Skip to content
Nullgen AI Blocker

Trust Center

Deployment for IT

Nullgen is built to be pushed, not installed by hand. Here is what your device-management tool installs, what people see, and what to allow on the network.

Last reviewed: September 23, 2026

What gets installed

  • Browser extension

    Force-installed in Chrome, Edge, Firefox, or Safari through your tool’s browser policies. A managed configuration carries your enrollment token, so each browser enrolls itself on install. End users see no prompt and cannot remove or disable it.

  • Phones and tablets

    The app is pushed as a required managed app with an app configuration that enrolls the device. An optional configuration profile installs the filter so protection turns on with no approval prompt and locks the Connect On Demand switch; it needs no supervision. Apple does not deliver that profile under User Enrollment, so devices enrolled that way approve the VPN once instead. One launch of the app completes enrollment.

    Available today: iOS. Coming next: Android, macOS, and Windows.

  • Macs and Windows PCs

    The desktop agents will use the same enrollment token as your browsers and phones, and the Provisioning page will carry their payloads when they ship. Nothing to re-issue.

Supported management tools

The Provisioning page generates payloads with the identity placeholders each tool fills in automatically, so one policy covers every user.

  • Microsoft Intune
  • Jamf
  • Iru (formerly Kandji)
  • Google Workspace
  • Windows GPO

What end users see

  • Nothing to install or approve. Typing and pasting into AI prompts stops working; everything else on the page keeps working.
  • With the configuration profile, protection is on before the person opens the app, and iOS shows its standard VPN indicator while the filter is active. Without the profile, the person approves the VPN once.
  • When something is blocked that the person needs, they can request access for a set time. Approvers decide in the dashboard and the change syncs to the device.

Network requirements

Allow these hosts on outbound HTTPS. Live updates also use an AWS-hosted realtime endpoint; if it is blocked, changes still arrive on the next refresh.

  • nullgen.ai — dashboard, API, policy sync, access requests
  • cdn.nullgen.ai — detection updates and assets

Store downloads use the vendors’ own hosts: the Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons, and the App Store.

Step-by-step guides live in the dashboard

Vendor-specific instructions, generated payloads, and your organization’s enrollment token are in your Dashboard under the Provisioning page.