WebSitter Enterprise runs silently on every device in your network — blocking harmful content, logging every event, and letting you enforce different rules for every department or class group. No cloud. No subscriptions. No per-seat fees.
No network changes. No cloud agents. No SaaS contracts to sign. WebSitter sits on each device and filters silently from day one.
Push a sub-5 MB installer to every endpoint via MSI, PKG, or bash. Compatible with Intune, Jamf, Group Policy, and Ansible. Staff and students never see a prompt.
Map users and devices to policy groups by class, department, or role. Import existing groups from Active Directory or LDAP — no re-entering data.
Block content categories — adult, social media, gambling — or specific domains. Schedule time-based access windows. Whitelist the tools your teams rely on.
Live fleet status, per-group weekly reports, and tamper-evident audit logs built for CIPA reviews, IT security audits, and HR investigations.
Every feature exists because an IT head, school admin, or compliance officer asked for it. Nothing is there just to fill a feature list.
One URL. Every device in your organization — its assigned group, active policy, and live status — all visible without juggling spreadsheets.
Set a baseline for the whole organization, then override per group. Students follow different rules than staff. Engineering has access that Marketing doesn’t.
Every filtering decision is made on-device. No browsing data, DNS queries, or logs ever leave your network — required for HIPAA, FERPA, and data-residency compliance.
Pull your existing user tree from Active Directory or any LDAP server. Policy assignment happens at login, automatically, based on group membership.
Every DNS event is timestamped and stored. Export to CSV for CIPA submissions, annual IT reviews, or HR policy enforcement. Tamper-evident by design.
Automated weekly summaries broken down by group — block rates, most-attempted domains, and time-of-day activity patterns. Everything a manager or board wants to see.
Under 5 MB, no visible interface, runs as a background system service. Students and staff have no way to detect, disable, or circumvent it.
Pay once for your organization tier. No annual renewal, no per-seat fees, no surprise invoices as you add devices. 10 endpoints or 10,000 — same price.
See exactly what your IT admin console looks like on day one — fleet view, group policies, audit log, and weekly reports.
| Device | User | Dept | Policy | Status |
|---|---|---|---|---|
| WS-MBP-001 | j.smith | Marketing | Strict | Active |
| WS-WIN-042 | a.jones | Engineering | Standard | Active |
| WS-WIN-017 | r.patel | HR | Restricted | Active |
| WS-MBP-008 | k.lee | Exec | Custom | Alert |
Most organizations run a mix. WebSitter Enterprise manages Mac, Windows, and Linux fleets from one console — same policies, same reports, same audit log across every OS.
macOS 12+ support. PKG installer, Jamf compatible, runs as a privileged system daemon.
Windows 10/11 support. MSI installer, deployable via Group Policy or Intune, runs as a Windows Service.
Ubuntu, Fedora, Debian, RHEL support. Bash/DEB/RPM installers, Ansible playbook available.
Enterprise is built for IT admins managing fleets. It adds a central web-based admin console, group-based policy engine, AD/LDAP sync, CIPA-compliant audit logs, and flat-rate organizational licensing. The Home edition is a single-device app for parents.
No. Filtering is handled by a local agent on each device via DNS interception. No browsing history, no query logs, and no personal data are ever sent to external servers — ours or anyone else’s. Fully air-gap compatible.
The admin console reads your directory tree and maps OUs or security groups to WebSitter policy groups. Users inherit the correct policy at login — automatically, based on group membership. Sync is read-only. We never write to your directory.
Yes. The audit log produces tamper-evident, timestamped records covering all filtered DNS activity — exactly the documentation CIPA requires. Logs export to CSV and JSON. We also support general HIPAA security controls and internal IT audit requirements.
No. WebSitter Enterprise uses flat-rate, one-time pricing by device tier. Pay once, own it permanently. No annual renewal, no per-seat calculation. Pricing is available on request during early access.
Windows: MSI installer — works with Intune, Group Policy, and SCCM. macOS: PKG installer — works with Jamf and MDM profiles. Linux: DEB, RPM, and bash installers — works with Ansible, Chef, Puppet, and Salt.
WebSitter Enterprise is in early access for schools, offices, and organizations in India. Contact us to schedule a live walkthrough or discuss deployment for your environment.
Early Access · India only · macOS, Windows & Linux supported
We typically respond within one business day.