NeuralShield
AI-powered content filtering for schools. 10+ months in production.
How Drakon Systems built a purpose-built AI content filtering appliance that sits inside a school, classifies every DNS query in real-time, and keeps all student data on-premises. No cloud. No per-student licensing. No blocklist gaps.
10+
Months in production
100%
On-premises
0
Student data sent to cloud
24/7
Automated protection

The NeuralShield dashboard — real-time DNS classification, traffic monitoring, and threat detection.
The Client
An Independent Preparatory School, London
An ISI-inspected independent preparatory school in London, serving children aged 3-11. ISI-inspected, with the same safeguarding obligations as every UK school — and the same frustrations with traditional web filtering.
The Challenge
- ✕Traditional filters rely on static URL blocklists — new threats slip through
- ✕Cloud-based filters route student data through third-party servers
- ✕Per-student licensing costs scale with enrollment
- ✕Manual safeguarding reporting is time-consuming and error-prone
- ✕No AI classification — just matching domains against a list
The Solution
How NeuralShield works.
A dedicated appliance that sits physically inside the school, inline between the router and the local network. Transparent to existing infrastructure.
DNS Interception
Pi-hole captures every DNS request from every device on the school network.
AI Classification
A custom-trained DistilBERT model analyses each domain and categorises it — safe, explicit, gaming, VPN, streaming, and more.
Instant Blocking
Harmful domains are blocked before the page even loads. The student never sees the content.
Upstream Filtering
Unbound DNS forwards to CleanBrowsing Family for an additional layer — IWF and CTIRU lists for UK-specific protection.
Automated Reporting
Weekly PDF safeguarding reports emailed directly to the headteacher. Incident register generated automatically.
Features
What schools get.
AI-Powered Classification
Custom DistilBERT model trained on school-specific DNS patterns. Not a blocklist — real-time AI inference on every query.
Completely On-Premises
All data stays inside the school building. No student browsing data sent to the cloud. Ever. GDPR compliance by architecture.
Automated Safeguarding Reports
Weekly PDF reports emailed to the headteacher. KCSB-compliant incident register generated automatically. Ofsted-ready documentation.
Real-Time Protection
Every DNS query classified in milliseconds. New threats caught immediately — no waiting for blocklist updates.
Device Identity Mapping
Maps IP addresses to specific devices and users. Know exactly which device accessed what, when.
Self-Healing Network
Dual watchdog system monitors the bridge. Automatic recovery within 60 seconds if issues arise. 10+ months with zero downtime incidents.
In Production
What it looks like in the real world.

The custom block page students see when a domain is denied.

The alerts dashboard — AI-classified domains with real-time threat detection.
Traditional Filters vs NeuralShield
Why AI beats blocklists.
URL blocklists (static, always behind)
AI model classifies in real-time
Student data routed through US cloud servers
100% on-premises — nothing leaves the school
£3-8 per student per year (scales with enrollment)
One-time hardware — no per-student fees
New threats missed until list is updated
AI catches new domains the moment they appear
Manual safeguarding reports
Automated weekly PDFs to the headteacher
Limited customisation
Model trained specifically for your school
Cost Comparison
Better technology. Competitive cost.
Traditional Cloud Filter
Year 1
£1,500 – £4,000
200 students × £3-8 + setup
Year 2
£1,500 – £4,000
Renewal — same cost every year
3-Year Total
£4,500 – £12,000
✕ Data processed in the cloud
✕ URL blocklists only
✕ No custom AI training
NeuralShield
Year 1
£3,500 – £7,000
Hardware + on-site deployment
Year 2+
£2,000 – £4,000
Support + model updates only
3-Year Total
£7,500 – £15,000
✓ 100% on-premises
✓ Real-time AI classification
✓ Custom model for your school
NeuralShield costs more in Year 1 but breaks even by Year 2–3 — with significantly better technology and complete data sovereignty. No per-student licensing. Ever.
The Hardware
Purpose-built. GPU-accelerated.
NeuralShield runs on a dedicated server with NVIDIA GPU acceleration for real-time AI inference. It connects inline between your router and network switch — completely transparent to existing infrastructure.
| Processor | AMD Ryzen 9 9800X3D (8-core/16-thread) |
| Memory | 64GB DDR5 |
| GPU | NVIDIA RTX 4070 Super (12GB VRAM) |
| Storage | 400GB NVMe |
| Network | Dual Gigabit NICs — active-backup bond, transparent bridge mode |
| Installation | Zero changes to student devices, software, or network configuration |
Deployment
What your school gets.
Standard Deployment
- Pre-configured appliance — tested and loaded before arrival
- On-site installation (1-2 days) — zero disruption
- AI model training on your school's network patterns
- Staff training — DSL and IT walkthrough
- Ongoing remote support and monitoring
- Automated weekly safeguarding reports
- Threat feed updates and model improvements
Optional Add-Ons
- +Custom Kibana dashboards for senior leadership reporting
- +Real-time safeguarding alerts via email, Slack, or Microsoft Teams
- +Multi-site deployment for school groups and MATs
- +Custom AI model training for school-specific filtering needs
- +Integration with school management information systems (SIMS, iSAMS)
Compliance
Built for UK schools. Built for inspectors.
KCSB Part 2 Compliance
- ✓ Appropriate filters and monitoring systems
- ✓ Every DNS query logged and searchable
- ✓ Automated incident register
- ✓ Screenshot evidence capture for DSL investigations
GDPR & Data Privacy
- ✓ No student data transmitted to third parties
- ✓ No reliance on external cloud services
- ✓ Complete data ownership and control
- ✓ Simplified GDPR compliance by architecture
Frequently Asked Questions
How does NeuralShield differ from Smoothwall, Securly, or Lightspeed?+
Traditional filters rely on URL blocklists — static lists of known-bad domains. NeuralShield uses a fine-tuned AI model that classifies DNS queries in real-time, catching new threats the moment they appear. It also runs entirely on-premises, so no student data leaves the school building.
What happens if NeuralShield goes down?+
NeuralShield has a dual watchdog system that monitors the network bridge continuously. If an issue is detected, it automatically recovers within 60 seconds. In 10+ months of production, there have been zero downtime incidents affecting student internet access. A hardware bypass option is also available for additional resilience.
What hardware is required?+
NeuralShield runs on a dedicated server with an NVIDIA GPU for AI inference. We provide a pre-configured appliance that connects inline between your router and network switch — transparent to your existing infrastructure. No changes to student devices or network configuration required.
How long does installation take?+
On-site installation takes 1-2 days. The appliance arrives pre-configured and tested. We connect it inline, train the AI model on your school's specific network patterns, and walk your IT staff and DSL through the dashboard.
Is NeuralShield GDPR compliant?+
By design. All data processing happens on-premises inside the school. No student browsing data is transmitted to any third party. No cloud dependencies for filtering decisions. Complete data ownership and control.
Can the AI model be customised for our school?+
Yes. The model is fine-tuned on your school's specific DNS traffic patterns. If you need to adjust classification categories, add custom rules, or retrain for new threats, we handle that as part of the ongoing support.
Protect your school with AI that actually works.
NeuralShield has been protecting students at a UK independent school for over 10 months. If you want smarter filtering, better safeguarding reports, and complete data sovereignty, we'd like to talk.