FluxMoat
FluxMoat

FluxMoat

An on-device network privacy monitor and firewall for iPhone.

FluxMoat observes and filters network activity locally. Your traffic never passes through servers operated by FluxMoat.

Coming soon to the App Store.

What it does

See the network your phone has been using without you

Throughout the day your device connects to services around the world — mostly out of sight. FluxMoat makes that visible, then lets you do something about it.

  • Dashboard

    Protection on or off, the last hour of traffic as it happens, anything waiting on your decision, and the destinations your device has been talking to most.

  • Live Traffic

    The connection-by-connection view: destination, port, protocol, bytes out and in, and the verdict each one got. Sent and received are read as one instrument.

    • Sent
    • Received
  • Insights

    Trends over a period you choose, and a map of where connections went. Country labels are estimated from IP addresses, so read the map as an indication rather than a fact about where anyone is.

  • Rules

    Allow or block by exact target, by whole site, by network range, by port or protocol — plus country policies. Precedence is described in words, not numbers.

  • Threat intelligence

    ThreatFox already works. FluxMoat ships with a subscription to its own mirror of the feed, rebuilt every 6 hours, no account and no key. An abuse.ch Auth-Key is optional, never required.

  • Blocklists

    Ads-and-malware hosts lists and threat feeds, matched on your device. Nothing downloads until you ask for it the first time; after that FluxMoat keeps what you chose from going stale.

How rules resolve

A ladder of shapes, not a field of numbers

Nobody can hold a 0–100 priority scale in their head. FluxMoat decides by how far a rule reaches: the narrower the target, the more it wins.

  1. 1 An exact target — one hostname, one IP address.
  2. 2 Site-wide *.example.com, or a network range.
  3. 3 A country policy — covers targets seen from that country, and new ones as they show up. Block-only, by design.
  4. 4 A port or protocol rule — sits under all three.
  5. then Threat feeds, then blocklists — checked after your rules, so a rule of yours can overrule an entry on a list.
  6. last The mode decides — Standard allows what nothing matched, Strict blocks it, Ask applies the profile default and asks you afterwards.

When two rules reach equally far and disagree, Allow wins. That tie-break applies between rules of the same reach — a broader Allow never beats a narrower Block.

Know the boundaries

What FluxMoat will never claim to do

The app puts these on screen at first launch, before you have decided anything. They are limits of what iOS and encryption permit, and no amount of product work removes them. We would rather lead with them than have you discover them.

  • Network activity is shown for the whole device. iOS doesn't identify the originating app. iOS does not expose source-app identity to a consumer packet tunnel. Any app claiming a per-app breakdown on iPhone is guessing.
  • Encrypted content stays encrypted. FluxMoat does not decrypt HTTPS, does not install a root certificate, and does not inspect what is inside a connection. It sees where traffic goes, never what it says.
  • Alerts don't pause a connection while waiting for your response. Ask mode is asynchronous and notification-driven. It is not a blocking dialog, and the app is labelled accordingly.
  • Locations are estimates and may be inaccurate. Country comes from an IP-address lookup against a database bundled in the app. VPNs, CDNs and cloud regions all move the answer.
  • iOS allows one VPN of this kind at a time. Turning FluxMoat on turns off another VPN of this kind, and turning the tunnel off stops filtering. Blocking here is a control, not a security boundary.
  • Apps using their own encrypted DNS may bypass domain-based filtering; IP rules still apply. An app pointed at its own private resolver is a permanent blind spot. No list of public resolvers closes it, so we say so instead of pretending otherwise.
  • Ping (ICMP) traffic isn't filtered yet, so ICMP rules have no effect. The rule editor says the same thing at the moment you pick ICMP, rather than letting you build a rule that will never fire.

Privacy

There is no server to trust

This is the part most network apps get to be vague about. We would rather be specific.

  • All analysis happens on this device

    The tunnel begins and ends on your iPhone. Your traffic is not routed through, or copied to, anything we operate.

  • No account, ever

    No sign-up, no email, no device identifier, no advertising identifier. There is nothing to log in to.

  • No analytics, no ad SDK

    Not disabled by default — absent. The app contains no analytics, advertising, attribution or crash-reporting SDK at all.

  • History stays local

    Traffic history never leaves this device unless you export it. No payloads, page contents or credentials are ever stored — only domains, IP addresses, ports, protocols and byte counts.

The privacy policy lists every server the app can contact and what makes it happen. It is a table with six rows, and it is meant to stay exhaustive.