NETWORK CONTROL · THE DNS LAYER

The lookup is the
last honest signal.

Before any AI tool loads, the laptop asks a DNS question. Network Control answers it. Allow the tool, block it, or coach the user to the sanctioned one. Malware and phishing die at resolution time. And the queries no extension ever sees still show up on your dashboard.

Included in Sentinel · No appliance · No router change
DNS resolver
On device · in path
2 allowed · 1 coached · 2 blocked
claude.ai ALLOW
notion.so ALLOW
rando-chat.ai COACH
free-gpt.top BLOCK · SINKHOLE
login-paypa1.ru BLOCK · PHISHING
Verdicts enforced the instant the lookup fires.
3
verdicts on every AI domain: allow, block, coach.
200+
AI service hosts fingerprinted by outbound signature.
24h
to your first shadow-AI discovery from network queries.
0
appliances, router rewrites, or MITM certs to deploy.
THE LAYER UNDER ALL OF IT

Browser, desktop, CLI, MCP. Then the network underneath.

Northbeams governs the four surfaces where AI happens. Network Control governs the DNS layer they all sit on. A new AI tool no one has catalogued yet still has to resolve a domain. That query is the first thing you can see, and the first place you can stop it. Every AI request starts with a lookup. So does every block.

THREE VERDICTS, ONE LOOKUP

Allow it. Block it. Coach it.

Every AI domain gets one of three admin-authored verdicts, enforced on the device the instant a user tries to reach it.

Allow
The sanctioned tools resolve like normal. Your approved stack stays fast, and the rest of the catalogue does not. Set it once by tool, team, or the whole company.
Block
The lookup is sinkholed to a local loopback address, so the user lands on a branded page instead of a dead connection. No timeout, no mystery. They know why, and where to go instead.
Coach
The middle path. Redirect the lookup to a branded coach page that nudges the user to the approved tool. You move the behaviour without blocking the person. Work keeps moving.
WHAT SHIPS ON DAY ONE

More than your own rules.

Your admin-authored allow, block, and coach rules run next to live feeds Northbeams maintains for you.

Threat feeds.
Known-malicious hosts, malware, phishing, and newly-registered domains are blocked at resolution time. The feed refreshes on the device with no daemon restart, so a host that turned bad this morning is dead by lunch.
Category filters.
Block broad web-content categories, gambling, adult, piracy, at the DNS layer using free Northbeams-maintained blocklists. Separate from your AI rules, on when you want them, off when you do not.
Shadow-AI discovery.
A weekly report of the AI tools seen in your network queries, including the ones no extension or process watcher caught. New AI domains surface the day they appear. Your company, by name.
ON THE DEVICE. NOT ON YOUR ROUTER.

The Sentinel daemon enforces it. Nothing else changes.

Network Control lives in the same on-device Sentinel runtime that already covers browser, desktop, CLI, and MCP. It resolves and rules on the laptop itself. No on-prem DNS appliance. No router rewrite. No MITM certificate. No network to re-architect. It follows the laptop home, to the coffee shop, and onto the hotel wifi, because it never depended on your network in the first place.

GOVERNED FROM ONE DASHBOARD
The same policy layer as every other surface. One place for allow, block, and coach across browser, desktop, CLI, MCP, and the network.
FEEDS THE SAME LOG
Every DNS verdict lands on the immutable, signed audit log and into the Evidence Pack, alongside every other signal. One log. One export.
THE PRICE

Included in Sentinel. Not an add-on.

Network Control ships with Sentinel at no extra charge. The threat feeds refresh for free. The category filters run on free blocklists. Governing the network is not a premium tier or a checkbox with its own invoice, it is part of the platform you already pay for per seat. The compliance evidence stays bundled too, not upsold.

WHERE THE LINE SITS
Sentinel
DNS allow, block, and coach rules. Threat feeds. Category filters. Weekly shadow-AI discovery. All included, per seat.
Enterprise
The heavy, regulated edge: custom and private threat feeds, data residency, and 7-year retention on network events. Quoted to your deployment, with volume pricing on every seat.

Every price on the pricing page is the real price. See the plans →

See the lookups. Rule on them. By Monday.

One install covers all four surfaces and the network under them. No appliance, no router change to start.

Start your 14-day trial Poke the live demo. No signup.
Discover and control your real AI exposure.