Back to Explore

Browzer

Knowledge base software

Build any automation with a click - the n8n alternative

💡 Browzer is an AI-powered workflow automation tool that learns your repetitive tasks and processes to automate them with just one prompt. Record your actions once and automate them forever. Unlike other agentic tools or browsers, Browzer doesn't guess your workflow; it truly understands your processes to automate work exactly the way you would do it yourself.

"It turns complex Zero Trust security into a 'just open Chrome' experience, effectively cloaking your web apps from the public internet."

30-Second Verdict
What is it: BrowZer makes web apps invisible to the internet, accessible only to authorized users via a standard browser without client software.
Worth attention: Worth exploring for enterprise IT/Security leads tired of VPNs or needing secure access for external partners.
7/10

Hype

8/10

Utility

62

Votes

Product Profile
Full Analysis Report

BrowZer: The Open-Source Solution for Enterprise-Grade "Clientless" Zero Trust Access

2026-01-29 | NetFoundry Official Site | OpenZiti GitHub


30-Second Quick Judgment

What is it?: BrowZer makes your web apps "invisible" to the internet. Only authorized users can access them through a standard browser without installing any client software. Simply put, it simplifies complex Zero Trust networking into a "just open Chrome" experience.

Is it worth your attention?: If you are an enterprise IT/Security lead tired of VPN headaches, or if you need to provide secure access to internal apps for external partners, this is definitely worth exploring. It's open-source, Cisco just invested in it, and 8 of the top 10 US banks are already using the underlying OpenZiti technology.

Comparison: The main competitors are Cloudflare Access and Zscaler ZPA. BrowZer’s unique selling point is being completely clientless and fully open-source.


Three Key Questions

Is it for me?

Target Users:

  • Enterprise IT/Security Teams: Looking to replace VPNs or implement Zero Trust access.
  • B2B Companies: Needing to give external partners access to internal systems without forcing them to install software.
  • Remote Teams: Employees accessing company resources from various devices.

Does this sound like you?: You are the target user if:

  • A partner says, "Our company policy doesn't allow us to install your VPN client."
  • The IT department complains, "Managing VPN compatibility across so many different devices is a nightmare."
  • Security audits require that "all internal applications must not be exposed to the public internet."

Common Use Cases:

  • B2B Collaboration: External vendors accessing your internal systems.
  • BYOD Scenarios: Employees working from their own devices.
  • Compliance: Apps must be "invisible" and unscannable by external threats.

Is it useful?

DimensionBenefitCost
TimeNo client installation for users; IT doesn't have to maintain multi-platform VPNs.Initial deployment is complex; requires 1-2 days to learn OpenZiti concepts.
MoneyOpen-source version is completely free; commercial version is $5-15/endpoint/month.Self-hosting requires internal DevOps labor costs.
SecurityApps are "invisible," making it much more secure than traditional VPNs.Currently in Beta; requires careful evaluation for production environments.

ROI Judgment: If you are already using Cloudflare Access or Zscaler and are happy with them, there's no need to switch. However, if you require a fully open-source solution (for compliance) or a completely clientless setup (for B2B), BrowZer is the most mature option available.

Is it user-friendly?

The "Wow" Factor:

  • Truly zero-install: Users just open Chrome and log in. IT no longer has to deal with "I can't install the VPN" tickets.
  • Total Cloaking: Attackers can't scan your application because it simply doesn't exist on the public internet.

Real User Feedback:

"Ziti allowed us to innovate and drive new business with a competitive edge. Today, Ozone is the only CI/CD tool that automates private cluster deployments across any platform." - Moteesh Reddy, Ozone Technical Lead

Community Forum Feedback: Identity management configuration is a bit complex; every device needs an individual identity certificate. I hope they simplify this. - OpenZiti Discourse


For Developers

Tech Stack

LayerTechnologyDescription
FrontendJavaScript, Service Worker, WorkboxAutomatically injected into the web app at runtime.
BackendNodeJS (Bootstrapper)Handles bootstrapping and certificate management.
NetworkOpenZiti Overlay NetworkProprietary Zero Trust network protocol.
BuildYarn, Babel, Rollup, MochaStandard JS toolchain.

Core Implementation

BrowZer works through the collaboration of three components:

  1. BrowZer Gateway - An HTTP proxy that establishes a trusted tunnel between the browser and the app.
  2. Ziti BrowZer Runtime (ZBR) - A JS runtime transparently injected into the target web app.
  3. Service Worker (ZBSW) - Intercepts all network requests and routes them through OpenZiti.

Unlike traditional VPNs, BrowZer doesn't funnel all traffic through a single gateway; it establishes secure point-to-point tunnels.

Open Source Status

RepositoryDescriptionStars
ziti-browzer-coreCore ComponentsOpen Source
ziti-browzer-runtimeJS RuntimeOpen Source
ziti-browzer-bootstrapperBootstrapper ServerOpen Source

Build Difficulty: High. Requires deep understanding of Zero Trust networking, OIDC, and Service Workers. Estimated 6+ person-months to replicate. Since it's already open-source, using or forking it is much more efficient.

Business Model

Open-Core + Commercial SaaS:

  • OpenZiti is fully open-source (Apache 2.0).
  • CloudZiti provides managed services, charging per endpoint.

Giant Risk

Cisco made a strategic investment in NetFoundry in November 2025. This indicates:

  1. Industry giants validate this direction.
  2. Cisco likely won't build a direct competitor in the short term.
  3. A long-term acquisition is highly probable.

For Product Managers

Pain Point Analysis

Pain PointIntensityBrowZer Solution
VPNs require client installationHighBrowser-only access
B2B partners refuse to install softwareHighZero-install required
Apps exposed to public scansMedium"Dark Mode" cloaking
Complex VPN configs/IT ticketsHighSimplified operations

User Personas

  1. Enterprise IT/Security Lead: 30-50 years old, responsible for network security, currently frustrated by VPN issues.
  2. B2B Business Owner: Needs to provide system access to vendors/partners.
  3. DevOps Engineer: Needs secure access to internal tools (CI/CD, monitoring, etc.).

Feature Breakdown

FeatureTypeDescription
Clientless AccessCoreOnly requires a browser
Application Cloaking (Dark Mode)CoreApp is not reachable via public internet
OIDC Identity IntegrationCoreSupports Azure AD, Okta, etc.
Layer 6 SecurityCoreEnd-to-end encryption
Hotkey Setup (alt+F12)DelighterFor debugging purposes

Competitive Differentiation

vsBrowZerCloudflare AccessZscaler ZPA
ClientNone requiredOptional AgentAgent required
Open SourceFully Open SourceNoNo
Pricing$5-15/endpoint or Free Self-hosted$7+/userEnterprise Pricing
Network ScaleSelf-hosted275+ Cities73+ Data Centers
Best ForB2B, Open-source ComplianceMid-to-Large EnterpriseLarge Enterprise

Key Takeaways

  1. Extreme "Zero-Install": Simplifies the complex concept of Zero Trust into "just open your browser."
  2. Dual-track Strategy: Uses open-source for acquisition and commercial SaaS for monetization.
  3. Memorable Branding: The "Dark Mode" concept for application cloaking is very sticky.

For Tech Bloggers

Founder Story

NetFoundry is a "slow company"—founded in 2017 and operational by 2019, but it didn't take its first VC check until 2025. It spent six years self-funding, landing massive clients like Oracle, Microsoft, and IBM, and serving 8 of the top 10 US banks.

This is the polar opposite of the "blitzscaling" culture. The founders clearly prioritize technical depth and customer validation over rapid burn rates.

Interesting Angle: Cisco’s strategic investment in late 2025 signals a major consolidation trend in the Zero Trust market.

Controversies & Discussion Points

  1. Browser Lock-in: Only supports Chromium (Chrome/Edge/Brave). No support for Firefox or Safari is a major hurdle for some users.

  2. The Beta Tag: BrowZer is still in Beta. Using it in production requires confidence, though the underlying OpenZiti is already enterprise-proven.

  3. Configuration Complexity: Setting up OIDC, certificates, and Chrome Origin Trials isn't exactly "plug and play." The barrier to entry is high.

  4. Open vs. Commercial Balance: How they handle feature parity between the free and paid versions will be interesting to watch.

Hype Data

  • Clients: 8 of the top 10 US banks, Oracle, Microsoft, IBM.
  • Funding: $15M+ Series A, strategic investment from Cisco.
  • GitHub: Very active OpenZiti project.
  • Community: Active Discourse forum.

Content Angle Suggestions

  • "Is the VPN Dead? This Company Makes Your Apps Completely Invisible."
  • "The Open-Source Zero Trust Solution Used by 8 Top Banks."
  • "Why Cisco Invested in This 'Slow Company'."

For Early Adopters

Pricing Analysis

TierPriceFeaturesIs it enough?
Open SourceFreeFull features, self-hostedEnough for tech-savvy teams
Business Basic$5/endpoint/moManaged serviceGood for small teams
Business Advanced$15/endpoint/moAdvanced featuresFor mid-sized enterprises
EnterpriseCustom99.995% SLA, 24x7 SupportFor large corporations

Free Trial: 30-day Enterprise trial, no credit card required.

Getting Started Guide

The Fast Way (15-minute experience):

  1. Visit the ZEDS Sandbox - A multi-tenant dev environment.
  2. Follow the tutorial to create your first service.
  3. Experience Zero Trust access firsthand.

Full Deployment (1-2 days):

  1. Deploy the OpenZiti controller and router.
  2. Configure your OIDC identity provider.
  3. Obtain a wildcard certificate.
  4. Register for Chrome Origin Trials.
  5. Deploy the BrowZer Bootstrapper.

Learning Resources:

Pitfalls & Gripes

  1. Browser Limitations: Only Chrome/Edge/Brave. If your users are on Firefox or Safari, this is a dealbreaker.
  2. Step-Heavy Setup: OIDC + Certificates + Origin Trials. If one step fails, debugging is difficult.
  3. Learning Curve: OpenZiti has its own vocabulary (Controller, Router, Service, Identity) that takes time to master.
  4. Beta Risk: It is explicitly labeled Beta; use with caution in production.

Security & Privacy

  • Data Storage: Data is end-to-end encrypted via the OpenZiti network.
  • Cloaking: Apps are not public-facing; attackers cannot scan or discover them.
  • Authentication: Integrates with major OIDC providers (Azure AD, Okta, Auth0, etc.).
  • Auditability: Code is fully open-source and available for audit.

Alternatives

AlternativeProsCons
Cloudflare AccessFast global network, easy to useNot open-source, requires client
Zscaler ZPAEnterprise full-stackExpensive, requires client
TailscaleExtremely easy to useNot a pure Zero Trust architecture
Self-built VPNTotal controlHigh maintenance overhead

For Investors

Market Analysis

MetricDataSource
2026 ZTNA Market$4.84BStraits Research
2033 Forecast$14.74BSNS Insider
CAGR25-28%Multiple sources
North America Share38.62%GlobalNewswire
APAC CAGR28.5% (Fastest)GlobalNewswire

Growth Drivers:

  • Normalization of remote work and poor VPN experiences.
  • Enterprises phasing out legacy VPNs.
  • Growth of cloud apps rendering perimeter security obsolete.
  • Increasingly strict compliance requirements.

Competitive Landscape

TierPlayersCharacteristics
LeadersCloudflare, Zscaler, Palo AltoFull-stack security, massive networks
Mid-MarketNetskope, Fortinet, CiscoEnterprise security ecosystems
Emerging/Open SourceNetFoundry/OpenZitiDifferentiation through open-source + clientless

Timing Analysis

Why Now?:

  • VPNs are being replaced at scale.
  • ZTNA has moved from a concept to a standard procurement item.
  • Remote work has created a desperate need for "clientless" solutions.

Tech Maturity:

  • BrowZer itself is in Beta.
  • However, the underlying OpenZiti has been validated by Oracle, Microsoft, and IBM.

Moat:

  • Strong open-source community and ecosystem.
  • Endorsement from 8/10 top banks.
  • Strategic backing from Cisco.

Funding History

RoundAmountDateInvestors
Strategic$50M+HistoricalStrategic Investors (currently 10% stake)
Series A$12M2025.04Led by SYN Ventures
Series A (Add-on)$3M+2025.11Cisco Investments

Total: $15M+ Series A, with historical strategic funding over $50M.

Team Background

  • Size: 72 people.
  • HQ: Charlotte, NC.
  • Founded: 2017.
  • Note: Bootstrapped for 6 years before taking VC money in 2025.

Investment Recommendation

Bull Case:

  • Validated by top-tier clients (8/10 US banks).
  • Strategic backing from Cisco.
  • Open-source model lowers the cost of customer acquisition.
  • Market CAGR of 25%+.

Bear Case:

  • BrowZer is still in Beta.
  • Intense competition from giants like Cloudflare and Zscaler.
  • Browser limitations may hinder mass adoption.

Conclusion

The Bottom Line: BrowZer is the most mature "clientless" open-source Zero Trust access solution available. It is perfect for B2B scenarios and companies with open-source compliance needs. While the Beta status carries risk, the core technology is already trusted by the world's largest financial institutions.

User TypeRecommendation
DevelopersWorth studying; the open-source code is a masterclass in modern networking.
Product ManagersWatch the "clientless" and "cloaking" selling points for differentiation.
BloggersGreat story angles: the "slow company," Cisco's investment, and the bank clients.
Early AdoptersTry the ZEDS sandbox first; wait for the stable release for production.
InvestorsHigh potential, but monitor Beta risks and the competitive landscape.

Resource Links

ResourceLink
Official Websitehttps://netfoundry.io/
GitHubhttps://github.com/openziti
Documentationhttps://openziti.io/docs/learn/quickstarts/
Community Forumhttps://openziti.discourse.group/
Sandboxhttps://zeds.openziti.org
Pricinghttps://netfoundry.io/pricing/
Free Trialhttps://nfconsole.io/signup

Sources


2026-01-29 | Trend-Tracker v7.3

One-line Verdict

BrowZer is the most mature "clientless" open-source Zero Trust access solution available.

FAQ

Frequently Asked Questions about Browzer

BrowZer makes web apps invisible to the internet, accessible only to authorized users via a standard browser without client software.

The main features of Browzer include: Clientless Access, Application Cloaking (Dark Mode).

$5-15/endpoint/month or Free Self-hosted

Enterprise IT/Security Teams, B2B Companies, Remote Teams

Alternatives to Browzer include: Cloudflare Access, Zscaler ZPA.

Data source: ProductHuntFeb 2, 2026
Last updated: