FluxMoat
An on-device network privacy monitor and firewall for iPhone.
FluxMoat observes and filters network activity locally. Your traffic never passes through servers operated by FluxMoat.
Coming soon to the App Store.
What it does
See the network your phone has been using without you
Throughout the day your device connects to services around the world — mostly out of sight. FluxMoat makes that visible, then lets you do something about it.
-
Dashboard
Protection on or off, the last hour of traffic as it happens, anything waiting on your decision, and the destinations your device has been talking to most.
-
Live Traffic
The connection-by-connection view: destination, port, protocol, bytes out and in, and the verdict each one got. Sent and received are read as one instrument.
- Sent
- Received
-
Insights
Trends over a period you choose, and a map of where connections went. Country labels are estimated from IP addresses, so read the map as an indication rather than a fact about where anyone is.
-
Rules
Allow or block by exact target, by whole site, by network range, by port or protocol — plus country policies. Precedence is described in words, not numbers.
-
Threat intelligence
ThreatFox already works. FluxMoat ships with a subscription to its own mirror of the feed, rebuilt every 6 hours, no account and no key. An abuse.ch Auth-Key is optional, never required.
-
Blocklists
Ads-and-malware hosts lists and threat feeds, matched on your device. Nothing downloads until you ask for it the first time; after that FluxMoat keeps what you chose from going stale.
How rules resolve
A ladder of shapes, not a field of numbers
Nobody can hold a 0–100 priority scale in their head. FluxMoat decides by how far a rule reaches: the narrower the target, the more it wins.
- 1 An exact target — one hostname, one IP address.
-
2
Site-wide
—
*.example.com, or a network range. - 3 A country policy — covers targets seen from that country, and new ones as they show up. Block-only, by design.
- 4 A port or protocol rule — sits under all three.
- then Threat feeds, then blocklists — checked after your rules, so a rule of yours can overrule an entry on a list.
- last The mode decides — Standard allows what nothing matched, Strict blocks it, Ask applies the profile default and asks you afterwards.
When two rules reach equally far and disagree, Allow wins. That tie-break applies between rules of the same reach — a broader Allow never beats a narrower Block.
Know the boundaries
What FluxMoat will never claim to do
The app puts these on screen at first launch, before you have decided anything. They are limits of what iOS and encryption permit, and no amount of product work removes them. We would rather lead with them than have you discover them.
- Network activity is shown for the whole device. iOS doesn't identify the originating app. iOS does not expose source-app identity to a consumer packet tunnel. Any app claiming a per-app breakdown on iPhone is guessing.
- Encrypted content stays encrypted. FluxMoat does not decrypt HTTPS, does not install a root certificate, and does not inspect what is inside a connection. It sees where traffic goes, never what it says.
- Alerts don't pause a connection while waiting for your response. Ask mode is asynchronous and notification-driven. It is not a blocking dialog, and the app is labelled accordingly.
- Locations are estimates and may be inaccurate. Country comes from an IP-address lookup against a database bundled in the app. VPNs, CDNs and cloud regions all move the answer.
- iOS allows one VPN of this kind at a time. Turning FluxMoat on turns off another VPN of this kind, and turning the tunnel off stops filtering. Blocking here is a control, not a security boundary.
- Apps using their own encrypted DNS may bypass domain-based filtering; IP rules still apply. An app pointed at its own private resolver is a permanent blind spot. No list of public resolvers closes it, so we say so instead of pretending otherwise.
- Ping (ICMP) traffic isn't filtered yet, so ICMP rules have no effect. The rule editor says the same thing at the moment you pick ICMP, rather than letting you build a rule that will never fire.
Privacy
There is no server to trust
This is the part most network apps get to be vague about. We would rather be specific.
-
All analysis happens on this device
The tunnel begins and ends on your iPhone. Your traffic is not routed through, or copied to, anything we operate.
-
No account, ever
No sign-up, no email, no device identifier, no advertising identifier. There is nothing to log in to.
-
No analytics, no ad SDK
Not disabled by default — absent. The app contains no analytics, advertising, attribution or crash-reporting SDK at all.
-
History stays local
Traffic history never leaves this device unless you export it. No payloads, page contents or credentials are ever stored — only domains, IP addresses, ports, protocols and byte counts.
The privacy policy lists every server the app can contact and what makes it happen. It is a table with six rows, and it is meant to stay exhaustive.