Software for companies that run on it.
We build the operating system and the browser a company hands to its staff on their first morning — the tools people use for eight hours a day, not the ones they try once and forget.
A company’s machines are only as controlled as its browser.
Almost everything an employee touches at work now runs in a browser — the CRM, the payroll system, the reports, the internal dashboards. The browser is where the company’s data actually lives during the working day, and on most machines it is the one piece of software nobody administers.
A shared laptop stays signed in overnight. Somebody leaves and their session outlives them. Passwords are written on a card taped under a desk because eleven internal systems each wanted their own. None of that is negligence; it is what happens when the tool was designed for one person and handed to a company.
Two products in service, one being replaced.
They share an identity because they are meant to be handed to the same people, on the same machine, on the same day.
NeX OS
A secure operating system. System files are read-only and an update arrives as one verified image, so a machine is either the version you shipped or it is not — with nothing half-applied in between to diagnose.
NeX Browser
A managed browser on Chromium. Locked until an employee proves who they are, then it carries them into your internal systems without a second password.
browser.nexsoftware.devNeX Shield
Our first managed browser, and the product that proved the idea. Still in service while customers move across to NeX Browser, which carries its colours on purpose.
What an administrator actually gets.
Locked until somebody signs in
nex://lock · enforced in the browser processA machine nobody is signed in to shows a lock screen and nothing else — no tabs, no address bar, no way past it. Quitting the browser ends the session, because sessions are held in memory and never written to disk. The next person signs in as themselves, even on a shared desk.
One sign-in, then every internal app
RS256, per-application grantsOnce an employee is in, your internal applications recognise them automatically. Tokens are signed asymmetrically and scoped to the applications that employee has been granted, so an application can verify a person without being able to impersonate one — and nobody needs a second password to write down.
Configured centrally, applied everywhere
standard Chromium policyWhich sites are reachable, which extensions are allowed, what the homepage is. Set once in the admin panel and it reaches every machine within about a minute, with no restart. They are ordinary Chromium policies, so anything you already know about managing Chrome applies unchanged.
Access you can withdraw
device and employee, revocableRevoke a device or an employee and the browser locks itself wherever it is, within the same minute. Somebody leaving on a Friday afternoon does not need their laptop collected before their access ends.
An audit trail that reads the same either way
every request, decision and sign-inWho asked for access, who approved it, from which machine and when. Automatic approvals are recorded with the same event kind as human ones, so the log does not quietly become less useful the more you automate.
Updates that either happened or did not
NeX OS · verified imagesOn NeX OS the system is read-only and updates arrive whole rather than as packages applied in sequence. A machine cannot end up half-updated, and a bad release is undone by starting the previous image instead of by a recovery procedure.
What it looks like from the desk.
The whole point is that an employee does almost nothing. Four steps, and only two of them involve a person.
They open the browser
It is locked. Their work email is already filled in from the last time, so there is nothing to remember.
They ask for access
One press. The request appears in the administrator’s queue with the person, the machine and the time.
The code arrives by itself
On approval it fills itself into the screen. Nobody reads digits down a phone or types them wrong.
They press unlock
Their tabs come back as they left them, and every internal application already knows who they are.
Nobody using our software chose it.
It was installed on their machine by their employer, and they use it every working day whether they like it or not. That is an unusual responsibility, and it settles most arguments about what to build.
It has to be quick.Software people are required to use should never make them wait — a second of latency, eight hours a day, is somebody’s afternoon every month.
It has to be unsurprising. A managed browser that behaves differently from the one they already know costs them an hour a week, forever. Ours is Chromium underneath for exactly that reason.
It has to be honest. An employee should be able to read, in plain words, what their browser records and what their administrator can see. We publish that rather than bury it.
Asked before every deployment.
The six that come up in every conversation, answered the way we answer them on a call.
Can you see our employees’ browsing?
No. The browser talks to your identity server, not to ours, and it has no feature that transmits browsing at all. We see your data only if an administrator sends it to us while asking for help.
Can an administrator read someone’s history?
No. They control which sites are reachable and can see devices, sign-ins and access decisions. Page contents, history and saved passwords are not available to them through NeX Browser.
What happens if your identity server is unreachable?
A signed-in employee keeps working — the session is already in the browser. It locks only after the browser has failed to confirm the session repeatedly, so a brief network problem does not throw a room full of people out of their work.
Do we have to replace our operating system to use the browser?
No. NeX Browser runs on ordinary Linux and Windows machines. NeX OS is the option for companies that also want the machine itself managed, and it ships with the browser included.
Is this a Chromium fork we have to trust blindly?
It is Chromium, tracking upstream security updates rather than forking away from them. Google’s consumer services — sync, sign-in, usage reporting — are removed rather than switched off. Certificate revocation and Safe Browsing continue to work.
How do employees get help?
Their own administrator first, since almost every answer is visible to them and actionable immediately. Everything else is documented at browser.nexsoftware.dev/support, in language written for the person at the desk rather than for us.
Deployed with us, not downloaded.
The first step is a conversation about how your machines are managed today and whether this is a sensible fit. We will tell you if it is not.