Hostname Hierarchy
Rows group per registrable domain and expand into individual hostnames, so cdn.example.com can get a different rule than example.com.
SENTYRA RESEARCH
A per-site matrix of which third party may load what — rebuilt on Manifest V3 foundations, for people who want to see and decide what runs on the pages they visit.
Research Problem
Request-matrix tools used to work by interception: the extension saw every request and decided, live, whether it passed. Manifest V3 ended that model for public Chrome extensions — blocking webRequest is gone.
VIGIL Matrix asks whether meaningful per-site control can be rebuilt the other way around. The user states policy in a visible matrix, the extension compiles it into declarativeNetRequest rules, and the browser enforces those rules itself — no traffic monitoring, no broad host permissions, no remote telemetry.
Core Model
Source domain → Target domain → Resource type → Local browser rule
The matrix shows the hosts a page actually loaded as rows, and resource types as columns: scripts, frames, XHR, images, media, stylesheets, fonts and cookies. Every cell is a decision — allow, block, or no rule.
Those decisions compile into declarativeNetRequest rules, and the browser does the enforcing. Browsing activity never leaves the device for classification or policy decisions, because there is nothing to send it to.
Current Capabilities
Rows group per registrable domain and expand into individual hostnames, so cdn.example.com can get a different rule than example.com.
Rules can apply everywhere, to one registrable domain, or to one exact hostname. Where rules overlap, the most specific one applies.
A cell click takes effect immediately as a temporary rule. Reload the page, watch what changes, then save it — or throw it away.
Block every subresource type by default and allow your way back, uMatrix-style. Pages will break until configured — that is the point of a hard posture.
Strip Cookie and Set-Cookie headers per target host. Built so that allowing a script can never quietly re-enable its cookies.
An optional bundled blocklist of known tracker domains, off by default. Your explicit allow rules always outrank it.
The whole policy as plain text: load it, edit it, review the line diff, apply. Easy to back up, share and version-control.
See which rules actually fired on the current tab — blocked, cookie-stripped, CSP-injected — within the browser's MV3 diagnostics quota.
uMatrix-Inspired, MV3-Native
VIGIL Matrix does not recreate a runtime firewall in extension code. Each matrix cell becomes a declarative rule, and the cell's place in the hierarchy — scope, target, resource type, draft or saved — is written into that rule's priority.
Chrome's own rule evaluator then produces exactly the behavior matrix users expect: hostname scope beats domain scope, domain beats global, a hostname target beats a domain target, and a specific resource type beats an all-types cell.
Manifest V3 still draws the boundaries. This is not a uMatrix compatibility layer, and it deliberately avoids webRequest, broad host permissions, remote code and remote ruleset fetching.
Advanced Controls
A persistent per-site kill switch. The site's whole frame tree bypasses every VIGIL rule until you switch it back.
The same bypass, but session-only — for debugging a broken page without touching saved policy.
Injects a CSP header that stops inline scripts and inline event handlers, while external scripts stay under matrix control.
Injects worker-src 'none', disabling worker execution in the selected scope.
Removes the Referer header from the scope's requests.
Upgrades http:// requests to https:// using the browser's native upgradeScheme action.
Privacy by Design
These are not aspirations. Each line below is a checkable property of the source code.
Research Status
VIGIL Matrix Lite v0.9 is an experimental research preview for advanced users, security architects and browser security researchers. It is not a finished security product, and it does not promise protection against all tracking, phishing or malware — no request-level tool can.
The roadmap ahead is mostly about dependability: tagged and reproducible releases, CI, broader manual testing, accessibility and localization.
Research Resources
Source code, architecture notes, threat model, permission rationale, design decisions and release notes — all public.