TR7 Add-ons — specialized capability modules that plug into the bundles.

PREMIUM ADD-ON

ZeroLeak Visual Isolation

Sensitive applications never reach the client — only a secure pixel stream does.

WAF stops the attack. AAM verifies identity. DLP can mask sensitive data. But the moment a sensitive application's HTML, JavaScript, session data, and API responses reach the user's device, that data is already inside the client-side risk surface.

ZeroLeak closes this risk at the architectural level. The real web application runs inside an isolated browser environment on your network. Only a live pixel stream reaches the user's device. The application's code, data, and session information never touch the client.

The user sees the application. The data never lands on the device.

ZeroLeak keeps the sensitive web application's HTML, JavaScript, API responses, tokens, and session data inside your network. Only a live pixel stream reaches the user; keyboard and mouse input flow back through a controlled channel. The browser-based attack surface closes at the source.

NEW-ERA RISK

The Browser Is Now at the Center of the Attack Surface

Classic web security long focused on stopping attacks aimed at the server. Today a significant share of the risk starts in the user's browser. The moment a page reaches the client, the DOM, session data, cookies, localStorage, and API responses are processed on the device. If the device isn't secure, neither is the sensitive application. ZeroLeak flips that assumption: the sensitive page never reaches the client in the first place.

Browser-Side Data Exfiltration

DOM content, session tokens, cookies, and localStorage become visible on the client side. WAF and DLP are strong on the server side; once data reaches the browser, the control surface narrows.

AI-Driven Automated Inspection

AI agents can read web pages, analyze form fields, parse visible data, and automate repetitive operations. This is not a problem confined to classic bot detection.

Device and Memory Risk

When a user's device is compromised, browser memory, open page content, tokens, and temporary files come under risk. The enterprise application becomes dependent on endpoint security the moment it reaches the client.

Screen Capture and AI Vision

Sensitive information leaks not only through HTML but also the moment it appears on screen. Screen recording, screen sharing, screenshots, and AI-based OCR tools amplify this risk.

THE MISSING LAYER

WAF, AAM, and DLP Are Strong; They Just Don't Stop the Page from Reaching the Client

WAF filters attacks, AAM verifies access, DLP controls sensitive fields. But at the end of that chain, the web page still lands in the user's browser. ZeroLeak fills the gap: the sensitive application is never sent to the client — only a secure visual session is.

Classic Browser Model

What reaches the client?

  • Full HTML / DOM
  • JavaScript execution context
  • Session cookies and tokens
  • localStorage / sessionStorage
  • API response bodies
  • Loaded images and files
ZeroLeak Model

What reaches the client?

  • Only a live pixel stream
  • No DOM
  • No tokens
  • No localStorage
  • No API responses
  • No file contents

ZeroLeak lets users work with sensitive applications — without ever delivering them to the client.

A DIFFERENT POSITION

ADC, WAAP, and Visual Isolation on One Platform

In the enterprise market, ADC, WAAP, identity-based access, and browser isolation are typically positioned as separate product families. ADC handles load balancing, WAAP protects the application, AAM manages access, and browser isolation is usually offered as a separate SaaS service. TR7 ZeroLeak removes that split. Sensitive application access, web security, identity policy, visual isolation, Anti-OCR, and forensic recording all run inside the same platform.

01

Visual isolation built into ADC/WAAP

ZeroLeak delivers visual isolation as a native security layer of the TR7 platform — not as a separate product. The operator manages access, security, isolation, and recording policies side-by-side from the same management UI.

02

Runs on-premises, no SaaS dependency

Many browser isolation approaches route traffic into a third-party cloud. ZeroLeak runs inside your network. Sensitive applications, session data, and recordings stay under your control.

03

Anti-OCR — an extra layer against visual leakage

Keeping the page off the client is step one. But what appears on screen can still be read via screenshots, screen recording, or AI vision. ZeroLeak adds a visual-protection and policy-based masking layer for that risk.

04

Licensing built for the business scenario

Instead of complex bandwidth-based models, ZeroLeak is licensed by concurrent-user capacity. Organizations plan a clear capacity model by counting how many users will hold isolated sessions at the same time.

ZeroLeak's distinction isn't a single feature; it's the architectural combination — ADC, AAM, WAAP, visual isolation, Anti-OCR, and forensic recording running in the same security flow.

THE PIXEL DOCTRINE

Data Doesn't Reach the Client. The User Only Works with a Secure View.

ZeroLeak's security model rests on three core layers. First, the application itself is separated from the client. Then, sensitive on-screen regions are protected against visual leakage. Finally, the entire session becomes an auditable forensic record.

Pixels Only

The sensitive web application runs inside an isolated browser environment on your network. The application itself never reaches the user's device — only a live pixel stream does.

  • HTML, JavaScript, session tokens, cookies, and localStorage never reach the client
  • API calls and response bodies stay inside the isolated session
  • Users connect from a standard browser; no agent installation required
  • Keyboard and mouse input flow into the session over a controlled channel
  • Even if the device is compromised, sensitive application data is never on it

Anti-OCR Visual Protection

What appears on screen is also a surface to protect. ZeroLeak applies policy-based protection to sensitive regions against screenshots, screen recording, and AI-based OCR.

  • Dynamic visual protection and obfuscation layers on sensitive regions
  • Extra defense against screenshots, screen recording, and screen sharing
  • Pixel-level countermeasures against AI vision and OCR-based reading attempts
  • Masking policies by role, application, and data type
  • Per-session invisible watermarking — source attribution on leaks

Full Session Recording

ZeroLeak doesn't just isolate access — it makes the entire access auditable. For critical applications, the question of who did what and when has a complete retrospective answer.

  • Video-quality session recording
  • Timestamped capture of clicks, keystrokes, navigation, and action steps
  • Unified visibility across user, application, device, IP, and access context
  • Active event streaming to SIEM for security teams
  • Policy-based retention aligned with GDPR, HIPAA, PCI DSS, and internal audit
ARCHITECTURE

Inside Your Network, a Separate Isolation Cell per Session

ZeroLeak is not a SaaS routing service or a client agent. It is a security layer that runs inside your network and creates a separate isolated browser cell for every user session. The session starts, the cell opens; the session ends, the cell collapses. Application data never moves to the client, and the session environment never persists.

Session lifecycle

1
User access request
The user connects to the TR7 portal from any HTML5-capable browser.
2
AAM authentication
TR7 AAM applies identity, MFA, role, and access policies.
3
Isolation cell opens
ZeroLeak starts a separate, isolated browser cell for the user session.
4
Target application connection
The isolated cell connects to the sensitive application from within your network.
5
Pixel stream + Anti-OCR
Only a live image is sent to the user; sensitive regions receive visual protection.
6
Forensic + SIEM
Session recording, event data, and security signals stream to forensic storage and SIEM.
  • Separate isolation cell per session — no shared browser environment across users
  • No agent required — any HTML5-capable standard browser works
  • Application traffic stays inside your network
  • Integrated with TR7 AAM for SSO, MFA, OAuth2, OIDC, SAML, LDAP, and RADIUS
  • Shares attack context and security policy with TR7 WAAP
  • Policy, license, and recording management through TR7 Central Management
  • Event streaming to Splunk, Elastic, QRadar, and similar SIEM platforms
USE-CASE SCENARIOS

5 Critical Battlefields Where ZeroLeak Excels

ZeroLeak delivers the most value in scenarios where device trust is weak but application data is critical. Users are granted access — but the application data is never delivered to their device.

Third-party remote access in banking

Tehdit

Contractors, auditors, or external developers need remote access to sensitive banking screens. The device is not under organizational control and the risk of data leakage is high.

ZeroLeak Çözümü

The user connects from their own browser into an isolated session. The core banking screen stays inside your network; only a pixel stream reaches the user's device. Every session is recorded for audit and forensic review.

Healthcare BYOD access to patient records

Tehdit

A clinician or field worker wants to access patient records from their personal tablet. Health data is sensitive, and the device's security posture cannot always be guaranteed.

ZeroLeak Çözümü

Patient data never lands on the tablet. The user can view and act on the data, but HTML, files, API responses, and session information never reside on the client device.

Sensitive management consoles in government

Tehdit

When access to government management panels, classified applications, or critical internal portals is opened over classic VPN, endpoint and screen-leak risks remain.

ZeroLeak Çözümü

The console runs inside your network and the user receives only an isolated visual session. Anti-OCR is applied to sensitive regions; every action becomes an auditable record.

Partner and supplier portal access

Tehdit

Suppliers, business partners, and dealers access B2B portals. The security level of those devices cannot be directly managed by your organization.

ZeroLeak Çözümü

The partner portal is never delivered to the client. The user can take action, but data, files, and session information never stay on the partner device. New devices, different locations, and temporary access scenarios are handled with more control.

AI agents and automation risk

Tehdit

A user may access an enterprise application through an AI agent or automation extension acting on their behalf. These tools can read, parse, or exfiltrate page content.

ZeroLeak Çözümü

An AI agent cannot see the DOM, API responses, or page code — only the pixel stream. Structured scraping risk drops, behavioral anomaly policies and forensic recording make the process traceable.

CAPACITY OPTIONS

Licensed by Concurrent-User Count

ZeroLeak capacity is planned by the number of users who hold isolated sessions at the same time. Every license tier ships the same core feature set; only the concurrent-user capacity changes.

Evaluation included with Base Bundle

Evaluation usage is included with every TR7 platform: 1 concurrent user, 30 minutes per day, all features unlocked. For production use, the capacity options below take over.

1
Concurrent User
5
Concurrent Users
10
Concurrent Users
25
Concurrent Users
50
Concurrent Users
100
Concurrent Users
250
Concurrent Users
500
Concurrent Users
Unlimited
Concurrent Users

Every tier ships the same capability set — the only difference is the number of isolated sessions that can run at the same time.

Real capacity depends on hardware resources, application type, session duration, and forensic recording policy. As a planning average, you can assume roughly 1 GB RAM, 1 vCPU per user, and roughly 500 MB/hour of disk for forensic recording.

COMPLIANCE

A Strong Layer for Audit, Data Minimization, and Remote-Access Control

ZeroLeak supports data minimization, remote-access control, session recording, and auditability requirements for sensitive web application access. Because data never reaches the client, it forms a strong additional control layer in regulation-driven security architectures.

GDPR Article 32

Supports technical and organizational measures for personal data security. Because sensitive data never lands on the client device, it strengthens the data-minimization principle.

HIPAA Security Rule

Contributes to ePHI access control, audit, and integrity safeguards. Isolated sessions, forensic recording, and policy-based access work together.

ISO 27001 Annex A

Provides an additional security layer for remote access to critical systems. Management consoles and sensitive applications can be used without being delivered to the client.

SOX (Sarbanes-Oxley)

Provides a strong audit layer for financial-system access — insider risk, third-party access, and transaction traceability.

PCI DSS 4.0.1

Reduces the client-side attack surface for the cardholder data environment. Sensitive screens, access policy, and session recording are managed with tighter control.

LICENSING

Premium Add-on — Per Concurrent User

ZeroLeak is available as a Premium add-on for all four TR7 bundles (Base, Geo, Secure, and Enterprise). The license model is based on concurrent-user capacity rather than bandwidth — because every user session creates a separate isolation cell with its own resource footprint.

  • Per concurrent-user (CCU) licensing — 1, 5, 10, 25, 50, 100, 250, 500, or unlimited
  • Attaches to all four bundles — Base, Geo, Secure, and Enterprise
  • Runs on a hardware appliance or a virtual machine
  • On hardware appliances, ZeroLeak resources can be planned from a separate CPU/RAM pool

Deliver Sensitive Applications with Pixelized Security

Let's walk through a ZeroLeak demo against your own scenario: which applications should be isolated, how many concurrent users you need, how forensic recording should be retained, and how it fits into your existing TR7 architecture.

Licensing Guide