Streamed cloud browser & desktops

Browse from a machine that isn't yours.

Tunnel Browser runs a real Firefox or Chrome — and full Ubuntu or Windows desktops — on a private cloud machine, and streams the picture to your device. Your session lives away from your laptop, on hardware you spin up for the task and throw away when you're done.

1  machine per session Destroyed on exit Encrypted & attested tiers EU-sovereign options

Why a browser in the cloud

The web runs over there, not on your device

Whatever a page loads — scripts, trackers, downloads, the occasional nasty — happens on a throwaway cloud machine. Your device only ever receives video and sends clicks.

💨

One machine per session

Every session gets its own dedicated cloud VM — not a shared container. Disposable sessions are wiped and the machine is deleted the moment you leave.

🛡️

Isolation by default

Malware, drive-by scripts and tracking run on the remote machine, never your endpoint. You stream the desktop over WebRTC — the page never touches your device.

🔒

Encryption you can verify

Persistent profiles are encrypted at rest. Higher tiers use a key only you hold, or a hardware enclave attested in your own browser before anything starts.

🌍

Pick your location & IP

Choose the server region, and optionally lock a stable egress IP so sites see the same address each time. For consistency and separation — not anonymity.

🖥️

Not just a browser

Spin up a full Ubuntu or Windows desktop in the same way — a cloud workstation you reach from any device, with sound, clipboard and file transfer.

✉️

Sign in, no password

Passwordless email one-time-code sign-in. No password to leak, no extension to install — it runs in the browser you already have.

Browser tiers

From throwaway to hardware-sealed

Every tier is a real browser on its own machine. What changes is how much is kept, and who can read it.

💨 Casual

Disposable

A clean browser for a quick look. The machine is destroyed on exit and nothing is stored server-side.

  • Nothing saved
  • Firefox or Chrome
  • Fastest to start
💼 Professional

Persistent

Your everyday browser — logins, bookmarks, history and extensions kept for next time, on an encrypted volume.

  • Encrypted profile
  • Optional locked IP
  • Resume where you left off
🔐 Secure

Your key only

Persistent, but the encryption key is derived from your passphrase and never held by us at rest.

  • User-held key
  • Unreadable when powered off
  • Recovery phrase
🧬 Confidential

Hardware enclave

Runs inside a memory-encrypted CPU enclave (AMD SEV-SNP or Intel TDX), attested in your browser before the key is released.

  • Encrypted in use
  • In-browser attestation
  • Operator can't read it

Workstations

A full desktop, in your browser tab

When a browser isn't enough — a complete Ubuntu or Windows computer, streamed to any device you happen to be on.

  • Ubuntu 24.04 desktop (fast boot)
  • Windows Server 2022 desktop
  • Windows with sound, mic & gamepad
  • Clipboard sync both ways
  • Web file browser (upload / download)
  • Adjustable quality & frame rate
  • Disposable or persistent profiles
  • Reach it from any device

Security posture

Honest about what we can and can't see

We'd rather tell you the boundary than pretend it isn't there.

🧱

Per-session isolation

Each session is a dedicated VM with a default-deny network boundary — no reaching private ranges, no shared kernel with another user's session.

📼

No content logging

We record session lifecycle and placement for operating the fleet — never the URLs you visit, page content, keystrokes or files.

🔓

Not zero-knowledge — except Confidential

The operator terminates TLS at the edge, so for most tiers we could technically see traffic in transit. The Confidential tier removes even that: the session is sealed to an attested enclave.

🇪🇺

Location & sovereignty

Choose EU regions and EU-sovereign providers. Persistent data stays in the region you pick; nothing silently moves clouds.

🗝️

Crypto-shred on delete

Delete your data and the encryption key is destroyed with it — the volume becomes unrecoverable, not just "marked deleted".

🧭

IP-isolation, not a VPN

Your egress IP is the cloud machine's, optionally locked to stay stable. It separates your browsing from your device — it is not an anonymity or evasion tool.

FAQ

Straight answers

Is this a VPN or a proxy?

No. A VPN reroutes your device's traffic; Tunnel Browser runs a whole browser somewhere else and streams you the picture. The page executes on the remote machine, so your device never loads it. Your egress IP is the cloud machine's, which is about isolation and consistency — not anonymity.

Can you see what I browse?

We log session lifecycle and placement to run the service, never your URLs, content, keystrokes or files. Because the operator terminates TLS at the edge, most tiers are "not zero-knowledge" — we could technically see traffic in transit. If that matters, the Confidential tier seals the session to a hardware enclave that even we can't read.

What happens to my data when I leave?

Casual sessions store nothing — the machine is destroyed on exit. Persistent tiers keep an encrypted profile you can resume, and "Delete my data" crypto-shreds it (the key is destroyed, so the volume is unrecoverable).

Why is there a limit on concurrent machines?

Each session runs on its own real cloud VM, and we keep a safety cap per cloud account to stay within provider quotas and prevent runaway cost. Capacity scales by raising the cap or adding provider accounts — it's a configuration change, not a rebuild.

Do I need to install anything?

No. It runs in the browser you already have. Sign in with an email one-time code and start a machine.

Which regions can I use?

Multiple regions across several clouds, including EU-sovereign options. You pick the location per session; persistent data stays where you put it.

Start a machine in under a minute

Sign in with your email, pick a tier and a location, and you're browsing from the cloud.

Get started →