How Fowlguard protects your data.
A product that sits between your people and the internet earns scrutiny. Each answer on this page describes how the product already behaves.
What the product does, whatever the settings.
Decided on the device
Rules run on the device before a connection opens. Your traffic goes where it was going, and never through our data centre to be judged.
Inspection stays with you
Where TLS inspection is switched on, content is decrypted and judged on your own machine under your own certificate, and never shipped to us.
Sensitive categories start exempt
Banking, healthcare, government and legal destinations are excluded from inspection until your administrator decides otherwise.
It fails closed
Where trust cannot be established, the product stops rather than carrying on without it.
Your keys are yours alone
There is no vendor key that unlocks more than one organisation.
Devices are recognised
Each device reports a hardware fingerprint, so a cloned or stolen credential can be told apart from the machine it was issued to.
Two consoles, two different views.
Your console and ours are separate builds with separate data. The boundary is in the product, not in a policy.
Your own security decisions
- Filter rules, access policy and blocked lists
- Device posture and interception settings
- Your block pages and your logs, exportable any time
Only what running the service needs
- Contacts, plan, licences and payments
- Service health, connection and audit records
- Never your rules, content, recordings, credentials or keys