Most filters tell you "the whole home is covered" and hope you never ask what that means. Here is the device-by-device truth: what is protected, what travels with the device when it leaves your house, and where the honest limits are.
Layer 1 — the device itself. Each family device carries its own named protection profile. It filters and reports wherever that device goes: home, school, a hotspot, a friend's WiFi. This is the layer that follows you.
Layer 2 — the home network. Your router filters every screen that connects to your WiFi, including devices we have never seen before. This is the net that catches everything else.
A device covered only by Layer 2 is protected at home and unprotected the moment it leaves. That is why we put a named profile on everything that has wheels.
| Device | How it is protected | Travels with the device? | Can it be removed? |
|---|---|---|---|
| iPhone / iPad | Named DNS profile installed in two taps. Filters every app and browser. | Yes — any network, anywhere | Locked behind Screen Time; supervised setup makes it effectively permanent |
| Android | One settings field (Private DNS) with your family's protection address. | Yes | Lockable with Family Link on kids' devices |
| Windows laptop | Small protection app, installed once by the parent. | Yes | Not removable from a child (non-admin) account |
| Mac | Named profile, same two-tap install as the iPhone. | Yes | Not removable without the parent's admin password |
| Chromebook | Special case. No lockable DNS on personal Chromebooks. We use Google Family Link: forced SafeSearch, site blocking, no incognito, no guest mode. At home, the network layer covers it fully. | Partially — Family Link rules travel; DNS alerts do not | Family Link supervision cannot be removed by the child |
| Amazon Fire tablet | Per-network filtered DNS plus Amazon Parental Controls behind a partner-held PIN. | Per network — set once for each WiFi it joins | Parental Controls PIN blocks changes |
| Older iPad or Android (even 10 years old) | Same filter via a fallback path: manual DNS on old iPads, the free Intra app on old Androids. | Yes (Intra) / per network (old iPad) | Lockable with a store PIN |
| Xbox / PlayStation | Home network layer covers it automatically, plus a manual DNS lock and console family settings behind a partner passkey. | No — home coverage only (consoles rarely travel) | Console family passkey blocks changes |
| Smart TVs, guests' phones | Covered by the home network layer whenever they are on your WiFi. | No — home coverage only | n/a |
Step-by-step installers for every device above →
If someone turns on a phone's hotspot and connects a laptop, the laptop does not inherit the phone's protection. Phone hotspots pass traffic straight through to the carrier. The phone itself stays filtered; the tethered laptop does not.
That is exactly why Layer 1 exists: a laptop with its own named profile stays protected on any connection, including a hotspot. If your household laptops are enrolled, the hotspot trick gets nobody anywhere.
Accountability only works if it is fair. Breaking Chains reports follow one hard rule:
Your nephew's friend spending the night cannot put a false alert in front of your accountability circle. Blocking still works on every device; blame only ever lands where the evidence is.
Anyone who joins your WiFi is filtered by the home layer automatically: a visiting teenager cannot pull up porn in your living room on their own phone. Their activity lands in the unidentified bucket, visible to you as the household lead, never presented to your circle as yours.
A palm-sized box we configure before it ships. Plug it into whatever router you already own and it broadcasts a protected network with device naming, guest separation, and identical behavior in every home, no matter the router brand. In testing now.