Domain and Category Policy

Filtering that works without decrypting HTTPS page content

BusinessProxy enforces domain, category and allow/deny policy before browser traffic leaves through an approved egress region. The browser-proxy path does not decrypt HTTPS content or read page bodies. The category list is a local, versioned baseline today.

Inputs to a policy decision

On the browser-proxy path the gateway decides using domain/host metadata, a local versioned category list and your workspace allow/deny rules — applied before traffic leaves through the approved egress region.

  • Domain / host metadata
  • Versioned category list
  • Workspace allow / deny overrides
  • Routing mode and egress region

Not content inspection

On the browser-proxy path BusinessProxy does not decrypt HTTPS page content, inspect the page DOM, parse private form fields, read files inside encrypted sessions, or provide DLP classification. If a page is allowed by domain/category policy, its encrypted content stays encrypted through the proxy path.

  • No TLS interception on the browser path
  • No page DOM or form-field inspection
  • No DLP / content classification

Versioned local feed first

The MVP category source is a local, versioned feed — a deliberate operating model that keeps policy decisions reproducible and reviewable. External threat-intelligence feed integration is planned, not part of the default baseline until it is explicitly loaded and verified.

  • Versioned category baseline
  • Workspace allow/deny overrides
  • Operational deny rules
  • External threat feed planned / not enabled

FAQ

Do you inspect HTTPS page content?

Not on the browser-proxy path. BusinessProxy enforces browser policy using domains, network metadata, category decisions and allow/deny rules. It does not decrypt HTTPS page content, read the page DOM, or inspect form fields on that path.

How does filtering work without TLS inspection?

Filtering is domain/category based. The gateway applies a versioned category list and your allow/deny rules before traffic leaves through the approved egress region. This is not content/DLP inspection and should not be described as reading the page.

What is the category feed today?

The MVP uses a local, versioned category feed plus operational allow/deny rules. External threat-intelligence feed integration is planned, not part of the default baseline until it is explicitly loaded and verified.

US egress for controlled web testing