If you stop it being able to see your traffic, it stops working.
If you stop it being able to get to the Internet, it stops working.
The problem here is needing to trust the filter program. Moving code into a sandbox doesn't help, because you still need an app outside the sandbox to make it actually filter, and the problem is not being able to trust an app.
You have X inside a sandbox. It has the filtering logic, and can't report home. Cool.
But you need Y outside the sandbox so that your content actually gets filtered. Without Y, your "filtering app" does nothing. You need code that is outside the sandbox.
But how do we set up Y? In the context of a mobile device, Y would have to be a VPN app.
But the original problem is that we can't trust VPN apps to do what they say.
So even though you moved the actual filtering logic into X, and put it in a secure sandbox, you didn't solve the problem of needing to trust an app.
(And "put Y into the trusted OS" is not a valid solution toward getting filtering on "locked-down mobile platforms".)
But the part of the code that does the vpn CANNOT be inside a sandbox. It has to interface with actual connections.
If you sandbox 100% of the code, it doesn't work.
I've been thinking about doing this and scrapping all but one of my data plans, and having a robust default-deny whitelist of allowed IPs/netblocks/hostnames on the phone vlan/ssid, but haven't worked out all the details yet.
How are you doing it?
Regarding LTE modems, I do not use a data plan on "locked-down" mobile devices for personal use. Somehow I have been able to survive on WiFi alone.
I’m looking at something like a raspberry pi zero, using the built in wifi to serve as an AP, powered from a large-ish USB battery pack, something that could run 18h+, with a USB LTE modem. Ideally I could get it small enough to strap to an ankle or something so I don’t need to bring a bag.