Destination groups
Destination groups are where policy rules apply — the “into” of every rule.

Platform groups
Section titled “Platform groups”Platform groups are managed for you and follow the app catalog automatically. The categories:
| Group | Examples |
|---|---|
| AI chat | ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek |
| AI coding | Cursor, GitHub Copilot, Replit, Windsurf, v0 |
| Local AI runtimes | Ollama, LM Studio, Jan |
| AI image, video and audio | Midjourney, Runway, ElevenLabs, Sora |
| AI meeting notes | Otter, Fireflies, Descript |
| AI developer platforms | OpenAI Platform, Anthropic Console, Hugging Face |
| AI writing and documents | Grammarly, Notion, Jasper |
| Cloud storage | Google Drive, Dropbox, OneDrive, Box, iCloud Drive |
| Code hosting | GitHub, GitLab, Bitbucket, Azure DevOps |
| File transfer | WeTransfer, Gofile, Filemail |
| Messaging | Slack, Teams, WhatsApp, Discord, Telegram, Signal |
| Paste and snippet sharing | Pastebin, GitHub Gist, CodePen |
| Translation | DeepL, Google Translate |
| Webmail | Gmail, Outlook, Yahoo Mail, Proton Mail |
When the platform catalog adds a new AI tool’s domains, every rule targeting AI chat covers it with no action from you — that is the point of referencing groups instead of hand-typed domain lists. Exact app lists and selector counts follow your catalog version; the Destination groups page in the console always shows the live set.
Everywhere
Section titled “Everywhere”Everywhere is the reserved whole-device scope: rules scoped to it enforce at copy time, device-wide, before any destination is known. It cannot be forked or deleted. Use it for the small set of data types that should never even sit on a clipboard un-redacted.
Custom groups
Section titled “Custom groups”Custom groups are yours: fork a platform group to add or trim apps, or build one from scratch (e.g. “Approved client portals”) with New group. Custom groups are targeted by rules exactly like platform ones — including as Allow carve-outs above stricter rules.
Each group lists its apps and its selectors (domains, desktop bundle ids, executable names). Selectors are maintained in the catalog by the platform team; you choose which groups your rules point at, not the raw domains.
Groups and interception scope
Section titled “Groups and interception scope”The same catalog defines what the traffic proxy can intercept — the device’s certificate is constrained to exactly the catalog’s domains (see How the proxy works). A destination outside the catalog is not un-policied: pastes into it are still governed by your everywhere rules — it simply is not intercepted at the network layer.