fbpx
Netspark — Whole-Family Protection for ISPs
INTRODUCING WHOLE-FAMILY PROTECTION

The only family safety platform built for
the home and the phone.

Most parental-control vendors do one or the other. Netspark is the only carrier-grade platform that combines network-edge filtering at your gateway with deep on-device governance — under a single white-labeled product your subscribers actually want to pay for.

NETWORK EDGE
The Home
Router · Smart TV · IoT · Console
+
UNIFIED
DEVICE-LEVEL
The Phone
Android · iOS · Windows · macOS
Deployed at carrier scale across regulated markets
Millions
of subscribers protected
4 tier-1
ISP deployments
25+
content categories
The Coverage Gap

Point-solutions leave half the family unprotected.

Network-only vendors stop at the front door. App-only vendors stop at the device. Subscribers churn because protection breaks the moment a child leaves home Wi-Fi — or the moment a guest brings a smart TV onto the network.

One platform. The whole family. Every device.

Netspark's hybrid architecture filters traffic at the ISP gateway and governs each enrolled device at the OS level. Policies follow the child onto 5G, public Wi-Fi, and back home — without gaps, handoffs, or double licensing.

Network-only
Home only
App-only
Phone only
Router agent
Per-router
Netspark
Full
The Hybrid Protection Engine

Two protection layers. One subscriber experience.

Zero-touch network protection keeps the home safe automatically. A lightweight on-device agent extends the same policy off-network. Both share one parent dashboard.

ISP CORE NETSPARK FILTER ENGINE HOME
LAYER 01 · NETWORK

Carrier-grade filtering at the gateway.

Deployed inside your data center, Netspark's engine inspects every flow before it reaches the home — across HTTP, HTTPS, DNS, and encrypted protocols. Real-time AI classification across 25+ content categories, with millisecond latency budgets.

  • SNI inspection · partial TLS introspection · DNS-layer filtering
  • Smart TV, console, IoT, and guest-device coverage with no agent
  • Per-household policy from the parent dashboard — instant sync
  • Zero impact on browsing speed at tier-1 carrier scale
LAYER 02 · DEVICE

Three tiers of on-device governance.

A white-labeled agent runs on Android, iOS, Windows, and macOS — same dashboard, same policy, off-network protection. Operator chooses the depth: web filtering only, full device control, or maximum-resilience VPN-bypass mode.

  • App blocking, screen-time, location, contact governance
  • Supports LTR and RTL languages; full SAML 2.0 / OAuth 2.0 / OIDC SSO
  • 10-meter GPS precision · geofencing · entry/exit alerts
  • Tier-3 mode kills VPN-bypass apps and processes in real time
One policy. One parent app. Whether the child is on home Wi-Fi, school Wi-Fi, or 5G — protection follows the user, not the network.
Service Tiers

Three tiers. Three ARPU stories.

Operators package and price each tier independently. Most ISPs lead with Tier 2 as the flagship subscription and use Tier 3 to address regulated markets.

01
Web Filter
Lightest-touch tier. Filtered browsing, anywhere the user goes.
CONTENT GOVERNANCE
  • Filtered web access on/off-network
  • Same dashboard as Tiers 2/3
  • No device-level controls
03
Resilient
Maximum-strength tier for regulated markets and high-trust accounts.
REGULATED · HIGH-TRUST
  • Everything in Tier 2
  • Active VPN-bypass app/process kill
  • Tamper-resistant device agent
  • Full audit-log export

Operator economics: tier mix varies by market, but typical deployments see Tier 2 carry the bulk of paid attach with Tier 3 as a regulated/premium upsell. Onboarding handoff means no PII or billing leaves your stack — the LTV stays with the operator.

Capabilities

Engineered for the parent and the policy committee.

Every capability surfaced in the parent dashboard maps to a policy primitive operators can enable, restrict, or hide per tier. No black boxes, no surprise features.

25+ content categories

Real-time AI classification — not blocklists. Updated continuously without operator intervention.

App-level controls

Block, time-limit, or schedule individual apps on Android & iOS. Per-child policies.

Real-time location

10-meter GPS precision. Geofencing with entry/exit alerts to the parent app.

Screen-time governance

Daily caps, bedtime windows, school-hours restrictions. Per-app or per-device.

Contact governance

Allow-lists, block-lists, and time-bounded communication windows on enrolled devices.

Smart-home protection

Agent-less coverage for TVs, consoles, and IoT devices via gateway-level filtering.

VPN-bypass resilience

Tier-3 mode actively detects and kills bypass apps and processes at the OS level.

Instant policy sync

Zero-latency synchronization across every enrolled device the moment a parent updates a rule.

LTR & RTL languages

Supports LTR and RTL languages out of the box, including parent and child UIs.

Infrastructure

Engineered for your data center.

Full on-premise deployment inside operator infrastructure — no third-country data egress, no shared cloud tenancy, no compromise on regulatory posture.

  • Full on-premise deployment Local GPU nodes inside your data center. No outbound dependencies for filtering decisions.
  • SSO & identity Native SAML 2.0, OAuth 2.0, OpenID Connect — integrates with your subscriber CRM.
  • Millions of concurrent subscribers Stateful flow architecture, RIPROXY clusters, designed for tier-1 carrier load.
  • Privacy-by-design Onboarding requires only a username. No billing, no PII handover. Operator owns the customer.
deploymenton-premise
data_residencyoperator_dc
node_min_threads40
node_min_ram64GB
gpu_accelerationenabled
image_video_moderationreal-time
sso_protocolsSAML2 · OAuth2 · OIDC
policy_synczero_latency
language_supportLTR · RTL
device_limit_per_familyoperator_defined
audit_logsfull_export
White-label Onboarding

Your brand. Your billing. Our engine.

Subscribers see your product, end to end. We never receive billing data, payment details, or PII beyond a username. The customer relationship — and the LTV — stays with you.

ISP creates license

Your CRM calls the Netspark API with the subscriber's username. We return an XML payload with an activation code.

SMS delivered

Your system sends the subscriber an SMS with the activation code and a download link to the white-labeled app.

Subscriber installs

The subscriber installs your branded app on Android, iOS, Windows, or macOS — no separate account creation.

Activation & bind

The activation code links the license to the device's hardware ID. Policies sync instantly. The flow is fully customizable per operator.

RFI Compliance Snapshot

Every committee question, already answered.

A working extract from our latest tier-1 operator response. Full matrix available on request.

Requirement
Status
Technical brief
Full on-premise hosting
SUPPORTED
Local GPU nodes inside operator data center.
SSO integration
SUPPORTED
Native SAML 2.0, OAuth 2.0, OpenID Connect.
App blocking (iOS / Android)
SUPPORTED
MDM and local-loopback VPN on iOS; native control on Android.
Windows / macOS support
SUPPORTED
Full desktop agent with identical filtering logic.
IoT / smart-home protection
SUPPORTED
Agentless protection via ISP gateway-level filtering.
Real-time location
SUPPORTED
10-meter GPS precision, geofencing, entry/exit alerts.
Instant policy sync
SUPPORTED
Zero-latency synchronization across all enrolled devices.
LTR & RTL language support
SUPPORTED
Supports LTR and RTL languages, including parent and child UIs.
VPN bypass protection
SUPPORTED
High-resilience app/process kill in Tier 3; network-level blocking in Tier 2.

Ready to see how Whole-Family Protection changes the conversation with your subscribers?

Book a 60-minute technical deep-dive with our solutions architects. We'll walk your team through the deployment topology, policy model, and ARPU economics — tailored to your network.