Plans & Pricing
Every plan runs in your browser with nothing to install.
What changes is how long you get, what you can run, and what stays when you leave.
| LITE | PRO | ULTRA | |
|---|---|---|---|
| Session and Usage Limits | |||
| Session Duration | 1 hour | 8 hours | 24 hours |
| Inactivity logout | 5 minutes | — | — |
| Monthly usage | 20 hours | Unlimited | Unlimited |
| Compute (CPU and RAM) | Standard | 2x (v2.1) | 2x (v2.1) |
| Secure Authentication and Anti-Hijacking | |||
| Invisible Passwordless MFA (MasterKey) | ✓ | ✓ | ✓ |
| Passkeys Proof-of-Presence (v2.1) | ✓ | ✓ | ✓ |
| Network Resilience and Recovery Sessions continue during network dropouts and require re-authentication (and Proof-of-Presence in v2.1). | 5 minutes | 15 minutes | 1 hour |
| Invisible Encrypted Keyboard + Mouse Pad | ✓ | ✓ | ✓ |
| Workspace | |||
| Temporary workspace A completely fresh, empty session each time where nothing is saved. | ✓ | ✓ | ✓ |
| Persistent workspace Settings, favorites, and history remembered (with the option to reset) | ✓ | ✓ | ✓ |
| File Storage | |||
| Temporary file storage (for the current session) | ✓ | ✓ | ✓ |
| Persistent file storage (Permanent encrypted vault for files and keys) (v2.1) | — | — | ✓ |
| Shared deal rooms with other members ★ Signature ULTRA Feature (v2.2) | — | — | ✓ |
| Desktop Applications | |||
| Image viewer | ✓ | ✓ | ✓ |
| PDF viewer | ✓ | ✓ | ✓ |
| Office Documents (LibreOffice for editing Word, Excel, PowerPoint files) | — | ✓ | ✓ |
| x3270 terminal emulator (IBM mainframes) | ✓ | ✓ | ✓ |
| Browsers | |||
| Chrome Your favorites, plugins, settings, and password manager. | ✓ | ✓ | ✓ |
| Firefox Your favorites, plugins, settings, and password manager. | ✓ | ✓ | ✓ |
| Brave Your favorites, plugins, settings, and password manager. | ✓ | ✓ | ✓ |
| File Transfers and Clipboard | |||
| Import Click and drag into the remote desktop | ✓ | ✓ | ✓ |
| Export Copy back to your local machine | — | ✓ | ✓ |
| One-way Local Clipboard (paste from your local desktop into the remote desktop) | ✓ | ✓ | ✓ |
| Isolated Remote Clipboard (for security reasons it cannot be seen by, or paste back to, your local machine) | ✓ | ✓ | ✓ |
| Printing | |||
| Print to PDF (Generates a PDF and sends it back to your local machine) | ✓ | ✓ | ✓ |
| Password Managers | |||
| Install browser based password managers (LastPass, 1Password, Bitwarden, Dashlane, etc.) | ✓ | ✓ | ✓ |
| Copy-paste from your local password manager (except via Firefox) | ✓ | ✓ | ✓ |
| Cryptocurrency Wallets | |||
| Software wallets | |||
| Install your own browser plugin wallet (MetaMask, Trust Wallet, Phantom, Rabby, etc.) | ✓ | ✓ | ✓ |
| Exodus (desktop) | ✓ | ✓ | ✓ |
| Sparrow (desktop) | ✓ | ✓ | ✓ |
| Electrum (desktop) | ✓ | ✓ | ✓ |
| Wasabi (desktop) | ✓ | ✓ | ✓ |
| Hardware wallet support (v2.1) | |||
| Ledger Live (desktop) | — | ✓ | ✓ |
| Trezor Suite (desktop) | — | ✓ | ✓ |
| Blockstream Green (desktop) | — | ✓ | ✓ |
| Bitbox App (desktop) | — | ✓ | ✓ |
| Camera Pass-Through (for air-gapped wallets via QR code) | — | — | ✓ |
| Features marked with a version number are planned for upcoming releases and are not yet available. Roadmap plans may change. | |||
| Take control of your own cybersecurity. | |||
Choose Your Plan
LITE
- 1-hour sessions | 5-min inactivity logout
- Limited to 20 hours / month
- Standard compute
- Temporary file storage during session
- File Import (No Export)
- Essential apps for browsing and images
- Software wallets, browser and desktop
PRO
- 8-hour sessions | No inactivity logout
- Unlimited hours
- 2x compute (CPU and RAM) (v2.1)
- Temporary file storage during session
- File Import and Export
- Adds office and productivity apps
- Adds hardware wallet support (v2.1)
ULTRA
- 24-hour sessions | No inactivity logout
- Unlimited hours
- 2x compute (CPU and RAM) (v2.1)
- Permanent encrypted vault for files and keys
- File Import and Export
- Adds office and productivity apps
- Adds hardware wallets + air-gapped QR (v2.1)
- Shared deal rooms with other members (v2.2)
Frequently Asked Questions
Every login builds a pristine virtual workspace in the cloud, isolated from your device and invisible from the internet. Your session runs there, not on your computer. What reaches your browser is a stream of pixels over an encrypted connection, not code, so malware on your device has nothing to intercept and no path to cross-infect.
Passwords and recovery phrases are typed on the Invisible Encrypted Keyboard, an illusion created on your phone’s browser by the remote virtual workspace. On a laptop or tablet, scan the QR code on the login screen. Keyloggers on your device, or on your phone, see nothing but asterisks and encoded data they can never decipher. The temporary encryption keys are never released by the virtual workspace.
The virtual workspace is destroyed at logout. What survives is your choice. (i) Temporary Workspace is built empty and keeps nothing. (ii) Your Workspace remembers your settings, favorites, history and browser plugins, held encrypted and opened with your phone. Factory Reset returns it to an empty machine at any time.
You can paste into the remote machine from your local clipboard, or type into it with the Invisible Encrypted Keyboard. You cannot paste out. For security, your local device cannot read the remote machine’s clipboard. Files transfer both ways, depending on your plan.
A traditional VPN only encrypts your internet traffic. It does not stop malware, phishing, or keyloggers on your device. A Fortified VPN, means:
✔ You work inside a disposable, remote machine, not your own device.
✔ Your activity is isolated from your device, so malware on it cannot can access your session.
✔ Keyloggers and MitB attacks are defeated because credentials never pass through your local device.
99% of cyber attacks target end user devices. VanishingPoint assumes yours is already compromised. Your session runs on a remote machine and your credentials are typed on the Invisible Encrypted Keyboard, so nothing sensitive touches your local machine.
✔ Keyloggers. Passwords are never typed into your device, so keyloggers have nothing to capture.
✔ Man-in-the-Browser. Your session runs in the remote browser. An attack on your local browser has no session to intercept.
✔ Infostealers. Credentials, cookies and session tokens stay inside the remote machine, out of reach of malware on your device.
✔ Phishing links and attachments. They open inside the disposable machine, not on your local computer.
✔ Ransomware. Nothing you open in a remote session can reach your local files.
✔ Tracking. Your browsing activity is invisible to tracking on your device or local network.
Isolation cannot stop social engineering. If someone persuades you to type your credentials into a fake site, no technology prevents that.
That is your choice at every login.
Temporary Workspace stores nothing. When you log out or disconnect, the workspace is destroyed along with everything in it. No files, no cookies, no history.
Your Workspace remembers what you choose to keep: settings, favorites, history and plugins. Between sessions it is held encrypted on our servers. The key that opens it is held by MasterKey, BankVault’s patented passwordless MFA technology, in a decentralized protocol that releases it only when your phone initiates login. We store ciphertext. Nobody here can open it, and neither can an attacker who steals our storage. How it works is set out in Before Your Session.
While you are logged in, the workspace is open inside your remote machine so you can use it. Log out or disconnect and the machine is destroyed and the workspace returns to ciphertext.
Lose your phone and you re-enroll with your recovery code. There is no other way in, for you or for anyone else.
Factory Reset wipes Your Workspace back to an empty machine whenever you choose.
From v2.1, Proof-of-Presence adds a further check: your workspace decrypts only when you and your phone are present together.
Not by us, and not where we can read it.
You type it on the Invisible Encrypted Keyboard. Each keystroke is encrypted on your phone and decrypted only inside the remote machine, where your wallet software uses it. It never passes through your computer, and it never lands on your device.
In Temporary Workspace it is destroyed with the machine when you log out. In Your Workspace, if a wallet extension you installed keeps keys, they may be held encrypted like everything else there, and only your phone can decrypt them.
For a wallet recovery you will not repeat, use Temporary Workspace.
No, and what matters more is that we cannot open what you leave behind.
Between sessions your workspace is ciphertext. The key that opens it sits in MasterKey, held in a decentralized protocol that releases it only when your phone initiates login. Nobody here can read your data, whether by curiosity, by mistake, or under instruction. That is a property of the design, not a policy.
While you are logged in, your session runs on a machine we host, as with any hosted service. The stream between that machine and your browser is encrypted. The Invisible Encrypted Keyboard encrypts each keystroke on your phone and decrypts it only inside the machine, so a password is readable in exactly one place. Our staff do not watch sessions and have no console into a running machine.
We host on AWS, Google Cloud, Equinix and OVHcloud, the same providers the major banks now trust with their own systems.
We can only hand over what we hold. Our storage holds your workspace and its data key, both as ciphertext. The key that opens them sits in MasterKey, in a decentralized protocol that will not release it without your phone initating the process. An attacker who copies our storage gets ciphertext. A court order gets ciphertext. Neither gets a usable key, because no single system holds one.
Temporary Workspace leaves nothing to hand over at all.
To re-enroll a new phone, a link is sent to the email address you signed up with. You then enter your secret recovery code on the Invisible Encrypted Keyboard, and your access is rebuilt. There is no other way in, for you or anyone else. Without both, Your Workspace cannot be recovered, by you or by us.
Keep the recovery code somewhere that is not your phone.
From v2.1, Passkeys let you enroll additional backup devices, each requiring your Proof-of-Presence.
It runs in a browser, so it opens on any device with nothing to install. But it is a full desktop, built for a desktop or laptop screen. A phone screen is too small to work in.
Your phone is the second device. It logs you in and becomes the Invisible Encrypted Keyboard. Every session needs both.
The computer can be your own, a borrowed one, or one you do not trust. Nothing from the session touches it. It can even run on an internet TV, with the phone as a real keyboard instead of the one on the remote.
Files move into your session on every plan by drag-and-drop. What moves out depends on your plan.
- LITE: drag and drop files into the remote workspace. Nothing downloads back to your device. Print, and the session hands a PDF back to your device. Or email a document to yourself from inside the session.
- PRO: drag and drop files in. Click, select download, and they come back to your device.
- ULTRA: upload and download as on PRO, plus a permanent encrypted vault for your files. From v2.2, share it with other users.
On every plan the clipboard is one-way. Paste in, not out. No software to install on any plan.
Version 2.1, the next release.
PRO and ULTRA gain hardware wallet support over USB for Ledger Live, Trezor Suite, Blockstream Green and BitBoxApp.
ULTRA also gains an air-gapped path: your wallet’s QR code is read through your camera and never connects to the session by cable.
Software wallets run today on every plan.
If you’re concerned about network sniffing, or firewalls throttling or blocking the internet, then travelers will find their mobile’s global roaming provides clear internet. The remote virtual machine sets up an encrypted connection with your devices browser, equivalent to a VPN. You then conduct your work on the remote virtual machine. Providing you use the invisible encrypted keyboard (on desktops by scanning the QR code) then there is no single attack surface to intecept making it incredibly difficult to compromise. On mobiles the invisible encrypted keyboard is there by default. On password fields it steps up security further by slightly shuffling the keyboard characters left or right. The background changes to red to alert the user that the keyboard has changed slightly to protect them.
Yes, as long as your company allows remote logins. Many professionals use VanishingPoint to securely access corporate portals, email accounts, and cloud-based services while traveling.
We have Remote Desktop Protocol (RDP) for secure access to Microsoft Terminal Servers, and x3270 for accessing IBM Mainframes.
No. This internet isolation technology operates remotely in the cloud, so your browsing experience depends on your connection. If you have good internet, it runs smoothly. In some cases, pages may even load faster because it eliminates background tracking and malware that slow devices down.
We host across our own physical infrastructure and multiple cloud providers: AWS, Google Cloud, Equinix and OVHcloud. You connect to the closest node automatically. Choosing your own location returns in v2.2.
Workspaces run Linux, built by us from a hardened, immutable image. There is no shell and no way to install software. You cannot reach anything beyond the applications provided, and every login builds a pristine new workspace, invisible from the internet.
No organization or technology can ever guarantee the integrity of a laptop or smartphone, because every device carries different components, firmware, applications and history. In contrast, VanishingPoint is built to stringent technical standards on transparent, stable long-term-support open source releases, vetted and approved by the industry. No experimental code. Every workspace, when built, is identical.
Once you have purchased a plan:
1️⃣ In the very top bar of this website, click Login. A new page appears with a QR code.
2️⃣ Choose either (i) Temporary Workspace or (ii) Your Workspace, then scan it with your phone and tap to confirm login.
3️⃣ When your session begins, scan the QR code on screen to pair your phone and open the Invisible Encrypted Keyboard.
Your phone was enrolled when you first signed up: you scanned a QR code and set your email and a secret recovery code. Every login from then on is passwordless, with Multi-Factor Authentication in one step, not two. No password to type, no email link to click, no code to copy across.
Before your first session, read Important – Before Your Session. It covers what the protection does and where it ends.