Remote Browser Isolation · WebRTC · On-Prem Ready

Your browser is the attack surface.
We moved it.

Dejanu executes every browsing session inside a disposable, policy-governed container—and streams only pixels to the endpoint. Malware never gets a path in. Data never gets a path out.

0%lower TCO vs VDI
<0msWebRTC latency
0%code execution on endpoint
invoice_Q4.pdf
ClamAV + MIME validation
Malware scan: CLEAN
malware.exe
Policy enforcement
Download BLOCKED
isolated-session.acme.dejanu.io
LIVE · VP8 · 42ms
Domains
247 allowed
Session
2h 14m
Files
12 scanned today
Recording
ON
Meet Deji

Your guardian of safe browsing

Deji is Dejanu's guide through every session—creating isolated spaces where teams explore freely, while policy keeps them protected, monitored, and in control.

Secure browsing. Under control.

Deji — Dejanu mascot
The Problem

83% of breaches start in the browser

  • Firewalls and EDR filter traffic—but active web code still runs on the laptop
  • VDI costs 40–80 million rials/user/month just to give someone a browser
  • When auditors ask "what did user X do?"—you have no session evidence
  • SWG/SASE filters URLs but cannot stop zero-day execution on endpoints

Dejanu: isolation by architecture, not detection

Run Chromium in a remote container. Stream the viewport via WebRTC. Enforce policy at the network boundary. Scan every file. Record every session. Destroy the container when done.

0B rialsavg. annual savings
0haudit prep time
Platform

Enterprise RBI that ships like a product

Not a science project. Not a VDI workaround. A complete platform with policy, governance, billing, and compliance built in.

MOAT Mode

Lock the browser to a single application. No tabs, no URL bar, no lateral browsing. Unique in the RBI market.

Policy at the Boundary

Domain allow/deny, time windows, IP geofencing, usage caps, MIME controls—all enforced in the runtime network path.

File Scanning Pipeline

ClamAV + optional VirusTotal. Chunked uploads with MIME re-validation. Clear verdicts: clean, infected, or denied.

Session Recording

Configurable retention from 30 days to 7 years. MP4 + JSON export. Auto-expiry and S3 lifecycle cleanup.

True Chargeback

Meter CPU, RAM, bandwidth, and storage per session. Auto-invoice departments. Gregorian + Jalali calendars.

Multi-Tenant Ops

Branded portals, tenant admin, warm pools, Docker/K8s runtimes, and air-gapped deployment with full feature parity.

How It Works

Launch to destroy in three steps

01

Authenticate & launch

User signs in via OAuth, LDAP, or OIDC. Branded portal starts a fresh container in seconds.

02

Browse in isolation

Chromium runs behind enforced proxy + firewall. Policy controls domains, files, clipboard, and recording.

03

Stream & destroy

WebRTC delivers sub-50ms video. Session ends → container destroyed. Telemetry persisted for governance.

Security by Design

Defense-in-depth, all the way down

Isolation is the headline. Underneath it sits a hardened control plane and an enforced runtime—so policy is something you prove, not something you hope holds.

Forced proxy egressFirewall rules block direct HTTP/HTTPS so every request flows through the enforced proxy path—bypass routes are closed, not just discouraged.
mTLS device bindingBind sessions to approved devices with mutual-TLS certificates. Stolen credentials alone can't open a session.
Anti-replay integrityEvery API request is signed with timestamp + nonce + HMAC, with nonce uniqueness tracked in a distributed cache.
Hardened tokensJWTs carry IP-binding and expiry checks with server-side revocation and blacklisting for instant cut-off.
Admin 2FA & lockoutTOTP two-factor, per-user and per-IP account lockout, and device fingerprinting protect the system-admin plane.
Tenant crypto isolationPer-tenant keys, encrypted config chains, and strict CSP/HSTS security headers keep tenants cryptographically separated.
AI Assistant

Understand any page—without leaking it

An optional, tenant-gated assistant works from a screenshot of the current view—never your raw browsing history. Summarize a dense report, translate a foreign portal, explain an error, or extract a table in one click.

SummarizeExplainTranslateExtractKey PointsNext StepsCompareTroubleshoot
Tenant-gatedRate-limited per minute & dayScreenshot-scopedKeys encrypted at restProvider-flexible
youSummarize this incident report
AI3 systems affected · root cause: expired cert · MTTR 42m
youTranslate the vendor portal
AIRendered in English — 14 fields mapped
Compare

Why teams choose Dejanu over alternatives

VDI

50M+ rials/user
  • 3–6 month rollout
  • Full desktop overhead
  • No browser-native policy
  • Expensive for web-only users

SWG / SASE

Filter only
  • Code executes locally
  • No session recording
  • No file scanning boundary
  • Detection, not isolation

1st-gen RBI

Isolation only
  • No billing/chargeback
  • No MOAT app-lockdown
  • Limited on-prem options
  • No device binding

Dejanu

Complete platform
  • 7–30 day deployment
  • MOAT single-app mode
  • mTLS device binding
  • Session recording + billing
  • On-prem + air-gapped
Proof

Results security teams report

Our SOX audit went from 40 hours to 2 hours. We just showed them the session recordings.
TB
Top 5 US BankCISO · 5,000 users
225 billion rials annual savings vs VDI
We finally have a defensible way to allocate web access costs across departments.
RH
Regional HealthcareIT Director · 2,000 users
Zero HIPAA audit findings
We give contractors access to our procurement portal via MOAT. They can only use that portal.
NB
National BPOSecurity Lead · 2,000 agents
QA review time cut 75%
0%malware blocked by design
0fastest deployment
0%gross margin (Rust core)
0max retention

Stop securing endpoints.
Start isolating browsers.

30-day free pilot · 25–50 users · Architecture review included · No credit card required

Start Free Pilot