You have no idea what's running on any of it.
Screen Time is bypassable in thirty seconds. The family Apple ID has your credit card attached. iCloud Keychain is sharing passwords to every device including the kids' iPad. Nobody set this up to fail — it failed because nobody set it up. Sentinel builds the household tech stack that actually holds.
These aren't exotic attack scenarios. They're the default state of every household that hasn't had someone deliberately configure it differently.
One Apple ID for the whole family means shared App Store purchases, shared iCloud storage, shared family photos — and a credit card attached to every device in the house. Your teenager's Roblox friends can see the same iCloud prompts your financial apps use. Your 9-year-old's iPad has the same iCloud Keychain access as your MacBook. Apple Family Sharing solves most of this. Almost no family has it configured correctly.
Apple Screen Time and Google Family Link are browser-based controls. Any kid with access to Safari or Chrome can find the bypass in thirty seconds — the workarounds are indexed, shared, and updated within days of every iOS patch. DNS-level filtering is the architectural layer that actually holds: it operates at the network level, before the device, and can't be circumvented from the device itself. It is not built into any household's default router setup. It requires deliberate configuration.
iCloud Keychain syncs to every signed-in device. If your kids are on the family Apple ID, or if their devices are signed into your iCloud, they have access to every credential in the keychain — including your brokerage login, your email, your healthcare portal. Most families have never audited which devices are signed into their iCloud account. The shared credential surface is often broader than any parent realizes until something goes wrong.
Apple Watches and AirTags tied to kids' accounts report location to the family's shared iCloud. That data is visible to every device signed into the account — including any device you've given away, sold without wiping, or forgotten about. Location access has no expiration. Devices you no longer own may still be pulling your children's location from iCloud. This is not a theoretical edge case. It is the default state of any Apple household that has added devices and never audited account membership.
One engagement. Documented, tested, and handed back to you with a household runbook every family member can actually follow — including the one who forgets every password.
Every child gets their own Apple ID — separate iCloud account, separate keychain, separate photo library. Apple Family Sharing is configured so parents approve app purchases, content ratings are enforced at the account level, and family location sharing is deliberate, not accidental. Parents retain master access. Kids see exactly what they need. The family Apple ID becomes the parents' Apple ID only — not a shared key to every device in the house.
DNS-level filtering through NextDNS is configured on your home network and on every household device as a system-level profile — not a browser extension, not Screen Time. Filtering operates before the device, at the DNS layer, and cannot be bypassed by switching browsers, using a VPN the child installed, or toggling settings. Blocked categories are configured by parent decision: adult content, social media during school hours, gaming sites during homework time. Each profile is per-child, not a household sledgehammer. It integrates with the network VLAN setup in your smart home configuration.
1Password Families gives every household member their own private vault plus shared vaults by role. Parents hold a household vault with every shared credential — streaming accounts, home systems, school portals. Kids have a personal vault with age-appropriate credentials. No family member has access to the parents' financial or healthcare credentials. The parents never again text a password in plain text. Kids stop using "password123" because they're never asked to remember passwords anymore. Emergency access is configured so either parent can recover any account in the household.
Screen Time as a supplementary layer — not the only layer. The Screen Time passcode is different from the device passcode and known only to parents. Downtime schedules are set. Communication limits control who kids can contact during school and sleep hours. Combined with DNS-level filtering, the controls are layered: DNS blocks categories at the network level, Screen Time blocks specific apps at the device level, and Apple Family Sharing limits content by rating at the account level. No single layer is the answer. All three together are.
For teenagers who are on Instagram, Snapchat, and Discord: privacy lockdown on every account. Instagram is set to private, direct message requests are restricted to followers, data sharing with third-party apps is audited and revoked. Snapchat's location sharing features are reviewed — Snap Map is off or friends-only. Discord is configured with server-level privacy, DM restrictions from unknown users, and two-factor authentication enabled. Every account gets a strong unique password in the household vault. Every account gets 2FA. Parents have documented access to every account without needing the child's device.
School-issued and household iPads and Chromebooks are enrolled in a lightweight MDM profile that enforces the DNS filtering profile, prevents removal of parental control configurations, and locks certain settings that kids commonly toggle off. On iPads, Guided Access is configured for focused study sessions. On Chromebooks, the Google Family Link configuration is hardened — account switching is restricted, SafeSearch is enforced at the account level, and extension installs require parental approval. The setup survives a factory reset: enrollment is device-level, not app-level.
Concrete changes. Not aspirational security theater — actual differences in how your household operates day to day.
Kid device hardening and parental controls don't operate in isolation. They're most effective when the network, the vault, and the photo archive are already solid.
Not a teenager who figured out the bypass, not a parent texting passwords in a group chat, not a "set it and forget it" Screen Time configuration that stopped working in October. Start with an assessment — we'll map your household's current setup and tell you exactly what needs to change.
Family safety setup is included in the Family Guard tier →