Stop bots, fraud and agentic AI at the edge
Haven Enterprise prevents session takeovers by removing your app's code, DOM and tokens from the browser for the workflows that matter. No code changes. No user installs.
MirrorTab is now Haven Enterprise. Same technology, same team, now under one name alongside the Haven browser extension.
Block bots. Prevent fraud. Stop AI automation.
Automation is the attacker's primary weapon. Bots, fraud tools and agentic AI target logins, transactions and APIs. Haven Enterprise shuts them off at the edge, using the stack you already have in place.
- Account takeovers
- Concurrent session exploitation
- Content scraping
- Automated money movement
- Transaction fraud
- Malicious browser extensions
- Cookie and token theft
- Formjacking
- API abuse
- Data leakage
- AI-powered bots
- Data harvesting
- Script injection
- Agentic AI attacks
- Untrusted device access
Protect your customers against
- Man-in-the-Browser attacks
- Malicious browser extensions
- Cross-site scripting
- Credential stuffing
- Chainloading
- Formjacking
- Click-jacking
- Redirect attacks
- On-path browser attacks
- Directory traversal
- JavaScript injection
- Broken link hijacking
- Server-side request forgery
- Cross-site request forgery
Automation defense without the friction
Haven Enterprise extends the edge you already run: your CDN, WAF, load balancer and fraud platforms.
No DOM exposure
Your app's code, APIs and data never touch the end user's browser.
No data leakage or fraud
Even a compromised device can't leak sensitive data.
No plugins or agents
Fully edge-driven. No code changes. No user installs.
- Triggers from your WAF, bot score, auth state or a feature flag
- Fully server-side. No code, no customer installs
- Works with any edge platform: CDN, WAF, load balancer and more
- Improves performance over low-bandwidth links, tested on Viasat and Starlink
Man-in-the-Browser, explained and stopped
A trojan installs a browser extension that waits for your transaction page, then reads and rewrites the form before it is sent. Your server cannot tell the difference. Here is where the chain breaks.
- On submit, a malicious extension reads every form field through the DOM.The extension never sees the submit or the data.
- The extension rewrites the values through the DOM.There is no DOM to modify.
- The browser sends the tampered form to your server.The extension cannot view or modify network or API traffic.
- Your server accepts the altered request as genuine.Only the true form is accepted, because the DOM is immutable.
How Haven Enterprise compares
Other tools detect or slow automation. Haven Enterprise turns it off.
| Category | What they do | Haven Enterprise |
|---|---|---|
| Enterprise browsers | Built for employees. Requires endpoint adoption. | Built for external web apps and APIs. |
| Bot detection | Detect bots using rules and behavioral models. | Shuts off automation for select product workflows. |
| Account protection | Stop bad logins. | Protects external workflows, post-login. |
| Code obfuscation | Hide front-end code. | Removes code, DOM and tokens entirely. |
| Remote browser isolation | Designed for employee use (email, risky links). | Protects external sensitive workflows. |
The story behind it
Haven Enterprise was built by the CTO and co-founder of Honey, acquired by PayPal.
At Honey, we built the world's most popular browser extension by working deep in the DOM. Now we're flipping the model, removing the DOM entirely to stop automation from bots, fraud and agentic AI.
MirrorTab stands out for its remarkable conceptual simplicity. Their approach to owning the client solves for a missing security control and addresses multiple application security vulnerabilities.
Your web apps and APIs, fully protected.
Zero automation.
See Haven Enterprise on your own workflows in a live demo.
Frequently Asked Questions
Answers for MirrorTab customers and teams evaluating Haven Enterprise.
Book a demo