Skip to main content

Kasm Workspaces Documentation

Access the Resource, Not the Network

Security-focused organisations that currently operate VPN, VDI, and Remote Browser Isolation (RBI) products increasingly want a safer, simpler way to provide secure access to sensitive enterprise resources and risky web destinations.

Kasm Workspaces is a browser-delivered Zero Trust access platform that reduces the client software, endpoint dependencies, and persistent infrastructure commonly associated with traditional remote access architectures such as Citrix Virtual Apps and Desktops, Omnissa Horizon, VPNs, and RBI solutions.

Zero Trust Workspace Architecture

Kasm Technologies holds SOC 2 Type 2 and CMMC 2.0 Level 2 certifications, aligned with NIST SP 800-171 requirements. This gives regulated organizations and any team that wants a Zero Trust access platform a proven security foundation for secure workspace delivery.

The platform uses standard HTTPS and WebSockets to deliver browser-based access to Windows, Linux, and macOS systems. Users can access applications, desktops, and isolated browser sessions without requiring direct network-level access from the endpoint.

Built for Enterprise Adoption

Deploy Kasm Workspaces alongside existing identity, security, logging, and infrastructure investments while maintaining control over policy, topology, capacity, and operations.

The platform supports Windows, Linux, macOS and Android systems. It also provides automated scaling and Kasm-maintained workspace images to simplify deployment.

Isolate Risk in Both Directions

Use the same controlled session architecture to protect users from untrusted content and to protect enterprise resources from unmanaged devices.

Start with the isolation requirement that presents the highest risk or operational burden. Validate the outcome with a defined user group before extending the architecture to additional workloads.

Inside-Out Access
Protect users from untrusted destinations

High-risk websites and applications run inside isolated environments instead of executing directly on the user's local device. The session is discarded when the user is finished.
Outside-In Access
Protect enterprise resources from untrusted devices

Contractors, partners, BYOD users, and remote employees can interact with authorized resources through a browser while the endpoint remains separated from the protected environment.

A Common Platform for Desktops, Secure Access and Isolation

Kasm Workspaces brings virtual desktops, enterprise access, remote browser isolation (RBI), application streaming, and secure AI environments onto a common Zero Trust platform.

Start with the highest-priority access requirement, prove the outcome, then extend the same identity, policy, and delivery model to additional use cases.

Virtual Desktops
Outcomes: Deliver managed desktops through the browser while reducing persistent per-user infrastructure and simplifying provisioning and patching.
Secure Remote Access
Outcomes: Provide contractors, partners, and remote users access to approved resources without extending network-level access to unmanaged devices.
Application Streaming
Outcomes: Provide controlled access to approved applications without requiring endpoint installation or exposing the underlying application environment.
Non-Attributable Research
Outcomes: Reduce the risk of exposing analyst identity, endpoints, or organizational infrastructure during sensitive OSINT research.
Remote Browser Isolation
Outcomes: Reduce endpoint exposure to untrusted web content while maintaining access to the websites users need.
Public/Private AI Sandbox
Outcomes: Enable approved AI use while maintaining control over access, sensitive data, and audit requirements.

Business Value at Enterprise Scale

Kasm Workspaces can reduce infrastructure and operational overhead by scaling compute capacity to match demand, see how one municipal customer benefited below.

For contractor and BYOD access, Kasm Workspaces can provide approved resources through the browser without requiring a traditional VDI or VPN client. This can reduce the number of deployment steps required for access.

Together, these capabilities give organizations a practical path to lower cost, faster access, validated security, and scalable operations on a common platform. Explore additional solutions and integrations at Kasm Insights.

Proven Customer Outcomes
The City of Hamina used Kasm Workspaces to shift from dedicated end-user computing toward real-time workspace orchestration and shared compute. The city reported a 45% reduction in recurring IT operational costs, a 15% reduction in hardware purchase expense, and 2X more computing power.

Read the Hamina customer story
Validated for Regulated Environments
Kasm Technologies has achieved CMMC Level 2 certification, providing independent validation of its security practices for protecting Controlled Unclassified Information (CUI) and supporting organizations within the Defense Industrial Base.

Review compliance and security validation
Kubernetes Operations at Scale
Kasm Workspaces core services can be deployed with Kubernetes and Helm. This provides a declarative and portable deployment model while allowing workspace session infrastructure to scale independently of the core services.

Explore Kubernetes workspace delivery
Infrastructure and Security Integrations
Kasm Workspaces integrates with existing infrastructure, security, and endpoint technologies, while a broad selection of Kasm-maintained workspace images helps reduce the effort required to prepare common deployments.

Explore validated integrations

Choose the Right Kasm Solution

Kasm Technologies offers two purpose-built solutions.

Choose Kasm Workspaces for centralized enterprise workspace delivery, or KasmVNC when your engineering team wants the streaming technology and plans to provide its own orchestration.

Help and Support Resources

Support is part of the product, not an afterthought. Get the documentation, community resources, and commercial support needed to evaluate, deploy, operate, and scale Kasm Workspaces successfully in production.

The Kasm Customer Support team and community resources are available to help your organization deploy and operate the Kasm Workspaces platform successfully.

How This Documentation Is Organized

This documentation follows the Diataxis framework. Choose the resource type that matches your task, from initial evaluation through production deployment, operation and integration.