A secure browser that runs in your own AWS account.
Cloud Certainty Secure Browser gives your staff, contractors and partners safe access to the web and to internal applications. Every session is a disposable Chromium in your AWS account, streamed to the user as encrypted pixels. Nothing runs on the device, and nothing leaves the session unless your policy allows it.
ONE CLOUDFORMATION STACK · YOUR VPC · YOUR IDP · $0.10 PER SESSION-HOUR · LATEST 0.1.6
03 · BROWSE Only encrypted pixels reach the user’s browser. The page itself, intranet.corp.example/wiki, runs in user A’s container.
HOVER, TAP OR TAB THROUGH THE DIAGRAM · ESC TO RESET
[ A ] USE CASES
Give agencies, contractors and outsourced teams your internal web apps without a VPN account or a managed laptop. Turn off copy-out, download and print for their group, and the data stays in your account.
- Contract value
- €184,000 / yr
- Renewal
- 12 Mar 2027
- Primary contact
- [email protected]
- Notes
- Discount approved to 14%. Do not share externally.
[ B ] FROM SUBSCRIPTION TO FIRST SESSION, WITH ZERO TRUST AT EVERY STEP
- 01
Subscribe and deploy
Subscribe on AWS Marketplace and launch one CloudFormation stack in your own account, or use the Terraform module. It is serverless, takes about ten minutes, and runs in any Region with the AWS services it needs.
Stays in your account
Sessions, browsing, settings, audit records and logs never leave your AWS account. Nothing is sent to Cloud Certainty.
Patched promptly
Critical browser vulnerabilities are fixed in a new release within 72 hours of the fix being available. You choose when to upgrade.
- 02
Connect your identity provider
Users sign in through AWS IAM Identity Center, Microsoft Entra ID, Okta or any SAML 2.0 or OIDC provider. You can also manage users in Amazon Cognito. Your MFA and sign-in policies apply.
Your identity, your MFA
Access is granted by verified identity from your own provider and checked on every request, not once at the door.
- 03
Users start a session
Each session is a fresh Chromium container in your VPC, streamed to the user’s own browser tab as a fast, end-to-end encrypted live stream. Web content never runs on the device.
No inbound access
Sessions accept no inbound connections. No load balancer, no open ports, no public IP in private subnets. Only outbound traffic on port 443.
Pixels, not pages
The device receives an end-to-end encrypted video stream. Malicious code on a website never reaches the endpoint.
- 04
The session is destroyed
When the user ends the session, goes idle or reaches the time limit, the container is destroyed with everything in it: pages, cookies, cache and files. The next session starts clean.
One container per session
Every session is its own isolated, single-use container. Users and sessions never share a browser.
Read the security overview for the detail a security review needs.
[ C ] WHAT ADMINISTRATORS CONTROL
Policy profiles decide what may cross the isolation boundary. Assign them per user or per group from your identity provider; they are enforced inside every session, not just hidden in the interface. The default profile allows nothing until you say so.
- Clipboard
- Copy out and paste in, allowed separately. Copied text reaches the user’s clipboard only when they click.
- File transfer
- Upload and download, each on or off, with a size limit. Dangerous file types are always blocked.
- Printing
- Print to a PDF on the user’s device without opening a general download path.
- Web access
- URL allow and block lists, homepage and managed bookmarks; developer tools, extensions and incognito on or off.
- Timeouts
- Idle, disconnect and maximum session length, with a warning before an idle session ends.
- Network access
- An IP allowlist for the portal, and global and per-user session limits.
- Audit
- Sessions, refusals, configuration changes, file transfers and clipboard use, logged in your account and ready for your SIEM.
- Clipboard copy out on
- Clipboard paste in on
- File upload on
- File download off
- Printing off
- URL filtering Allow list
- Idle timeout 15 min
- IP allowlist 203.0.113.0/24
[ D ] PRICING
Pay as you go through your AWS bill. Metered per second while a session runs. No upfront fee, no minimum commitment, no per-user licences.
See pricing on AWS Marketplace →(opens in a new tab)Idle costs almost nothing
Containers exist only while someone is browsing, and the rest of the stack is serverless. With nobody using it, the bill is a few cents a month, plus a NAT gateway if you add one just for this.
AWS infrastructure is billed by AWS
The compute for each running session (roughly $0.10 an hour at the default size in us-east-1), streaming relay minutes, and small amounts for the serverless parts. Prices vary by Region.
An example
A user who browses for two hours a day over 21 working days uses 42 session-hours: $4.20 in software fees, plus the AWS compute for those hours. Indicative only.
Support
Basic support is included. Paid plans with response times, plus fixed-price installation and migration services, are on the support page.
Amazon Web Services, AWS, Amazon WorkSpaces and AWS Marketplace are trademarks of Amazon.com, Inc. or its affiliates. Cloud Certainty Secure Browser is a product of Cloud Certainty OÜ and is not affiliated with or endorsed by Amazon.