One Policy, Every Device
Pick a Level, Add Your Domains
Meet Corral, network filtering built into Appaloosa. Ads, trackers, phishing sites, gambling, adult content: decide what your managed phones and tablets can reach, from the console.
Corral runs on the device itself. No proxy, no third-party server, nothing for users to install.
Highlights
One Policy, Every Device
Pick a Level, Add Your Domains
Filtering Stays Local
Nothing Leaves the Device
Nothing to Install
Enrolled Means Protected
How it works
No appliance, no VPN gateway, no extra account. The policy lives in your Appaloosa configuration and the device enforces it. Three steps.
Pick a protection level and the categories to block: threats, ads and trackers, gambling, social media, adult content, telemetry, newly registered domains and more.
Add the domains your business needs to block, and the ones that must always work. Your lists come on top of the categories.
Assign the policy to a device group. Devices pick it up in seconds and start filtering, with a local log of what was blocked and why.
Phishing links in text messages, fake login pages, malware served by ad networks: Corral stops the connection before the page loads, so a wrong tap on a company phone stays harmless.
They trust us
Get started
Get started today with unrestricted access to our platform and help from our product experts.
FAQ
Android 8.0 and later on Android Enterprise, on company-owned devices (fully managed, including COPE). iOS and iPadOS 26 and later on supervised devices enrolled through Apple Business Manager. On iOS the filter is not available on personal devices enrolled through a link, because Apple reserves system-wide filtering for supervised devices. macOS is not covered at launch.
No. Filtering happens on the device, by domain name, against lists the device downloads from Appaloosa. There is no proxy and no traffic sent to a third-party server. Content is never inspected or decrypted.
The page simply doesn't load: the browser shows a connection error, with no warning page or redirection. The on-device app shows the protection status, the number of blocked requests and the latest events, with the domain and the list that blocked it.
No. The filter is deployed by the device configuration and can't be disabled or uninstalled by the user. Your support team can pause it for five minutes on the spot with an administrator code, for troubleshooting.
A DNS filter: it works at the domain level, globally on the device, not per app and not per URL. You can block gambling.example, not a single page on an allowed site. Known encrypted DNS providers (DoH, DoT) are blocked to prevent bypass.
In the on-device log, which lists blocked domains and events and can be exported or sent to support as a diagnostic report in one tap.