AI Assistant
Drive every module in plain English. ~60 tools, parallel actions, zero command-line.
GateKeeper unifies a per-app firewall, DNS sinkhole, and network control into one platform — across every device, driven by an AI you command in plain English.
// On-device. No cloud. No compromise.
Blocked a domain in Pi-hole? Your firewall has no idea. Blocked an app? Your DNS proxy kept resolving domains for it anyway. Fragmented tools create fragmented protection.
Most people give up before they're actually protected. The tools that work best are the tools you actually use. GateKeeper is built to be used.
The device that carries your location history, banking apps, and private messages is usually the least protected thing you own.
GateKeeper covers every attack surface — from the kernel to the DNS layer to your phone.
8 enforcement filters per app. Crash-safe. Protocol-complete. No bypass possible.
Malicious domains return 0.0.0.0. Immediately. Always. No caching delay.
Covers what app-level rules can't reach. Independent of the originating process.
All three layers, tied together by the AI Assistant — one platform, zero blind spots.
Every layer of protection in a single console — each module sharp on its own, unstoppable together.
Drive every module in plain English. ~60 tools, parallel actions, zero command-line.
Per-process firewall enforced at the kernel — 8 filters per app, crash-safe, no bypass.
DNS sinkhole. Bad domains never resolve.
Block bad IPs, ports and whole protocols.
Detonate unknown files and URLs in an isolated VM with per-resource policy.
Android firewall plus 5 threat detections — no root required.
No rule syntax. No iptables. Just ask — GateKeeper translates intent into kernel-level action.
Live traffic, module health and global reach — refreshed every second on one calm console.

Live CPU, memory and bandwidth for every running process, with publisher verification built in.

Search your full installed-app inventory — thousands of entries — and cut any one off before it ever runs.

Expand a process to see every live connection with full IP, country and ASN intelligence.

Persistent allow and block rules, enforced at the kernel in 3.2 ms — and crash-safe by design.

Blacklist or whitelist mode, per-domain rules and one-click DNS setup. Bad domains never resolve.

Apply DNS protection across all network interfaces at once — wired, wireless and virtual.

A live rules engine for inbound and outbound traffic — blocklist or whitelist, with global port blocks.

Over 118,000 malicious IPs from Spamhaus, Blocklist.de and TOR exit nodes — blocked in a click.

Toggle QUIC, BitTorrent, Telnet and more at the network layer — independent of any single app.

Powered by Gemini. Block apps, inspect DNS or audit every service — all in plain English.

Stage suspicious URLs and files in an isolated Windows Sandbox with granular, per-resource policy.

Full endpoint security on Android — no root — plus five threat detections nothing else offers.
GateKeeper Mobile brings the same per-app firewall and DNS sinkhole to Android — and adds threat detection your laptop never needed.
GateKeeper uses the kernel's own security APIs — not workarounds.
The same kernel API enterprise security software uses. If GateKeeper exits unexpectedly, the kernel cleans up. You can never get locked out.
Three enforcement layers. Layer 2 uses an eBPF cgroup/sendmsg hook — the only correct solution to the QUIC/HTTP3 blocking problem that most tools get wrong.
System-level traffic interception without root. PacketFilter evaluates every packet: ALLOW, DROP, DNS_INTERCEPT, DNS_SINKHOLE, or DNS_LEAK. Microsecond decisions.
All service APIs bind exclusively to 127.0.0.1. No data leaves your device. Ever.
Verified against Portmaster, OpenSnitch, Pi-hole, and NetGuard.
| Capability | GateKeeper | Portmaster | OpenSnitch | Pi-hole | NetGuard |
|---|---|---|---|---|---|
| Windows | ✔ | ✔ | ✗ | ✗ | ✗ |
| Linux | ✔ | ✔ | ✔ | ✔ | ✗ |
| Android | ✔ | ✗ | ✗ | ✗ | ✔ |
| Per-app firewall | ✔ | ✔ | ✔ | ✗ | ✔ |
| DNS sinkhole | ✔ | ✔ | ✗ | ✔ | Partial |
| IP / port rules | ✔ | ✔ | ✗ | ✗ | ✗ |
| AI assistant | ✔ | ✗ | ✗ | ✗ | ✗ |
| Mobile threat detection | ✔ | ✗ | ✗ | ✗ | ✗ |
| On-device, no cloud | ✔ | Partial | ✔ | ✔ | ✔ |
Feature comparison based on verified product documentation. Last updated June 2026.
Book a 30-minute walkthrough and we'll show you per-app firewalling, DNS interception and AI-driven control — live, on Windows, Linux and Android.