Security

Browseterm is built around one rule: your machine is never reachable from the outside, and Cloud never holds a copy of your workspace data.

Your machine only ever calls out

The Browseterm software on your machine opens a single outbound, encrypted connection to Browseterm Cloud. Cloud can send commands over that already-open connection, but nothing on Cloud — and nothing on the public internet — can open a new connection into your machine. Your local management interface is never exposed publicly.

Every device has its own credential

Each machine you register gets its own independent, revocable credential, scoped only to that machine. No machine you control ever holds a shared or global credential that could affect any other user's account or device.

Terminal traffic is ticketed, not open

When you open a terminal in your browser, Cloud issues a short-lived, single-use ticket bound to your account, your device, and that specific workspace. The ticket is required to connect and expires quickly — possessing the connection URL alone is never enough.

Your workspace data stays on your machine

Workloads run entirely on the machine you registered. When you save a workspace so it can be restored later, only the resulting saved image is stored — Cloud tracks metadata about your devices, workspaces, and saved images; it does not run your workloads or hold a live copy of your working files.

Reporting a security issue

If you believe you've found a security issue in Browseterm, please report it privately rather than opening a public issue. Contact details will be published here before general availability.