Fix it now
PC Matic blocks everything that is not on a list of known-good software, which is the opposite of how conventional antivirus works. It is sold in three tiers – Antivirus at five devices, Antivirus plus VPN at five, and Antivirus plus VPN plus Family Identity Protection at ten – and the model suits a household that runs the same programs every week.
- Buy it if the household computers run a stable, familiar set of applications and nobody is installing new software every week.
- Buy it if you want protection that does not depend on somebody having seen the malware first.
- Buy the middle tier if you want the unlimited VPN, a firewall and 25 GB of cloud backup, since all three arrive together there.
- Buy the top tier if you want identity theft insurance and stolen funds reimbursement, which is also where the count rises from five devices to ten.
- Skip it if you write software, compile your own binaries, run game mods or use niche tools, because you will be the one clearing the blocks.
- Skip it if being told no by your antivirus, then waiting, would make you switch it off.
There is no product called PC Matic Home Security. The home product is PC Matic, sold in those three tiers, and asking for it by the right name saves an awkward conversation at the order page.
If the model appeals you can stop here. If you want to know exactly what default-deny does and does not cover, read on.
Why it happens
PC Matic does not work the way other antivirus products work, and reviewing it as though it does would tell you nothing useful. A conventional antivirus is a blocklist: it carries signatures, reputation data and behavioural rules describing things known to be bad, and anything not matching those descriptions is allowed to run. That works well against the enormous volume of recycled malware and less well against something written last night, because there is nothing yet to describe.
An allowlist inverts it. PC Matic describes SuperShield as a default-deny approach that blocks all unknown applications from running, backed by a global list of known good applications and patented digital signature technology, and it positions this against the NIST standard for Zero Trust. If a program on your machine is not on that list, it does not run – whether it is malicious, obscure or simply new.
Against novel or targeted executables that is genuinely strong, because it needs no prior knowledge. A freshly compiled ransomware binary has no reputation and no signature, which under a blocklist is an advantage for the attacker and under an allowlist is the reason the file is refused. For the classic route of a downloaded installer that turns out to be something else, this is a meaningful improvement over the conventional model.
Be equally clear about what it does not cover. Allowlisting does not stop an attack conducted with software that is already approved, which is the entire point of living-off-the-land techniques built on the scripting hosts and administrative tools that ship with Windows. It does nothing about credential phishing, a stolen browser session, or somebody typing their password into a convincing fake login page. If you believe an allowlist makes you immune, you have swapped one false comfort for another.
The cost side is the false positive tax, and it is not hypothetical. The software most likely to be blocked is exactly the software with a small user base: a utility from a one-person developer, an installer for hardware nobody sells any more, a mod for a game, a tool you built yourself. Popular applications clear quickly because somebody else has already met the problem. What PC Matic publishes is the global known-good list and the default-deny behaviour; it does not publish a submission and review workflow, so how a block gets cleared is exactly the thing to test during the trial rather than to take on trust from any review.
The tiers are worth knowing before you shop, because two features people assume are absent are not. The base Antivirus tier at five devices carries real-time protection, dark web monitoring and a free VPN limited to 300 MB a day. The middle tier, also five devices, upgrades that to PC Matic Standard VPN with unlimited traffic and adds 25 GB of secure cloud backup and a firewall. The top tier raises the count to ten devices and adds $1M identity theft insurance and $1M stolen funds reimbursement. Supported systems are Windows 10 and newer, macOS 10.12 and newer, iOS 13 and newer and Android 4.4 and newer.
Around the security model sits a set of extras that older reviews miss: a PC Matic Adblocker extension with fake virus scam protection, free security awareness training delivered through KnowBe4, and automated maintenance covering driver updates, registry cleaning, SSD optimisation, junk file removal, startup app management and software vulnerability fixes. The training is the unusual one. Awareness training is the control that addresses phishing, which is exactly the gap the allowlist leaves.
Full reference
The three home tiers
| Tier | Devices | What it includes |
|---|---|---|
| Antivirus | 5 | Real-time protection against viruses, malware, ransomware and phishing, scan and clean, device performance booster, dark web monitoring, and a free VPN capped at 300 MB a day |
| Antivirus + VPN | 5 | All of the above, with PC Matic Standard VPN and unlimited traffic, 25 GB of secure cloud backup and a firewall |
| Antivirus + VPN + Family Identity Protection | 10 | All of the above, plus $1M identity theft insurance and $1M stolen funds reimbursement, on twice the device count |
Note where the jumps sit. The VPN, the firewall and the backup all arrive together at the middle tier, and the device count only doubles at the top. If you need more than five seats, the top tier is the only route to them, and you get the identity cover whether that was what you wanted or not.
Supported systems
| Platform | Minimum PC Matic publishes |
|---|---|
| Windows | Windows 10 and newer |
| macOS | macOS 10.12 and newer |
| iOS | iOS 13.0 and newer |
| Android | Android 4.4 and newer |
What else is in the box
- A PC Matic Adblocker browser extension, with protection against fake virus scam pages.
- Free security awareness training provided through KnowBe4, which is the control that addresses the phishing gap the allowlist does not close.
- Automated maintenance: driver updates, registry cleaning, SSD optimisation, junk file removal, broadband optimisation, automatic software updates, startup app management.
- Dark web monitoring at every tier, not only in the identity bundle.
- No password manager appears in any published list, so plan to use one from elsewhere.
Testing the model before you commit
- Install it on the machine you actually use, not a spare one, and do so during the trial rather than after paying.
- Spend a week doing normal work, and write down every block.
- For each block, time how long it takes you to clear it and what you had to do. That number is the product’s real cost to you.
- Try installing something obscure on purpose – an old utility, a small developer’s tool – and see what happens.
- If the machine belongs to someone you support remotely, do this test on their machine and not on yours, because their software mix is the one that matters.
Who this genuinely suits
- A machine used by someone who runs the same handful of familiar programs, especially an older relative you support at a distance. Default-deny removes a class of risk that conventional products handle less well.
- A household worried specifically about ransomware arriving as a download.
- Someone who wants the security awareness training as much as the software, because it addresses the part the allowlist does not.
- Not a gaming PC. Games with anti-cheat drivers, mods, launchers and constant updates are the moving target an allowlist handles worst.
- Not a machine where software changes weekly, and definitely not one used for development.
What this review does not claim
No false positive rate appears here, and no laboratory score. The trade-off is structural and you can measure it yourself in a week, which is more useful than a number from a test whose software mix is nothing like yours. Nor does this review describe how blocked software is submitted, reviewed and cleared, because PC Matic does not publish that workflow. That absence is the single best reason to run the trial before paying rather than after.
When a licence is the actual fix
If the default-deny approach fits the way your household uses its computers, Arco can supply PC Matic – ask for it by that name rather than as PC Matic Home Security, which is not a product the vendor sells. Tell us how many devices you need and we will point you at the right tier: five devices at the Antivirus tier, five with the unlimited VPN, firewall and 25 GB of cloud backup, or ten with the identity cover on top. And tell us honestly what those machines are used for. If the answer involves development work, game mods or a lot of new software, we will say that a conventional product will annoy you far less, because a licence you switch off protects nobody.
Questions people ask about this
Does allowlisting mean I cannot be infected?
No. It substantially raises the difficulty of running an unknown executable, which is a real improvement. It does not stop attacks that abuse already-approved software, and it does nothing about phishing, which is how a great many people actually lose money. Treat it as a strong control rather than a guarantee, and use the security awareness training that comes with it.
Is there a VPN?
Yes, at every tier, but the shape differs. The base Antivirus tier includes a free VPN capped at 300 MB a day. The Antivirus + VPN tier upgrades it to PC Matic Standard VPN with unlimited traffic and adds a firewall and 25 GB of cloud backup. Older reviews saying there is no VPN in this product are wrong.
What happens when a program I need is blocked?
It is refused until it is known. PC Matic publishes the global known-good list and the default-deny behaviour but not the submission and review workflow, so how quickly a block clears is the thing to test during the trial rather than to take on trust. Mainstream software is usually already known; obscure and self-built software is where the waiting happens.
Is it a good choice for a gaming PC?
Usually not. Games with anti-cheat drivers, mods, launchers and constant updates are exactly the moving target an allowlist handles worst. You can make it work, and you will spend time on it, and a conventional product will annoy you far less.
How many devices does one licence cover?
Five on the Antivirus tier and on Antivirus + VPN, and ten on the tier that adds Family Identity Protection. If you need more than five seats, the top tier is the only route to them and the identity cover comes with it.
