-time grants ask for how long, and the approver sets the duration. The approval is the change: the grant is written on approve and removed when the clock runs out. Nobody edits a rulebase, and nobody has to remember to close it.
Administrative protocols are the ones worth never exposing to the internet. Fowlguard Remote brokers them: a session tied to a person and a grant, opened from the console.
Being let in is not the same as being allowed to do anything. A session privilege policy governs what a brokered session may do, clipboard and screen recording included.
Who asked, who approved, for how long, and what happened. “Who had access to that box in March” is a query, not an archaeology project.
Internet Access does not need an office to be useful. The same filtering, on the same device, on every network it joins, which is the part a home router cannot do.
A router filters the house. A child on school wifi, a phone on mobile data, a laptop in a cafe is past it. These rules live on the device.
Consumer filtering usually means pointing your household DNS at a company that then sees every name anyone looks up. Your family’s browsing is not a dataset we hold.
Nothing is routed through us, so streaming, games and calls take the path they always took.
When something is blocked, the block page says so in your own words and offers a way to ask for it. Personal covers up to 10 people and unlimited devices.
Every rule here resolves against a person’s groups, so the groups have to be right. Most products take whatever their provisioning feed sent and call it the directory.
SCIM pushes the users and groups your identity provider was configured to send. We query your directory as well, so a group outside provisioning scope is still one you can write policy against.
Provisioning covers users and security groups and never a mail-enabled distribution list. Asking returns it; waiting for a push never will.
SCIM sends direct members only, so someone who belongs through another group is simply absent. An approver who does not resolve is an approval nobody can give.
Microsoft Graph, PingOne, or an on-premises Active Directory or LDAP reached through a Router, without publishing it to anything.
A security product is judged on its worst day, not its demo. These are the pieces that matter when something has gone wrong and somebody is asking you what happened.
Every connection and every block, filterable by user, device and host.
The console shows which devices have picked up the current policy, so “saved” and “in force” stay distinguishable.
Entitlement and bandwidth defined once, applied per group or per person, stricter of the two winning.
Stand up the control plane, enrol a few devices, and have a rule in force the same hour. Report-only first is an option, not a phase you have to pass through.