Kasm Workspaces Documentation
Access the Resource, Not the Network
Security-focused organisations that currently operate VPN, VDI, and Remote Browser Isolation (RBI) products increasingly want a safer, simpler way to provide secure access to sensitive enterprise resources and risky web destinations.
Kasm Workspaces is a browser-delivered Zero Trust access platform that reduces the client software, endpoint dependencies, and persistent infrastructure commonly associated with traditional remote access architectures such as Citrix Virtual Apps and Desktops, Omnissa Horizon, VPNs, and RBI solutions.
Zero Trust Workspace Architecture
Kasm Technologies holds SOC 2 Type 2 and CMMC 2.0 Level 2 certifications, aligned with NIST SP 800-171 requirements. This gives regulated organizations and any team that wants a Zero Trust access platform a proven security foundation for secure workspace delivery.
The platform uses standard HTTPS and WebSockets to deliver browser-based access to Windows, Linux, and macOS systems. Users can access applications, desktops, and isolated browser sessions without requiring direct network-level access from the endpoint.
Built for Enterprise Adoption
Deploy Kasm Workspaces alongside existing identity, security, logging, and infrastructure investments while maintaining control over policy, topology, capacity, and operations.
The platform supports Windows, Linux, macOS and Android systems. It also provides automated scaling and Kasm-maintained workspace images to simplify deployment.
Isolate Risk in Both Directions
Use the same controlled session architecture to protect users from untrusted content and to protect enterprise resources from unmanaged devices.
Start with the isolation requirement that presents the highest risk or operational burden. Validate the outcome with a defined user group before extending the architecture to additional workloads.
High-risk websites and applications run inside isolated environments instead of executing directly on the user's local device. The session is discarded when the user is finished.
Contractors, partners, BYOD users, and remote employees can interact with authorized resources through a browser while the endpoint remains separated from the protected environment.
A Common Platform for Desktops, Secure Access and Isolation
Kasm Workspaces brings virtual desktops, enterprise access, remote browser isolation (RBI), application streaming, and secure AI environments onto a common Zero Trust platform.
Start with the highest-priority access requirement, prove the outcome, then extend the same identity, policy, and delivery model to additional use cases.
Business Value at Enterprise Scale
Kasm Workspaces can reduce infrastructure and operational overhead by scaling compute capacity to match demand, see how one municipal customer benefited below.
For contractor and BYOD access, Kasm Workspaces can provide approved resources through the browser without requiring a traditional VDI or VPN client. This can reduce the number of deployment steps required for access.
Together, these capabilities give organizations a practical path to lower cost, faster access, validated security, and scalable operations on a common platform. Explore additional solutions and integrations at Kasm Insights.
Read the Hamina customer story
Review compliance and security validation
Explore Kubernetes workspace delivery
Explore validated integrations
Choose the Right Kasm Solution
Kasm Technologies offers two purpose-built solutions.
Choose Kasm Workspaces for centralized enterprise workspace delivery, or KasmVNC when your engineering team wants the streaming technology and plans to provide its own orchestration.
Commercial Editions: For organizations that want an enterprise-supported platform for centralized secure workspace delivery, orchestration, lifecycle management, and scale.
Community Edition: Get started for free. Use Community Edition for evaluation, proof of value, nonprofit deployments, or individual use, then move to a commercial edition as requirements grow.
- Secure access to Windows, Linux, and macOS from a browser
- Centralized policy and audit controls across access types
- Unmanaged devices do not require direct network-level access
- Deploys alongside existing identity and logging systems
- Commercial support with defined response-time SLAs
Bring Your Own Orchestration: For engineering teams that want the streaming technology behind Kasm Workspaces and are prepared to build and operate their own orchestration layer.
Open Source Licensing: Available under GNU GPL v2.0 for deployments that do not require centralized orchestration, identity workflows, or policy automation.
- Secure access to Linux from a browser
- Multi-user collaboration with built-in DLP controls
- GPU acceleration and dynamic image compression
- Community supported without centralized orchestration
Help and Support Resources
Support is part of the product, not an afterthought. Get the documentation, community resources, and commercial support needed to evaluate, deploy, operate, and scale Kasm Workspaces successfully in production.
- Official Kasm Customer Support - Get direct assistance from Kasm experts with guaranteed response times.
- Knowledge Base - In-depth how-to guides and advanced troubleshooting articles.
- Troubleshooting Guide - Find configuration walkthroughs, implementation guidance, and advanced troubleshooting.
- GitHub Community Issue Tracker - Submit reproducible bugs, search known issues, or request product enhancements.
- Reddit Community (r/kasmweb) - Exchange deployment ideas, use cases, and practical lessons with other Kasm users.
- YouTube Video Tutorials - Watch guided demonstrations, administration, integrations, and end-user workflows.
- FAQ - Quick answers to the most common installation, configuration, licensing, and architecture questions.
The Kasm Customer Support team and community resources are available to help your organization deploy and operate the Kasm Workspaces platform successfully.
How This Documentation Is Organized
This documentation follows the Diataxis framework. Choose the resource type that matches your task, from initial evaluation through production deployment, operation and integration.