INNERLUXES Enterprise Browser — secure Chromium workspace home page with the INNERLUXES Admin Console

An In-House Chromium Enterprise Browser That Keeps Client Source Code From Leaking

Industry
Software Development
Technologies
Chromium · C++ · Cloud · AI · RDP/SSH

Executive Summary

INNERLUXES is a Chromium-based enterprise browser built in-house by INNERLUXES, a software development company, for its own engineering and delivery teams. It is the company's single secure work environment — where access, security, data protection, application governance, and an AI assistant are all built directly into the browser.

The company builds software for external clients, which means its people work with client source code, repositories, cloud consoles, and confidential intellectual property every day. A single leak — a downloaded repo, a copied code snippet, a screenshot, or a secret pasted into an unapproved AI tool — could breach a client's trust and its NDA. Protecting that client data is the company's first responsibility and a core competitive advantage.

Rather than stitching together VPNs, virtual desktops (VDI), and heavy endpoint DLP agents, INNERLUXES took the enterprise-browser approach: put the controls exactly where the work happens — inside the browser. The result is the INNERLUXES Browser, paired with the INNERLUXES Admin Console for centralized governance.

Bottom line: INNERLUXES turns "never leak client code" from a rule employees must remember into a default that the work environment enforces automatically — while keeping developers fast, familiar, and productive.

At a Glance

  • Product — INNERLUXES Browser (enterprise browser)
  • Companion — INNERLUXES Admin Console (Application Access & governance)
  • Type — Chromium-based enterprise browser, a Chrome/Edge-like experience
  • Built by — INNERLUXES, a software development company (in-house build)
  • Built for — Internal engineering & delivery teams, plus vetted contractors
  • Primary mission — Prevent leakage of client source code, credentials, and IP
  • Core modules — Secure Workspaces · Data Protection (DLP) · Application Access · Shadow IT visibility · RDP/SSH access · Ask INNERLUXES AI
  • Deployment — Internal, company-wide
  • Status — Live and in use across the team

Background — Why INNERLUXES Was Built

The business context. INNERLUXES is a software development company that builds and maintains software for external clients. Client code, secrets, and credentials live across developer machines and many SaaS and cloud tools — all of which are accessed through the browser.

The trust problem. Clients hand over their most sensitive intellectual property under strict NDAs. Keeping that IP safe is not just a compliance checkbox — it is the company's first responsibility and a key reason clients choose to work with it.

Why off-the-shelf tools fell short. Virtual desktops (VDI) are costly and slow; VPNs secure the connection but do nothing to stop a copy/paste or a screenshot; endpoint DLP is heavy and frustrates developers; and fully managing employees' personal devices (BYOD) is intrusive and impractical for contractors.

The decision. The company chose to build its own enterprise browser — following the proven enterprise-browser model — so that protection lives at the exact point where client code is viewed and handled, instead of being bolted on around it.

The Problem in Detail — How Client Code Leaks

Engineers spend their day in GitHub/GitLab, cloud consoles (AWS), Jira, internal tools, and docs — all in the browser. Yet a normal consumer browser gives the company no visibility or control over what happens inside it. These are the main leak vectors the INNERLUXES Browser is designed to close:

  • Downloading or cloning client repositories onto a local (possibly personal) disk.
  • Copying and pasting source code, API keys, or secrets out of approved tools.
  • Taking screenshots or printing screens that contain client code.
  • Uploading files to personal cloud storage or personal email.
  • Pasting client code into public AI chatbots that are not approved.
  • Contractors or freelancers being given access broader than the one project they are on.
  • "Shadow IT" — unsanctioned apps and logins the company cannot see.

Remote staff and freelancers often work on personal devices the company cannot fully manage, so the protection has to travel with the work, not the device. The browser is the "last mile" where a human actually sees and touches client data — only there can the company govern the screenshot, the copy, the paste, the download, and the AI prompt.

The Solution — Inside the INNERLUXES Browser

The INNERLUXES experience is organized around secure workspaces, data-protection controls, centralized application governance, visibility, a built-in AI assistant, and a familiar user experience.

Secure Workspaces — separation and isolation

  • Secured Workspace — An isolated, locked workspace for sensitive client projects; code and data stay inside it, and risky actions (download, copy, screenshot) are restricted by policy.
  • Work sections — Separate workspaces per client or project, so one client's apps and data never mix with another's.
  • Personal Browsing — Keeps employees' personal activity separate and private from monitored work — essential for BYOD and for earning employee trust.
  • Custom sections — Teams can spin up their own workspaces as needed.
  • Most Used & shortcuts — Fast, governed access to the apps each person actually uses, right from the home page.

Data Protection — the anti-leak core

  • Last-mile DLP — Granular control over downloads, copy/paste, printing, and screenshots, so source code cannot be exfiltrated from the controlled environment.
  • Application boundaries — Data is allowed to move between approved client apps, but blocked from leaving for personal storage, email, or unapproved destinations.
  • AI guardrails — Employees use the built-in assistant instead of pasting client code into public chatbots, keeping corporate and client data out of personal AI accounts.

Application Access & Governance — the Admin Console

  • Application Library — A catalog of pre-integrated apps (AWS, Box, Dropbox, Gmail, Google Workspace, Jira, Microsoft 365, OneDrive, Salesforce, Slack, Teams, Zoom) plus Custom Web, SSH, and RDP apps the company adds itself.
  • Application Access Policy — Conditional access rules deciding who can reach which app, from which device and workspace.
  • Policy Simulator — Test a policy's impact safely before enforcing it across the team.
  • Approval Workflow — Employees and contractors request access; admins approve — enforcing least-privilege by default.
  • Web & Legacy support — Governed access to SaaS and web apps, including older IE / legacy applications.
  • RDP & SSH access — Developers reach remote servers and machines directly and securely through the browser — no separate clients, with access scoped and logged.

Visibility & Shadow IT

  • Application Logins & Usage — See which apps employees actually log into and use, catch unsanctioned "shadow IT," and tighten policy accordingly.
  • Audit trail — Work activity is logged for incident response and to demonstrate how client data is handled.

Built-in AI — "Ask INNERLUXES AI"

An AI assistant is embedded directly in the browser for writing, research, and summarizing — so the team gets AI productivity without ever sending client code to external, unapproved tools.

User Experience

  • Familiar browser — A branded, Chromium-based browser that feels like Chrome, so there is almost no learning curve.
  • Branded home — A custom home page with a greeting, clock, and weather, giving the team a consistent, branded workspace.
  • Unified search — One search bar across apps, history, open tabs, and workspaces (Ctrl K), with "All" and "My shortcuts" views.

How It Works

  • Chromium foundation — Built on Chromium, so the day-to-day experience is familiar and training needs are minimal.
  • Last-mile control — Because the controls live inside the rendering browser, INNERLUXES can govern actions that network tools and VPNs simply cannot see — a screenshot, a copy/paste, or a download of on-screen code.
  • Workspace isolation — The Secured Workspace seals off sensitive client projects, so their data and apps stay contained and exfiltration paths are closed.
  • Work / personal separation — Policies apply only to work-related activity; personal browsing remains private and unmonitored, which makes BYOD acceptable to employees.
  • Browser-delivered access (Zero-Trust style) — Access to web apps, RDP, and SSH flows through the browser with policy and logging, instead of granting broad network access — a contractor reaches exactly one client's resources and nothing else.

Use Cases

  • Onboard a contractor or freelancer — Grant scoped access to one client's apps and repo via the Approval Workflow; revoke instantly when the project ends.
  • Sensitive client project — Run it inside the Secured Workspace, where code cannot be downloaded, copied, or screenshotted out.
  • BYOD / remote engineers — Protect client code on personal devices without managing the whole device; personal browsing stays private.
  • Access cloud & dev tools — Reach AWS, Jira, repos, and SaaS apps governed by the Application Access Policy.
  • Reach remote servers — Connect via in-browser RDP/SSH, fully scoped and logged — no separate clients.
  • AI productivity — Use Ask INNERLUXES AI instead of public chatbots, keeping client code in-house.
  • Catch unsanctioned tools — Shadow IT visibility surfaces risky apps before they become incidents.

Benefits and Outcomes

  • Leak risk closed — Client source code stays inside the controlled environment — the number-one goal.
  • Simpler stack — One environment replaces a stack of VPN, VDI, and DLP tools, lowering cost and complexity.
  • Faster, safer onboarding — Contractors are onboarded and offboarded in minutes, with access scoped to a single client.
  • Demonstrable trust — A full activity log helps prove compliance with client NDAs and security requirements.
  • Better developer experience — A familiar Chromium browser with built-in AI is far better for developers than a slow VDI session.
  • Employee privacy preserved — Work/personal separation keeps personal activity private, so BYOD is accepted by the team.

Security and Compliance

Protection by design. Encryption in transit and at rest, least-privilege access, audit logging, and policy enforcement at the browser level form the foundation.

Meeting client requirements. Because access is governed per app, per workspace, and per user, INNERLUXES helps satisfy the security clauses and NDAs that clients impose — configurable to each client's specific requirements.

Privacy-respecting monitoring. Visibility covers work activity only; personal browsing is kept separate and private, balancing security with employee trust.

Conclusion

By building its own enterprise browser, INNERLUXES made client-code protection the default rather than a rule employees must constantly remember. Access, data protection, application governance, and AI all live in one place — the browser — so the work environment itself prevents leaks while keeping engineers fast and productive.

It is a clear example of a software company putting client trust first: instead of bolting security around the work, INNERLUXES built it directly into the tool where the work actually happens.

Technologies and Tools

Chromium, C++, cloud infrastructure, a built-in AI assistant, in-browser RDP/SSH, per-app access policies, and last-mile data-loss prevention (DLP).