Check Point Harmony SASE Browser Feature Extends Zero Trust Capabilities

Cybersecurity solutions provider Check Point Software Technologies has added Enterprise Browser to its Harmony SASE offering. The new feature is designed to extend Zero Trust security to unmanaged devices, such as those from contractors, BYOD users and third-party partners, to deliver visibility, policy enforcement and compliance-ready data protection without agents or endpoint ownership.

Built on Chromium, Enterprise Browser creates “an isolated, ephemeral workspace that enforces enterprise-grade controls for the duration of each session and removes all sensitive data once closed,” the company said.

“As hybrid workforces and third-party ecosystems grow, unmanaged devices have become one of the largest security blind spots,” Check Point officials said. “Organizations face heightened risks including data leakage, compliance gaps and limited visibility into device hygiene. Traditional approaches, such as provisioning VPN access or providing laptops, are costly, inefficient and hinder today’s compliance mandates like HIPAA, GDPR and NIS2.”

Among its capabilities is a data isolation and wipe function, in which enterprise applications and data remain isolated from the underlying operating system (OS), and sensitive data is erased at the close of a session. In addition, integrated data loss prevention (DLP) enforces restrictions on uploads, downloads, copy/paste and printing as well as applying watermarks to documents and screens, the company said.

The browser also verifies device posture (antivirus, OS version, disk encryption) before granting access and enables navigation history, screen capture and full session recording for compliance and forensic investigations, officials said.

“Enterprises can no longer afford to choose between productivity and security,” said Amit Bareket, VP of SASE. “Check Point Enterprise Browser delivers both. It enables fast access for third parties and BYOD users, while giving IT teams stronger control, compliance and visibility on devices they don’t manage.”