Browser security

Stop the attack
before the click costs you.

Most attacks on a small firm now arrive through the browser — a fake login, a page that talks someone into pasting a command, an add-on nobody remembers installing. Yazoul blocks them in the browser, before anything runs on the machine.

Works in Chrome, Edge and Brave. From $125 a month.

Why your current tools miss this

Nothing here replaces your antivirus or your spam filter. It covers the gap between them — the browser, where the damage actually starts.

Your spam filter

Catches the email. Not the link someone opens from a text, a chat, or a search result.

The browser

Where the fake page loads, the password gets typed and the session gets taken. Almost nothing watches it.

Your antivirus

Catches the file once it runs. For a pasted command, that is after the staff member has already run it.

What it stops

159 detection rules covering 26 recognised attack techniques. These four are the ones that actually turn up.

Fake sign-in pages

A page that looks exactly like Microsoft 365, QuickBooks, Xero or your bank, on an address nobody checks. Staff sign in and the credentials go straight to the attacker.

Blocked before the page finishes loading. Nobody types anything into it.

Copy-and-paste attacks

A page claims a document will not open and asks the user to paste something into Windows to fix it. What they paste installs malware, in their own name, with their own permissions.

The copy never happens. The page cannot put the command on the clipboard in the first place.

Stolen sessions

One visit to the wrong site and the tokens that keep staff signed in are taken. The attacker walks into email or accounting as them, without ever needing a password.

Caught as it happens, and the theft is stopped in the page.

Bad browser add-ons

An extension installed from outside the store, quietly reading what staff type and where they go. Most people never look at their extension list.

Every add-on is inventoried and anything installed outside the store is flagged.

Getting it running

An afternoon, not a project. If someone already manages your browsers, it is minutes.

1

Push it out

It installs through the browser settings your IT already manages. Nobody clicks anything, nobody types a licence key.

2

It runs quietly

No training, no prompts, no new habits. Staff only ever see it when it stops something.

3

You see what it caught

A dashboard showing what was blocked, on which machine, and what to do next. Exportable when someone asks for evidence.

What it never sees

Something that watches the browser could, in principle, watch everything. That is the fair question, so here is the full answer rather than a reassuring phrase. Checks happen on the machine itself, and a page that triggers nothing is never sent anywhere.

  • The content of the pages your staff visit
  • Their browsing history — a page that triggers nothing is never reported
  • Passwords or anything typed into a form
  • Keystrokes or screenshots
  • Anything from tabs unrelated to a block

Set out in full in the privacy policy.

What it costs

One price per size band, published. $125 a month covers up to 25 people, rising in steps to $450 at 100. Every band gets the same protection — they differ by size, not by what you get. Larger organisations and IT providers are priced on a call.

We also run a free threat intelligence service, published daily. The detection rules in this product come out of that work — read it here.

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.