Documentation

Guides, security and troubleshooting.

Set up browser access, protect CMS admin areas, publish private apps and resolve common errors — practical, task-oriented pages.

Product overview

What is BusinessProxy?

BusinessProxy is a managed secure web access gateway

BusinessProxy gives teams secure browser access to internal web applications, admin panels, CRM, CMS, ERP and support tools without publishing those systems to the open internet.

We intentionally chose a narrow model: access only to the specific application, not to the whole network. Instead of a device-wide VPN, a remote desktop (RDP), shared accounts or a public admin panel, you give people managed access exactly to the web services they need for work.

How it works

  • Users work through a regular browser and a lightweight extension. There are no heavy clients or complex user-side settings.
  • For applications inside your network, BusinessProxy uses an outbound connector. It initiates the connection from inside the customer network, so private services do not need open inbound ports or public addresses.

Control and convenience for administrators

Administrators keep centralized control over access rights, sessions, routing policies and immediate access revocation.

Many teams can start on the first day. Operational overhead is lower because there is no need to roll out a full VPN, maintain an RDP farm, install desktop agents or build a complex offboarding process for every temporary user.

What BusinessProxy is designed for

BusinessProxy is built specifically for managed work web access and controlled private-app access with activity logging.

It is not an anonymity service, scraping proxy, unblock tool or endpoint-control system.

On the browser route, the service does not intercept all operating-system traffic and does not decrypt HTTPS page content. Private applications are served through a separate Layer-7 alias route and the outbound connector.

Typical use cases

  • Private app access without VPN
  • CMS and admin panel protection
  • Contractor and BYOD access
  • Partner access for SaaS, ERP and service providers
  • Support, operations and QA workflows
  • E-commerce back-office access

Documentation sections

Guides by task, product and security.

Quick start

Quick start for a new workspace

Account setup, country, plan, workspace, extension sign-in and first private app.

Workspaces

Workspaces: concept and first steps

What a workspace is, what it contains, when to create a separate one, and how to set up members, groups, apps and access.

Browser extension

Browser extension user guide

Private-app-only mode, workspace switching, downloads, sign out and common states.

CMS Admin Gateway

CMS Admin Gateway guides

Protect WordPress, Drupal, Magento and ERP/SAP-style admin portals behind a managed BusinessProxy session.

Private Apps

Private apps and policy

Define one app: public addresses, upstreams, location rules, allow/deny presets and session TTL.

Identity SSO

Sign in with your corporate IdP

Connect Keycloak, Okta or a compatible OIDC provider. Users sign in with corporate SSO, accounts are created on first login and access groups come from your IdP.

MFA & passkeys

Passkeys and MFA before private app access

Use TOTP and WebAuthn passkeys for account security, passkey-first sign-in and fresh verification before private app launch.

Regional routing

Route work domains through the right country

Route selected work domains through approved exit countries with exact host, suffix and TLD rules, plus temporary user exceptions.

Event export / SIEM

Send BusinessProxy events into your SOC workflow

Export access, denied, routing and security events through signed HTTPS notifications and deterministic Syslog JSON/CEF adapter mappings.

Connectors

Connectors

Administrator setup for the outbound connector: package access, runtime values, network reachability, readiness, diagnostics and rotation.

Connector HA

High-availability mode for the App Gateway Connector

Run two or three outbound connector instances for one workspace connector, verify health, perform rolling maintenance and collect release evidence.

GitLab behind BusinessProxy

Run GitLab behind BusinessProxy App Gateway

Step-by-step setup for publishing a self-hosted GitLab through BusinessProxy without exposing the GitLab server directly.

Webhook Connector

Webhook Connector: receive public events into a private service

Purpose, safe use cases and step-by-step setup for forwarding provider webhooks to one fixed private upstream.

Security model

Security model

What traffic is routed, where TLS is terminated, what is logged and the threat model per layer.

Troubleshooting library

Problem pages support can send directly: errors, permissions, connectors and recovery.

ReleasesVersions, checksums and signatures for every download.Open