Your team is getting watched in two different ways right now, and neither one shows up in a security report.
The first is the network. The moment someone opens a laptop in a hotel, an airport, or a conference hall, their outbound traffic is visible to anyone else watching that network.
The second happens everywhere, including on the network you own. The sites your team visits are quietly collecting: Location trackers, mail trackers, data brokers, and ad networks build profiles in the background on every single visit.
We have had tools for the first problem for years. The catch is that most of them only work when the user remembers to turn them on. They forget. They skip it on fast hotel Wi-Fi. They turn it off when it slows something down.
That gap, between "we have a tool for that" and "protection is actually running," is where traffic gets intercepted and users get profiled.
SecureTransit closes it.
SecureTransit is endpoint privacy, enforced as policy. It does two things.
It encrypts outbound traffic before it leaves the device. Every time your team connects from a hotel, an airport, or a conference, they are on a network you do not own, and traffic on those networks can be observed and intercepted. SecureTransit encrypts it at the device, so what crosses the wire is unreadable to anyone watching locally.
It blocks trackers at the source. Location trackers, mail trackers, data brokers, and ad networks get cut off before data ever leaves the device. This one applies on any network, from the office to home network to hotel Wi-Fi.
SecureTransit ships inside the DNSFilter Roaming Client, the same lightweight agent you already use for filtering and for user activity intelligence through CyberSight. There is no second agent to deploy and no second console to learn.
Admins set the mode per organization or per device: Always-On, Manual, or Disabled. Credentials are provisioned and managed server-side, so your users never configure anything. That means they cannot misconfigure anything, and in Always-On mode, they cannot opt out.
SecureTransit is currently in beta and is available in our existing two-week free trial.
Login or start your free trial today.
Fair question, and yes, at the DNS layer. DNS filtering blocks trackers during DNS resolution, before a connection is ever made, and it runs everywhere your Roaming Clients run.
SecureTransit blocks the tracker connection at the source, as traffic passes through the tunnel. That catches what DNS-layer blocking alone cannot, and it encrypts everything else along the way.
One distinction worth making: DNS-over-TLS and DNS-over-HTTPS encrypt the DNS query itself, but everything that comes after that query is still in the clear. SecureTransit encrypts the whole path, device to internet.
The two run as complementary layers with a graceful fallback. If the tunnel is disconnected or disabled, the device falls back to DNS-layer tracker filtering. Protection degrades. It never disappears.
This is the part I want to be clearest about, because "privacy" can sound a lot like "a place my users go that I cannot see."
SecureTransit shields users from local-network observers and third-party trackers. It never shields them from your own admins. You keep the same DNS query visibility you have today, so there are no blind tunnels and no reporting gaps. Your users get privacy from outsiders, and you keep the audit trail.
With SecureTransit, the DNSFilter Roaming Client delivers three distinct capabilities through a single lightweight agent:
One deployment. Three capabilities. One place to manage all of them.
SecureTransit is a per-device add-on. You license it where the risk lives instead of paying for every endpoint in the building.
For most teams, that is a short list: The people who travel, the executives, the fully remote staff, and honestly, the users who keep failing your phishing simulations. If you are running 100 Roaming Clients and 10 of those users are the ones genuinely working off untrusted networks, you cover those 10.
Cost scales with exposure, not headcount.
For MSPs, that is what makes it sellable. SecureTransit runs inside the same multi-tenant dashboard you already use, so your techs deploy it without adding a vendor, a console, or a new workflow. This way, you can lead the conversation around privacy with: "Privacy is enforced as policy on every device that needs it."
Enforcement has been a weak point for structural reasons more than technical ones. Most privacy tools are separate products with a separate agent, a separate console, and a separate vendor. That means another deployment to manage, another set of credentials to maintain, and a dependency on users to actually connect.
Every one of those is a place where it can quietly fail. The tool sits in a different workflow than your filtering policy. There is no way to tie enforcement to the organizational hierarchy you already manage. And when a user is off-network on a connection you do not control, you have no way to confirm anything is running at all.
We built SecureTransit for managed environments, where policy enforcement, not user behavior, is the security model.
DNSFilter blocks the threats. SecureTransit handles the privacy. Your data should be yours: On hotel Wi-Fi, on the office network, and inside every site your team visits.
SecureTransit entered beta on Aug. 17, 2026, and it is available today on the Windows Roaming Client, version 3.7 and up. Support for our other platforms is coming.
You can test it today in our 14-day trial. Then go look at how many trackers it blocked for those people in two weeks. That number tends to be the whole argument.