Safeguarding on every student and resident network
Schools, campuses and student accommodation carry a duty of care on networks full of devices they do not manage. Shield applies safeguarding per network and per VLAN, stops infected devices calling home, proves exactly what was stopped on each network, and does it with nothing installed on a single student device.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defence firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
What is at stake
A duty of care on networks you do not control
Safeguarding
Students and residents need harmful content kept off the network.Shared networks
One infected device calling home puts every other student at risk.Ageing firewalls
Hardware and firmware age faster than refresh budgets.
How Shield fits
A policy per group, per VLAN
- Student and resident networksSafeguarding categories and Safe Search on Google, Bing and YouTube.
- xPSK communitiesEach accommodation block or group on its own VLAN and its own policy.
- Staff networksThreat defence first, with their own lists.
- By time of dayStricter overnight or during the school day, as you choose.
See everything Shield stopsWiFi for education on Purple Access
Proof
Standards you can show the governors
- 10 days
- earlier warning of new threats than standard blocklists
- Friendly WiFistandard met for family-safe filtering
- IWFfiltering meets the bar set by the Internet Watch Foundation
FAQ
Questions we hear from teams like yours
Can each accommodation block have its own policy?
Yes. Shield applies a policy per SSID and per VLAN, so each block or group on an xPSK network can carry its own rules.
Do students need to install anything?
No. Shield works at the DNS layer, so every device on the network is covered with nothing installed.
Can guests get round it with a VPN or encrypted DNS?
Shield answers every DNS lookup on the network it protects, on every device, with nothing on the device to switch off. A Shield expert shows you exactly how your network handles VPNs and encrypted DNS before you trial.
Other industries
Healthcare
Around 241,000 threats a week, stopped on hospital guest WiFi
Threat defence on patient and visitor WiFi, proven at St George's Healthcare NHS Trust.Public sector
Public WiFi that is safe for everyone who walks in
Family-safe WiFi for councils, libraries, airports and public spaces, with threat defence per site and per network.Offices
Protective DNS: a threat layer behind the office firewall
Threat defence behind the firewall, with staff and guest networks kept apart.
Decide what your WiFi reaches, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.