Customer-owned app domains

Private apps that open on the customer domain

A user opens crm.apps.customer.com instead of a technical BusinessProxy link. The app domain is verified through DNS, the sign-in surface belongs to that app address and the internal upstream remains hidden behind the connector.

This is app-level branding: domain, launch and sign-in for a selected private app. The dashboard, support, transactional email and legal identity remain BusinessProxy-branded.

Verified customer-owned domainApp-domain sign-inDomain-scoped passkeysExtension-required launch mode

Trust at the URL bar

The link looks like the customer environment

For partners, MSPs and customer-facing private apps, the public address matters. A verified customer domain is easier to approve, send in onboarding material and recognize in the browser.

DNS verification

The app domain is created only after the customer proves domain ownership through the required DNS record.

Certificate and domain state

The app domain has explicit status, certificate lifecycle and launch-mode configuration.

Passkey RP per host

Passkeys are scoped to the app domain; they do not silently move between unrelated domains.

Launch modes

Choose how the app may be opened

Each app domain can use branded portal, BusinessProxy portal or extension-required launch depending on the customer rollout and risk boundary.

  • Branded portal keeps sign-in on the app domain.
  • Extension-required mode is explicit for extension-only applications.
  • Disabled private apps do not issue new app sessions.
  • The internal app host and private IP stay outside the user-facing URL.

Current boundary

Not full white-label platform identity

Branded app access does not replace the BusinessProxy dashboard, legal publisher identity, email sender or billing relationship. It brands the selected app entry point while preserving BusinessProxy product and legal boundaries.

  • Full platform white-label is not included.
  • Passkeys do not move across unrelated domains.
  • This is not a device-wide VPN or endpoint-control product.

Next step

Review the rollout details before turning it on

The documentation page shows what to configure, how to verify the setup and which operational boundaries to review before rollout.