Remote browser isolation
Open anything. Touch nothing.
Secluding runs a real browser on our hardware and streams you the pixels. Nothing the page does reaches your machine, and every session leaves a record you can cite.
What you get
Contained by default
Four things, stacked on one idea: a disposable browser that runs somewhere else.
A real browser, sealed off
Chrome or Tor Browser runs on our hardware, inside a sandbox. Only pixels and input cross the wire. The site never touches your device or your network.
A record you can cite
Every session produces a HAR, an event timeline, screenshots, and a hashed manifest — evidence you can attach to a ticket, not a claim you have to make.
Clearnet and Tor, one workflow
Open a clearnet URL or a .onion address from the same dashboard. Tor sessions egress through Tor; clearnet sessions egress from our node.
Slots your team can see
Plans grant a number of concurrent sessions. Teams share a pool, see who is using it, and end a stale session without opening a ticket.
The airlock cycle
Every session is a decompression cycle
The ring around a session is the only status indicator you need — its shape and motion tell you the state even before you read the label.
A slot is reserved the moment you ask, before the browser exists.
A sandbox is built on a node and a browser is launched inside it.
The viewer connects. You open the URL and start working.
You interact through the pane. Every request and response is recorded.
You end the session, or a limit does. The browser is told to stop.
Artifacts are finalized and uploaded. The sandbox is wiped.
A short dwell confirms the slot is clean before it can be reused.
The witness
Every session ends with a bundle you can hand to someone else
Eight kinds of evidence, hashed and manifested, so what you saw is what the record shows.
HAR archive
Every request and response the browser made.
Event timeline
Navigation, console output, and downloads, in order.
NetLog
The browser's own network log, for Chrome profiles.
Packet capture
Wire traffic from the session's network bridge.
DNS log
Every name the session resolved, clearnet or through Tor.
Screenshots
Periodic captures of what was on screen.
Downloads
Anything the session saved, kept alongside the record.
sha256 manifest
A hash for every file, so the bundle can be verified later.
Not a scraper
Real browsers, not headless
Sessions run Google Chrome stable or Tor Browser in a real display, not a headless automation client. Sites that cloak, fingerprint, or block bots see a normal desktop browser — because that is what it is.
Interactive, not scripted
You drive the session. The forensic capture is a passive recorder, not a bot.
Sandboxed by default
gVisor intercepts every syscall on our nodes today; Firecracker takes over where a host exposes KVM.
Access is per session
The viewer only accepts your allowlisted IP. Your machine is never exposed to the sandbox.
Pricing
Start on Free, grow into Pro or Team
Sessions are the unit of value. Plans grant a number of concurrent slots; teams share a pool.
For occasional, low-risk sessions.
- 1 session at a time
- Clearnet or Tor, one kind per session
- 30 min max length, 5 min idle timeout
- 60 s cooldown between sessions
For an individual analyst working daily.
- 3 sessions at a time
- Clearnet and Tor, same session
- 4 h max length, 15 min idle timeout
- 20 s cooldown between sessions
For a team sharing a pool of sessions.
- 10 sessions, pooled across the team
- Clearnet and Tor, same session
- 8 h max length, 30 min idle timeout
- 10 s cooldown between sessions
Ready to open something you don't trust?
Sign up for free with an invite, or bring your team onto a pooled plan.