An afternoon to roll out. Nothing new to learn.
LayerT arrives through the tools you already run: your MDM installs it, your directory tells it who’s who, and your people keep using the browser they know.

Rolled out through the tools you already run.
- Your directoryJumpCloud, over SCIM 2.0
LayerT consoleRules, shared accounts, Inbox
- Signed policy to the extensionChrome, pushed by your MDM
- The pageWhere LayerT blocks, asks or fills in
Requests, sign-ins and sessions flow back to the Inbox and audit log.
Deploy
Your MDM pushes a Chrome policy that installs LayerT and pins it to the toolbar. People sign in once with their company identity.
Windows, macOS, LinuxSet policy
Write rules and add shared accounts in the console. Build a rule by pointing at the page.
Signed before it shipsEnforce
The extension watches only what your rules name. It blocks or fills in before anything leaves the browser.
Fails closed on stale policyDecide and prove
Requests land in the Inbox. Every block, approval, sign-in and session goes into one audit log, in plain words.
Kept 365 days by defaultReviewing LayerT for your company?
The architecture pages cover every component, data flow and limit, written for your security team.
Questions a good security lead asks.
Straight answers. If yours isn’t here, ask us in the demo.
Do people have to switch browsers?
No. LayerT is an extension in Chrome, the browser they already use. Your MDM rolls it out, and people sign in once with their company identity.
Does LayerT read everything people do in the browser?
No. It watches only the sites and fields your rules name. Recording is off by default, needs your company to confirm a lawful basis, and tells people on the page when it’s on.
What happens if LayerT can’t reach its servers?
The extension keeps working from its last signed policy. If that policy gets too old, LayerT fails closed: it blocks the actions your rules cover and tells the person why, until it can sync again.
Can people see or copy a shared password?
No. LayerT fills the sign-in form for them, and the password never shows on screen or lands in the browser’s password manager. Revealing one takes a second person, and it’s logged.
Which identity providers does it work with?
LayerT is built for JumpCloud, over SCIM 2.0 and OpenID Connect. Other providers that speak those standards may work, but we haven’t certified them yet.
Is this data loss prevention?
Not in the broad sense. LayerT controls sign-ins and shared accounts. It doesn’t scan file uploads, documents or the clipboard, and we’d rather tell you now than in a security review.
Is LayerT SOC 2 or ISO 27001 certified?
Not yet. LayerT is pre-launch. What it does today is produce the evidence your own auditors ask for: approvals, sign-ins and sessions in one readable log.
How much does it cost?
Pricing is on application. It depends on how many people use LayerT and which parts you need, so tell us about your team in a demo request and we’ll put a proposal together.
Put a layer on the browser.
LayerT is pre-launch and taking demo requests. Tell us what you want to solve, and we’ll show you the product doing it.
