Enforcement that lives on the device. Law that outranks the settings menu.
CPO turns child-safety legislation into enforced behaviour on real devices — a policy engine that stamps jurisdiction law onto every rule set, a control panel for parents, and a protection app a child cannot switch off.
Children carry the whole internet in their pocket.
Network-level filtering — the model of the last decade — no longer reaches them. Modern apps and browsers hide what a network filter needs to see.
Encrypted traffic
Filtering built for the web misses where kids actually spend time.
Apps bypass browsers
Most exposure now happens inside apps a network filter never sees.
VPNs beat filters
A free VPN defeats an ISP-level filter in about thirty seconds.
Meanwhile, the law is catching up
Minimum ages for social media, mandatory age assurance, and duty-of-care obligations are now being legislated worldwide. CPO's answer: one platform enforcing rules where they cannot be bypassed.
Enforcement happens on the device.
The panel is where decisions are made; the child app is where they are applied.
Parent Control Panel
Create child profiles, set rules, review activity, approve or deny access requests.
Policy Engine & API
Stores policy, stamps jurisdiction law onto it, serves the effective policy, receives events.
Child Protection App
Applies filtering, app blocks, time budgets and tamper protection locally — online or offline.
Because policy is resolved on the server and signed before delivery, a modified client cannot unlock a restriction the law imposes.
Jurisdiction mode — the law wins.
Each household loads the published rule set for its country. Where a legal restriction exists, the control is locked with a plain-language explanation — and a parent cannot switch it off. This is what separates CPO from a consumer parental-control app.
Minimum-age rules
Applied automatically from the child's date of birth.
Nationally banned platforms
Blocked regardless of parent settings.
Auto-denied requests
Access a law prohibits is denied, with the reason shown to both parent and child.
Law vs. preference
Legal rules and parent choices stay visually distinct — authority is never ambiguous.
Versioned rule sets
Dated and versioned, giving regulators and operators an auditable enforcement record.
Built for both established risks and the categories that came after.
Content and category controls, screen time, tamper protection, and a documented API for operators — each configurable per child, and locked wherever the law requires it.
Content & category controls
Established categories like adult content and violence, plus modern ones: AI companion apps, crypto and gambling, disappearing messaging.
Screen time & daily rhythm
Daily time budgets, bedtime windows, per-category schedules, and chores that release bonus minutes.
Tamper protection
Blocks VPNs, proxies, sideloading and private browsing; locks DNS; prevents uninstall. Every attempt is logged and surfaced to parents.
Guided supervision enrollment
Step-by-step setup tailored to iOS & iPadOS, Android, Chromebook and Windows — not left to the parent to figure out.
Parent dashboard
Supervision status, recent activity, an access-request inbox, and CSV export for schools or clinicians who need records.
Policy API for operators
A documented API — /policy, /activity, /request, /tamper — built for ISP-scale and government-scale deployment.
Policy on the left. Evidence on the right.
Every household sees exactly which rules come from the law and which are their own choices — and every action a child's device takes is written to an audit trail underneath it.
What the child sees.
Nothing silent. Every block names its reason — and whether that reason is a parent's choice or the law.
Protection active
No hidden state — time and limits shown plainly.
Blocked by law
Attributed to statute — the parent cannot lift it.
Category blocked
Parent policy, with the category named on screen.
Time's up
Daily budget reached; enforced locally, so it holds offline.
Ask a parent
One tap to the panel. Statutory blocks aren't requestable.
VPN blocked
Bypass refused and logged as a tamper event.
One platform, four different jobs to do.
CPO is built primarily as infrastructure for regulators and the operators they work with — and it's what parents and schools use day to day.
Regulators
PrimaryA mechanism that turns written law into enforced behaviour on real devices — versioned rule sets, aggregate compliance reporting, never child-level surveillance.
Operators & ISPs
A deployable child app and policy API offered to a subscriber base, or bundled with devices at national scale.
Schools & institutions
Consistent, auditable policy on managed devices, on and off the premises.
Parents
One panel for every child and device; protection that survives a determined child — no need to understand DNS, VPNs or MDM.
What CPO will not compromise on.
Enforce on the device
Anything else is advisory.
Law above preference
Resolved server-side and never overridable on the client.
Default to protected
Safety controls ship on, not off.
Minimum data
Children have profiles, not accounts; regulators see aggregates, not children.
Explain every block
A restriction a family cannot understand is one they will work around.
Evaluating CPO for your jurisdiction or organization?
We prioritise briefings with regulators and operators assessing CPO for national or regional deployment. Parents and schools are welcome to reach out too.