← ALL DOCS
DOCS · EVERYONE

Frequently asked questions

What is Cloud Certainty Secure Browser?

A remote browser isolation product that you deploy in your own AWS account. Each user gets a disposable Chromium browser that runs in your cloud and is streamed to their own browser tab. Administrators control clipboard, file transfer, printing, website access and session timeouts per user or group.

Pricing

How much does it cost?

You pay $0.10 per browser session-hour through AWS Marketplace, metered per second while a session runs. There is no upfront fee, no minimum commitment and no per-user licence. Installing and upgrading the stack also runs one short setup task of about a minute, billed the same way.

What else do I pay for?

The AWS resources the product uses in your account are billed by AWS as usual. The main ones are:

  • the compute for each running session (roughly $0.10 per hour for the default size in us-east-1);
  • streaming relay minutes, a small amount per session;
  • a NAT gateway, if you use private subnets and don't already have one;
  • small amounts for the serverless parts (API, database, sign-in, hosting and logs).

Prices vary by Region; check the AWS pricing pages for yours.

What does it cost when nobody is using it?

Close to nothing. Sessions exist only while someone is browsing, and the rest of the stack is serverless, so idle cost is a few cents a month for the serverless parts, plus your NAT gateway if you run one just for this.

Deployment

Which AWS Regions are supported?

Most commercial AWS Regions in North America, South America, Europe and Asia Pacific, for example us-east-1, eu-west-1, eu-central-1 and ap-southeast-2. The same template URL works in every supported Region, and the stack checks the Region for you when you deploy.

How do I install it?

Subscribe on AWS Marketplace and deploy one CloudFormation stack, or use the cloudcertainty/secure-browser/aws Terraform module. See Getting started.

Does it need inbound access, a load balancer or public IP addresses?

No. Sessions accept no inbound connections and need only outbound internet access on port 443.

Can users reach internal web applications?

Yes. Sessions run in the VPC and subnets you choose, so they can reach private applications those subnets can reach, without a VPN on the user's device.

How do upgrades work?

Each release is a new template. You update the stack with the new template URL and keep your parameter values; running sessions are not interrupted. See the admin guide and the release notes.

Using it

Which browsers can users use?

A current version of Google Chrome, Microsoft Edge, Mozilla Firefox or Safari on a desktop or laptop. Nothing needs to be installed.

Which identity providers work?

AWS IAM Identity Center, any SAML 2.0 provider (for example Microsoft Entra ID or Okta), OIDC providers, or users managed in Amazon Cognito.

Is audio supported?

Not in the current version. Webcam and microphone are not supported.

Does the remote browser remember my logins?

No. Every session starts with a clean browser and is destroyed when it ends.

Migrating from Amazon WorkSpaces Secure Browser

Why move?

Amazon WorkSpaces Secure Browser stops accepting new customers on 29 October 2026. Cloud Certainty Secure Browser offers the same model, a managed remote browser with admin policy controls, and runs entirely in your own AWS account.

How do my settings carry over?

Most settings have a direct equivalent: clipboard, file transfer and print settings, timeouts, URL filtering, IP access, and per-group policies. The admin guide has the full mapping. Watermarking, audio and some WorkSpaces Secure Browser features are not available yet.

Can you help us migrate?

Yes. Our fixed-price migration service maps your existing portal settings to profiles, sets up the stack and your identity provider with your team, and plans the cut-over. See support plans and services.

Support and data

What support is included?

Basic support is included: documentation, release and security notices, and email to [email protected] on a best-effort basis. Paid plans with response times are described on the support page.

Does any of our data go to Cloud Certainty?

No. Everything runs in your AWS account. AWS Marketplace tells us only the usage we bill for. See the security overview.

Something unclear or missing? Email [email protected].

Tell us what you have. We'll make it better and cheaper.

Send a short description of your current setup. We will tell you what we would improve, what it would cost, and where the savings are. A considered reply from an engineer, not a sales sequence.

TELL US ABOUT YOUR SETUP →