ZeroLeak Visual Isolation
Sensitive applications never reach the client — only a secure pixel stream does.
WAF stops the attack. AAM verifies identity. DLP can mask sensitive data. But the moment a sensitive application's HTML, JavaScript, session data, and API responses reach the user's device, that data is already inside the client-side risk surface.
ZeroLeak closes this risk at the architectural level. The real web application runs inside an isolated browser environment on your network. Only a live pixel stream reaches the user's device. The application's code, data, and session information never touch the client.
The user sees the application. The data never lands on the device.
ZeroLeak keeps the sensitive web application's HTML, JavaScript, API responses, tokens, and session data inside your network. Only a live pixel stream reaches the user; keyboard and mouse input flow back through a controlled channel. The browser-based attack surface closes at the source.
Three security layers, one architectural principle
The Browser Is Now at the Center of the Attack Surface
Classic web security long focused on stopping attacks aimed at the server. Today a significant share of the risk starts in the user's browser. The moment a page reaches the client, the DOM, session data, cookies, localStorage, and API responses are processed on the device. If the device isn't secure, neither is the sensitive application. ZeroLeak flips that assumption: the sensitive page never reaches the client in the first place.
Browser-Side Data Exfiltration
DOM content, session tokens, cookies, and localStorage become visible on the client side. WAF and DLP are strong on the server side; once data reaches the browser, the control surface narrows.
AI-Driven Automated Inspection
AI agents can read web pages, analyze form fields, parse visible data, and automate repetitive operations. This is not a problem confined to classic bot detection.
Device and Memory Risk
When a user's device is compromised, browser memory, open page content, tokens, and temporary files come under risk. The enterprise application becomes dependent on endpoint security the moment it reaches the client.
Screen Capture and AI Vision
Sensitive information leaks not only through HTML but also the moment it appears on screen. Screen recording, screen sharing, screenshots, and AI-based OCR tools amplify this risk.
WAF, AAM, and DLP Are Strong; They Just Don't Stop the Page from Reaching the Client
WAF filters attacks, AAM verifies access, DLP controls sensitive fields. But at the end of that chain, the web page still lands in the user's browser. ZeroLeak fills the gap: the sensitive application is never sent to the client — only a secure visual session is.
What reaches the client?
- Full HTML / DOM
- JavaScript execution context
- Session cookies and tokens
- localStorage / sessionStorage
- API response bodies
- Loaded images and files
What reaches the client?
- Only a live pixel stream
- No DOM
- No tokens
- No localStorage
- No API responses
- No file contents
ZeroLeak lets users work with sensitive applications — without ever delivering them to the client.
ADC, WAAP, and Visual Isolation on One Platform
In the enterprise market, ADC, WAAP, identity-based access, and browser isolation are typically positioned as separate product families. ADC handles load balancing, WAAP protects the application, AAM manages access, and browser isolation is usually offered as a separate SaaS service. TR7 ZeroLeak removes that split. Sensitive application access, web security, identity policy, visual isolation, Anti-OCR, and forensic recording all run inside the same platform.
Visual isolation built into ADC/WAAP
ZeroLeak delivers visual isolation as a native security layer of the TR7 platform — not as a separate product. The operator manages access, security, isolation, and recording policies side-by-side from the same management UI.
Runs on-premises, no SaaS dependency
Many browser isolation approaches route traffic into a third-party cloud. ZeroLeak runs inside your network. Sensitive applications, session data, and recordings stay under your control.
Anti-OCR — an extra layer against visual leakage
Keeping the page off the client is step one. But what appears on screen can still be read via screenshots, screen recording, or AI vision. ZeroLeak adds a visual-protection and policy-based masking layer for that risk.
Licensing built for the business scenario
Instead of complex bandwidth-based models, ZeroLeak is licensed by concurrent-user capacity. Organizations plan a clear capacity model by counting how many users will hold isolated sessions at the same time.
ZeroLeak's distinction isn't a single feature; it's the architectural combination — ADC, AAM, WAAP, visual isolation, Anti-OCR, and forensic recording running in the same security flow.
Data Doesn't Reach the Client. The User Only Works with a Secure View.
ZeroLeak's security model rests on three core layers. First, the application itself is separated from the client. Then, sensitive on-screen regions are protected against visual leakage. Finally, the entire session becomes an auditable forensic record.
Pixels Only
The sensitive web application runs inside an isolated browser environment on your network. The application itself never reaches the user's device — only a live pixel stream does.
- HTML, JavaScript, session tokens, cookies, and localStorage never reach the client
- API calls and response bodies stay inside the isolated session
- Users connect from a standard browser; no agent installation required
- Keyboard and mouse input flow into the session over a controlled channel
- Even if the device is compromised, sensitive application data is never on it
Anti-OCR Visual Protection
What appears on screen is also a surface to protect. ZeroLeak applies policy-based protection to sensitive regions against screenshots, screen recording, and AI-based OCR.
- Dynamic visual protection and obfuscation layers on sensitive regions
- Extra defense against screenshots, screen recording, and screen sharing
- Pixel-level countermeasures against AI vision and OCR-based reading attempts
- Masking policies by role, application, and data type
- Per-session invisible watermarking — source attribution on leaks
Full Session Recording
ZeroLeak doesn't just isolate access — it makes the entire access auditable. For critical applications, the question of who did what and when has a complete retrospective answer.
- Video-quality session recording
- Timestamped capture of clicks, keystrokes, navigation, and action steps
- Unified visibility across user, application, device, IP, and access context
- Active event streaming to SIEM for security teams
- Policy-based retention aligned with GDPR, HIPAA, PCI DSS, and internal audit
Inside Your Network, a Separate Isolation Cell per Session
ZeroLeak is not a SaaS routing service or a client agent. It is a security layer that runs inside your network and creates a separate isolated browser cell for every user session. The session starts, the cell opens; the session ends, the cell collapses. Application data never moves to the client, and the session environment never persists.
Session lifecycle
- Separate isolation cell per session — no shared browser environment across users
- No agent required — any HTML5-capable standard browser works
- Application traffic stays inside your network
- Integrated with TR7 AAM for SSO, MFA, OAuth2, OIDC, SAML, LDAP, and RADIUS
- Shares attack context and security policy with TR7 WAAP
- Policy, license, and recording management through TR7 Central Management
- Event streaming to Splunk, Elastic, QRadar, and similar SIEM platforms
5 Critical Battlefields Where ZeroLeak Excels
ZeroLeak delivers the most value in scenarios where device trust is weak but application data is critical. Users are granted access — but the application data is never delivered to their device.
Third-party remote access in banking
Contractors, auditors, or external developers need remote access to sensitive banking screens. The device is not under organizational control and the risk of data leakage is high.
The user connects from their own browser into an isolated session. The core banking screen stays inside your network; only a pixel stream reaches the user's device. Every session is recorded for audit and forensic review.
Healthcare BYOD access to patient records
A clinician or field worker wants to access patient records from their personal tablet. Health data is sensitive, and the device's security posture cannot always be guaranteed.
Patient data never lands on the tablet. The user can view and act on the data, but HTML, files, API responses, and session information never reside on the client device.
Sensitive management consoles in government
When access to government management panels, classified applications, or critical internal portals is opened over classic VPN, endpoint and screen-leak risks remain.
The console runs inside your network and the user receives only an isolated visual session. Anti-OCR is applied to sensitive regions; every action becomes an auditable record.
Partner and supplier portal access
Suppliers, business partners, and dealers access B2B portals. The security level of those devices cannot be directly managed by your organization.
The partner portal is never delivered to the client. The user can take action, but data, files, and session information never stay on the partner device. New devices, different locations, and temporary access scenarios are handled with more control.
AI agents and automation risk
A user may access an enterprise application through an AI agent or automation extension acting on their behalf. These tools can read, parse, or exfiltrate page content.
An AI agent cannot see the DOM, API responses, or page code — only the pixel stream. Structured scraping risk drops, behavioral anomaly policies and forensic recording make the process traceable.
Licensed by Concurrent-User Count
ZeroLeak capacity is planned by the number of users who hold isolated sessions at the same time. Every license tier ships the same core feature set; only the concurrent-user capacity changes.
Evaluation usage is included with every TR7 platform: 1 concurrent user, 30 minutes per day, all features unlocked. For production use, the capacity options below take over.
Every tier ships the same capability set — the only difference is the number of isolated sessions that can run at the same time.
Real capacity depends on hardware resources, application type, session duration, and forensic recording policy. As a planning average, you can assume roughly 1 GB RAM, 1 vCPU per user, and roughly 500 MB/hour of disk for forensic recording.
A Strong Layer for Audit, Data Minimization, and Remote-Access Control
ZeroLeak supports data minimization, remote-access control, session recording, and auditability requirements for sensitive web application access. Because data never reaches the client, it forms a strong additional control layer in regulation-driven security architectures.
GDPR Article 32
Supports technical and organizational measures for personal data security. Because sensitive data never lands on the client device, it strengthens the data-minimization principle.
HIPAA Security Rule
Contributes to ePHI access control, audit, and integrity safeguards. Isolated sessions, forensic recording, and policy-based access work together.
ISO 27001 Annex A
Provides an additional security layer for remote access to critical systems. Management consoles and sensitive applications can be used without being delivered to the client.
SOX (Sarbanes-Oxley)
Provides a strong audit layer for financial-system access — insider risk, third-party access, and transaction traceability.
PCI DSS 4.0.1
Reduces the client-side attack surface for the cardholder data environment. Sensitive screens, access policy, and session recording are managed with tighter control.
Premium Add-on — Per Concurrent User
ZeroLeak is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). The license model is based on concurrent-user capacity rather than bandwidth — because every user session creates a separate isolation cell with its own resource footprint.
- Per concurrent-user (CCU) licensing — 1, 5, 10, 25, 50, 100, 250, 500, or unlimited
- Attaches to all four bundles — Base, Geo, Secure, and Enterprise
- Runs on a hardware appliance or a virtual machine
- On hardware appliances, ZeroLeak resources can be planned from a separate CPU/RAM pool
Deliver Sensitive Applications with Pixelized Security
Let's walk through a ZeroLeak demo against your own scenario: which applications should be isolated, how many concurrent users you need, how forensic recording should be retained, and how it fits into your existing TR7 architecture.