Pilot access is invite-only.Request access

spot-suite. clearscreen. endpoint web policy

Clear web policy for every managed device.

ClearScreen ties endpoint DNS decisions, branded block pages, and review evidence to the same Spot Suite operating record.

No TLS decrypt Windows + Linux Branded review loop
clear-screen.ai / customer environment Acme Academy policy
AC

Acme Academy IT

ClearScreen managed policy

Blocked by policy

Policy decision

This site is not available on school devices

AI chat tools are blocked during class time. Ask IT for review when this destination is needed for approved coursework.

Destination
chatgpt.com
Reason
Students policy group blocks AI services.
Review email
helpdesk@acme.example
Duplicate requests stay under review.

The policy loop is visible from device to review.

ClearScreen is built for IT teams that need explainable controls, not another black box that leaves the helpdesk guessing.

01

Managed policy

Security teams set blocked categories, allowlists, blocklists, and host exclusions from the management plane.

02

Company block page

Each Customer Environment can set its own logo, message, review email, and review instructions.

03

Local enforcement

The endpoint agent handles DNS decisions on the device, so every browser and background app gets the same verdict.

04

Review loop

Users can report a false positive from the block screen, and reviewers see the original policy reason attached.

Inspect a domain before it reaches a device.

The demo calls the same check endpoint used by operators. It returns verdict, category, score, and feed reasons without exposing a Customer Environment key.

Ready
Verdicts appear here with source feed and first-seen context.

Coverage follows the device, not the browser.

ClearScreen enforces at the DNS layer. IT does not need a separate extension strategy for every browser family.

Windows

Primary deployment

Service install, tray status, local block screen, Intune packaging, and managed reporting.

Linux

Server and workstation builds

Systemd service path for managed clients, lab machines, shared workstations, and engineering fleets.

Built for Intune and device-group rollouts.

ClearScreen fits managed Microsoft estates without becoming a Defender replacement. Use Intune to assign the agent, then manage policy centrally.

Open deploy guide
01

Assign the agent

Package the Windows binary as a Win32 app, assign it to Intune groups, and keep pilot hostnames excluded until rollout is ready.

02

Enroll devices

The install writes managed configuration and exchanges an enrollment key for a device-scoped credential.

03

Review exceptions

False-positive reports arrive with device, hostname, domain, category, and the original policy reason.

A cleaner layer for web policy.

ClearScreen is not trying to be a firewall, proxy, or giant appliance. It is the fast endpoint decision layer IT can explain.

The usual gaps

  • Browser-only controls miss background apps and alternate browsers.
  • Network gateways often need inspection-heavy routing or brittle PAC files.
  • Legacy block pages rarely explain the policy reason well enough for support.

ClearScreen response

  • Endpoint DNS enforcement follows the device across browser families.
  • No TLS decryption is required for the policy and threat indicator path.
  • The block screen and review queue carry the same reason, source, and device context.

Start with a pilot, scale by policy group.

Use clear-screen.ai for product evaluation, then enroll teams and device groups as the rollout expands.

Standalone

Local filtering with public threat bundle and editable device policy.

Managed

Central policy, enrolled devices, hostname exclusions, reporting, and reviewer workflow.

Enterprise

Procurement support, own-domain routing, rollout help, and managed fleet terms.