Off-Network Filtering for K-12 Take-Home Devices: Architecture, Coverage, and Evaluation
Last updated
Off-network filtering is the layer that keeps K-12 web filtering active when a school-issued device leaves campus. How well it holds up depends on the filtering architecture and the device OS: coverage that is straightforward on a Chromebook gets more variable on Windows, macOS, and iPad. This page covers how off-network filtering works, how GoGuardian Admin enforces it across a mixed device fleet, and how to evaluate any vendor against the 1:1 take-home program your district actually runs.
The Take-Home Gap
The 1:1 device mandate has shifted the K-12 filtering problem. Districts that once managed filtering on a campus network now ship Chromebooks, iPads, and Windows laptops home with students. The buyer-side question that follows is direct: "what protects kids at home?" That question dominates parent meetings, school board reviews, and RFP scoring rubrics in a way it didn't five years ago.
The filtering vendor's answer depends on architecture. A web filter built around a campus appliance treats off-network as a coverage gap to bolt on later. A web filter built around a device-level agent or extension treats off-network as a default mode that's always on, with policy adjustments for school hours vs. home hours. The architectural posture a vendor chose at product inception largely determines how their off-network story reads today.
The procurement implication for Directors of Technology evaluating filtering vendors in 2026: the on-network filtering question is largely settled, but the off-network filtering question varies sharply across vendors. The dimensions that separate them include per-OS coverage, on/off-network feature parity, and program operations like a parent-facing app and district-controlled off-campus policy. The rest of this page works through each.
On-Network vs Off-Network Feature Parity
The harder question than “does it work off-network” is “does the same filtering apply off-network.” With some architectures, off-network coverage exists but with a narrower feature set than on-network. GoGuardian Admin filters on and off the school network with no feature degradation off-network, provided the student stays signed into a school-managed account on a managed device. Administrators configure the off-campus policy set independently, but the filtering capability itself does not downgrade when the device leaves campus.
The parity question carries real procurement weight because off-network is where many of the highest-stakes student safety events happen: after-school hours, weekends, and parent-supervised but device-mediated use. A filter that downgrades to a narrower feature surface off-campus may surface the same content categories but miss contextual signals it would catch on the campus network. Buyers should ask each vendor for an explicit on-network vs. off-network feature parity statement during RFP review.
Capability Comparison
A capability comparison across GoGuardian Admin, Lightspeed Filter, and Securly Filter on the dimensions that matter off-network. GoGuardian Admin covers every OS in a typical mixed Chromebook, Windows, macOS, and iPad fleet, with the program-operations layer (parent app, policy scheduling, MDM breadth) around it. For the deeper head-to-head against each, see the GoGuardian vs Lightspeed off-network comparison and the GoGuardian vs Securly off-network comparison.
| Capability | GoGuardian Admin | Lightspeed Filter | Securly Filter |
|---|---|---|---|
| Chromebook coverage (off-network) | Chrome extension | Chrome extension | Chrome extension |
| Windows / macOS coverage (off-network) | On-device GoGuardian App via MDM, filters every browser | SmartAgent (on-device) | SmartPAC or browser extension |
| iPad (iPadOS) coverage (off-network) | GoGuardian App via MDM | iOS app via MDM | SmartPAC via MDM |
| On- vs off-network feature parity | No feature degradation off-network on a managed, signed-in device | Parity on managed devices | Method-dependent: SmartPAC drops Chat scanning, YouTube controls, and full logging |
| Off-network policy control | Out-of-School Mode: time-of-day + public-IP scheduling, automatic off-campus detection | After School Rules (time / network based) | Take-Home Policy (one policy per district; force-login default) |
| Parent-facing app | GoGuardian Parent App (Apple App Store and Google Play): activity summary, pause internet, block sites, schedule availability on managed devices | Parent Portal | Securly Home |
| MDM deployment (named platforms) | Windows: AD, Intune, PDQ. iPadOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Workspace ONE/AirWatch, Iru, Mosyle, Addigy. macOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Iru, Mosyle. Manual also supported. | Generic MDM support; no comprehensive named list | 6 named platforms |
| Security certification | SOC 2 Type II | SOC 2 Type II | SOC 2 Type II |
| Off-network filtering releases (last 24 months) | Windows stability across network interruptions (December 2025); Theft Recovery off-campus filtering (July 2025) | None identified | None identified |
The practical implication for the Director of Technology: the cross-platform coverage profile maps directly to the district’s existing device fleet. On an all-Chromebook fleet, filtering is delivered through a Chrome extension across the category, so the vendors separate on the program-operations layer: the parent app, district-controlled off-campus policy, and off-network product velocity. A mixed Chromebook, Windows, and iPad fleet adds a second axis of separation, where the on-device app and MDM breadth determine how consistently a vendor covers the non-Chromebook devices.
How GoGuardian Enforces Off-Network
GoGuardian Admin enforces off-network filtering through the Chrome extension on Chromebook and the GoGuardian App on Windows, macOS, and iPadOS, governed by Out-of-School Mode. A fourth layer, DNS Precision Filtering, covers devices on the school network rather than off-campus use.
1. Chrome extension on Chromebook. Deployed via Google Admin Console as a managed extension. Filtering applies to managed-browser traffic; ChromeOS architecture constrains student web activity to the managed browser, so the practical coverage is consistent with the web filtering the GoGuardian App provides on other OSes.
2. GoGuardian App on Windows, macOS, and iPadOS. An on-device app delivered via MDM enrollment. The GoGuardian App filters web traffic across every browser on the device, on or off the network, and keeps enforcing district policy when the device leaves campus. It does not filter non-browser application traffic the way a kernel-level agent does. MDM support covers the vendors with official setup guides. Windows: Active Directory, Intune, and PDQ. iPadOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Workspace ONE/AirWatch, Iru (formerly Kandji), Mosyle, and Addigy. macOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Iru (formerly Kandji), and Mosyle. Manual deployment is also supported, and in practice any MDM that can push apps (plus registry keys on Windows, or mobileconfigs on iPad and macOS) works.
3. Out-of-School Mode. The off-network policy mechanism. Out-of-School Mode uses time-of-day scheduling and public-IP-range detection to determine which policy set is active. During school hours and when the device is on a recognized district network, the standard filtering policy applies. Outside those windows (evenings, weekends, breaks, off-campus access), the Out-of-School policy set takes effect. District administrators configure the off-campus policy independently of the on-campus policy, so a district can apply tighter or looser filtering off-network depending on program structure.
4. DNS Precision Filtering (on-network and BYOD). DNS Precision Filtering (released November 2025) enhances GoGuardian Admin's on-premises DNS filtering to protect all devices connected to the school network, including unmanaged and BYOD devices. Administrators can apply tailored filtering policies by subnet or private IP range, with enhanced reporting, CNAME identification, and agent awareness. It is bundled with Admin, not a separate SKU. This layer covers devices on the school network; it is not part of the off-campus enforcement path.
The Out-of-School Mode mechanism is the policy layer; the Chrome extension and the GoGuardian App are the off-network enforcement layers. The combination produces a filtering posture that follows the device regardless of network location, with district-controlled policy adjustments for school hours vs. home hours.
Evaluation Framework
The questions districts should ask any K-12 off-network filtering vendor during RFP review. Designed to be vendor-agnostic and reusable across a shortlist.
1. Off-network architecture
What's the underlying mechanism for filtering off-network, and what coverage does that mechanism produce?
Questions to ask:
- Is the off-network filter a kernel-level agent, browser extension, on-device app, DNS layer, or combination?
- Which OSes does each method support, and what's the delivery channel (MDM, Google Admin Console, manual install)?
- Does coverage apply system-wide on the device, or only to managed-browser traffic?
- For browser-extension models: what happens if a student opens an unmanaged browser?
What good looks like:
- Vendor publishes the architecture per OS in product documentation (not just generic "off-network supported")
- Vendor is explicit about which traffic the mechanism filters per OS (web traffic across browsers vs. all application and protocol traffic)
- MDM delivery channel is named explicitly with supported platforms
2. Cross-platform coverage
Does the vendor cover the district's actual device fleet?
Questions to ask:
- Which OSes are in the published coverage list (Chromebook, Windows, macOS, iPad, Android)?
- For each OS, what's the specific delivery mechanism?
- Are there OSes the vendor doesn't cover where the district has devices?
- For Android specifically: is it in the product page, or only mentioned in press releases?
What good looks like:
- Published coverage matches the district's device fleet across all primary OSes
- Each OS has a documented delivery mechanism (not "contact sales for details")
- Android coverage, if claimed, is named on the product page, not just in press
3. On-network vs off-network feature parity
Does the same filtering apply when the device leaves campus?
Questions to ask:
- Which features (SSL decryption, real-time alerting, image filtering, Chat scanning, YouTube controls) are available on-network?
- Of those, which remain available off-network?
- For multi-method architectures (e.g., Extension OR Hybrid): does method choice affect which features are available?
- For browser-extension models: what's the parity gap vs. on-device app or kernel agent on the same OS?
What good looks like:
- Vendor provides an explicit on-network vs. off-network feature parity statement
- Where parity gaps exist, the vendor names which features specifically degrade
- For multi-method architectures, the trade-off is documented per method
4. Take-home program operations
What collateral does the vendor provide for the operational side of running a take-home device program?
Questions to ask:
- Does the vendor publish a take-home program guide (downloadable, ungated)?
- Are there sample AUP templates for take-home device use?
- Is there a parent communication template or parent-engagement kit?
- Does the vendor support multi-language parent communication (Spanish, French, others)?
What good looks like:
- Downloadable take-home program guide available without a sales gate
- Parent communication template in English plus at least Spanish (most common second language in U.S. K-12)
- Sample AUP language districts can adapt vs. having to draft from scratch
5. Vendor due diligence
What's the vendor's track record, certification stack, and product velocity on off-network filtering specifically?
Questions to ask:
- What certifications does the vendor hold (SOC 2 Type, ISO 27001, iKeepSafe FERPA/COPPA, 1EdTech TrustEd Apps)?
- What's the product velocity on off-network features in the last 24 months? Are they actively building, or treating Filter as steady-state?
- Are there published case studies of districts running 1:1 take-home programs on this filter?
- What's the support model for off-network deployment issues (response time, escalation path)?
What good looks like:
- SOC 2 Type II at minimum, plus at least one student-data privacy attestation (iKeepSafe or 1EdTech)
- Visible product velocity on off-network in trade press / changelogs / release notes (not just acquisitions in adjacent product lines)
- Named case studies from districts comparable in size + device fleet to the evaluating district
Frequently Asked Questions
What's the difference between on-network and off-network filtering?
On-network filtering applies when the device is on a school network, typically via an appliance, proxy, or DNS server on the campus network. Off-network filtering applies when the device leaves campus and connects to home wifi, public networks, or cellular. The on-network case is the historical default for K-12 web filtering. The off-network case is the gap that emerged when 1:1 device programs sent Chromebooks, iPads, and Windows laptops home with students. Most modern K-12 filters address both via a device-level extension or on-device app that follows the device regardless of network location.
How reliable is off-network filtering on a take-home Chromebook?
Chromebook off-network coverage is consistent across the three major vendors because all three deliver Chromebook filtering via Chrome extension, which is the OS-level managed channel for ChromeOS. ChromeOS architecture constrains student web activity to the managed browser, so extension-based filtering covers the device's web traffic comprehensively. The reliability question is more interesting on Windows, macOS, and iPad, where vendor architectures diverge (kernel agent vs. on-device app vs. extension-only). Districts running mixed-OS fleets should ask each vendor for the specific delivery mechanism per OS during RFP review.
Which K-12 web filter has the best off-network protection: GoGuardian, Lightspeed, or Securly?
For most K-12 districts, the deciding factor is consistent coverage across a mixed device fleet plus the program-operations layer around it. GoGuardian Admin filters off-network across Chromebook (Chrome extension), Windows, macOS, and iPad (the GoGuardian App, delivered via MDM), governed by Out-of-School Mode, with no feature degradation off-network on a managed device where the student stays signed in. Paired with the GoGuardian Parent App, broad MDM support, and district-controlled off-campus policy, that is a filtering posture that follows the device home without a separate off-network product to bolt on. See the GoGuardian vs Lightspeed off-network comparison and GoGuardian vs Securly off-network comparison for the per-vendor detail.
Does GoGuardian's off-network filtering actually work at home?
Yes, via the GoGuardian App on Windows, macOS, and iPadOS (delivered via MDM) and the Chrome extension on Chromebook (delivered via Google Admin Console). The GoGuardian App filters web traffic across every browser on the device, on or off the network, and keeps enforcing district policy when the device leaves campus. It does not filter non-browser application traffic the way a kernel-level agent does. GoGuardian Admin filters on and off the school network with no feature degradation off-network, provided the student stays signed into a school-managed account on a managed device. The Out-of-School Mode mechanism applies the district's off-campus policy set, which administrators configure independently of the on-campus policy.
What's Out-of-School Mode and how does it decide which policy applies?
Out-of-School Mode is GoGuardian Admin’s off-network policy mechanism. It uses time-of-day scheduling and public-IP-range detection to determine which policy set is active. During school hours on a recognized district network, the standard policy applies. Outside those windows, the Out-of-School policy set takes effect, which administrators configure independently of the on-campus policy. Other K-12 filters offer analogous off-campus policy modes; the mechanics differ by detection trigger (time of day, IP range, or both).
What devices does GoGuardian filter off-network?
GoGuardian's published off-network coverage includes Chromebook (via Chrome extension), Windows (via GoGuardian App, MDM-delivered), macOS (via GoGuardian App, MDM-delivered), and iPad (via GoGuardian App, MDM-delivered). Android is available today via GoGuardian's Gateway deployment. Gateway is being deprecated, so Android is not part of the GoGuardian App off-network coverage set.
How does parent communication work for a 1:1 take-home program?
Parent communication for a take-home device program typically includes the take-home AUP (acceptable use policy), the off-campus monitoring disclosure, parent-facing visibility into filtering events, and a process for parents to flag concerns or request policy adjustments. The GoGuardian Parent App is available on the Apple App Store and Google Play; parents can see a summary of their student’s browsing activity and can pause internet access, block specific websites, and schedule internet availability on managed devices.
What's the difference between the GoGuardian App, the Chrome extension, and DNS Precision Filtering?
These are three layers of the GoGuardian Admin filtering stack. The Chrome extension applies to Chromebook (the OS-level managed channel). The GoGuardian App is an on-device app for Windows/macOS/iPadOS that filters web traffic across every browser on the device, on or off the network; it does not filter non-browser application traffic the way a kernel-level agent does. The Chrome extension and the GoGuardian App are the layers that follow a device off-campus. DNS Precision Filtering, released November 2025, enhances GoGuardian Admin's on-premises DNS filtering to protect all devices connected to the school network, including unmanaged and BYOD devices; it is an on-network and BYOD capability, not part of the off-campus enforcement path. The relevant mechanism on a given device depends on its OS, how it accesses the internet, and whether it is on or off the school network.
Does GoGuardian work with our MDM platform?
GoGuardian Admin's Windows, macOS, and iPadOS deployment depends on MDM enrollment. GoGuardian App MDM support covers the vendors with official setup guides. Windows: Active Directory, Intune, and PDQ. iPadOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Workspace ONE/AirWatch, Iru (formerly Kandji), Mosyle, and Addigy. macOS: Jamf Pro, Jamf School, Intune, Meraki, FileWave, Iru (formerly Kandji), and Mosyle. Manual deployment is also supported, and in practice any MDM that can push apps (plus registry keys on Windows, or mobileconfigs on iPad and macOS) works.