Architecture
Limits and open work
Every security product has limits. Here are LayerT’s, in one place, so your review doesn’t have to find them the hard way.
Describes LayerT as built on 18 September 2026. Anything not built is labelled.
What LayerT is not
- Not content DLP. LayerT controls sign-ins and shared accounts. It doesn’t scan file uploads, documents or the clipboard, and doesn’t classify data.
- Not a network control. It works inside the browser. Traffic from other apps, other browsers or the command line isn’t its concern.
- Not a zero-knowledge vault. LayerT’s servers can decrypt shared-account passwords and recordings, for approved and logged purposes.
- Not certified. LayerT is pre-launch and holds no SOC 2, ISO 27001 or similar certification. It produces evidence for your own audits.
Coverage
| Area | Today |
|---|---|
| Browsers | Google Chrome on managed profiles. Edge, Firefox and Opera Coming soon. No Safari, mobile or desktop apps |
| Identity providers | Built for JumpCloud. Others speaking SCIM 2.0 and OpenID Connect aren’t certified |
| What rules act on | Form submissions and pastes into the fields a rule names |
| Rule actions | Monitor, block, block with a request, force sign-out. Warn currently behaves like block |
| Shared-account sign-in forms | Most HTML forms, including multi-step ones. Not forms inside cross-origin frames (use the toolbar launcher), drawn on canvas, or inside a site’s closed shadow roots |
Limits of what LayerT does
- An authorised person can read a filled password from the vendor’s field with DevTools. LayerT’s protection is approval, time limits, audit and offboarding, not secrecy from the person signed in.
- Signing out of a shared account clears the whole site’s cookies, including the person’s own session there, if any.
- A remote sign-out takes up to about a minute to reach the browser. Until then the vendor’s session cookie still works there.
- Recordings show page text unless text masking is on for that account, and they’re evidence rather than tamper-proof proof.
- A watermark deters and attributes. DevTools, switching off the extension or a phone camera defeat it.
- Emergency stop and new policy reach browsers on their next sync, within 15 minutes, sooner after navigation.
Still being built
| Item | Status |
|---|---|
| Force-install from a signed extension package, so people can’t remove LayerT | Coming soon |
| Keys held in a managed cloud key service | Coming soon |
| Edge, Firefox and Opera | Coming soon |
| Warn that lets the person continue | Coming soon |
| Email alerts for approvers, and real-time alerts for password reveals and exports | Coming soon |
| Audit log filters, export, per-rule redaction and tamper evidence | Coming soon |
| Database row-level security as a second isolation layer | Coming soon |
| Scoping Team Approvers to their own team | Coming soon |
| Automatic password rotation | Proposed |
| Gateway routing to production | Early access waiting on governance sign-off |
How we keep this page honest. This page is written from the product’s own specs and code, and dated. When something here changes, the date changes with it. The roadmap shows what’s coming next.