Remote browser isolation, in the access direction
RBI runs a web session in a remote, isolated browser and streams only safe output — applied to internal apps, users reach intranet and SaaS apps without the app or its data ever touching the endpoint.
Remote isolated browser
The internal/SaaS app loads in a browser inside your environment, not on the user's device.
Only pixels reach the device
Content, cookies and tokens execute and stay remote; the endpoint gets a safe stream.
No VPN, no VDI, no agent
Device never joins the network; no full desktop to license; copy/print/download controls on any web app.
Each session is a disposable browser pod on your OKE
A user opens a clientless portal, signs in with SSO/MFA, and Thinfinity spins up an isolated browser pod on your OKE cluster that loads the app — destroyed at logout.
Disposable browser pods on OKE
One ephemeral container per session, born clean, destroyed at logout — no state crosses between users.
Autoscaled on Kubernetes
Cluster Autoscaler / HPA grow and shrink the fleet with demand — pay only for active sessions.
Clientless, reverse gateway
Any browser, no agent; outbound-only connection — internal apps are never exposed, no inbound ports.
No inbound ports — nothing reaches the endpoint
Every isolated browser runs in your OKE cluster and connects outbound to the Thinfinity gateway, which delivers the session to the user — so no inbound ports are opened and only pixels reach the device.
Isolated browser pod
On your OKE cluster - loads the internal app/SaaS. Files, code, cookies & tokens stay here.
Thinfinity gateway
Pods reverse-connect outbound. No inbound ports, no exposed apps. SSO / MFA / RBAC enforced.
User's browser
Any device. Receives only a pixel stream - nothing else reaches the endpoint.
Zero Trust by design: users are brokered to a single isolated session, never to the network. Clipboard, download and print are opt-in by policy, off by default.
Access to intranet apps, internal web apps & SaaS
The clientless way to give managed and unmanaged users isolated access to internal web apps and SaaS — the app and its data stay in your cloud.
BYOD / unmanaged devices
Internal apps from personal laptops & phones — no agent, no MDM, data off the device.
Third-party & contractor access
Onboard outsiders in minutes to specific apps; revoke instantly — no VPN, no standing access.
SaaS governance & DLP
Block download/upload/copy/print + watermark to stop data leaving sanctioned SaaS.
Privileged web consoles
Admin UIs, Kubernetes & DB consoles — credentials and data never land on the endpoint.
Beyond day-to-day internal access
M&A & seasonal workforce
Grant thousands temporary isolated access fast, then revoke — no VDI/VPN.
Offshore / outsourced / BPO
CRM & internal apps for low-trust agents with anti-screen-scrape controls.
Regulated & sovereign access
App & data stay in your OKE cluster & OCI region — data-residency mandates met.
Replace VPN/VDI for web users
Right-size: isolated browser for the many, full VDI only where needed.
Outbound risky-web isolation
Bonus: the same engine isolates risky sites & email links — phishing, malvertising, zero-days.
Why run RBI on Oracle Kubernetes Engine?
Disposable pods, native autoscale
RBI's per-session, stateless model maps directly onto OKE pods + Cluster Autoscaler / HPA.
Penny-per-core Arm + low egress
Ampere Arm density for many lightweight pods; 10 TB/month free egress attacks RBI's biggest cost (Oracle list).
Sovereign & government regions
EU Sovereign Cloud, FedRAMP High / IL5, air-gapped — plus deploy-anywhere (Azure/AWS/GCP/on-prem K8s).
Data-leak controls + multi-protocol
Because the app renders in the OKE pod, you control exactly what crosses to the device — and the same platform brokers more than the browser.
Data stays in the pod
Only a safe stream reaches the endpoint; page, cookies and tokens never land locally.
Granular DLP
Toggle clipboard, upload/download and print per profile; add watermarking and session recording.
Multi-protocol, one platform
Isolated web apps + SaaS, plus RDP, VNC, SSH and full VDI — on the same OKE-based infrastructure.
Thinfinity RBI Main Features
Isolated browser sessions running in Kubernetes pods, delivered through the Web Application Gateway.
| Feature | What it does | Policy control |
|---|---|---|
| Isolated browser session | The browser runs in a container pod in your cluster, never on the endpoint; only the rendered session reaches the user | Per user or group |
| Ephemeral sessions | The pod is created at session start and destroyed at logoff, leaving no residual state between users | On by default |
| Clipboard redirection | Copy and paste between the endpoint and the isolated browser | Off / in / out / bidirectional |
| File transfer | Upload to and download from the isolated session | Off / download / upload / both |
| Audio redirection | Audio from the remote browser played on the user endpoint | Enable / disable per resource |
| Printing | Print from the isolated session to the user's local printer | Enable / disable per resource |
| Authentication at the gateway | SSO via SAML, OAuth/OIDC and directory sources, with MFA | Per application |
| RBAC | Which users and groups can open which published browser resources | Per user or group |
| Session recording | Recording of the isolated browser session for audit | Enable / disable per resource |
| Access hours | Restricts when a resource can be opened, by day and hour | Per user or group |
| Monitoring | Gateway, broker and pod-level metrics for capacity and performance | Platform-wide |
Remote browser isolation on OKE FAQs
Yes — a remote isolated browser in your environment loads the app; only a safe stream reaches the device. No VPN or agent.





































