← Back to Cloudflare One
RBI

Remote Browser Isolation

Risky web content executes in Cloudflare — never in the user's browser.

✓ Guided dashboard demo
Mental model

How RBI works across users, traffic, and policy

Remote Browser Isolation moves active web execution into a disposable browser in a Cloudflare network location. The endpoint receives safe rendering instructions, which reduces exposure to risky code and enables controls over data in use.

Gateway chooses isolateAn HTTP policy selects risky traffic for isolation instead of making a binary allow-or-block decision.
Cloudflare executes the pageHTML, JavaScript, and active content run in a remote browser close to the user.
NVR delivers safe outputNetwork Vector Rendering streams drawing commands to the local browser while policy controls copy, paste, upload, download, and print.
Execution boundary

The website runs in Cloudflare. The endpoint receives safe drawing instructions.

Gateway makes the isolate decision, a disposable remote browser executes active content, and Network Vector Rendering delivers the visual result without sending the original page code to the endpoint.

Configured proof

Use fast.com to make the remote execution boundary visible.

The speed reading reflects the isolated browser's Cloudflare-side connectivity. It is a memorable visual cue, not a test of the UTM Demo Mac and not an RBI performance promise.

fast.com — isolated
REMOTE SESSIONFAST

Page execution: Cloudflare network location

Configured

Isolate fast.com

  1. Connect Zero Trust WARP on the UTM Demo Mac.
  2. Open fast.com and confirm the isolated session.
  3. Point out that the page executes remotely in Cloudflare.
  4. Verify the isolate action in Gateway HTTP logs.
No endpoint benchmark. No exact throughput claim.
Data in use

Isolation replaces allow-or-block with granular browser controls.

Once execution is remote, policy can limit how information moves between the isolated session and the local device.

↔

Copy / paste

Prevent sensitive content from crossing the isolation boundary through the clipboard.

↓

Download

Allow browsing while stopping risky or sensitive files from reaching the endpoint.

↑

Upload

Restrict local files from being submitted into untrusted web sessions.

▤

Print

Control printing when an unmanaged device opens a sensitive application.

Where it fits

Use isolation when blocking is too rigid and direct execution is too risky.

Suspicious links and zero-days

Let users investigate unfamiliar destinations while active content remains off the endpoint.

Unmanaged and BYOD access

Protect data in use when contractors or partners cannot install an endpoint agent.

Clientless private applications

Pair Access with isolation to expose a browser application without exposing its code or data directly.

Selective risk treatment

Gateway can isolate only the destinations, categories, or users that require stronger handling.

Open in dashboard

The policy and evidence behind the RBI proof.

Browser Isolation ↗Isolation settings and data-in-use controlsGateway HTTP policies ↗Open the configured Isolate fast.com ruleGateway logs ↗Verify identity, destination, matched policy, and isolate action
Built by Rodrigo Nobre with Cloudflare Workers