[ P1 ] PRODUCT: ZERO-TRUST BROWSER ISOLATION

A secure browser that runs in your own AWS account.

Cloud Certainty Secure Browser gives your staff, contractors and partners safe access to the web and to internal applications. Every session is a disposable Chromium in your AWS account, streamed to the user as encrypted pixels. Nothing runs on the device, and nothing leaves the session unless your policy allows it.

ONE CLOUDFORMATION STACK · YOUR VPC · YOUR IDP · $0.10 PER SESSION-HOUR · LATEST 0.1.6

SECURE BROWSER DEMO · 1:36
View on AWS Marketplace →(opens in a new tab) Read the docs →
HOW IT WORKS: FROM SIGN-IN TO A DESTROYED CONTAINER
[ S1 ] YOUR USERS[ S2 ] YOUR AWS ACCOUNT · ONE CLOUDFORMATION STACKYour user’s browserANY MODERN BROWSERNOTHING INSTALLED · PIXELS ONLYYOUR IDENTITY PROVIDERIAM IDENTITY CENTER · ENTRA IDOKTA · ANY SAML OR OIDC · MFAPORTAL & APIFEDERATED SIGN-INIDENTITY CHECKED ON EVERY CALLIP ALLOWLIST · SESSION LIMITSPOLICY PROFILESCLIPBOARD · FILES · PRINT · URLSTIMEOUTS · PER USER OR GROUPAUDIT LOGEVERY SESSION AND CHANGEENCRYPTED RELAY · PORT 443END-TO-END ENCRYPTED · FAST STREAMYOUR VPC · PRIVATE SUBNETSNO INBOUND ACCESSSession of user ASession of user BSession of user CSESSION ENDEDCONTAINER DESTROYEDSESSION · USER ASESSION · USER BSESSION · USER CONE DISPOSABLE CHROMIUM CONTAINER PER SESSIONPAGES, COOKIES AND FILES ARE DESTROYED WHEN IT ENDSOUTBOUND 443 ONLY · NO LOAD BALANCER · NO PUBLIC IPYOUR INTERNAL WEB APPS, REACHABLE WITHOUT A VPN01 SIGN IN WITH YOUR IDP02 START · FRESH CONTAINER03 BROWSE · ENCRYPTED PIXELS04 END · CONTAINER DESTROYED

03 · BROWSE Only encrypted pixels reach the user’s browser. The page itself, intranet.corp.example/wiki, runs in user A’s container.

HOVER, TAP OR TAB THROUGH THE DIAGRAM · ESC TO RESET

[ A ] USE CASES

Give agencies, contractors and outsourced teams your internal web apps without a VPN account or a managed laptop. Turn off copy-out, download and print for their group, and the data stays in your account.

USES · CLIPBOARD · FILE TRANSFER · PRINTING
https://crm.corp.internal/accounts/4471 SESSION a41f · contractors
Account 4471 · Northwind Logistics
Contract value
€184,000 / yr
Renewal
12 Mar 2027
Primary contact
[email protected]
Notes
Discount approved to 14%. Do not share externally.
AUDIT LOG · YOUR ACCOUNT
09:14:07 OK Session a41f started · [email protected] · group contractors
Try the actions. Every one is checked against the group's policy.
ILLUSTRATIVE DEMO · SAMPLE USERS AND DATA

[ B ] FROM SUBSCRIPTION TO FIRST SESSION, WITH ZERO TRUST AT EVERY STEP

  1. 01

    Subscribe and deploy

    Subscribe on AWS Marketplace and launch one CloudFormation stack in your own account, or use the Terraform module. It is serverless, takes about ten minutes, and runs in any Region with the AWS services it needs.

    Stays in your account

    Sessions, browsing, settings, audit records and logs never leave your AWS account. Nothing is sent to Cloud Certainty.

    Patched promptly

    Critical browser vulnerabilities are fixed in a new release within 72 hours of the fix being available. You choose when to upgrade.

  2. 02

    Connect your identity provider

    Users sign in through AWS IAM Identity Center, Microsoft Entra ID, Okta or any SAML 2.0 or OIDC provider. You can also manage users in Amazon Cognito. Your MFA and sign-in policies apply.

    Your identity, your MFA

    Access is granted by verified identity from your own provider and checked on every request, not once at the door.

  3. 03

    Users start a session

    Each session is a fresh Chromium container in your VPC, streamed to the user’s own browser tab as a fast, end-to-end encrypted live stream. Web content never runs on the device.

    No inbound access

    Sessions accept no inbound connections. No load balancer, no open ports, no public IP in private subnets. Only outbound traffic on port 443.

    Pixels, not pages

    The device receives an end-to-end encrypted video stream. Malicious code on a website never reaches the endpoint.

  4. 04

    The session is destroyed

    When the user ends the session, goes idle or reaches the time limit, the container is destroyed with everything in it: pages, cookies, cache and files. The next session starts clean.

    One container per session

    Every session is its own isolated, single-use container. Users and sessions never share a browser.

Read the security overview for the detail a security review needs.

SECURE BROWSER DEMO · 1:36

[ C ] WHAT ADMINISTRATORS CONTROL

Policy profiles decide what may cross the isolation boundary. Assign them per user or per group from your identity provider; they are enforced inside every session, not just hidden in the interface. The default profile allows nothing until you say so.

Clipboard
Copy out and paste in, allowed separately. Copied text reaches the user’s clipboard only when they click.
File transfer
Upload and download, each on or off, with a size limit. Dangerous file types are always blocked.
Printing
Print to a PDF on the user’s device without opening a general download path.
Web access
URL allow and block lists, homepage and managed bookmarks; developer tools, extensions and incognito on or off.
Timeouts
Idle, disconnect and maximum session length, with a warning before an idle session ends.
Network access
An IP allowlist for the portal, and global and per-user session limits.
Audit
Sessions, refusals, configuration changes, file transfers and clipboard use, logged in your account and ready for your SIEM.
SESSION POLICY group: finance
  • Clipboard copy out on
  • Clipboard paste in on
  • File upload on
  • File download off
  • Printing off
  • URL filtering Allow list
  • Idle timeout 15 min
  • IP allowlist 203.0.113.0/24
An example profile. Changes apply to the next session that starts.

[ D ] PRICING

$0.10
PER BROWSER SESSION-HOUR

Pay as you go through your AWS bill. Metered per second while a session runs. No upfront fee, no minimum commitment, no per-user licences.

See pricing on AWS Marketplace →(opens in a new tab)

Idle costs almost nothing

Containers exist only while someone is browsing, and the rest of the stack is serverless. With nobody using it, the bill is a few cents a month, plus a NAT gateway if you add one just for this.

AWS infrastructure is billed by AWS

The compute for each running session (roughly $0.10 an hour at the default size in us-east-1), streaming relay minutes, and small amounts for the serverless parts. Prices vary by Region.

An example

A user who browses for two hours a day over 21 working days uses 42 session-hours: $4.20 in software fees, plus the AWS compute for those hours. Indicative only.

Support

Basic support is included. Paid plans with response times, plus fixed-price installation and migration services, are on the support page.

Amazon Web Services, AWS, Amazon WorkSpaces and AWS Marketplace are trademarks of Amazon.com, Inc. or its affiliates. Cloud Certainty Secure Browser is a product of Cloud Certainty OÜ and is not affiliated with or endorsed by Amazon.

Tell us what you have. We'll make it better and cheaper.

Send a short description of your current setup. We will tell you what we would improve, what it would cost, and where the savings are. A considered reply from an engineer, not a sales sequence.

TELL US ABOUT YOUR SETUP →