Product tour
See the whole thing in five minutes.
Five stops, from the first sign-in to a rule that is enforced and logged. Every screen below is the real product layout with example data.
| Area | What it shows |
|---|---|
| My Access | Systems you can reach |
| Users | People and groups |
| Endpoints | Every enrolled device |
| Access Requests | Who is waiting on you |
| Logs | Access, audit and endpoint |
People use the account they already have.
Your organisation signs in through Google, Microsoft or your own SAML 2.0 provider. Users and groups can arrive by SCIM, so nobody is typed in twice.
- Email first, then your organisation's sign-in
- A second factor from an authenticator app
- Join rules decide who may sign up with your domain
One app on the device does the work.
Fowlguard Connect brings up the tunnel and holds the rules on the device. Press Connect, sign in when the browser opens, and you reach the systems you have been granted.
- Windows, macOS and Linux
- Device posture reported by the device
- Ask for access from the app
- Device
- HP-LAP-042 · Compliant
- Can reach
- 2 systems
- Web rules
- Enforced on this device
Say who, what and what happens.
Rules are categories, hostnames and keywords, scoped to a person or a group. Global rules set the floor, and a group's rules are merged over them.
- Rules apply in the order shown
- One answer where two overlap
- Your own categories alongside ours
Report-only shows who it would stop.
A new rule can run in report-only. The logs show what it would have caught, and nobody loses access while you check.
- See the effect before anyone is blocked
- Fix the rule, not the fallout
- Write your block page before you switch
| Time | Person | Site | Result |
|---|---|---|---|
| 09:41 | Sam Reyes | share.example.net | Would Block |
| 09:40 | Lena Park | docs.harborpine.example | Allow |
| 09:38 | Sam Reyes | files.example.org | Would Block |
Switch it on, and the log names the rule.
When the rule is right, move it from Report to Block. Every entry in the log says which rule decided it, so a question about a block has a one-line answer.
- Access, audit and endpoint logs
- A blocked page offers a way to ask for access
- Log streaming on the Medium plan
| Time | Person | Site | Result | Rule |
|---|---|---|---|---|
| 10:02 | Sam Reyes | share.example.net | Block | Contractors: File Sharing |
| 10:01 | Mei Tan | docs.harborpine.example | Allow | Global |
| 09:58 | Sam Reyes | files.example.org | Block | Contractors: File Sharing |
Four products. One answer to who someone is.
Each product is useful on its own, and they all share the same identity, rules and agent.
Private Access
Zero-trust access to your own servers and subnets. Peer-to-peer where the network allows, with a relay where it refuses.
Private AccessInternet Access
Categories, hostnames and keywords, per person or group, decided on the device.
Internet AccessApplication Control
Crawlers, scripts, CI runners and AI agents, named and owned.
Application ControlFowlguard Remote
RDP, SSH and WinRM to a machine you have been granted, over the same tunnel and with no port left open.
Fowlguard RemoteIdentity
OIDC · SAML 2.0 · SCIM · TOTP · Google · Microsoft
IdentityDevice Posture
Encryption, antivirus and management, checked before a device is trusted.
Device PostureProductivity In development
Mail, docs, sheets and meetings on the same identity.
What we are building