Secure browser isolation & remote workspaces
Containerized browsers and remote desktops, streamed straight to the user. Multi-region, autoscaling, isolated per session. Pick your model: we host it for you, or we deploy it on your own Kubernetes — same scalability, same patterns, your choice of ownership.
All infra included. You log in and use it.
We run your VDI desktops for you on our multi-region Kubernetes platform. Dedicated namespace per tenant, isolated networking, autoscaling agents, and a control plane managed end-to-end by our team. You don't touch a cluster — you log in and use isolated browsers and remote desktops.
Workspaces run in the region closest to the user — EU, US, APAC — so input lag stays under 50 ms.
Idle clusters scale to zero. Bursts of sessions spin up new agent pods automatically.
Each customer gets a dedicated namespace, isolated network, and its own VDI database.
What's included
- Fully managed VDI control plane and agents
- Dedicated tenant namespace on our K8s clusters
- Multi-region deployment (EU, US, APAC) for low latency
- Autoscaling VDI agents based on active sessions
- SSO/OIDC integration (Google, Okta, Entra ID)
- Custom workspace images and image registry
- TLS, custom domain, and WAF in front of the portal
- 24/7 monitoring, backups, and version upgrades
Ideal for
Teams that want browser isolation, remote workspaces, or training environments without running Kubernetes themselves. Great for security teams, support agencies, training providers, and remote-first companies.
Want us to host your VDI for you?
Book a 30-minute discovery call to get a tailored quote.
Common questions
What is the VDI Desktop Service, exactly?
It streams containerized browsers and full Linux desktops to any user's browser. Each session is a fresh, isolated container — when the user closes it, the container is destroyed. It's commonly used for secure browsing, support agent workstations, training environments, and DevOps sandboxes.
How is your managed VDI different from running it ourselves?
We run the VDI platform on a multi-region Kubernetes platform with dedicated namespaces per tenant, autoscaling agent pools, regional session routing, and 24/7 monitoring. You don't operate a cluster — you log in, get workspaces, and pay a monthly fee. Most teams reach the same setup themselves in 6–8 weeks of engineering work.
Can you deploy the VDI into an air-gapped or on-prem environment?
Yes. The self-deploy mode supports air-gapped clusters, private registries, and on-prem Kubernetes. We bring our own Helm charts, Terraform modules, and image build pipeline so the deployment works without any internet access.
How does multi-region work?
We deploy the VDI control plane in one primary region and agent pools in each region you serve. Users get routed to the nearest agent pool via geo-DNS or session affinity rules, keeping input latency under ~50 ms. Workspaces never leave their region — useful for data residency.
What licenses do we need?
For managed, all licensing is included. For self-deploy, you can start with a free community edition (limited concurrent sessions) or bring your own enterprise license — we help you size it.
Can users bring their own workspace images?
Yes. We set up an image build pipeline (GitHub Actions or GitLab CI) so your team can ship custom Dockerfiles — for example, a workspace pre-configured with internal tools, VPN clients, or training labs. Images push to a registry the VDI platform pulls from.
How do you bill for the managed VDI?
Base monthly fee for the dedicated tenant + per-concurrent-session pricing. We give you a transparent quote based on expected peak sessions. No surprise bills — autoscaling is capped at a number you approve.