Overview
The Enigm Link secure browser is designed to:- Open a controlled browsing session.
- Run within the Enigm Link protected environment.
- Require official device validation.
- Require VPN validation before protected state is displayed.
- Keep protected-state indicators visible to the user.
- Support update and device lifecycle policy.
Protected State Model
Enigm Link should show a protected state only when:- The official USB is validated.
- The environment is prepared.
- VPN validation succeeds.
- Required update and device policy checks are satisfied.
VPN Requirement
VPN validation is a security requirement for Enigm Link protected state. The update path and secure environment are designed around VPN-gated access:- Update traffic should use the authorized VPN path.
- Protected state depends on VPN validation.
- The user should not be led to believe that the environment is protected before validation succeeds.
- If required security configuration is unavailable, protected workflows should fail closed.
Browser Session Boundary
The browser session is an Enigm Link environment boundary, not a guarantee that every website, external service, or endpoint condition is trustworthy. Security assumptions remain affected by:- Host device state.
- User behavior.
- Network availability.
- Website behavior.
- Credential disclosure.
- External downloads.
- Platform permissions.