Nantevo delivers authenticated Protective DNS through a novel transport-layer architecture — no endpoint software, no enrollment friction, no attack surface on your devices. Per-client 1:1 attribution, MDM-native deployment, and cloud, hybrid, or on-premise infrastructure aligned to NIST SP 800-81r3.
Traditional Protective DNS fails at the deployment model. Browsers independently implementing their own DoH bypass corporate controls entirely. Nantevo's transport-layer authentication architecture eliminates both problems simultaneously.
These projections extrapolate 2.5 years of production telemetry to a 500-employee fleet. Ad and tracker filtering doesn't just reduce the attack surface — it removes bandwidth and latency overhead from every device on your network. Ad networks are a well-documented malvertising delivery channel; blocking them at the resolver is a security control, not a convenience feature.
Architectural choices — not feature additions — with consequences that compound across every device in your fleet from day one.
Every DoH request carries a unique high-entropy endpoint subdomain and ClientID. The reverse proxy validates both before routing to the resolver. Unauthenticated requests receive no response — not an error, silence. DNS is treated as a Policy Enforcement Point in the Zero Trust sense: no query proceeds without verified identity. Per NIST SP 800-207, no network is inherently trusted.
Nantevo generates per-client MDM profiles containing unique high-entropy DoH endpoints pre-bound to unique ClientIDs. Deploy through your existing Apple MDM. OS-level DoH configures silently, system-wide — overriding browser-level DoH, covering every application and process simultaneously. The Encrypted DNS Gap closes the moment the profile installs.
Because every query carries an authenticated client identity, threat telemetry is scoped to the individual device. When RoCi detects a C2 beacon, the SOC gets the exact device, exact timestamp, and exact domain immediately — without needing network access or VPN correlation. This is what eliminates the visibility gap that slows incident response on agent-free competitor platforms.
RoCi analyzes the telemetry log stream asynchronously — after responses are already delivered. This is an architectural constraint, not a limitation: DNS resolution latency is a hard constraint, AI inference is not. RoCi's detections update the synchronous threat feed, building a defense-in-depth stack that improves with every detection across every client.
The same authentication architecture and RoCi intelligence operate across all three models. What changes is where the resolver runs and where DNS queries travel.
Globally distributed resolver nodes across the US with expansion roadmap to 32 locations. MDM profile push for zero-touch Apple fleet enrollment. Fastest path to full fleet protection — operational within hours of decision. All RoCi intelligence and per-client telemetry included.
Your DoH endpoint lives on your own subdomain. A local forwarding layer in your data center handles internal domain resolution. External queries route upstream to Nantevo resolvers. RoCi threat intelligence and unified per-client telemetry operate seamlessly across both layers.
Complete resolver stack deployed as a virtual appliance in your data center. DNS queries never leave your network. Only anonymized RoCi threat signals stream outbound — query content never crosses your boundary. Sub-10ms response times on-network. CDN outages have zero impact on resolution.
Device coverage was proven with real households and real devices — not claimed on a spec sheet. Every category below has been operational in production since October 2023.
Provision, deploy, and activate protection across your entire fleet without touching a single device directly.
Generate a unique MDM configuration profile per client group from the Nantevo dashboard. Each profile contains a unique high-entropy DoH endpoint and bound ClientID — 128-bit entropy per credential, combined authentication required. Per-client filtering policy, content categories, and RoCi sensitivity are configured at this stage.
Deploy through your Apple MDM infrastructure. The profile installs silently at OS level, overriding browser DoH configuration system-wide. No user interaction. No application download. Every application, every process, every DNS query covered simultaneously — including browsers that would otherwise use their own DoH resolver.
From the moment the profile installs, every DNS query is encrypted, authenticated at the proxy, filtered against live threat intelligence, and logged with 1:1 device attribution. RoCi monitors behavioral patterns asynchronously — never in the query path — and surfaces threats with the exact device identity needed to begin containment immediately.
RoCi analyzes per-client DNS query behavior continuously and classifies threats across every authenticated client simultaneously. When it detects a C2 beacon, a DGA pattern, or a tunneling attempt, it pushes a block rule to the synchronous threat feed immediately — cutting the attacker's communication channel before the device can receive a payload.
Enterprise security teams need logs. Nantevo gives you control over exactly what is retained, for how long, and where — without your data ever being used for anything other than your own security operations.
Compliance & framework alignment
Where Nantevo is today
Nantevo has run in continuous production since October 2023 — the sole DNS resolver for a live fleet of real devices across every platform we support. Every metric on this site comes from that deployment, not a lab benchmark.
— 2.5 years of operational history
Enterprise deployment is new territory for the platform, and we say so plainly. Design partners get 50% pricing for 24 months, direct access to the founder, and real influence on the roadmap.
— Design partner program, now accepting
We publish our live component status, our production telemetry, and our incidents — including upstream CDN events — where anyone can check them. Trust should be verifiable, not asserted.
— Live status at nantevo.com/status
Two and a half years of continuous operation across geographically distributed infrastructure. Production telemetry plus live component status from the same platform your organization will run on.
Live demo. Your devices. No software installed before, during, or after.