← SECURE BROWSER
[ P1 ] RELEASE NOTES

What changed, release by release.

Every release is a new, immutable CloudFormation template. To upgrade, update your stack with the new release's template URL and keep your parameter values. Running sessions are not interrupted. We support the latest release and the one before it.

[ A ] ALL RELEASES, NEWEST FIRST

  1. 0.1.6

    Latest

    Simpler setup.

    • New Launch stack link on this page: it opens AWS CloudFormation with the template already selected.
    • Two support-only parameters are removed from the stack: Marketplace product code and Artifact bucket prefix. Release images have the product code built in, so these did nothing.
    • Clearer stack description in the CloudFormation console.
    • Upgrade: update the stack with the 0.1.6 template URL and keep the current parameter values. The removed parameters are dropped automatically.

    Release notes: https://cloudcertainty.com/secure-browser/releases/0.1.6

    Notes and upgrade instructions →for 0.1.6
  2. 0.1.5

    Design and usability release.

    • New look for the portal and admin console, matching cloudcertainty.com.
    • Theme switch in the footer: System (default, follows your device setting), Light or Dark.
    • Links to the product page, documentation, support plans and release notes in the footer and under Admin > About & updates. These are plain links; the product still sends no data to Cloud Certainty.
    • Upgrade: update the stack with the 0.1.5 template URL and keep the current parameter values.
    Notes and upgrade instructions →for 0.1.5
  3. 0.1.4

    Withdrawn. Do not install

    This version has been withdrawn from AWS Marketplace and can't be installed. If you run it, upgrade to 0.1.6.

    Security hardening release.

    • Licensing: the Marketplace licence check now also runs when each browser session starts its stream, with automatic retries if the metering service is briefly unavailable.
    • Identity: users whose email address is not verified by the identity provider are refused (403). OIDC providers must send email_verified (see the OidcEmailVerifiedClaim parameter). The first administrator is bound to their user ID on first sign-in.
    • Browser lockdown: JavaScript runs without JIT by default (admins can re-enable it per policy profile), more Chrome management policies are enforced, browser internal pages such as chrome://flags are blocked, and DNS-over-HTTPS is off.
    • File transfer: closes a gap where a file could leave as a print when downloads were disabled; transferred files are recorded with a SHA-256 hash in the audit log; copying remote text to the local clipboard now needs a click.
    • Deployment: the stack is limited to AWS Regions that support Marketplace metering; ImageUriOverride must be digest-pinned.
    • Upgrade: update the stack with the 0.1.4 template URL and keep the current parameter values.
    Release details →for 0.1.4
  4. 0.1.3

    Withdrawn. Do not install

    This version has been withdrawn from AWS Marketplace and can't be installed. If you run it, upgrade to 0.1.6.

    Fixes installation of the AWS CloudFormation stack.

    • The one-time installer step now reports its result to CloudFormation, so stack creation, rollback and deletion complete reliably.
    • The web portal deployment step has the Amplify permissions it needs.
    • The ECS cluster no longer requires the ECS service-linked role to exist in new accounts.
    • Upgrade: update the stack with the 0.1.3 template URL and keep the current parameter values.
    Release details →for 0.1.3
  5. 0.1.2

    Withdrawn. Do not install

    This version has been withdrawn from AWS Marketplace and can't be installed. If you run it, upgrade to 0.1.6.

    First release of Cloud Certainty Secure Browser.

    • Zero-trust remote browser isolation that runs entirely in your own AWS account: one ephemeral Chromium container per session on Amazon ECS (Fargate), streamed over end-to-end encrypted WebRTC.
    • Sign-in through AWS IAM Identity Center, any SAML 2.0 or OIDC identity provider, or Amazon Cognito.
    • Admin console with policy profiles per user or group: clipboard in/out, file upload/download, printing, URL allow/block lists, timeouts and IP allowlists, plus an audit log.
    • Browser tasks have no inbound network access. Deploy in any AWS Region that offers Kinesis Video Streams WebRTC, Amplify Hosting and Amazon Cognito.
    • Update notifications in the admin console and by email (Amazon SNS).
    Release details →for 0.1.2

Generated from the AWS Marketplace listing. Get notified of new releases in the admin console, by email or in chat. See updates and upgrading.

Tell us what you have. We'll make it better and cheaper.

Send a short description of your current setup. We will tell you what we would improve, what it would cost, and where the savings are. A considered reply from an engineer, not a sales sequence.

TELL US ABOUT YOUR SETUP →