Protective DNS that keeps harmful content and threats off every WiFi network you run
Every phone on your guest WiFi can reach whatever it asks for, and you answer for what it finds. Shield does three jobs in one layer: family-safe content filtering, threat defense behind your firewall, and ad blocking that makes pages load up to 500% faster.
- news.exampleOpenAllowed
- casino-bonus.exampleOpenBlocked
- ads.tracker.exampleOpenStripped
- c2-callback.exampleSecureBlocked
- bookings.exampleSecureAllowed
- phish-login.examplexPSKBlocked
- video.examplexPSKAllowed
- malware-cdn.exampleOpenBlocked
No hardware, no agents, no card. Live in minutes, or piloted on one SSID with our engineers.
Point the network's DNS at Shield and adult content stays off the family table, infected devices stop calling home, and every network runs its own rules, stricter after dark. Run it standalone on any WiFi network or bolt it straight onto Purple Access. No hardware, no agents, nothing installed on a single device.
- Up to 500% faster pages, ads stripped
- 241k threats blocked a week at St George's
- Threats flagged up to 10 days earlier
- 30-day free trial
- Filtering to the Internet Watch Foundation bar
- No hardware, no agents on devices
In the same category as DNSFilter and Cisco Umbrella, built for the guest and public WiFi they were never designed around. Live in minutes, free for 30 days.
- news.exampleOpenAllowed
- casino-bonus.exampleOpenBlocked · Gambling
- ads.tracker.exampleOpenStripped · Ads
- c2-callback.exampleSecureBlocked · Command and control
- bookings.exampleSecureAllowed
- phish-login.examplexPSKBlocked · Phishing
- video.examplexPSKAllowed
- malware-cdn.exampleOpenBlocked · Malware
- 241k
- threats blocked a week at St George's
- 10 days
- earlier warning than standard blocklists
- 500%
- faster page loads with ads stripped
Shield runs at
- Whitbread
- AGS Airports
- St George's Healthcare NHS Trust
The gap
Your WiFi lets people in. What they reach is still your problem.
Shared networks carry devices you do not manage and people you have a duty of care to. When something goes wrong on them, nobody asks the device owner. They ask you. Can you prove nothing harmful got through? Ask yourself three questions, one for each gap that stays open until something checks every lookup.
One infected device puts everyone at risk
A phone that arrived already infected joins your network and starts calling home to its command-and-control server. Every other user on that network now shares it with an active threat. Shield blocks the callback at the lookup, before the connection starts.
Your firewall is older than you think, and it never sees the guest phones
Firewall hardware and firmware age, and a gap opens long before the next refresh. Shield adds a layer behind the firewall you already run, and covers the guest and BYOD devices a firewall agent never touches.
- Open
- Secure
- xPSK
Guest and BYOD devices, no agent
Harmful content reached on your WiFi is reached in your venue
Public, guest and student WiFi carries a duty of care. Harmful content has to stay off the network for every device, including the ones you will never see, with nothing to install on any of them.
What Shield does
Three jobs, one layer, every device covered
Every app and browser makes a DNS lookup before it connects. Shield answers it. So one layer filters content, stops threats and strips ads on every device on the network, phones you will never manage included.
Family-safe content, on every device
Block adult, gambling and other categories in a click. Safe Search is enforced on Google, Bing and YouTube, every venue keeps its own allow and block lists, and anyone who hits a blocked site sees your branded block page, not the site. Filtering meets the bar set by the Internet Watch Foundation and the Friendly WiFi standard.
- Category filtering for every device: iOS, Android and Windows, with no app to install
- Safe Search enforced on Google, Bing and YouTube
- Allow and block lists per venue
- A branded block page in place of the blocked site
Guest WiFi policy
- Adult contentBlocked
- GamblingBlocked
- Safe Search on Google, Bing and YouTubeEnforced
- Streaming at busy timesLimited
Allow list
bookings.examplemenu.exampleBlock list
rival-venue.exampleStop devices calling home
Shield blocks command-and-control callbacks and known phishing and malware domains at the lookup, so the connection never starts. AI detection flags new threats up to 10 days before standard blocklists list them.
- Command-and-control callbacks blocked at the lookup
- Threats flagged up to 10 days before standard blocklists
- Fails closed, so an outage never opens the network
- Runs across multiple data centers
Blocked at the lookup
- Command-and-control callback
- Phishing domain
- Malware domain
- Newly flagged domain
The only safety layer that makes the network faster
Most security costs you speed. Shield strips ads, trackers and bloatware at the DNS layer, so they never load and the safety layer is a performance layer too. Pages arrive up to 500% faster, web traffic drops 20 to 40%, and metered backhaul costs fall with it.
- 500%
- faster page loads
- 44%
- less data used
- 62%
- fewer DNS queries
- 20-40%
- less web traffic across the estate
Ads, trackers and bloatware load on every page
Ads and trackers stripped before they load
Bolts onto Purple Access
A different policy for every network you run
Strict where families are, threat-first for staff, safeguarding for students and residents, separate rules for paid WiFi, and stricter after dark. Picture it set once and left to run: it runs every night without you. Shield applies after the connection, so every network and every VLAN carries its own policy.
Open: strict for guests and family areas
Guest WiFi through the Access captive portal gets the strictest policy: family-safe categories, Safe Search and ad blocking. Every guest gets a clean, fast network, and every parent gets one less thing to worry about.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defense firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
Secure: different rules for staff
Staff on EAP-TLS with MDM, and devices on Passpoint and OpenRoaming, get a policy built around threat defense, with their own allow and block lists.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defense firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
xPSK: safeguarding for students and residents
PPSK, iPSK and EasyPSK networks carry IoT, communities and concessions. Student accommodation, MDU and elderly care groups each get the safeguarding policy that fits.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defense firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
Paid and free WiFi kept apart
A paid tier carries its own rules, separate from the free network, and streaming can be limited at busy times to protect bandwidth.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defense firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
Policies that change by the hour
Every policy changes by time of day and day of week, per venue. Stricter in the evening, different at the weekend, set once and left to run.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defense firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
See and control
One dashboard to prove it is working, at every venue, on every network
Monday morning, one screen: what was blocked, which threats were stopped and how the network was used, at every venue and on every SSID. When the ops director, a school board member or a parent asks whether the WiFi is safe, you prove it.
Need logs in your SIEM, or Shield behind an existing firewall and NAC? Talk it through with a Shield expert.
- Blocked URLsSee what was blocked, on which network and at which venue.
- Threat analysisTrack the threats Shield stopped, including devices calling home.
- UsageRead network usage alongside the policy that shaped it.
- Policy per SSID and venueChange a policy, a list or a schedule from the same screen.
Proof
Proven at St George's, Whitbread and AGS Airports: around 241,000 threats blocked a week
Whitbread protects its hotel guest WiFi with it. AGS Airports protects passengers at Aberdeen, Glasgow and Southampton with it. St George's Healthcare NHS Trust blocks around 241,000 threats a week with it. And it runs on the Purple platform behind 80,000+ venues in 90 countries, for customers including McDonald's, Harrods and Premier Inn.
Threats means malware, phishing and command-and-control lookups stopped by Shield.
- St George's Healthcare NHS TrustThreat defense241kthreats blocked a week on its guest WiFi
- WhitbreadHospitalityProtects its hotel guest WiFi with Shield.
- AGS AirportsTransportProtects passengers at Aberdeen, Glasgow and Southampton.
- 10 days
- earlier warning of new threats than standard blocklists
- 500%
- faster page loads with ads stripped
- 80,000+
- venues on the Purple platform
Certified, and aligned to recognized security and child-safety standards
- ISO 27001
- GDPR
- CCPA
- Cyber Essentials
- Friendly WiFi
- Internet Watch Foundation
Filtering meets the Friendly WiFi and Internet Watch Foundation standards.
Compare
DNSFilter and Umbrella protect the laptops you own. Shield protects the phones you never will.
All of them filter. Shield is the one built for guest and public WiFi: ad blocking included, a policy per network, nothing to install, new threats flagged up to 10 days before standard blocklists, and the WiFi platform that already runs sign-in and analytics for your venues behind it.
| Compared with | Where Shield wins | What it is built for |
|---|---|---|
| DNSFilter | Where Shield winsBuilt for guest and public WiFi, with ad blocking included, a policy per SSID and VLAN and nothing to install | What it is built forPure-play protective DNS for managed and roaming endpoints |
| Cisco Umbrella | Where Shield winsPurpose-built for WiFi filtering, live in minutes across a multi-site venue estate | What it is built forA broad secure-access suite, from DNS security to SWG and ZTNA, for large enterprises on quote-based pricing |
| Legacy filtering appliance | Where Shield winsNo hardware, no firewall change, and it fails closed across multiple data centers | What it is built forA box at every site that inspects traffic at the network edge |
Behind your firewall
A firewall on its own, or a firewall with Shield behind it
Shield does not replace your firewall. It closes the gaps a firewall leaves on shared WiFi. Read across and decide which one you want answering for your guest network.
| What matters | Firewall with Shield | Firewall on its own |
|---|---|---|
| When a bad domain is stopped | Firewall with ShieldAt the lookup, before the connection starts | Firewall on its ownOnce a connection has started |
| Guest and BYOD devices | Firewall with ShieldCovered, with no agent on any device | Firewall on its ownOut of reach of an endpoint agent |
| New threats | Firewall with ShieldFlagged up to 10 days before standard blocklists | Firewall on its ownCaught when the blocklist catches up |
| Page speed | Firewall with ShieldUp to 500% faster page loads with ads stripped | Firewall on its ownAds and trackers still load |
| Policy | Firewall with ShieldPer network, VLAN, venue and time of day | Firewall on its ownDepends on the hardware at each site |
Who it is for
Built for the networks with the most at stake
Pubs and hotels, schools, hospitals, councils, airports and offices each run a different mix of guests, staff and residents. Find yours and see the policy it gets.
Around 241,000 threats a week, stopped on hospital guest WiFi
Threat defense on patient and visitor WiFi, proven at St George's Healthcare NHS Trust.HealthcareFamily-safe, faster guest WiFi with protective DNS for pubs, hotels and venues
Family-safe guest WiFi and faster pages for pubs, hotels and family venues.Safeguarding on every student and resident network
Safeguarding per network and per VLAN for schools, campuses and student accommodation.Public WiFi that is safe for everyone who walks in
Family-safe WiFi for councils, libraries, airports and public spaces, with threat defense per site and per network.Protective DNS: a threat layer behind the office firewall
Threat defense behind the firewall, with staff and guest networks kept apart.
Give every Access network its own policy, live in minutes
Point a network's DNS at Shield and filtering is live. No hardware, no agents on devices, nothing to roll out. On a change-controlled estate, we plan it with your team.
FAQ
The questions IT teams ask before they switch on Shield
We already have a firewall. Why add Shield?
Because your firewall cannot see the guest phones on your WiFi. Shield is an extra layer behind your firewall, not a replacement for it. It blocks the DNS lookup before a connection starts, stops command-and-control callbacks from infected devices, covers guest and BYOD devices a firewall agent never touches, and flags new threats up to 10 days before standard blocklists.
Can guests get round it with a VPN or encrypted DNS?
Shield answers every DNS lookup on the network it protects, on every device, with nothing on the device to switch off. A Shield expert shows you exactly how your network handles VPNs and encrypted DNS before you trial.
Will Shield slow the network down?
No. It speeds it up. Stripping ads and trackers at the DNS layer makes pages load up to 500% faster, cuts web traffic by 20 to 40%, uses up to 44% less data and makes up to 62% fewer DNS queries.
How is Shield different from DNSFilter or Cisco Umbrella?
All three are protective DNS. Shield is built for guest and public WiFi rather than corporate endpoints, includes ad blocking as a first-class feature, sets a policy per SSID, VLAN, venue and time of day, and comes from the WiFi platform that already runs sign-in and analytics for the same venues. One resolver change, not a suite to roll out.
Do I need Purple Access to run Shield?
No. Shield runs standalone on any WiFi network: point its DNS at Shield and filtering is live. On Purple Access it bolts onto every open, secure and xPSK network. Either way, you start with 30 days free.
What happens to my guest WiFi if Shield has a problem?
Protection does not lapse. Shield fails closed, so an outage never leaves a network unfiltered, and it runs across multiple data centers, so a fault in one does not take your service down and users stay protected wherever they are. You never trade safety for uptime. Shield runs on the Purple platform, which carries 500 million logins a year at a 99.999% uptime SLA.
Can different venues and networks have different rules?
Yes. Policies are set per SSID, VLAN and venue, can change by time of day and day of week, and each venue keeps its own allow and block lists.
Do I need hardware or software on devices?
No. Shield works at the DNS layer, so there is no appliance to rack, no firewall change and nothing to install on iOS, Android, Windows or guest devices.
Can I prove it is working?
Yes. One dashboard shows blocked URLs, threat analysis and usage, by network and venue.
Decide what your WiFi reaches, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.