A user has to open something you do not trust. The page still has to render. It cannot execute on their laptop. Isolation moves the browser off the device so the site never gets a local engine, a corporate IP, or the cookie jar.
That pitch hides four deliveries in one line. A hosted workspace for named analysts, a hardware appliance, a container farm you host, and an add-on on a Secure Service Edge (SSE: cloud web, SaaS, and private-app security) you already pay for are not the same purchase. Those four get sold as remote browser isolation, which is why comparing category pages is confusing. They do not agree on where the browser lives or who operates it.
If the job is investigative browsing with attribution, start with Authentic8 Silo. If you need hardware-enforced isolation or an on-prem appliance, Everfox ULTRA. If you will run the farm yourself and want a public Community tier to prove it, Kasm. If Zero Trust is already the edge, Cloudflare Browser Isolation is the add-on on that edge. This page is how isolation is delivered. The remote browser isolation platforms list is isolation as a dedicated product or as a policy on SSE. The method is on How we review tools.
What usually goes wrong when choosing browser isolation
Most bad fits start with buying a remote tab without asking who operates the browser.
| Problem | Solution |
|---|---|
| Isolation is an add-on inside another product | Write whether isolation is the product or an add-on |
| You cannot tell who operates the remote browser | Ask who operates the browser |
| A bundle price hides the isolation line | Use a public isolation price, or treat it as quote-only |
| The job is internet isolation and the product is app publishing | Match the job to the product you are actually buying |
How we evaluated browser isolation
Four checks: who operates the remote browser, whether isolation is the product or an add-on, whether any price is public, and whether the job is investigative workspaces, hardware enforcement, a farm you host, or an edge policy. Secure-enterprise-browser feature lists did not decide the list. Neighbor products sit under Other browser isolation tools worth considering.
TL;DR: The Four Compared
| Platform | Best for | What to check |
|---|---|---|
| Authentic8 Silo | Intel, investigations, and fraud teams that need in-region attribution for named analysts |
Who operatesTheir cloud. Isolation-as-a-service workspace
ProductSilo Workspace. Tiers are one region, two regions, or all regions
PriceLocal $1,450 / user / year. Multi-Region $2,450. Global $3,450. 30-day trial free
|
| Everfox ULTRA | Public sector shops that want isolation enforced in hardware, on-prem or hosted |
Who operatesOn-prem Isolation Appliance, or Everfox-hosted ULTRA
ProductHardsec FPGA stream. ULTRA Plus adds content disarm on downloads
PriceQuote-only. Name ULTRA or the Isolation Appliance
|
| Kasm Workspaces | Teams that will run the isolation farm themselves and want a free five-session proof |
Who operatesYou host Docker containers, or they host a cloud
ProductDisposable browsers, desktops, and apps from one control plane
PriceCommunity Edition free, 5 concurrent sessions. Starter and Enterprise are quote
|
| Cloudflare Browser Isolation | Orgs already on Cloudflare One that want to isolate sites without a second vendor |
Who operatesCloudflare edge. User keeps their own browser
ProductAdd-on on Zero Trust Pay-as-you-go and Enterprise (Contract)
PricePay-as-you-go $7 / user / month annual is Gateway and Access. Isolation add-on is quote
|
Authentic8 Silo

Authentic8 Silo is isolation-as-a-service for people who have to visit sites they do not trust: OSINT, threat intel, fraud, journalism, without handing the site a corporate IP or a local browser. The page runs in Authentic8's cloud. The analyst gets a managed browser plus a library of desktop and messaging apps (Telegram, Signal, Maltego, LibreOffice among the ones they name).
Attribution is the paid axis. Tiers are one region, two regions, or all regions on the Silo Managed Attribution Network (North America, Europe, Central and South America, Asia-Pacific, Africa and Middle East, dark web, and rapid-response nodes). Every paid tier includes the full workspace, admin controls, and Silo Nexus AI at up to 10 prompts per day.
Best for: Intel, investigations, and fraud teams that need in-region attribution for named analysts.
What you get:
- Remote Silo for Research browser with configurable profiles and persistent or single-use browsing data.
- Managed attribution network with regional and dark-web egress. Local is one region; Global is all of them.
- Workspace apps, encrypted personal and shared storage, case management, Silo Collector, Silo Gofer multi-site search, and Silo Translate.
- Silo Nexus AI: source-grounded answers, identity-shielded queries, no prompt retention for model training, encrypted conversation logs.
Why we like it: It is the only isolation product here with a public, mechanical per-user price that matches the actual job: research workspaces for named analysts. If the RFP is OSINT, start here instead of an SSE add-on.
Limits:
- Wrong buy for fleet-wide employee browsing. You do not buy Silo to isolate YouTube.
- Nexus AI is capped at 10 prompts per day on the public tiers. Unlimited is an enterprise conversation.
- No AWS Marketplace listing. Procurement goes through Authentic8.
Price: 30-day trial, free. Then Local $1,450, Multi-Region $2,450, or Global $3,450 per user per year. Same workspace on every paid tier. Enterprise Nexus options are quote.
Everfox ULTRA

Everfox ULTRA is the hardware isolation buy. Garrison Technology built ULTRA and the Isolation Appliance on hardsec: FPGA silicon that turns the remote page into an interactive video stream so web code never lands on the endpoint. Everfox, formerly Forcepoint Federal, closed the Garrison acquisition in August 2024. The living products are the Isolation Appliance (on-prem, 3U Enterprise or 1U Reduced) and Everfox ULTRA in the cloud. Name Everfox on the contract, not Garrison.
On 6 May 2025 Everfox launched ULTRA Plus: the same hardsec remote browser isolation plus their content disarm and reconstruction path, which rebuilds a downloaded file from the format spec instead of scanning it. ULTRA entered FedRAMP In Process on 3 April 2025. Quote-only. Do not budget from an old Garrison listing.
Best for: Public sector shops that want isolation enforced in hardware, on-prem or hosted.
What you get:
- Hardsec isolation: one system fetches the page, FPGA logic streams video and rate-limits keystrokes and mouse back. No browser engine on the trusted side.
- Isolation Appliance with three physically separate NICs for on-prem or air-gapped networks; cloud ULTRA if you do not want a rack.
- ULTRA Plus (6 May 2025) adds content disarm and reconstruction on downloads.
- Data loss prevention (DLP), copy/paste and password friction, persistent profiles, SIEM APIs, SAML/AD. NCSC-assessed hardsec heritage.
Why we like it: If the buying reason is that software isolation is still a browser you have to patch, this is the remaining hardware answer. The appliance is the differentiator versus every cloud isolation product on the platforms page.
Limits:
- Everfox is a high-assurance vendor. Expect a sales cycle.
- Name ULTRA or the Isolation Appliance on the contract, not Garrison SaaS.
- No public list price on everfox.com.
Price: Quote-only. Contact Everfox. Do not budget from an old Garrison listing.
Kasm Workspaces

Kasm Workspaces is the self-hosted isolation farm: disposable Docker containers stream a browser, a desktop, or an app into the user's existing browser. No agent. The threat of the page sits in the container. When the session dies, so does the container. That is why it shows up in isolation RFPs and in VDI replacements at the same time.
Community Edition is free for personal, non-profit, and non-commercial use, capped at five concurrent sessions. Starter and Enterprise are paid, per named user or per concurrent session. You can run it on your own metal or in a VPC; Kasm also sells a hosted cloud. Production commercial use needs a paid key.
Best for: Teams that will run the isolation farm themselves and want a free five-session proof.
What you get:
- Containerized browser isolation, plus full desktop and app streaming, from the same control plane.
- SaaS, single-server, or multi-node on-prem / AWS / GCP / Azure / GovCloud.
- Community Edition: 5 concurrent sessions, community support. Paid tiers add named-user or concurrent-session licenses and commercial support.
- A first lab you can stand up without a quote. Session queue waits for compute. It does not lift the five-session Community cap.
Why we like it: It is the only isolation product here with a public Community license you can read without a quote. If the question is whether you even want isolation, or disposable browsers for a lab, Kasm is the experiment.
Limits:
- You own uptime, image patching, and capacity. Isolation-as-a-service vendors own that for you.
- Community is not a commercial license. Five concurrent sessions is a lab.
- Starter and Enterprise dollars are a sales form.
Price: Community Edition is free for 5 concurrent sessions. Starter and Enterprise are quote. Hosted cloud is a separate subscription.
Cloudflare Browser Isolation

Cloudflare Browser Isolation is not a peer isolation workspace on this list. It is an SSE add-on on the Cloudflare edge. The user keeps their own browser. Every tab runs remotely; closing the tab deletes the session. It sits next to Gateway (a secure web gateway, or SWG: cloud filtering of internet traffic) and Access (zero trust network access, or ZTNA: replacing VPN access to private apps) as a Zero Trust add-on. Isolation is an add-on on Pay-as-you-go and Enterprise (Contract). There is no public isolation unit price.
Cloudflare for Government reached FedRAMP High on 10 Aug 2026. Isolation is still an add-on on that stack. If the RFP is High, ask whether isolation sits in the authorized boundary before you default to an appliance.
Best for: Organizations already on Cloudflare One that want to isolate sites without a second vendor.
What you get:
- Remote execution of active web content; the local browser gets a safe rendering. Session dies when the tab closes.
- Works with the user's existing browser. No new client for isolation itself.
- Policy through Gateway HTTP and DNS. Can block input on risky sites and control data into sensitive apps.
- Decrypts traffic with the Cloudflare root CA. Isolation is a security product.
Why we like it: If Cloudflare is already the SWG, adding isolation is an add-on on that edge. That is the opposite of Authentic8 (new workspace) and Kasm (new farm).
Limits:
- The published Zero Trust seat is not the isolation bill. Isolation is an add-on. Ask for that line in the quote.
- Enterprise isolation, DLP, and SaaS-data extras stack. The starter seat and the real seat are different numbers.
- It will not give you attribution, dark-web egress, or a hardware air-gap. Wrong product for those RFPs.
Price: Zero Trust Pay-as-you-go is $7 per user per month, paid annually, for Gateway and Access. Browser Isolation is an add-on on Pay-as-you-go and Contract; there is no public isolation unit price. Contract / Enterprise is quote.
Who operates the browser, and is isolation the product?
This grid plots two questions. Across is who operates the remote browser: the vendor on the left, you on the right. Up is the product: isolation is the product at the top, an add-on at the bottom.
Placement is Silo Workspace versus hardsec ULTRA / Isolation Appliance versus Community or paid Kasm versus a Zero Trust add-on. Everfox's on-prem appliance is hardware you rack; the logo stays on the product row because isolation is still the product, not an SSE extra. Hosted ULTRA is vendor-operated. Placement only, not review scores.
Published seat versus the isolation line
| Platform | Published rate | What the isolation line is |
|---|---|---|
| Authentic8 Silo | Local $1,450 / user / year. Multi-Region $2,450. Global $3,450. Trial free | The seat is the workspace. Tiers are attribution regions. Nexus AI is 10 prompts / day unless you quote Enterprise |
| Everfox ULTRA | Quote-only. No public list price on everfox.com | Appliance or hosted ULTRA. Name the product. Marketplace units are not Everfox's list |
| Kasm Workspaces | Community free, 5 concurrent sessions. Starter and Enterprise: request a license | You own the farm. Community is not a commercial production plan |
| Cloudflare Browser Isolation | Zero Trust Pay-as-you-go $7 / user / month, paid annually | Add-on. No public isolation unit price. Contract is quote |
Other browser isolation tools worth considering
These are real isolation products. They belong on a different comparison: isolate-as-policy on an SSE platform, or a hardened local browser.
- Menlo Security, Zscaler Cloud Browser Isolation, Netskope Remote Browser Isolation, Proofpoint Isolation, FortiIsolator, Prisma Access Remote Browser Isolation, iboss - cloud or appliance isolation inside an SSE policy engine. That conversation is the remote browser isolation platforms page. Cloudflare appears on both pages on purpose: here as the add-on delivery model, there as an SSE peer.
- Island, Chrome Enterprise Premium, Prisma Access Browser - secure enterprise browsers. They harden the local browser. Isolation keeps web code off the device. They can pair. They are not substitutes.
- Browser-safety plugins and dead isolation startups - not a remote browser you can buy in 2026.
Questions before you sign a browser-isolation contract
If operator, product, and job stay verbal, you are still buying a remote-tab demo.
- Who operates the browser? If they host the workspace or the edge, they operate it. If you host the containers or rack the appliance, you own uptime and patching.
- Is isolation the product or an add-on? A named-analyst workspace, a hardsec appliance, a Community farm, and a Zero Trust extra are not interchangeable. Pick the square, then pick the logo.
- Which published number is actually on the quote? Silo seats are the published region tiers per user per year. Kasm Community is five concurrent sessions. Cloudflare's $7 seat is not the isolation add-on. Everfox stays quote-only.
Which browser isolation product should you pick
Analysts who must visit hostile sites: Authentic8, and budget the region tier. Hardware or air-gap: Everfox ULTRA or the Isolation Appliance. A farm you will run: Kasm, starting with the free five-session Community tier. An edge you already pay for: Cloudflare isolation as an add-on on the $7 Zero Trust seat, which is Gateway and Access. If the need is risky categories for everyone inside SSE, use the platforms page. Two pages, two jobs.
Frequently asked questions
Do I need isolation, or a secure enterprise browser?
Isolation keeps web code off the device. An enterprise browser hardens the local browser. They can pair. They are not substitutes. If the threat is a drive-by on an unmanaged laptop, isolation wins. If the threat is copy-paste out of Salesforce, a hardened local browser may be the cheaper control.
Why isn't Menlo, Netskope, or Zscaler on this page?
They isolate as a policy on an SSE platform, or as a dedicated isolation product. That is the platforms comparison. This page is who operates the browser: a hosted workspace, a hardware appliance, a farm you run, or an add-on on an edge you already pay for. Cloudflare is on both pages: here as delivery, there as an SSE peer.
Can we start with Kasm Community and switch later?
Yes for a lab. No as a silent production plan. Community is five concurrent sessions and a non-commercial license. A production move is a Starter or Enterprise key, or a hop to Cloudflare, Authentic8, or Everfox.


