

The browser your SaaS work
should have been running in.
Mira is a desktop browser built for organizations, not for the open web. Every site opens as a real browser tab, only after your policy has allowed it. Every action, whether a person or an AI assistant took it, is written to a tamper-evident audit record.
- Fails closed by design
- Real top-level tabs, never embedded frames
- Signed in through your identity provider
- Metadata-only audit chain
Extract the action items from the open claim. Redaction preview: policy number •••••• masked before send.
public-share.example
Not on the signed allowlist for role claims-associate. Denied before load by policy revision 14.
Work moved into the browser. Control never followed it.
CRM, ticketing, banking portals, admin consoles and AI tools all run in a general-purpose browser that was designed for the open web. The gaps show up as cost, blind spots and leaked data.
Access is either all-or-nothing network access, or a remote desktop that is slow, expensive to run, and still leaves data on the screen of an unmanaged machine.
People sign in with your identity provider and reach only the apps on a signed allowlist. Downloads are contained, the window is excluded from screen capture, and an administrator can end a session from the center.
Browser history is per-user and editable. Proxy logs see hostnames, not decisions. An investigation reconstructs events from fragments.
Allowed and denied navigations, downloads, AI requests and administrative changes are recorded as linked, metadata-only events. Filter them, export them, or forward them to your SIEM.
Banning AI outright pushes it to personal devices. Allowing it without controls means prompts carry names, account numbers and contract terms out of the company.
The built-in assistant shows a redaction preview before anything leaves the device, routes through models you approved, and never executes a proposed action without a person’s approval. Public AI sites are governed on the same navigation path as everything else.
One governed surface for people and AI.
Each capability below is present in the current Mira build and covered by its automated security tests. Planned work is listed separately in the enterprise section.
Sites render in a Chromium engine as genuine top-level tabs, so enterprise apps that refuse to be embedded work normally. Each signed-in identity gets its own engine profile; cookie stores are never shared.
Addresses, link clicks, form submissions, redirects and pop-ups all cross the same gate: a signed central configuration with anti-rollback. Person-specific approvals from your control plane extend it. A denied page shows why.
Sign-in through your identity provider with OpenID Connect and PKCE. Directory groups map to roles, MFA state is carried into the session, sensitive actions require a fresh step-up, and idle sessions lock.
Choose what the assistant may see: nothing, the current tab or selected tabs. A redaction preview runs before anything is sent, requests are screened, and a proposed action is planned, approved and only then executed. A panic stop halts every agent.
Events are chained with keyed hashes so any edit is detectable. Filter by actor, action, decision and severity, export as NDJSON, or forward through a sequence-numbered SIEM cursor. Records hold metadata, never page content or secrets.
Policy is a signed, versioned bundle: drift is detected, history is kept, and a known-good revision can be restored with an audited rollback. A signed kill directive ends a user’s or role’s sessions immediately. Trusted time comes from your NTP servers.
Downloads only reach destinations policy allows. The governed window is excluded from screen capture, a watermark and recording indicator follow policy, and device posture such as disk encryption is checked at sign-in without managing the device.
Credentials rest in an AES-256-GCM vault sealed with a key wrapped by the operating system keychain. Operators open recorded SSH sessions from the browser, with pinned host keys and credentials injected from the vault, no VPN client involved.
English, Spanish and Arabic with full right-to-left layout. Every screen is checked against WCAG 2.2 AA in light, dark and sepia themes, and the whole interface works from the keyboard.
One afternoon in Mira, from sign-in to audit record.
The setting: Priya processes insurance claims for an outsourcing firm and works from her own laptop. Her employer’s client, the insurer, needs her to reach its claims portal and a document system, and nothing else, with proof of what happened.
- 01Sign in
Priya signs in with the insurer’s identity provider. Her directory group maps to the claims associate role; MFA state and device posture carry into the session.
- 02Open the portal
She types the portal address. Mira checks it against the signed allowlist and her approved exceptions, then opens it as a real top-level tab.
- 03Follow a stray link
A link in a claim points to a public file-sharing site. The navigation is denied before it loads, and the panel explains which policy decided.
- 04Ask the assistant
The redaction preview masks the policy number, the request routes through the approved model, and the reply is screened before it appears.
- 05Show the proof
Every decision from the afternoon sits in the audit chain. The administrator filters by Priya’s pseudonymous identity and exports the range for the auditor.
Where governed browsing pays for itself.
Each scenario uses capabilities in the current build. The teams differ; the pattern is the same: reach the right apps, keep data inside, and keep the record.
A back-office provider onboards a claims team for a new client in a week. Mira is the only thing installed on the associates’ own machines. At contract end, one signed kill directive ends every session for the role.
Controllers work across the bank portal, the ERP and the expense tool from one workspace. Vault holds shared portal credentials; payment approvals require a fresh MFA step-up; the audit range exports as NDJSON for the external auditor.
Assistant context is limited to the current tab, chosen per request. Redaction preview masks email addresses and identifiers before send. Site permissions keep the assistant read-only on the applicant system.
Mira brokers the SSH session with a pinned host key. The credential is injected from the vault; the engineer never sees it. The session is recorded and the console is part of the audit record.
Conditional access asks for step-up MFA when a signal is missing. The assistant has no access to the scheduling site unless an administrator grants it. Screen-capture exclusion protects what is on screen at the desk.
The gateway allows only published models; keys stay in the OS keychain. Provider-reported token usage is metered per tenant. Unsanctioned public AI sites are coached or blocked on the navigation path, with a justification captured.
What ships today, and what is in development.
Mira reports its own limits inside the product rather than hiding them. This table follows the same rule.
- OpenID Connect sign-in with PKCE
- Directory group to role mapping
- MFA state and step-up
- Session revocation list, idle lock
- Pseudonymous audit identity
- SAML transport
- SCIM provisioning and deprovisioning
- Just-in-time access grants
- Signed allowlist with anti-rollback
- Per-person approvals from the control plane
- Conditional access (audit-only by default, enforced when your signed configuration turns it on)
- Explainable denials
- Geolocation and impossible-travel signals
- Fleet dashboards
- Providers in the catalog: OpenAI, Azure OpenAI, Anthropic, Google Gemini, local Ollama; authentication cores for AWS Bedrock and Google Vertex
- Per-tenant model allowlist, redaction preview, prompt screening
- Plan-approve-execute, panic stop, token metering
- Public AI site governance
- DLP policy editor
- Cross-tab workspace memory
- Scheduled automations
- Keyed-hash audit chain
- Explorer with filters, NDJSON export
- SIEM forwarding cursor
- Governance dashboard with ranged KPIs
- One-click compliance presets
- Session replay
- Download containment, screen-capture exclusion
- Watermark and recording indicator
- Device posture (managed state, disk encryption)
- AES-256-GCM vault
- Brokered, recorded SSH
- Brokered RDP and VNC
- Remote wipe
- Extension governance
- Rust and Tauri desktop core
- Chromium engine behind a single adapter, with the native engine runtime shipped on macOS
- Signed updater with staged, verified artifacts
- English, Spanish, Arabic; WCAG 2.2 AA checks on every screen
- Native engine runtimes on Windows and Linux
- Mobile adapter
- Policy arrives as signed, versioned configuration bundles from your control plane; an unverifiable bundle is rejected, not applied.
- Settings you lock centrally show as managed by the administrator; users cannot override them.
- Application updates are verified against a pinned host and staged before install, with a forced-upgrade floor for retired versions.
- Time is taken from NTP servers you configure, so tokens and audit timestamps cannot be moved by a local clock.
- Memory-safe Rust core with unsafe code forbidden by default; the renderer reaches the core only through typed, capability-scoped commands.
- Cryptography from FIPS-validated libraries; secrets live in the operating system keychain and are never readable back.
- Role and attribute checks run in the core on every administrative command, never only in the interface.
- A published threat model, secure-coding standard and evidence pack, with test gates that fail the build when a trust boundary is crossed.
- Your OpenID Connect identity provider, with directory groups as the source of roles.
- Your model providers, or any OpenAI-compatible endpoint, behind the gateway.
- Your SIEM, through NDJSON export today and the forwarding cursor.
- Your NTP servers for trusted time, and your control plane for policy and per-person approvals.
A note on certifications. Mira does not claim third-party certifications at this stage. Its engineering standard is written against FIPS 140-3, NIST SSDF and OWASP ASVS, and the threat model, evidence pack and test results are available for your security team to review during evaluation.
See Mira on your own applications.
A pilot takes your allowlist, your identity provider and one team. Erup sets it up with you and walks through the audit export at the end.sales@erup.ai · mira.erup.ai
- 01Allowlist the apps one team actually uses.
- 02Connect your identity provider and map two roles.
- 03Review the audit chain and the assistant’s redaction preview with your security team.