
Your browser is the attack surface.
We moved it.
Dejanu executes every browsing session inside a disposable, policy-governed container—and streams only pixels to the endpoint. Malware never gets a path in. Data never gets a path out.
Your guardian of safe browsing
Deji is Dejanu's guide through every session—creating isolated spaces where teams explore freely, while policy keeps them protected, monitored, and in control.
Secure browsing. Under control.

83% of breaches start in the browser
- ✕Firewalls and EDR filter traffic—but active web code still runs on the laptop
- ✕VDI costs 40–80 million rials/user/month just to give someone a browser
- ✕When auditors ask "what did user X do?"—you have no session evidence
- ✕SWG/SASE filters URLs but cannot stop zero-day execution on endpoints
Dejanu: isolation by architecture, not detection
Run Chromium in a remote container. Stream the viewport via WebRTC. Enforce policy at the network boundary. Scan every file. Record every session. Destroy the container when done.
Enterprise RBI that ships like a product
Not a science project. Not a VDI workaround. A complete platform with policy, governance, billing, and compliance built in.
True Execution Isolation
Web code runs in a remote container. Endpoints receive a VP8 video stream and a controlled input channel—nothing else.
MOAT Mode
Lock the browser to a single application. No tabs, no URL bar, no lateral browsing. Unique in the RBI market.
Policy at the Boundary
Domain allow/deny, time windows, IP geofencing, usage caps, MIME controls—all enforced in the runtime network path.
File Scanning Pipeline
ClamAV + optional VirusTotal. Chunked uploads with MIME re-validation. Clear verdicts: clean, infected, or denied.
Session Recording
Configurable retention from 30 days to 7 years. MP4 + JSON export. Auto-expiry and S3 lifecycle cleanup.
True Chargeback
Meter CPU, RAM, bandwidth, and storage per session. Auto-invoice departments. Gregorian + Jalali calendars.
Multi-Tenant Ops
Branded portals, tenant admin, warm pools, Docker/K8s runtimes, and air-gapped deployment with full feature parity.
Launch to destroy in three steps
Authenticate & launch
User signs in via OAuth, LDAP, or OIDC. Branded portal starts a fresh container in seconds.
Browse in isolation
Chromium runs behind enforced proxy + firewall. Policy controls domains, files, clipboard, and recording.
Stream & destroy
WebRTC delivers sub-50ms video. Session ends → container destroyed. Telemetry persisted for governance.
Defense-in-depth, all the way down
Isolation is the headline. Underneath it sits a hardened control plane and an enforced runtime—so policy is something you prove, not something you hope holds.
Understand any page—without leaking it
An optional, tenant-gated assistant works from a screenshot of the current view—never your raw browsing history. Summarize a dense report, translate a foreign portal, explain an error, or extract a table in one click.
Why teams choose Dejanu over alternatives
VDI
- 3–6 month rollout
- Full desktop overhead
- No browser-native policy
- Expensive for web-only users
SWG / SASE
- Code executes locally
- No session recording
- No file scanning boundary
- Detection, not isolation
1st-gen RBI
- No billing/chargeback
- No MOAT app-lockdown
- Limited on-prem options
- No device binding
Dejanu
- 7–30 day deployment
- MOAT single-app mode
- mTLS device binding
- Session recording + billing
- On-prem + air-gapped
Results security teams report
Stop securing endpoints.
Start isolating browsers.
30-day free pilot · 25–50 users · Architecture review included · No credit card required
Start Free Pilot