Access for contractors, partners and BYOD users

When someone needs CRM, an admin panel or a partner portal, a device VPN gives them more network than the task requires.

Secure access to internal web apps without a device-wide VPN.

BusinessProxy opens only the approved app or work site in the browser. The network stays closed, sessions are time-limited, access is revocable, and administrators see active work paths. In Zero Trust terms, it is web-app access without placing the whole device on your network.

The portal opens selected internal apps. The browser extension adds browser-scoped policy, session binding and selected content-protection controls for desktop work browsing.

Access flow: outside user → app portal → BusinessProxy → connector → internal app
Selected internal web appsBrowser extension for desktop controlsNo device-wide VPNOutbound connectorTime-limited sessionsAdmin revoke and audit

Two access paths

Two ways to give web access without handing out a network route

Use the portal for selected internal web apps. Use the extension when you need a managed browser route for work web services.

Why BusinessProxy

Start with the application, not the network.

When an outside user needs CRM, an admin panel or a partner portal, the decision should be about that app session: who, which app, for how long, and how access ends.

See how we compare →
  • Application-scoped access. Publish selected private web apps, grant access by role or group policy, and keep the internal address behind the connector.
  • Portal first, extension when needed. Selected app launch starts from the BusinessProxy portal. On desktop, the extension supports managed browser routing, policy and session controls.
  • Control built into the session. Short session lifetime, admin revoke, audit history, connector readiness and browser-route policy are managed from the account.

Scoped by design

What changes compared with a device tunnel?

  • Separate session credentials. Account login, browser sessions and App Gateway sessions use separate access data. The account password is not reused as a browser-session or app credential.
  • Time-boxed and revocable. Browser proxy secrets rotate in minutes; App Gateway sessions have an app policy lifetime. Admins can end active access from the account.
  • Policy at the browser and app layer. Set browser routing policy, app session lifetime, connector readiness checks and access revocation without turning the user device into a network endpoint.

How it works

How access is opened and closed

A user signs in, opens an approved work path, and every active session remains visible to administrators.

App Gateway

Portal launch for selected apps

With App Gateway, the user opens the portal, chooses an app available to them and receives a short-lived app session. The internal address stays behind the connector.

Managed browser

Extension route for work browsing

For managed browsing, the browser extension applies routing policy, receives temporary access data and keeps the session tied to the signed-in user.

Security

See the full security model

What the gateway sees — and what it doesn't.

Use cases

For contractors, admin areas, BYOD, QA and support teams

Business controls

Operational control from one dashboard

Invite users, assign access, revoke sessions and review activity without running a separate network-access project.

  • Invite users and manage seats
  • Revoke any session on the spot
  • Set traffic and speed limits per plan
  • Apply category filtering policies
  • Choose allowed egress regions
  • Session and admin events are recorded
Admin dashboard preview

Evidence

Product facts your reviewer can check

~2 minTemporary browser-session credential lifetime
From the portalSelected internal apps open without requiring the extension
Any timeAdmins can end active sessions

The managed browser path governs access by domain, metadata and configured policy without decrypting HTTPS page content. App Gateway relays selected app traffic at the web layer through the connector. Security model →

Example scenario

Closing access after team changes

An ecommerce team can require an active authorized session before anyone reaches order data or admin areas. When managers leave the company, old account knowledge alone is not enough: administrators can end active sessions and remove future access from the workspace.

App GatewayGuided onboarding

Open selected internal web apps through a portal session

Pricing

Plans from one user to a partner platform

Start with a controlled work-access demo. Teams is per-seat with browser policy and audit. App Gateway publishes internal apps through an outbound connector group; Partner Access adds the multi-client layer.

Free Work Demo

A controlled work-access demo: approved domains or a demo app, never general internet.

$0

  • Work-scope routing (approved domains / demo app)
  • 1 browser profile
  • 1 active session
  • Domain/category policy baseline
  • Approved routing region
  • 1 GB / month fair-use
Request access

Solo Professional

For freelancers and external professionals working across multiple clients; personal internet stays direct.

$9 per month

  • Client workspaces in one professional profile
  • 2 devices, 2 sessions at a time
  • Session history
  • Personal internet stays direct (not proxied)
  • Standard support
  • Fair-use data allowance
Choose Solo Professional
Recommended

Teams

Per-seat managed access for teams that need policy, seats and an audit trail without an enterprise rollout.

$12 per user per month

  • Per-seat pricing — team seats and email invites
  • Device and session limits apply per seat
  • Workspace-level policy
  • Work-scope or full-browser routing
  • Domain allow/block rules
  • Domain/category policy
  • Admin session revoke
  • Session, device, and admin-event history
  • Standard documented retention defaults
  • Priority support
  • Per-plan data allowance (fair-use)
Choose Teams

See plans

FAQ

Is BusinessProxy a VPN?

No. BusinessProxy does not install a device VPN and does not route the whole machine. It manages a browser path through the BusinessProxy browser extension. Non-browser traffic, local apps, calls and other browsers stay outside the BusinessProxy path.

Do users install anything?

Yes. Users need the BusinessProxy browser extension for a supported desktop browser. The point is that there is no OS-level agent and no device-wide VPN client. Enforced deployments require customer-managed browser or device policy validation.

Do you inspect HTTPS page content?

Not on the browser-proxy path. BusinessProxy enforces browser policy using domains, network metadata, category decisions and allow/deny rules. It does not decrypt HTTPS page content, read the page DOM, or inspect form fields on that path.

Can users bypass it on unmanaged devices?

Yes, outside the managed browser path. On an unmanaged device, a user can use another browser, another unmanaged profile, or remove/disable the extension. If bypass prevention matters, validate the browser package through customer-managed browser or device policy before rollout.

Are session credentials the account password?

No. Account login and proxy access use different credentials. Session credentials are random and short-lived. BusinessProxy validates them with a server-side keyed one-way digest and does not store the raw session credential or reuse the account password.

Is this for anonymity, scraping or bypassing restrictions?

No. BusinessProxy is for accountable work browsing and controlled web testing. It is not an anonymity network, scraping platform, unblock tool, or way to evade terms or legal restrictions.

Discuss the access path for your apps

Tell us which internal web apps, users and browser controls you need. We will map the portal flow, extension flow, connector placement and session controls.