BROWSER ISOLATION™

Isolate Risky Web Execution

Remote Browser Execution • Threat Containment • Data Control

JupitoSecure Browser Isolation moves browser execution into a controlled remote environment so that higher-risk web workloads do not execute directly on the endpoint.

ISOLATE • CONTAIN • CONTROL

Normal browsing can remain in the Enterprise Browser. Higher-risk destinations can be moved into an isolated execution boundary according to risk.

SECURITY BOUNDARY

Move Risky Web Execution Away From the Endpoint

Higher-risk web activity executes remotely while users receive a controlled browsing experience.

USER → IDENTITY → POLICY → REMOTE BROWSER → WEB
4.1 OVERVIEW

Move Risky Web Execution Away From the Endpoint

Modern organizations cannot treat every website as equally trusted. JupitoSecure Browser Isolation provides a separate execution boundary for websites, content and browsing activity that require stronger containment.

NORMAL BROWSING

Enterprise Browser

Managed browsing for normal enterprise web activity.

HIGHER-RISK BROWSING

Browser Isolation

Remote execution for destinations and workflows requiring stronger containment.

CONTROLLED WORKSPACE

TeleWorkspace

Controlled workspace browsing for workloads requiring a stronger execution boundary.

PRIVATE RESOURCE

TeleConnect

Secure access to private resources without extending the browsing boundary.

AI WORKFLOWS

AI & Agent Execution

Governed web-enabled AI workflows under enterprise policy.

One Browser Strategy. Multiple Security Boundaries

The security boundary can be selected according to the risk of the activity rather than applying the same control to every browsing session.

4.2 CAPABILITIES

Remote Browser Execution With Containment and Control

EXECUTION

Remote Browser Execution

Execute web content in a remote controlled environment rather than directly on the endpoint.

SESSION

Isolated Browser Sessions

Create isolated sessions with defined lifecycle and policy controls.

CONTAINMENT

Threat Containment

Reduce direct endpoint exposure to potentially malicious or untrusted web content.

DATA

Data Protection

Control movement of information between the isolated environment and the endpoint.

IDENTITY

Identity-Aware Access

Apply user and group identity to isolated browsing policies.

VISIBILITY

Session Monitoring

Monitor sessions, security events and access activity.

AUDIT

Audit & SIEM

Generate audit trails and security events for operational and security visibility.

Core capabilities include remote execution, session lifecycle, threat containment, download/upload controls, clipboard controls, policy-controlled sessions and audit/SIEM integration.

4.3 PRODUCT PORTFOLIO

Browser Isolation Platform

01 REMOTE BROWSER

Remote Ephemeral Isolated Browser

A remotely executed browser environment designed for higher-risk web activity.

02 PLATFORM SERVICES

Browser Isolation Platform Services

Shared services for identity, policy, session management, DLP, data controls, monitoring, audit, security events and SIEM integration.

03 ARCHITECTURE

Platform Architecture

USER ↓ IDENTITY ↓ POLICY ↓ REMOTE ISOLATED BROWSER ↓ WEB ↓ CONTROLLED SESSION ↓ USER
4.4 REMOTE EPHEMERAL BROWSER

A Browser That Exists for the Risky Task

The Remote Ephemeral Browser provides an isolated execution environment for browsing activity that requires a stronger security boundary.

HIGH-RISK WEBSITES

Unknown or Higher-Risk Destinations

UNTRUSTED CONTENT

External Web Content

RESEARCH

Security Research

THIRD-PARTY

Third-Party Browsing

INVESTIGATION

Threat Investigation

SENSITIVE WORKFLOWS

Sensitive Browsing Workflows

CONTROLLED EXECUTION

WEB → REMOTE EXECUTION → CONTROLLED SESSION → USER

The isolated session can be created for the required activity and managed according to organizational policy.

4.5 THREAT CONTAINMENT

Contain the Web. Reduce Endpoint Exposure.

Browser-based threats can originate from websites, downloads, scripts, advertisements, documents and other external content. Browser Isolation moves higher-risk execution away from the endpoint and provides an additional execution boundary.

EXECUTION ISOLATION

Web content executes remotely.

SESSION ISOLATION

Browsing activity is separated into controlled sessions.

POLICY ENFORCEMENT

Access can be governed by identity, user/group and policy.

THREAT CONTAINMENT

Untrusted content remains within the remote execution boundary.

SECURITY VISIBILITY

Sessions and security events can be monitored and audited.

The underlying security model combines Zero Trust, DLP, encryption, policy and audit.

4.6 DATA CONTROL

Isolation Alone Is Not Enough

Moving browser execution remotely is only one part of the security model. JupitoSecure Browser Isolation also controls how information moves between the isolated browser and the endpoint.

DATA MOVEMENT

Downloads

Apply policy before information leaves the isolated environment.

DATA MOVEMENT

Uploads

Control information entering the isolated browsing environment.

DATA MOVEMENT

Clipboard

Control clipboard-based transfer paths.

SESSION

Session Data

Apply policy to information exchanged through the session.

PROTECTION

Data Leakage Paths

Control how information moves between the isolated environment and endpoint.

CONTROLLED DATA FLOW
REMOTE BROWSER → DOWNLOAD → POLICY → ENDPOINT
ENDPOINT → UPLOAD → POLICY → REMOTE BROWSER
CLIPBOARD / SESSION DATA → POLICY → CONTROLLED FLOW
4.7 DEPLOYMENT

Deploy the Security Boundary Where It Fits

Browser Isolation can be deployed across cloud, VM, on-premises and existing infrastructure. It can be integrated with existing JupitoSecure platforms and infrastructure rather than requiring an organization to redesign its entire browsing environment.

CLOUD

Cloud Deployment

VM

Virtualized Deployment

ON-PREMISES

On-Premises Deployment

EXISTING INFRASTRUCTURE

Integrated Deployment

INTEGRATED DEPLOYMENT
ENTERPRISE BROWSER → NORMAL WEB
ENTERPRISE BROWSER → HIGHER-RISK WEB → BROWSER ISOLATION → REMOTE BROWSER
4.8 USE CASES

Isolate Web Activity When the Risk Requires It

HIGH-RISK WEB

High-Risk Web

Isolate access to unknown or higher-risk websites.

UNTRUSTED CONTENT

Untrusted Content

Interact with external content through a remote execution environment.

SECURITY RESEARCH

Security Research

Provide controlled browsing for investigation and analysis.

THIRD-PARTY ACCESS

Third-Party Access

Provide external users with isolated browser environments.

THREAT CONTAINMENT

Threat Containment

Reduce direct endpoint exposure to browser-based threats.

DATA LEAKAGE CONTROL

Data Leakage Control

Control how information moves between the isolated environment and endpoint.

Best For

High-Risk Browsing • Untrusted Content • Third Parties • Security Research • Threat Reduction

4.9 GET IT NOW

Add Browser Isolation Where Risk Requires It

Start with managed browsing through Enterprise Browser and introduce isolation for destinations or workflows requiring an additional execution boundary.

EXPLORE

Explore Browser Isolation

Explore Browser Isolation →
TRIAL

Start a Trial

Start a Trial →
MARKETPLACE

Deploy from Marketplace

Deploy from Marketplace →
DEMO

Request a Demo

Request a Demo →

Expand the Security Boundary

ENTERPRISE BROWSER → BROWSER ISOLATION → TELEWORKSPACE → TELECONNECT → AI EXECUTION

Isolate Only When the Risk Requires It.

The goal is not to isolate everything. Use the appropriate execution boundary for the risk of the activity.

BROWSER ISOLATION™

Isolate Risky Web Execution

Add a stronger execution boundary for higher-risk browsing without changing the way users work.