← Solutions

Protect remote workers on any network

A DoH profile, no client software.

Home Wi-Fi, hotels, airports. DoH and DoT endpoints and virtual sites extend policy to every device.

control.securd.com/gateway/acme/logs
Traffic Logs protocol: doh
TimestampActionSiteQuery NameSource IPReason
2026-09-15 19:03:10acceptvs-laptop-jleeoutlook.office365.comdohallow list
2026-09-15 19:03:22blockvs-laptop-jleetorrent-tracker.ccdohcategory: P2P
2026-09-15 19:04:01threatvs-laptop-jleeinvoice-view.clickdohfeed: malware-domains
2026-09-15 19:04:37greywallvs-laptop-jleenewsletter-cdn.windohfirst seen, held 24h
A laptop on hotel Wi-Fi, identified by its virtual site, under the same policy as the office.
The problem

The network you do not control is the one they use

The corporate resolver protects the office. The laptop at the kitchen table resolves through the ISP, the hotel captive portal or a public DoH provider. Roaming clients add software to maintain and a tunnel to keep up.

No resolver, no policy

Off the VPN the device uses whatever resolver the network hands it.

Agents bloat the endpoint

Another client to install, update and support on every laptop.

No record of the click

The phishing link opened at home is invisible to the office logs.

How it works

One profile, every network

Capabilities

Remote workforce controls

DoH virtual sites

Policy assignment without a static IP. One address per device group or per user.

MDM profiles

Encrypted DNS configured by the device manager. Nothing for the user to install or disable.

Full policy

Categories, lists, feeds and the Greywall apply to the roaming device exactly as in the office.

Per-device events

Traffic Logs show the virtual site on every lookup. The user who clicked is in the log.

Rotation

Rotate a virtual site by creating a new one and updating the profile. No downtime.

Global anycast

The Securd anycast network answers wherever the device connects.

Profile

The whole deployment is a URL

The virtual site URL goes into the MDM DoH profile. Rotate by issuing a new virtual site and updating the profile.

DoH profile
https://doh.securd.com/<virtual site address>
control.securd.com/gateway/acme/policies/corp-office
Policy: corp-office Published
Greywall Mode
Enforce
Hold Time
86400 s
Default Action
Allow Traffic
Allow list3 entries
  • chatgpt.com
  • claude.ai
  • copilot.microsoft.com
Block list1 entries
  • free-gpt-unlimited.xyz
MalwareC2PornParkedSinkholeDoH providers
The office policy, applied to roaming devices through the virtual site.

Questions teams ask

Does this require a VPN?

No. The DoH profile applies on any network. The VPN remains for private application access.

What if the user changes the DNS setting?

Managed devices lock the profile through MDM. Unmanaged devices are not governed.

Does it work with Chrome and Firefox?

Both accept a custom DoH provider. The DoH page has the settings for browsers and operating systems.

Cover remote laptops without another agent

One virtual site, one MDM profile, and every device is under policy.