KASM WORKSPACES ·
CONTAINER STREAMING

The workspace comes
from the browser.
The data stays
with you.

Your people need access to systems that are none of the endpoint's business. Kasm Workspaces delivers browsers, applications and full desktops as isolated containers into any web browser. No client, no VPN. Nothing is left behind on the device. We plan the platform, introduce it and run it, on Proxmox VE in your own data centre if you want.

Ask for adviceWhat we do
SESSION — EPHEMERAL
START WORK GONE
Every session starts fresh from the container image and is discarded afterwards. Whatever happened inside it does not outlive it.
01 — ADVISEAssess the use caseWhich workspaces, which zones, which obligations. And whether Kasm carries them. We answer that with a proof of concept, not with slides.
02 — TRANSITIONIntroduce without a breakBuild in your infrastructure, connect to your identity management, migrate workspaces in waves. What you have keeps running alongside.
03 — OPERATERun it accountablyPlatform, images and updates from one place, monitored around the clock. As a managed service with binding response times.
01 — THE PLATFORM

Containers instead of VDI machinery.

Kasm delivers working environments as Docker containers rather than as full virtual desktops. That changes the effort: a workspace is an image you version, not a machine you maintain.

WEB-NATIVE

Every browser is the client

No agent and no plug-in, so no client rollout either. An HTML5 browser is enough, including on devices you do not own.

EPHEMERAL

Sessions without a memory

Containers start from the image in seconds and disappear without a trace. Persistent profiles exist only where you want them.

POLICY

Control down to the clipboard

Clipboard, printing, file transfer, watermarking and recording can each be set per group and per workspace.

IDENTITY

SAML, OIDC, LDAP

Connects to the identity management you already run, two-factor included. Access follows the role, not the network.

SOVEREIGN

From your own data centre to air-gapped

Run it on your premises, in the cloud or mixed, including networks with no internet access. Your data does not leave your infrastructure.

OPEN

Open-source core, a real API

KasmVNC is licensed under GPL 2.0, the workspace images are open source, and the platform is driven by a REST API. You can see what you are running.

WORKS WITH PROXMOX VE

Kasm runs virtualized on Proxmox VE, on a single server or spread across VMs in a cluster. Platform and virtualization then sit with one party, which is us. More on Proxmox VE →

02 — SYSTEM ARCHITECTURE

Few components, clear roles.

The endpoint needs nothing but a browser. The control plane hands out the sessions, the agents run them. This carries from a single server to several zones across sites.

CLIENTAny modern browser HTML5 and WebSocket, no client, no plug-in
CONTROL PLANE
Web app and APIInterface, sign-in, sessions ManagerScheduling and autoscaling PostgreSQL and RedisState and messaging
Identity comes from outside: LDAP or Active Directory, SAML 2.0, OIDC. A group mapping decides which workspaces and policies a person gets.
DOCKER AGENTS Container workspaces Browsers, terminals, development environments, full Linux desktops. KasmVNC streams every container into the browser over HTML5.
SERVER POOLS — OPTIONAL Fixed and autoscaled VMs Windows and Linux VMs over RDP, VNC or SSH, on Proxmox VE for instance. Zones and pools group the agents by site and by load.
03 — OPERATING MODES

Three routes, one stack.

You do not have to choose. Containers take over where they are stronger, Windows stays connected, and on Proxmox VE the capacity grows with demand.

MODE 1 — CONTAINERS

Applications and desktops, ephemeral

A single application in a tab or a full Linux desktop. Choose from more than 50 maintained Kasm images, or build your own via Dockerfile. Starts in seconds, with a GPU where you need one.

MODE 2 — SERVER POOLS

Windows and what you have, over RDP

Existing Windows and Linux VMs come in as a pool, with the same interface and the same policies as the containers. The Windows workspaces do not have to move all at once.

MODE 3 — AUTOSCALING

Elastic on Proxmox VE

Kasm clones agent VMs through the Proxmox API when demand rises and clears them away when it falls. Proxmox and Kasm have been official solution partners since April 2026.

WHAT CHANGES ON LICENSING

Proxmox VE is licensed per CPU socket, not per core and with no minimum. Kasm bills per named user or per concurrent session, and Linux containers need no Windows CALs where the use case allows it. Whether that works out cheaper for you depends on how many of your people work at the same time. We do that calculation with you before you commit.

04 — ZERO TRUST

The endpoint may be untrusted.
The session never is.

Kasm turns the security model around. Instead of hardening endpoints and opening networks, the work stays in the data centre. Only rendered pixels go out.

No direct network accessThe workspace runs inside the target network, the user only sees the picture stream. VPN tunnels into the internal network go away, and their attack surface with them.
Isolated browser sessionsRisky web access runs in a container that is discarded afterwards, not on the endpoint. Any damage stays inside the session.
Unmanaged devices, BYOD and contractorsExternal people work through the browser on controlled workspaces, with no device hardening and nothing to install, recorded where that is needed.
Evidence for audits and obligationsSession logs, recordings and policies produce the evidence that NIS2, DORA and BSI reviews ask for. The data stays in your own house.
05 — WHY SYSFACTS

Access is not a product here.
It is part of the infrastructure.

Anyone building access into critical zones has to understand the zones: segmentation, identity, virtualization and operations. That is exactly our field, from separating IT and OT to critical-infrastructure obligations. For us Kasm is the missing piece between the zero-trust ambition and the working day.

06 — WHAT WE DO

Kasm partner in the German-speaking region.

Enterprise subscriptions, support and advice from one place, from the architecture through to accountable operation. You have one point of contact instead of three vendors.

01 — PLAN

Architecture and migration planning

Sizing, zones and pools, the autoscaling design, and the plan for replacing an existing VDI estate. What comes out is an architecture your team understands and supports.

02 — INTRODUCE

Commissioning and migration

Installation, directory and SSO integration, autoscaling on Proxmox VE, the image pipeline. Through to going live, in waves and alongside what you already run.

03 — CARRY

Operations and subscriptions

Support and operational cover, updates and lifecycle. Kasm Enterprise subscriptions come through us, with binding response times.

07 — WHERE IT IS USED

Where Kasm works for our customers.

Four patterns from environments where downtime and data leaving the building are not options.

OT AND PRODUCTION

Maintenance access into the OT zone

Vendors and maintenance crews reach control-room and engineering systems through an isolated workspace inside the zone. No VPN tunnel across the network. Every session is logged, and recorded where you want it.

CRITICAL INFRASTRUCTURE AND PUBLIC SECTOR

Safe internet for protected networks

People in segregated networks browse through isolated container sessions. The internal network never touches the internet directly. It also runs with no internet access at all.

CONTRACTORS AND M&A

Workspaces for contractors and handovers

External teams, carve-outs and acquisitions get a controlled workspace within hours, with no devices to ship. At offboarding you switch off the access, and the workspace goes with it.

REPLACING VDI

The lighter route to a remote workspace

Where classic VDI has become too heavy and too expensive, container streaming delivers desktops and applications with a much smaller footprint. What that means for your estate is something we work out in the first call.

08 — NEXT STEP

Let us talk about your access.

30 minutes on your zones, your external people and your obligations, and on the question of whether Kasm carries them. If it does not, we say so in the first call and not in the third.

30 MINUTES · NO CHARGE

Ask for advice

No commitment, and with an engineer rather than a salesperson. Afterwards you know whether a proof of concept is worth it.Arrange a call+49 221 670572 0 · experts@sysfacts.com
Kasm Workspaces™ is a trademark of Kasm Technologies LLC. Proxmox® and the Proxmox logo are registered trademarks of Proxmox Server Solutions GmbH.