One machine per session
Every session gets its own dedicated cloud VM — not a shared container. Disposable sessions are wiped and the machine is deleted the moment you leave.
Tunnel Browser runs a real Firefox or Chrome — and full Ubuntu or Windows desktops — on a private cloud machine, and streams the picture to your device. Your session lives away from your laptop, on hardware you spin up for the task and throw away when you're done.
Why a browser in the cloud
Whatever a page loads — scripts, trackers, downloads, the occasional nasty — happens on a throwaway cloud machine. Your device only ever receives video and sends clicks.
Every session gets its own dedicated cloud VM — not a shared container. Disposable sessions are wiped and the machine is deleted the moment you leave.
Malware, drive-by scripts and tracking run on the remote machine, never your endpoint. You stream the desktop over WebRTC — the page never touches your device.
Persistent profiles are encrypted at rest. Higher tiers use a key only you hold, or a hardware enclave attested in your own browser before anything starts.
Choose the server region, and optionally lock a stable egress IP so sites see the same address each time. For consistency and separation — not anonymity.
Spin up a full Ubuntu or Windows desktop in the same way — a cloud workstation you reach from any device, with sound, clipboard and file transfer.
Passwordless email one-time-code sign-in. No password to leak, no extension to install — it runs in the browser you already have.
Browser tiers
Every tier is a real browser on its own machine. What changes is how much is kept, and who can read it.
A clean browser for a quick look. The machine is destroyed on exit and nothing is stored server-side.
Your everyday browser — logins, bookmarks, history and extensions kept for next time, on an encrypted volume.
Persistent, but the encryption key is derived from your passphrase and never held by us at rest.
Runs inside a memory-encrypted CPU enclave (AMD SEV-SNP or Intel TDX), attested in your browser before the key is released.
Workstations
When a browser isn't enough — a complete Ubuntu or Windows computer, streamed to any device you happen to be on.
Security posture
We'd rather tell you the boundary than pretend it isn't there.
Each session is a dedicated VM with a default-deny network boundary — no reaching private ranges, no shared kernel with another user's session.
We record session lifecycle and placement for operating the fleet — never the URLs you visit, page content, keystrokes or files.
The operator terminates TLS at the edge, so for most tiers we could technically see traffic in transit. The Confidential tier removes even that: the session is sealed to an attested enclave.
Choose EU regions and EU-sovereign providers. Persistent data stays in the region you pick; nothing silently moves clouds.
Delete your data and the encryption key is destroyed with it — the volume becomes unrecoverable, not just "marked deleted".
Your egress IP is the cloud machine's, optionally locked to stay stable. It separates your browsing from your device — it is not an anonymity or evasion tool.
FAQ
No. A VPN reroutes your device's traffic; Tunnel Browser runs a whole browser somewhere else and streams you the picture. The page executes on the remote machine, so your device never loads it. Your egress IP is the cloud machine's, which is about isolation and consistency — not anonymity.
We log session lifecycle and placement to run the service, never your URLs, content, keystrokes or files. Because the operator terminates TLS at the edge, most tiers are "not zero-knowledge" — we could technically see traffic in transit. If that matters, the Confidential tier seals the session to a hardware enclave that even we can't read.
Casual sessions store nothing — the machine is destroyed on exit. Persistent tiers keep an encrypted profile you can resume, and "Delete my data" crypto-shreds it (the key is destroyed, so the volume is unrecoverable).
Each session runs on its own real cloud VM, and we keep a safety cap per cloud account to stay within provider quotas and prevent runaway cost. Capacity scales by raising the cap or adding provider accounts — it's a configuration change, not a rebuild.
No. It runs in the browser you already have. Sign in with an email one-time code and start a machine.
Multiple regions across several clouds, including EU-sovereign options. You pick the location per session; persistent data stays where you put it.
Sign in with your email, pick a tier and a location, and you're browsing from the cloud.
Get started →