Skip to Content
Segment · ISPs and regional carriers

Browsing security as an ISP service

The subscriber's access point decides what goes through, by DNS, TLS/SNI and HTTP. Your team applies the policy across the whole fleet from the dashboard, with no new appliance in the traffic path.

No commitment. The technical team answers.

What ISPs face today

What already lands on an ISP's desk

Blocking orders in volume

In 2026, through September, Brazil's Ministry of Finance ordered 57,691 illegal betting addresses to be blocked. In September alone there were 10,590. The provider is the one that carries out the block.

Source: Estado de Minas, 25/09/2026

DNS blocking has a known limit

At a hearing in the Chamber of Deputies, Anatel pointed to VPNs, domain changes and the number of providers as limits of the blocking done today.

Source: Telesíntese, December 2025

Access alone does not sustain the margin

Abrint points to services such as managed Wi-Fi and network security as the next revenue layer for regional ISPs.

Source: Telesíntese, August 2026

How it applies

What changes in the ISP's operation

The decision moves down to the access point and management moves up to the dashboard. The rest of your network stays as it is.

01

Policy applied on the AP

The DNS query, the SNI of the TLS handshake and HTTP are read on the access point itself. Whatever matches the policy is dropped there, before it uses the link.

02

Bypass blocked

NetExperience documents the blocking of encrypted DNS and bypass VPNs, which are the most common ways around DNS-only filtering.

03

Managed Wi-Fi as a service

Policy per customer and per SSID, an ISP portal to manage all customers, and a separate portal for each customer to follow their own network.

04

Events and crowded venues, with the radio profile sized in the project

Radio profiles, automatic channel management and profile-based deployment, to set up and tear down a network quickly.

05

The whole fleet in one dashboard

Inventory, alarms, firmware, metrics and licenses for every access point in the same place.

Subscribers phone, laptop, TV ACCESS POINT Built-in gateway decides by DNS, TLS/SNI and HTTP dropped at the AP ISP network Internet NETEXPERIENCE DASHBOARD policy per customer, optional report

Diagram of the path of a request. The dashboard defines the policy and receives the events; the decision happens on the access point.

Questions for this segment

Does this replace the DNS blocking we do today?

It complements it. DNS filtering is still useful, but it stops working when the device uses another resolver or encrypted DNS. On the access point, the decision also uses the destination declared in the TLS handshake.

Can I sell it as a service to my subscribers?

Yes. The policy is defined per customer and per SSID, and each customer can have access to their own portal. Pricing and how the service is framed are up to the ISP.

What about the log retention rules of the Marco Civil?

Article 14 of Brazil's Marco Civil da Internet forbids connection providers from keeping application access logs. The gateway's activity report is optional per profile. When off, the blocks keep working and browsing is not logged. The configuration for your case is defined in the project.

Which equipment goes into the project?

Certified Edgecore access points, supplied by Padtec. Today they are the EAP101, EAP102 and EAP105, for indoor use with Wi-Fi 6 and Wi-Fi 7, and the OAP101, for outdoor use.

See the equipment and specifications

Start with the technical assessment.

Tell us how many points you need to cover and what the scenario is. We return the sizing and a sample of what would be blocked at the edge.