Security & Compliance Overview
A concise reference for the security architecture, controls, and compliance posture of the Coconut Cloud Browser — written for security architects and compliance leads.
What you get out of the box
Full session isolation
Each browsing session runs in a single-tenant container, destroyed at session end.
Data stays in the cloud
Files, cookies, and credentials live in the container — never on the endpoint.
Identity-first access
Every session is gated by your IdP with MFA enforced by your existing policy.
Granular policy
URL filtering, clipboard, uploads, downloads, printing, watermarking, and screenshot blocking.
Comprehensive audit
Per-session audit logs cover access, policy events, and admin actions; exportable to SIEM.
Network egress control
Outbound traffic is policy-controlled and observable, simplifying SaaS access governance.
Three steps from zero to secure
Authenticate
User authenticates through your IdP with MFA, then receives a session token.
Isolate
A clean Chromium container spins up in-region and streams to the user over an encrypted channel.
Audit and destroy
On disconnect, the container and its data are destroyed; logs are persisted per policy.
At a glance
| Isolation boundary | Single-tenant container per session, hardware-virtualized |
|---|---|
| Encryption in transit | TLS 1.3; WebRTC DTLS-SRTP for media streaming |
| Encryption at rest | AES-256 for any persisted artifacts (audit logs, configuration) |
| Identity | SAML 2.0, OIDC; MFA enforced upstream by IdP |
| Data residency | Pin sessions and logs to a specific region (US, EU, UK, APAC) |
| Logging | Session, policy, and admin audit logs; SIEM export (Splunk, Sentinel, Chronicle) |
| Vulnerability mgmt | Continuous Chromium patching; managed CVE response |
| Pen testing | Annual third-party penetration tests; reports under NDA |
Standards we align with
- SOC 2 Type II controls aligned
- GDPR-aligned data handling with regional residency
- HIPAA-aligned workflows available with BAA
- Aligns with NIST SP 800-207 Zero Trust Architecture
- Supports PCI DSS v4.0 scope reduction strategies