Browser Security
Browsers you can attest, not just trust.
The Inlinea browser extension turns a browser into an attested endpoint. A resource marked extension required opens only for a browser holding a current, signed attestation, verified by the gateway on every request. Inside the page, your policy controls clipboard, print, transfer, screen capture, watermark and focus.
- Workspace lock
- ~5 s
- After the browser extension disappears.
- attestation window
- 45 s
- Default life of an admitted resource's attestation, verified locally by the gateway.
- revocation
- At once
- Revoking a browser ends its session immediately.
Try it
Turn a control on and watch the page change
What this does
- Only a browser with a current attestation opens this page; the gateway checks on every request.
- 6 in-page controls are enforced, and every blocked attempt lands in the Browser Security Log.
- A watermark names the person and the time across the page.
Admission, decided by the server, is the security control. In-page controls are containment with an audit trail: a determined device owner can work around them, and every attempt is logged.
The attestation model
Enrol, attest, admit, lock
- 1BrowserEnrolThe extension holds a device key the browser cannot export and enrols the browser with your deployment. You can require approval first.
- 2Inlinea serverAttestSigned heartbeats keep a short-lived attestation alive. The browser family recorded at enrolment is checked on every heartbeat.
- 3ZERA gatewayAdmitThe gateway verifies the attestation locally on every request, with no round trip. No attestation, no page.
- 4WorkspaceLockIf the extension disappears, the Workspace locks within about five seconds. Revoking a browser ends its session at once.
Prevention versus containment
We draw the line precisely
Admission decided by the server is the security control. In-page controls stop casual leaks and log every attempt; a determined device owner can work around them, and we say so.
| Control | Where it is enforced | What it is |
|---|---|---|
| Admitting an attested browser | On the server, at the ZERA gateway and the Workspace | Prevention: no attestation, no page |
| Locking the Workspace | In the Workspace, within about five seconds | Prevention for the portal |
| Closing admitted resources | At the gateway, after the attestation window | Prevention, bounded by 45 seconds by default |
| Revoking a browser | On the server, at once | Prevention |
| Clipboard, print, transfer, capture, watermark | Inside the page, by the extension | Containment with an audit trail |
Deployment and evidence
Rolled out by policy, seen in the log
- Enrolment approvalApprove each browser, or admit by rule: browser family, minimum version and allowed users.
- Managed deploymentTemplates for Chrome, Edge and Firefox force-install the extension and pin your control plane, so people cannot remove or retarget it.
- Browser healthEvery enrolled browser reports online, late or offline and the policy revision it applied.
- Browser Security LogBlocked and observed controls, warnings, watermark tampering and the extension's own lifecycle, with export and retention.