Skip to main content
Corral · Beta

Block the web you don't want,on every managed device

Meet Corral, network filtering built into Appaloosa. Ads, trackers, phishing sites, gambling, adult content: decide what your managed phones and tablets can reach, from the console.

Corral runs on the device itself. No proxy, no third-party server, nothing for users to install.

iOS, iPadOS & Android On-device, no proxy Managed from the console
Beta coming soon Book a demo
No entry sign on a yellow wall: Corral blocks unwanted traffic on managed devices

Highlights

Why filtering belongs in your MDM

Most fleets protect the device and forget the network it talks to. A phishing link in a text message, an ad network serving malware, a gambling site opened on a shared terminal: none of that is stopped by a passcode policy. Corral closes that gap with one policy, applied from the console you already use.

One Policy, Every Device

Pick a Level, Add Your Domains

Choose a protection level, from ads only to maximum, add the categories you care about (threats, gambling, social media, adult content) and your own block and allow lists. Apply it to a device group. Done in minutes.

Filtering Stays Local

Nothing Leaves the Device

Domains are checked on the device against lists it downloads from Appaloosa. No proxy, no traffic sent to a third party. Known encrypted DNS bypasses (DoH, DoT) are blocked so the policy holds.

Nothing to Install

Enrolled Means Protected

The filter deploys with the device configuration. Users can't remove it or switch it off, and the services your MDM, app store and notifications depend on are never blocked.

How it works

How Corral works

No appliance, no VPN gateway, no extra account. The policy lives in your Appaloosa configuration and the device enforces it. Three steps.

  1. 01

    Choose

    Pick a protection level and the categories to block: threats, ads and trackers, gambling, social media, adult content, telemetry, newly registered domains and more.

  2. 02

    Adjust

    Add the domains your business needs to block, and the ones that must always work. Your lists come on top of the categories.

  3. 03

    Apply

    Assign the policy to a device group. Devices pick it up in seconds and start filtering, with a local log of what was blocked and why.

Where it makes the biggest difference

Frontline and Logistics

Handhelds and phones used on the road or in the warehouse only talk to the services your operations need. Fewer distractions, fewer phishing incidents, less data used on ads.

Shared Devices and Kiosks

A terminal used by many hands stays on task. Block what the device was never meant to reach, whatever the user tries, without touching the kiosk setup.

Employee Protection

Phishing links in text messages, fake login pages, malware served by ad networks: Corral stops the connection before the page loads, so a wrong tap on a company phone stays harmless.

They trust us

Get started

Ready to deploy MDM?

Get started today with unrestricted access to our platform and help from our product experts.

Get Started

Or talk to our sales team.

Free 14-day trial
Expert Support

FAQ

Frequently asked questions about Corral

Employee using a managed smartphone with network filtering

Android 8.0 and later on Android Enterprise, on company-owned devices (fully managed, including COPE). iOS and iPadOS 26 and later on supervised devices enrolled through Apple Business Manager. On iOS the filter is not available on personal devices enrolled through a link, because Apple reserves system-wide filtering for supervised devices. macOS is not covered at launch.

No. Filtering happens on the device, by domain name, against lists the device downloads from Appaloosa. There is no proxy and no traffic sent to a third-party server. Content is never inspected or decrypted.

The page simply doesn't load: the browser shows a connection error, with no warning page or redirection. The on-device app shows the protection status, the number of blocked requests and the latest events, with the domain and the list that blocked it.

No. The filter is deployed by the device configuration and can't be disabled or uninstalled by the user. Your support team can pause it for five minutes on the spot with an administrator code, for troubleshooting.

A DNS filter: it works at the domain level, globally on the device, not per app and not per URL. You can block gambling.example, not a single page on an allowed site. Known encrypted DNS providers (DoH, DoT) are blocked to prevent bypass.

In the on-device log, which lists blocked domains and events and can be exported or sent to support as a diagnostic report in one tap.

Still have questions?Our team answers in minutes.
Talk to us