Zero-trust remote browser isolation that runs entirely in your own AWS account. Each user gets an ephemeral, isolated Chromium session streamed to their browser, with admin control over clipboard, file transfer, printing and web access.
Cloud Certainty Secure Browser gives your workforce, contractors and third parties secure access to internal web applications and the internet without exposing devices or networks. Web content runs in a disposable Chromium session in your own AWS account and is streamed to the user as pixels. Nothing executes on the endpoint, and no data reaches it unless your policy allows.
Everything runs in your AWS account and VPC. One CloudFormation stack deploys a serverless control plane and an admin portal that users sign in to through AWS IAM Identity Center or any SAML 2.0 or OIDC identity provider. Each session is a single-use container that accepts no inbound network connections. It is created when the user clicks Start and destroyed when they finish, go idle or hit the maximum session length. Media is end-to-end encrypted (WebRTC DTLS-SRTP) and relayed through managed TURN, so no public IPs or load balancers are needed. Sessions can reach private applications in your VPC, so users don't need a VPN.
Administrators define policy profiles per user or group: clipboard copy and paste in each direction; file upload and download, with a size limit; printing; URL allowlists and blocklists, homepage and bookmarks; developer tools, extensions and incognito mode; idle, disconnect and maximum session timeouts; and an IP allowlist for the portal. Every session and configuration change is recorded in an audit log in your account.
You pay per browser session-hour, metered per second, plus the AWS infrastructure the sessions use in your account. When nobody is browsing, the cost is close to zero.
Highlights
Runs in your AWS account: sessions, browsing data and audit logs stay in your VPC. Deploy with one CloudFormation stack and sign in through IAM Identity Center, SAML or OIDC.
Zero trust by design: one ephemeral container per session with zero inbound network access, end-to-end encrypted streaming, least-privilege IAM, and automatic destruction at the end of each session.
Granular data-loss controls, pay per use: clipboard, file transfer, printing, URL filtering, timeouts and IP allowlists, set per user or group. Billed per session-hour, with nothing charged while idle.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This product uses one pricing dimension: Container Hours, billed by usage. You pay a software fee for each browser session-hour while a session runs, metered per second. There is no upfront fee, no minimum commitment, and no per-user licence. Your cost scales directly with how many hours your users spend in active browser sessions. When no one is browsing, containers are not running, so software fees stop. You also pay separately for the AWS resources the sessions use in your own account; those appear on your AWS bill from AWS.
Top-of-mind questions for buyers
What exactly counts as one container-hour for billing?
A container-hour is one browser session running for one hour. Each session is a single-use Chromium container in your account. The software fee meters per second while that session runs. If ten people browse at once, you accrue ten sessions' worth of hours during that time.
Am I charged when no one is actively browsing, or when sessions sit idle?
Software fees apply only while a session runs. When a session ends, goes idle past the limit, or disconnects, the container is destroyed and metering stops. With nobody browsing, no containers run. The rest of the stack is serverless, so idle software fees stop.
Besides the per-hour software fee, what AWS costs do I pay separately?
You pay AWS directly for resources the sessions use in your account. These include compute for each running session, streaming relay minutes, and small serverless charges. Adding a NAT gateway also incurs AWS fees. These appear on your AWS bill and vary by Region.
cloudcertainty.com
Helpful?
Vendor refund policy
This product is billed pay-as-you-go, per second of browser session time, with no upfront or prepaid fees, so refunds are not offered. If you believe you were billed in error, contact info@cloudcertainty.com within 30 days of the charge and we will investigate with AWS Marketplace.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Simpler setup.
New Launch stack link on this page: it opens AWS CloudFormation with the template already selected.
Two support-only parameters are removed from the stack: Marketplace product code and Artifact bucket prefix. Release images have the product code built in, so these did nothing.
Clearer stack description in the CloudFormation console.
Prerequisites: a VPC with private subnets that have outbound internet access (for example through a NAT gateway), in an AWS Region that offers Kinesis Video Streams WebRTC, Amplify Hosting and Amazon Cognito.
Set VpcId, TaskSubnetIds, BootstrapAdminEmail and IdentityProvider (IAMIdentityCenter, SAML, OIDC or CognitoOnly). Acknowledge that the stack creates IAM resources with custom names. Creation takes about 10 minutes. During creation a one-time installer task from this container image copies the application into a private S3 bucket in your account.
Identity provider:
IAM Identity Center or SAML: create a custom SAML 2.0 application using the SamlAcsUrl and SamlAudienceUri stack outputs, assign users or groups, then update the stack and set SamlMetadataUrl to the application's SAML metadata URL.
OIDC: store the client secret in AWS Secrets Manager and set OidcIssuer, OidcClientId and OidcClientSecretArn. Register https://<CognitoDomain output>/oauth2/idpresponse as the redirect URI.
CognitoOnly: the bootstrap admin receives an invitation email.
Open the PortalUrl stack output, sign in as the bootstrap admin, set policies under Admin, and start a secure browser session.
Billing: each browser session runs as one ECS task and is billed per task-hour (per second, 1-minute minimum). The AWS infrastructure the stack uses (Fargate, Kinesis Video Streams, Lambda, and so on) is billed to your account separately.
Upgrades: update the stack with the new version's template URL and keep the current parameter values. The admin console shows when a new version is available.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The Surf Security Enterprise Zero Trust Browser is a revolutionary tool built from the ground up with security at its core. It employs proactive threat detection, zero trust access principles, and a familiar user interface. This combination empowers businesses to operate confidently and efficiently, especially for unmanaged devices where organisations cannot risk security gaps by using optionally removable extensions.
Co-innovated with the AWS Generative AI Innovation Center (GenAIIC) Partner Agent Factory (PAF), Anchor Browser with agentic payments provides AI agents a production-grade cloud browser that can also autonomously pay for protected web resources. Spending is held, verified, and managed by Amazon Bedrock AgentCore payments capabilities.
Browse Bravely with Prisma Browser. Allow employees to work securely on any device, managed and unmanaged, while delivering a familiar user experience. Stop AI-generated phishing, advanced malware and data exposure. Safely enable access to any web, SaaS, GenAI and private application.
To speak with a sales rep, please use: https://www.paloaltonetworks.com/company/contact-sales
Prisma Browser for Business is the secure workspace designed for small business, combining browser security, AI data controls, and protection for the business and developer tools your team relies on every day. It blocks phishing and other browser-based threats, helps prevent sensitive data from leaking into AI tools, and sets up in minutes with no IT team required and a 30 day free trial. Try it free for 30 days.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.