Inputs to a policy decision
On the browser-proxy path the gateway decides using domain/host metadata, a local versioned category list and your workspace allow/deny rules — applied before traffic leaves through the approved egress region.
- Domain / host metadata
- Versioned category list
- Workspace allow / deny overrides
- Routing mode and egress region
Not content inspection
On the browser-proxy path BusinessProxy does not decrypt HTTPS page content, inspect the page DOM, parse private form fields, read files inside encrypted sessions, or provide DLP classification. If a page is allowed by domain/category policy, its encrypted content stays encrypted through the proxy path.
- No TLS interception on the browser path
- No page DOM or form-field inspection
- No DLP / content classification
Versioned local feed first
The MVP category source is a local, versioned feed — a deliberate operating model that keeps policy decisions reproducible and reviewable. External threat-intelligence feed integration is planned, not part of the default baseline until it is explicitly loaded and verified.
- Versioned category baseline
- Workspace allow/deny overrides
- Operational deny rules
- External threat feed planned / not enabled