💻Coming to SF Tech Week?We went through all 300 events so you don't have to. Here is where we will be.Read the guide
💻Coming to SF Tech Week?300 events, one guide.
Read the guide
Formerly MirrorTab

Stop bots, fraud and agentic AI at the edge

Haven Enterprise prevents session takeovers by removing your app's code, DOM and tokens from the browser for the workflows that matter. No code changes. No user installs.

MirrorTab is now Haven Enterprise. Same technology, same team, now under one name alongside the Haven browser extension.

Block bots. Prevent fraud. Stop AI automation.

Automation is the attacker's primary weapon. Bots, fraud tools and agentic AI target logins, transactions and APIs. Haven Enterprise shuts them off at the edge, using the stack you already have in place.

  • Account takeovers
  • Concurrent session exploitation
  • Content scraping
  • Automated money movement
  • Transaction fraud
  • Malicious browser extensions
  • Cookie and token theft
  • Formjacking
  • API abuse
  • Data leakage
  • AI-powered bots
  • Data harvesting
  • Script injection
  • Agentic AI attacks
  • Untrusted device access

Protect your customers against

  • Man-in-the-Browser attacks
  • Malicious browser extensions
  • Cross-site scripting
  • Credential stuffing
  • Chainloading
  • Formjacking
  • Click-jacking
  • Redirect attacks
  • On-path browser attacks
  • Directory traversal
  • JavaScript injection
  • Broken link hijacking
  • Server-side request forgery
  • Cross-site request forgery

Automation defense without the friction

Haven Enterprise extends the edge you already run: your CDN, WAF, load balancer and fraud platforms.

No DOM exposure

Your app's code, APIs and data never touch the end user's browser.

No data leakage or fraud

Even a compromised device can't leak sensitive data.

No plugins or agents

Fully edge-driven. No code changes. No user installs.

  • Triggers from your WAF, bot score, auth state or a feature flag
  • Fully server-side. No code, no customer installs
  • Works with any edge platform: CDN, WAF, load balancer and more
  • Improves performance over low-bandwidth links, tested on Viasat and Starlink

Man-in-the-Browser, explained and stopped

A trojan installs a browser extension that waits for your transaction page, then reads and rewrites the form before it is sent. Your server cannot tell the difference. Here is where the chain breaks.

  1. On submit, a malicious extension reads every form field through the DOM.The extension never sees the submit or the data.
  2. The extension rewrites the values through the DOM.There is no DOM to modify.
  3. The browser sends the tampered form to your server.The extension cannot view or modify network or API traffic.
  4. Your server accepts the altered request as genuine.Only the true form is accepted, because the DOM is immutable.

How Haven Enterprise compares

Other tools detect or slow automation. Haven Enterprise turns it off.

CategoryWhat they doHaven Enterprise
Enterprise browsersBuilt for employees. Requires endpoint adoption.Built for external web apps and APIs.
Bot detectionDetect bots using rules and behavioral models.Shuts off automation for select product workflows.
Account protectionStop bad logins.Protects external workflows, post-login.
Code obfuscationHide front-end code.Removes code, DOM and tokens entirely.
Remote browser isolationDesigned for employee use (email, risky links).Protects external sensitive workflows.

The story behind it

Haven Enterprise was built by the CTO and co-founder of Honey, acquired by PayPal.

At Honey, we built the world's most popular browser extension by working deep in the DOM. Now we're flipping the model, removing the DOM entirely to stop automation from bots, fraud and agentic AI.
MirrorTab stands out for its remarkable conceptual simplicity. Their approach to owning the client solves for a missing security control and addresses multiple application security vulnerabilities.
Joseph FinsterwaldFounder/President, Abberant.io; former CTO, First Republic Bank

Your web apps and APIs, fully protected.
Zero automation.

See Haven Enterprise on your own workflows in a live demo.

Frequently Asked Questions

Answers for MirrorTab customers and teams evaluating Haven Enterprise.

Book a demo
Yes. MirrorTab is now Haven Enterprise. It is the same technology and the same team, under the Haven name. The company behind it is still MirrorTab, Inc.
No. Haven Enterprise is fully server-side and runs at your edge. There is nothing for your users to install and no change to your application code.
The Haven extension protects people as they browse. Haven Enterprise protects your web application: it keeps your code, DOM and tokens out of the end browser for the workflows you choose, so bots, fraud tools and agentic AI have nothing to automate.
Any edge platform, including CDNs, WAFs and load balancers such as Cloudflare, Akamai, Fastly and HAProxy. It extends the stack you already have rather than replacing it.
You choose. Haven Enterprise switches on for select workflows, such as login, money movement or account changes, and can be triggered by your WAF, a bot score, the user’s auth state or a feature flag.