Share the account. Never the password.

A security layer in the browser your team already uses. People sign in to shared accounts without ever seeing a password.

Live demo

    A sheet of teal paper lifting off a stack of cream pages.

    No new browser. Nothing new to learn. Just a layer.

    LayerT runs inside Chrome, the browser your people already use. It stays out of the way until a sign-in or a shared account needs it.

    Half the team knows the password. That’s the problem.

    Shared logins live in spreadsheets and chat threads. When someone leaves, you change every password and hope you found them all.

    A fan of copied paper keys next to a single teal key set apart.
    Without LayerTWith LayerT
    Drag to compare. Fictional accounts and dummy passwords.Someone leaves? Remove them in your directory, and their access goes with them.

    Try it

    Type an email. Watch LayerT decide.

    This is a fictional mail site on an Acme Corp work laptop. Try a work address, then a personal one. Your network sees the same thing both times. LayerT doesn’t.

    Sign in

    Fictional mail, for this demo
    Signed in. A work account, so LayerT stays out of the way.
    Try itThe block card here is a picture of the real one.

    Nothing you type leaves this page.

    What your network sees

    Destination
    accounts.postbox.example:443
    Traffic
    Encrypted. The form’s contents aren’t visible.
    Whose account
    Unknown
    An ordinary website. Whatever you type, it goes through.

    What LayerT sees

    Page
    Sign-in form on accounts.postbox.example
    Typed address
    Nothing yet
    Person
    Alice Chen, Finance (from your directory)
    Rule
    Personal sign-ins on work laptops
    Waiting for a sign-in.Press Next to see what LayerT does.That isn’t an email address yet. Try one of the examples.A work account. LayerT lets the sign-in through and stays out of the way.Stopped before it left the browser. Alice can ask for access if she needs it for work.

    The product

    Four jobs, done inside the page.

    Scroll through four real LayerT flows, rebuilt with dummy data. Click any step to jump to it.

    Sign-in control

    See the last mile.

    Block a personal sign-in before it leaves the browser. People who need it can ask.

    Sign-in control

    A personal address is typed

    Alice types her personal address into a mail sign-in on her work laptop and presses Next.

    Stopped in the page

    LayerT checks what she typed against your rules and stops the sign-in before the request leaves the browser.

    She asks for access

    She says why she needs it. The prompt updates by itself when an approver decides.

    Approved for 1 hour

    An approver says yes and picks how long. Alice presses Try again. Every step lands in the audit log.

    DemoWhat your team sees on a blocked sign-in

    Shared accounts

    Share access, not passwords.

    Sensitive accounts need an approver first, and every session ends on time.

    Shared accounts

    Opens ready to search

    The LayerT launcher opens from the toolbar with search focused. Each account has one button that does what it says.

    Ask in place

    Vendor Billing Admin needs an approver. Alice gives a reason and sees who decides and how long the session lasts.

    Waiting on an approver

    The request waits in the launcher and in the approver’s Inbox. Accounts that one person holds at a time say who has them.

    Approved and signed in

    LayerT signs Alice in without showing her the password. The session ends on time, and LayerT signs her out.

    DemoThe LayerT launcher in the browser toolbar

    Session governance

    Know who did what.

    Every shared-account session in one list. Recording is off until you turn it on.

    Session governance

    Every session, live first

    Every time someone used a shared account, with live sessions at the top. Recorded sessions offer Watch.

    Watch, with typing masked

    Watching needs a reason and is logged against your name. It’s a replay of the page, not a video, and what people typed is masked.

    End it remotely

    An admin ends Alice’s live session from the console.

    Her browser signs out

    Within about a minute, LayerT signs Alice out of the vendor site. She’s told an administrator ended it, not who or why.

    DemoThe admin console

    The console

    Decide in one Inbox.

    The people who configure aren’t the people who grant exceptions.

    The console

    Everything waiting on you

    Shared-account requests, bypasses and rule changes in one list. The badge counts only what you can act on.

    Decide in place

    Pick how long: one attempt, 15 minutes, up to 24 hours. Permanent exceptions belong to Compliance, not IT.

    The badge counts down

    Bob sees the answer in the page he was blocked on, or as a desktop notification if he left. The decision is in the audit log.

    DemoThe admin console Inbox

    Why not just use what you already have?

    Fair question. Each of these does its own job well. None of them sits in the page at the moment someone signs in.

    “Our network security covers this.”

    Network and cloud security tools

    They seeEncrypted traffic to a website.
    LayerT seesThe sign-in form in the page, and whose account it is.

    “We could switch to an enterprise browser.”

    Enterprise browsers

    They askEveryone moves to a new browser, and you roll it out.
    LayerTWorks inside the browser your team already uses.

    “Our password manager can share logins.”

    Password managers with sharing

    They shareThe password. People can see it and copy it.
    LayerT sharesAccess. It signs people in and ends the session on time.

    “Isn’t this privileged access management?”

    Privileged access suites

    They bringHeavy infrastructure, built for large enterprises.
    LayerT bringsA browser layer, built for SaaS-heavy teams.

    Built on open standards. Tested like it matters.

    LayerT speaks the protocols your stack already uses, and its core flows are tested end to end in a real browser.

    Works with

    • BrowsersA Manifest V3 extension, rolled out by your MDM with Chrome enterprise policy templates for Windows, macOS and Linux.
      • Google ChromeToday
      • Microsoft EdgeComing soon
      • Mozilla FirefoxComing soon
      • OperaComing soon
    • JumpCloud Built forDirectory sync over SCIM 2.0. Console sign-in over OpenID Connect.
    • Your MDM Templates readyPushes the Chrome policy that installs LayerT and pins it to the toolbar.
    • Built-in sign-in rulesPersonal Google sign-ins, Telegram Web and WhatsApp Web, ready on day one. Point at any other site to write your own rule.
    • Other identity providers Not yet certifiedOkta, Microsoft Entra ID and Google Workspace speak the same standards (SCIM 2.0 and OpenID Connect), but we haven’t certified them yet.
    SCIM 2.0OpenID ConnectEd25519AES-256-GCMTOTP, RFC 6238Manifest V3rrweb replayS3-compatible storage

    Tested with

    As of 18 September 2026.

    • 2,450+Automated unit testsAcross the extension, the console and the design system.
    • 32End-to-end browser scenariosReal Chromium with the real extension loaded. All green on 18 September.
    • 363Numbered requirementsWritten down across 10 product specs before the code.
    • Colour contrast checked by testsEvery colour pair LayerT draws meets WCAG AA, checked automatically.

    End-to-end runs use fictional vendor sites and faithful stand-ins for the sign-in pages LayerT targets.

    Ed25519-signed policyAES-256-GCM, a fresh key per secretFails closed on stale policyRemote sign-out in about a minute365-day audit log6 built-in rolesAuthenticator secrets stay on the serverRecording off by default

    Rolled out through the tools you already run.

    Your directory feeds the LayerT console. The console publishes signed policy to the LayerT extension in Chrome, which acts in the page. Requests, sign-ins and sessions flow back to the console's Inbox and audit log.Your directoryJumpCloud, over SCIMLayerT consoleRules, accounts, InboxLayerT extensionChrome, via your MDMThe pageSign-ins, vendor sitespeople, groupssigned policyacts in pagerequests, sign-ins, sessions → Inbox and audit log
    1. Your directoryJumpCloud, over SCIM 2.0
    2. LayerT consoleRules, shared accounts, Inbox
    3. Signed policy to the extensionChrome, pushed by your MDM
    4. The pageWhere LayerT blocks, asks or fills in

    Requests, sign-ins and sessions flow back to the Inbox and audit log.

    Deploy

    Your MDM pushes a Chrome policy that installs LayerT and pins it to the toolbar. People sign in once with their company identity.

    Windows, macOS, Linux

    Set policy

    Write rules and add shared accounts in the console. Build a rule by pointing at the page.

    Signed before it ships

    Enforce

    The extension watches only what your rules name. It blocks or fills in before anything leaves the browser.

    Fails closed on stale policy

    Decide and prove

    Requests land in the Inbox. Every block, approval, sign-in and session goes into one audit log, in plain words.

    Kept 365 days by default

    Security

    What’s true today, and what isn’t yet.

    How it’s built
    • Signed policy, checked before it’s usedRules ship signed with Ed25519, and the browser’s own crypto checks them. Stale or tampered policy blocks rather than lets things through.
    • Every secret sealed with its own keyAES-256-GCM envelope encryption. Recordings are encrypted on the device, with a key made for that session.
    • Authenticator secrets stay on the serverCodes are made server-side. Revealing a password takes a second person, and it’s logged.
    • Separation of dutiesIT configures. Compliance grants lasting exceptions. Nobody approves their own request.
    Limits, stated plainly
    • Chrome todayEdge, Firefox and Opera are coming. No Safari, mobile or desktop apps.
    • Sign-in control, not content scanningLayerT doesn’t inspect file uploads, documents or the clipboard.
    • Recording is off by defaultYour company confirms a lawful basis first, people are told on the page, and what they type is masked. A watermark deters and attributes; it can’t stop a phone camera.
    • Pre-launch, with no certifications yetLayerT produces the evidence your auditors ask for. Keys held in a cloud key service are on the roadmap.

    How to tell a real LayerT prompt

    LayerT never asks for your password. And when it’s on the page, its icon in your toolbar lights up. A website can copy a prompt, but it can’t draw in your toolbar.

    The dot is on while LayerT is on the page

    What’s next.

    Everything above this section is built. These are on the way, each labelled with exactly where it stands.

    Early accessEarly access
    Gateway routing

    Send a shared account through a LayerT gateway, so the vendor sees one stable company IP address.

    Available to pilot teams once our internal sign-off lands.

    Coming soonIn progress
    Edge, Firefox and Opera

    LayerT in more browsers, each with its own enterprise policy templates.

    Force-install from a signed package

    So people can’t remove LayerT from a managed browser.

    Keys in a cloud key service

    Encryption keys wrapped and policy signed by a managed KMS.

    Extra sign-in fields and notes

    Account ID, organisation ID and PIN fields, plus notes on each shared account.

    See the current authenticator code

    For the person signed in, with a countdown. Every view is logged.

    Email alerts for approvers

    Today, requests arrive in the console Inbox and the extension.

    ProposedDesigning
    Email sign-in codes

    For shared accounts whose vendor emails a code at sign-in.

    Device-trust handling

    For vendors that ask to trust a new device.

    Self-installing gateways

    Stand up a gateway in your own region in a few clicks.

    Routing map

    See who reaches which account through which route, at a glance.

    Console home

    What needs you and what’s happening now, on one page.

    Want a say in the order? Pilot teams shape it. Request a demo and tell us what you need first.

    Questions a good security lead asks.

    Straight answers. If yours isn’t here, ask us in the demo.

    Do people have to switch browsers?

    No. LayerT is an extension in Chrome, the browser they already use. Your MDM rolls it out, and people sign in once with their company identity.

    Does LayerT read everything people do in the browser?

    No. It watches only the sites and fields your rules name. Recording is off by default, needs your company to confirm a lawful basis, and tells people on the page when it’s on.

    What happens if LayerT can’t reach its servers?

    The extension keeps working from its last signed policy. If that policy gets too old, LayerT fails closed: it blocks the actions your rules cover and tells the person why, until it can sync again.

    Can people see or copy a shared password?

    No. LayerT fills the sign-in form for them, and the password never shows on screen or lands in the browser’s password manager. Revealing one takes a second person, and it’s logged.

    Which identity providers does it work with?

    LayerT is built for JumpCloud, over SCIM 2.0 and OpenID Connect. Other providers that speak those standards may work, but we haven’t certified them yet.

    Is this data loss prevention?

    Not in the broad sense. LayerT controls sign-ins and shared accounts. It doesn’t scan file uploads, documents or the clipboard, and we’d rather tell you now than in a security review.

    Is LayerT SOC 2 or ISO 27001 certified?

    Not yet. LayerT is pre-launch. What it does today is produce the evidence your own auditors ask for: approvals, sign-ins and sessions in one readable log.

    How much does it cost?

    Pricing is on application. It depends on how many people use LayerT and which parts you need, so tell us about your team in a demo request and we’ll put a proposal together.

    Put a layer on the browser.

    LayerT is pre-launch and taking demo requests. Tell us what you want to solve, and we’ll show you the product doing it.

    A teal paper sheet with a window cut out, lifted over a cream paper browser window.