Murus · a deterministic web-category blocklist · honest-off by default
One mechanism, said plainly: a deterministic domain-category blocklist match — not TLS interception, not AI-based classification, not a real-time device block.
A filtering product name invites assumptions: certified, AI-smart, stopping every device right now. Murus is none of those things today, and we are saying so before we say anything else. What it actually is: a normalized hostname checked against a curated category list. A match returns a category; an unlisted domain is uncategorized, never “verified safe.” That is the whole mechanism — deterministic, auditable, and small enough for a school to read every entry in.
The match is pure and deterministic: no TLS interception, no packet inspection, no AI-based or machine-learning-based classifier. We say so before we say anything else.
What this page is not claiming
Murus does not claim to satisfy CIPA on its own and does not claim a federal filtering certification — a certification is a human legal act a school signs on its own Form 486, under its own policy, notice, and hearing; no software claims that for itself. Murus does not call itself a technology protection measure (TPM) — it may be used as part of one, but whether it qualifies is the school’s own attestation. Murus does not run any AI-based or machine-learning-based content classifier — the match is a deterministic lookup, nothing more.
And nothing on a device is being stopped in real time by this kit today. There is no device-enforcement agent shipping here. What exists is a school-admin policy view and a staff dry-run evaluate check — not a claim that any filtering is turned on for a real request.
What is built
Every item below is code that exists today. Where a card says dry-run only, that means the check reports a result without acting on any device — the other properties (the match itself, the policy view, no TLS interception) are exactly as described, every time.
The deterministic category match
A requested hostname is normalized (lowercased, scheme/path stripped, homoglyph-hardened) and walked up its own domain ladder against a curated category list. A match returns that category; a domain absent from the list is uncategorized — the mechanism never guesses. Pure and deterministic: the same domain against the same list always returns the same answer, which makes it exhaustively testable and auditable by a school. Shipped
School-admin policy view
A school or district admin can read and edit their own tenant’s category policy — a stored, editable configuration row that always stays inside the tenant’s own control, never something a school cannot change or take out. Shipped
Staff dry-run evaluate check
Staff can ask what a specific domain would match against the tenant’s policy and get an honest category-or-uncategorized answer back. This is a DRY-RUN read: it reports what would happen, and it does not write a block to any device or network path. Shipped — dry-run only
No TLS interception
The mechanism never terminates or inspects TLS, and never performs a man-in-the-middle interception of an encrypted connection. The match works from the requested hostname only. By design
What device enforcement would take — and where the platform stops today
Turning this dry-run check into a real-time stop on an actual device is a separate, external-dependency piece of work: an agent or network path that can actually intercept a device’s traffic and act on the category match. That agent is not part of this kit and is not shipped. Today, running the evaluate check tells a staff member what WOULD happen; it changes nothing on any device.
The category list itself is a small, curated seed today, illustrative of the mechanism rather than a claim of exhaustive coverage. A real deployment would grow that list through the same shape of category-to-domain mapping this page describes — not a different mechanism, just more of the same deterministic one.
How the money works, honestly
Nothing on this page carries a price. The mechanism — the deterministic match, the policy view, the dry-run evaluate check — is part of the platform; a deployed device-enforcement path, if a school wants one, is a separate operator conversation.
This is honest-off money: there is no pricing table and no checkout on this page, and nothing here takes a live charge. A conversation with a school works out what, if anything, applies.
Common questions
Does murus.network satisfy CIPA on its own, or hold a federal filtering certification?
No, on both counts. A federal CIPA certification is a human legal act a school’s own official signs on a Form 486, under a school’s own internet safety policy, public notice, and hearing -- it is not something a piece of software can claim about itself. Murus states only the mechanism it runs; whether that mechanism, combined with a school’s own policy and process, supports a school’s own federal filing is entirely the school’s own determination.
Is murus.network a technology protection measure (TPM)?
Murus does not label itself a TPM. It may be USED as part of a school’s technology protection measure, but whether it qualifies is the school’s own attestation, made by the school and its counsel -- never something this page or the underlying software asserts about itself.
Does murus use AI or machine learning to decide what to block?
No. The match is a deterministic lookup: a requested hostname is normalized and checked against a curated category list. There is no model, no scoring, no machine-learning or artificial-intelligence classifier anywhere in this mechanism. A domain that is not on the list is simply uncategorized -- never analyzed, never guessed at.
Does murus intercept or inspect encrypted (TLS) traffic?
No. Murus never terminates or intercepts TLS, and it never performs a man-in-the-middle inspection of an encrypted connection. The match works from the requested hostname only.
Is device-level blocking active today?
No. Nothing on a device is blocked by this kit today. What is shipped is a school-admin POLICY view (a stored, editable category list per school) and a staff DRY-RUN evaluate check -- a staff member can ask “what would this domain match?” and get an honest category-or-uncategorized answer. Neither stops traffic on any device or network path in real time. Device-level enforcement is a stated follow-on, not something this page claims is running.
If a domain is not on the list, is it safe?
No claim like that is made. An unlisted domain is uncategorized by this mechanism -- absent from the curated list a school is using, not verified safe. The blocklist is a curated, illustrative-scale list, not a claim of exhaustive internet coverage.
Does this cost anything?
Money is honest-off on this page: there is no pricing table, no checkout, and nothing here takes a live charge. A conversation with a school works out what, if anything, applies.
What this page is, and is not, claiming
Murus runs one mechanism: a deterministic DNS/category blocklist match — a normalized hostname walked against a curated list, a match returns a category, an unlisted domain is uncategorized, never verified safe. It does not terminate or inspect TLS, does not run any AI-based or machine-learning-based classifier, and does not claim to satisfy CIPA on its own, hold a federal filtering certification, or self-declare as a technology protection measure — those are the school’s own determinations, made outside this page. Nothing on a device is being stopped in real time today: the shipped surface is a school-admin policy view and a staff dry-run evaluate check, neither of which acts on any device. This is a for-profit vendor, not a charity. Money is honest-off: no pricing table, no checkout, no live charge on this page. There are no invented coverage numbers or testimonials here, and no competitor is named.