Product/Operate/Mira
Operate · Governed enterprise browser
MiraMira

The browser your SaaS work
should have been running in.

Mira is a desktop browser built for organizations, not for the open web. Every site opens as a real browser tab, only after your policy has allowed it. Every action, whether a person or an AI assistant took it, is written to a tamper-evident audit record.

  • Fails closed by design
  • Real top-level tabs, never embedded frames
  • Signed in through your identity provider
  • Metadata-only audit chain
Mira Policy · enforced
Claim #A22-4471
Allowed · signed allowlist
Attachment · Supporting documents shared via public-share.example/f/9k2…
Assistant · current tab only

Extract the action items from the open claim. Redaction preview: policy number •••••• masked before send.

Navigation denied

public-share.example

Not on the signed allowlist for role claims-associate. Denied before load by policy revision 14.

Request approval
Why was this denied?
Event chained · metadata only
Why it matters

Work moved into the browser. Control never followed it.

CRM, ticketing, banking portals, admin consoles and AI tools all run in a general-purpose browser that was designed for the open web. The gaps show up as cost, blind spots and leaked data.

Today
Contractor and personal devices reach company apps through VPNs and virtual desktops.

Access is either all-or-nothing network access, or a remote desktop that is slow, expensive to run, and still leaves data on the screen of an unmanaged machine.

With Mira
The browser itself is the controlled surface.

People sign in with your identity provider and reach only the apps on a signed allowlist. Downloads are contained, the window is excluded from screen capture, and an administrator can end a session from the center.

Today
Nobody can prove what happened in the browser, or that the record is intact.

Browser history is per-user and editable. Proxy logs see hostnames, not decisions. An investigation reconstructs events from fragments.

With Mira
Every decision lands in a tamper-evident chain.

Allowed and denied navigations, downloads, AI requests and administrative changes are recorded as linked, metadata-only events. Filter them, export them, or forward them to your SIEM.

Today
Staff paste customer data into whichever AI tool is open in the next tab.

Banning AI outright pushes it to personal devices. Allowing it without controls means prompts carry names, account numbers and contract terms out of the company.

With Mira
An assistant with guardrails, and a gateway you control.

The built-in assistant shows a redaction preview before anything leaves the device, routes through models you approved, and never executes a proposed action without a person’s approval. Public AI sites are governed on the same navigation path as everything else.

Core capabilities

One governed surface for people and AI.

Each capability below is present in the current Mira build and covered by its automated security tests. Planned work is listed separately in the enterprise section.

Real browser tabs

Sites render in a Chromium engine as genuine top-level tabs, so enterprise apps that refuse to be embedded work normally. Each signed-in identity gets its own engine profile; cookie stores are never shared.

Allowlist navigation that fails closed

Addresses, link clicks, form submissions, redirects and pop-ups all cross the same gate: a signed central configuration with anti-rollback. Person-specific approvals from your control plane extend it. A denied page shows why.

Identity-bound sessions

Sign-in through your identity provider with OpenID Connect and PKCE. Directory groups map to roles, MFA state is carried into the session, sensitive actions require a fresh step-up, and idle sessions lock.

Assistant with guardrails

Choose what the assistant may see: nothing, the current tab or selected tabs. A redaction preview runs before anything is sent, requests are screened, and a proposed action is planned, approved and only then executed. A panic stop halts every agent.

Tamper-evident audit

Events are chained with keyed hashes so any edit is detectable. Filter by actor, action, decision and severity, export as NDJSON, or forward through a sequence-numbered SIEM cursor. Records hold metadata, never page content or secrets.

Central control and rollback

Policy is a signed, versioned bundle: drift is detected, history is kept, and a known-good revision can be restored with an audited rollback. A signed kill directive ends a user’s or role’s sessions immediately. Trusted time comes from your NTP servers.

Data containment

Downloads only reach destinations policy allows. The governed window is excluded from screen capture, a watermark and recording indicator follow policy, and device posture such as disk encryption is checked at sign-in without managing the device.

Vault and privileged access

Credentials rest in an AES-256-GCM vault sealed with a key wrapped by the operating system keychain. Operators open recorded SSH sessions from the browser, with pinned host keys and credentials injected from the vault, no VPN client involved.

Built for every team

English, Spanish and Arabic with full right-to-left layout. Every screen is checked against WCAG 2.2 AA in light, dark and sepia themes, and the whole interface works from the keyboard.

How it works

One afternoon in Mira, from sign-in to audit record.

The setting: Priya processes insurance claims for an outsourcing firm and works from her own laptop. Her employer’s client, the insurer, needs her to reach its claims portal and a document system, and nothing else, with proof of what happened.

  1. 01
    Sign in

    Priya signs in with the insurer’s identity provider. Her directory group maps to the claims associate role; MFA state and device posture carry into the session.

  2. 02
    Open the portal

    She types the portal address. Mira checks it against the signed allowlist and her approved exceptions, then opens it as a real top-level tab.

  3. 03
    Follow a stray link

    A link in a claim points to a public file-sharing site. The navigation is denied before it loads, and the panel explains which policy decided.

  4. 04
    Ask the assistant

    The redaction preview masks the policy number, the request routes through the approved model, and the reply is screened before it appears.

  5. 05
    Show the proof

    Every decision from the afternoon sits in the audit chain. The administrator filters by Priya’s pseudonymous identity and exports the range for the auditor.

Audit explorer Chain intact
TimeActionTargetDecision
14:02navigationclaims.insurer.exampleallowed
14:07navigationpublic-share.exampledenied
14:11ai.requestapproved model · redactedallowed
14:20admin.policyrollback to rev 13denied
hmac-chain · seq 2 481 → 2 484
Export NDJSONForward to SIEM
Practical use cases

Where governed browsing pays for itself.

Each scenario uses capabilities in the current build. The teams differ; the pattern is the same: reach the right apps, keep data inside, and keep the record.

Outsourcing and BPO
Client work on staff-owned laptops, without the VDI bill.

A back-office provider onboards a claims team for a new client in a week. Mira is the only thing installed on the associates’ own machines. At contract end, one signed kill directive ends every session for the role.

allowlistgoverned downloadsscreen-capture exclusionkill directive
Finance and accounting
A month-end close the auditor can replay.

Controllers work across the bank portal, the ERP and the expense tool from one workspace. Vault holds shared portal credentials; payment approvals require a fresh MFA step-up; the audit range exports as NDJSON for the external auditor.

vaultstep-up MFANDJSON export
Recruiting agencies
Summaries of candidate pages that never leak the candidate.

Assistant context is limited to the current tab, chosen per request. Redaction preview masks email addresses and identifiers before send. Site permissions keep the assistant read-only on the applicant system.

tab-scoped contextredaction previewread-only sites
IT and infrastructure
Recorded server access from the browser, no VPN client.

Mira brokers the SSH session with a pinned host key. The credential is injected from the vault; the engineer never sees it. The session is recorded and the console is part of the audit record.

brokered SSHpinned host keysession recording
Healthcare administration
Scheduling and billing portals with conditional access.

Conditional access asks for step-up MFA when a signal is missing. The assistant has no access to the scheduling site unless an administrator grants it. Screen-capture exclusion protects what is on screen at the desk.

conditional accessassistant permissionscapture exclusion
Sales teams adopting AI
Say yes to AI, on an approved model, with a meter.

The gateway allows only published models; keys stay in the OS keychain. Provider-reported token usage is metered per tenant. Unsanctioned public AI sites are coached or blocked on the navigation path, with a justification captured.

model allowlisttoken meteringpublic AI governance
For evaluators

What ships today, and what is in development.

Mira reports its own limits inside the product rather than hiding them. This table follows the same rule.

Identity
  • OpenID Connect sign-in with PKCE
  • Directory group to role mapping
  • MFA state and step-up
  • Session revocation list, idle lock
  • Pseudonymous audit identity
  • SAML transport
  • SCIM provisioning and deprovisioning
  • Just-in-time access grants
Access policy
  • Signed allowlist with anti-rollback
  • Per-person approvals from the control plane
  • Conditional access (audit-only by default, enforced when your signed configuration turns it on)
  • Explainable denials
  • Geolocation and impossible-travel signals
  • Fleet dashboards
AI governance
  • Providers in the catalog: OpenAI, Azure OpenAI, Anthropic, Google Gemini, local Ollama; authentication cores for AWS Bedrock and Google Vertex
  • Per-tenant model allowlist, redaction preview, prompt screening
  • Plan-approve-execute, panic stop, token metering
  • Public AI site governance
  • DLP policy editor
  • Cross-tab workspace memory
  • Scheduled automations
Audit and observability
  • Keyed-hash audit chain
  • Explorer with filters, NDJSON export
  • SIEM forwarding cursor
  • Governance dashboard with ranged KPIs
  • One-click compliance presets
  • Session replay
Endpoint and data
  • Download containment, screen-capture exclusion
  • Watermark and recording indicator
  • Device posture (managed state, disk encryption)
  • AES-256-GCM vault
  • Brokered, recorded SSH
  • Brokered RDP and VNC
  • Remote wipe
  • Extension governance
Platform
  • Rust and Tauri desktop core
  • Chromium engine behind a single adapter, with the native engine runtime shipped on macOS
  • Signed updater with staged, verified artifacts
  • English, Spanish, Arabic; WCAG 2.2 AA checks on every screen
  • Native engine runtimes on Windows and Linux
  • Mobile adapter
Deployment
  • Policy arrives as signed, versioned configuration bundles from your control plane; an unverifiable bundle is rejected, not applied.
  • Settings you lock centrally show as managed by the administrator; users cannot override them.
  • Application updates are verified against a pinned host and staged before install, with a forced-upgrade floor for retired versions.
  • Time is taken from NTP servers you configure, so tokens and audit timestamps cannot be moved by a local clock.
Security engineering
  • Memory-safe Rust core with unsafe code forbidden by default; the renderer reaches the core only through typed, capability-scoped commands.
  • Cryptography from FIPS-validated libraries; secrets live in the operating system keychain and are never readable back.
  • Role and attribute checks run in the core on every administrative command, never only in the interface.
  • A published threat model, secure-coding standard and evidence pack, with test gates that fail the build when a trust boundary is crossed.
Integrations
  • Your OpenID Connect identity provider, with directory groups as the source of roles.
  • Your model providers, or any OpenAI-compatible endpoint, behind the gateway.
  • Your SIEM, through NDJSON export today and the forwarding cursor.
  • Your NTP servers for trusted time, and your control plane for policy and per-person approvals.

A note on certifications. Mira does not claim third-party certifications at this stage. Its engineering standard is written against FIPS 140-3, NIST SSDF and OWASP ASVS, and the threat model, evidence pack and test results are available for your security team to review during evaluation.

Next step

See Mira on your own applications.

A pilot takes your allowlist, your identity provider and one team. Erup sets it up with you and walks through the audit export at the end.sales@erup.ai · mira.erup.ai

  1. 01Allowlist the apps one team actually uses.
  2. 02Connect your identity provider and map two roles.
  3. 03Review the audit chain and the assistant’s redaction preview with your security team.
Talk to Erup

Bring AI into your enterprise, with confidence.

Let’s talk about a pilot, a platform evaluation, or where AI fits in your operating stack. A real conversation with the team that builds the products.