For Windows

A porn blocker for Windows that actually holds

Windows gives software deep enough access to make a block genuinely difficult to get around. Most Windows blockers do not use it.

Short answer

On Windows you should expect system-wide filtering across every browser, content screening, on-screen detection, and uninstall protection. Kellet runs all four on Windows 10 and 11, with a cool-down on every way out.

What Windows makes possible

  • System-wide filtering.A background service covers every browser and app, not just the one you added an extension to.
  • On-screen detection.On-device models flag explicit imagery by what is displayed, whatever app put it there.
  • Real uninstall protection.Removal through Add or Remove Programs becomes a request with a timer on it.
  • Full device lockdown.Scheduled blackouts that cover the whole machine, not a list of sites.

The Edge problem

Every Windows machine ships with Edge and it cannot be meaningfully removed. Any blocker that lives inside Chrome has left an unlocked door on the desktop, permanently.

This is the single most common reason a Windows setup fails, and it is entirely avoidable by filtering below the browser.

Kellet on Windows filters at the system level, so every browser is behind the same wall, including the ones you never open.

How to tell a real Windows blocker from a hosts-file edit

A surprising number of Windows tools, including some paid ones, are a script that writes entries into the hosts file and calls it filtering. It is worth knowing how to spot, because it is the difference between a wall and a note asking you not to go there.

  • It only names domains.A hosts file maps names to nowhere. It knows nothing about a domain registered this morning and nothing about what is actually on a page.
  • Notepad defeats it.Anyone with administrator rights can open the file and delete a line, and the product has no way to notice or object.
  • It cannot see inside an app.Anything using its own resolver or a hard-coded DNS server walks straight past it.
  • No service, no protection.If nothing is running in the background, nothing is enforcing anything between reboots.

The ways around it that still exist

No blocker on a machine you fully administer is absolute, and a page that claims otherwise is selling you something. What follows is what is genuinely still open on Windows, and why it does not matter as much as it sounds.

Safe mode starts Windows with third-party services disabled, so a determined reboot gets you a session with no filtering. A second administrator account, or a fresh one created for the purpose, sits outside a per-user setup. System Restore can roll a machine back to before an install. And a Linux subsystem or a live USB is a different operating system entirely.

Every one of those is a deliberate, multi-minute, technically-aware act. That is the whole design goal: the urge that a blocker exists to outlast does not survive a reboot into safe mode and a driver-signing dialogue. What kills people is the two-second exit, not the twenty-minute one.

The aim is never "impossible". It is "slower than the moment", and on Windows that is achievable.

Requirements and what to expect

Windows 10 or 11, 64-bit, with administrator rights to install. It runs as a background service and the machine behaves normally outside a scheduled blackout.

It is code-signed and visible: in your installed programs, in the tray, and never hidden from the person using the computer. Anti-tamper protection is the part you asked for, and it announces itself.

Straight answers

Common questions

Will my antivirus flag it?
It should not. Kellet is code-signed and behaves openly rather than trying to conceal itself, which is what antivirus heuristics react to.
Can I install it without admin rights?
No. System-wide filtering and uninstall protection both require administrator access. On a managed work machine, talk to whoever administers it.
Does it slow the computer down?
Not noticeably. Filtering is local and light, and the on-screen models run on the device rather than in a cloud service.
Is Windows Family Safety enough on its own?
It is built for a parent supervising a child, so it assumes the person holding the settings and the person being restricted are different people. Setting it up on your own machine leaves you holding both, which is the arrangement that already failed.
What about a second user account on the same PC?
Install on each account you actually use. A filter covering one profile while another sits unprotected on the same machine is a gap you will find eventually, usually at the worst time.
Does it survive safe mode?
Safe mode disables third-party services, so a session started that way is unfiltered. It is deliberate enough to be a decision rather than a reflex, which is the line a cool-down is drawn along.
One decision left

Calmer water is one decision away.

Kellet blocks the distractions you choose and lets you stay accountable to yourself, or to someone you trust.