Skip to main content
Authorized research workflow

Disposable browsers for security researchers.

A disposable browser can support authorized research. It separates one temporary browsing session. It never creates testing permission.

Read the target's disclosure policy first. Define scope, methods, data handling, and stop rules. Choose the environment afterward.

Legba Shield suits narrow visual inspection. It is not a complete research laboratory. Its session ends when the tab closes.

Published byLegbaReviewed byAakash HarishSecurity Research Contributor, LegbaReviewed 2026-08-28 · Updated 2026-08-28

The short version

Authorization comes first. The browser comes second.

Free for 30 days. No card required. $10 a month, or $100 a year.

Testing authority must exist before tooling.

Security research changes system behavior. Even careful testing can affect others. Tool selection cannot answer permission questions. Authorization needs a documented authorizing party.

NIST defines rules of engagement. Those rules exist before testing starts. They define constraints and detailed guidelines. They also provide authority for defined activities.

CISA's disclosure directive emphasizes published policies. Those policies identify authorized systems and testing. They also describe expected communications. Scope should remain readable and current.

DOJ provides one concrete policy example. Authorization depends upon policy compliance there. Activities outside that policy remain unauthorized. Other organizations publish different terms.

SourcesNISTNISTCISAUnited States Department of Justice

Read the policy as an authorization boundary.

A vulnerability disclosure policy can define authorization boundaries. It may list included systems. It may exclude vendors and subdomains. It may prohibit disruptive methods.

Read every scope statement literally. Similar domains may have different owners. Related applications may remain excluded. Shared infrastructure may introduce third parties.

Find the reporting channel next. RFC 9116 defines a standard disclosure file. That file can publish contacts and policies. Its scope follows the retrieved domain.

A missing policy needs clarification. Silence never means broad permission. Contact an authorized representative before active testing. Preserve that written exchange.

  • Confirm the authorizing party.
  • List every included hostname.
  • List every excluded hostname.
  • Record permitted testing methods.
  • Record prohibited testing methods.
  • Record data-handling requirements.
  • Record the reporting deadline.
  • Record the emergency contact.

SourcesCISAUnited States Department of JusticeRFC Editor

Pass this authorization gate first.

The gate converts policy language into operations. Every row needs a written answer. Unknowns should block active testing. Assumptions should never fill legal gaps.

Internal testing needs the same discipline. A manager's informal request may lack authority. System representatives and data owners may differ. Third-party services need separate review.

Update the gate before each engagement. Scope changes can happen quickly. Infrastructure can move between providers. Contacts and reporting systems can also change.

Store the approved gate with project records. Give every researcher the same version. Record changes and effective dates. Retire superseded instructions clearly.

Every active test begins with documented authorization answers.
FactorRequired evidenceBlocking unknownOwner
Authorizing partyDocumented authority from an authorized representativeWhether the requester controls the targetEngagement sponsor and legal reviewer
Technical scopeExact hosts, applications, accounts, and environmentsWhether related subdomains or vendors qualifyAuthorized representative and test lead
Allowed methodsPermitted techniques, rates, tools, and test windowsWhether active validation exceeds policyTest lead and authorized representative
Data handlingCollection, storage, encryption, and deletion rulesHow sensitive data should be handledData owner and security lead
Stop conditionsEvents requiring immediate testing suspensionWho decides whether testing resumesTest lead and emergency contact
Reporting pathApproved channel, encryption, timing, and recipientsWhere sensitive reports should be sentDisclosure coordinator

Every active test begins with documented authorization answers.

SourcesNISTUnited States Department of JusticeCISARFC EditorNIST

Choose the environment from the task.

Disposable browsing serves a limited research job. It can separate temporary web observation. It can reduce normal profile exposure. It also removes session state afterward.

Other jobs need persistent evidence. Some need network captures or instrumentation. Some require owner-provided test accounts. Others require dedicated analysis environments.

Choose from required capabilities first. Then consider convenience and speed. Never force every test through one tool. That shortcut can damage evidence quality.

The matrix favors safer escalation. It keeps Shield inside documented claims. It also gives stronger tools their proper role. Authorization remains mandatory everywhere.

Match the research task with its required environment properties.
FactorLikely starting environmentRequired evidenceDisposable-browser fit
Visual page inspectionApproved off-device browser without personal stateScreenshots or notes allowed by policyGood when temporary observation answers the question
Client-side behavior reviewInstrumented browser inside a controlled environmentConsole, network, storage, and reproducible stepsLimited unless required instrumentation is documented
Authenticated validationDedicated testing profile with approved accountsAccount scope, state, actions, and cleanup recordsPoor without explicit account and state controls
Exploit reproductionExplicitly authorized staging or dedicated research laboratoryExact versions, controls, evidence, and rollbackPoor for uncontrolled active validation
Unknown file analysisPurpose-built file or malware analysis environmentArtifact hashes, behavior records, and containment evidencePoor because Shield is not that laboratory
Long-running investigationPersistent workspace with approved evidence storageChain, timestamps, retention, and researcher accessPoor when closing destroys required session state

Match the research task with its required environment properties.

SourcesLegbaUnited States Department of JusticeOWASP FoundationNISTChromium

Know exactly where Shield fits.

Legba Shield opens pages off-device. The browser session stays separate. The user still controls navigation. Closing the tab ends the session.

That model fits temporary visual inspection. It also fits basic page confirmation. It can keep personal browser state separate. These remain meaningful workflow advantages.

The public page promises no research instrumentation. It promises no packet capture. It promises no evidence archive. It promises no exploit containment benchmark.

Session destruction can become a disadvantage. Required evidence may disappear with state. Reproduction may require stable tooling. Long engagements may need persistent environments.

  • Use Shield for narrow observation.
  • Keep personal profiles outside research.
  • Use only approved test data.
  • Avoid credentials without explicit authorization.
  • Record findings through approved systems.
  • Close after the question is answered.
  • Choose another tool when evidence must persist.

SourcesLegba

Plan the session before opening it.

A narrow session needs one research question. Write that question first. Define the minimum actions required. Avoid expanding scope during browsing.

Remove unrelated state before testing. Use no personal profile. Use no production credentials. Keep unrelated customer data elsewhere.

Define allowed observations and exports. Screenshots can contain sensitive data. Notes can reveal private identifiers. URLs can include tokens.

Define an explicit ending. Close after answering the question. Stop earlier when policy triggers occur. Record the closure and remaining artifacts.

  1. 01

    Write the research question.

    State one narrow fact requiring browser observation. Exclude curiosity-driven exploration.

  2. 02

    Attach the authorization evidence.

    Link scope, rules, contacts, test window, and permitted methods.

  3. 03

    Prepare controlled inputs.

    Use approved test accounts and synthetic data. Exclude personal secrets.

  4. 04

    Define evidence handling.

    Choose approved screenshots, notes, timestamps, storage, encryption, and retention.

  5. 05

    Define immediate stop rules.

    Stop on sensitive data, instability, scope drift, or unexpected impact.

  6. 06

    Select the environment.

    Choose Shield only when its public boundary meets requirements.

SourcesNISTUnited States Department of JusticeLegba

Preserve evidence without overcollecting data.

Useful reports need reproducible evidence. They do not need unrestricted data collection. Capture the minimum facts proving the issue. Follow every policy restriction.

DOJ's policy demonstrates strict minimization. Researchers should stop after confirming vulnerabilities there. Sensitive data triggers immediate notification. Other programs may define different rules.

Record timestamps and exact scoped assets. Record the approved test account. Record observable behavior and expected behavior. Avoid unnecessary personal data.

Store evidence through approved systems. Encrypt reports when required. Restrict access to assigned participants. Delete retained data according to policy.

Collect only evidence required for authorized reporting.
FactorUseful recordMinimization ruleShield consideration
Target identityExact approved hostname and pathExclude unrelated hosts and user identifiersRecord before session closure
Reproduction sequenceMinimum authorized steps confirming behaviorStop before unnecessary impact or data accessWrite steps outside the temporary session
Visual evidenceApproved screenshot showing relevant behaviorRedact unrelated identities and confidential valuesExport only through approved procedures
Timing evidenceTime zone, request time, and observed responseAvoid excessive repeat testingCapture before ending the session
Researcher environmentApproved browser mode, versions, and relevant settingsExclude unrelated device and account detailsLegba publishes no automatic evidence archive

Collect only evidence required for authorized reporting.

SourcesUnited States Department of JusticeNISTOWASP FoundationLegba

Stop early and report clearly.

Stop rules protect targets and researchers. Trigger them before material impact. Sensitive data should halt further exploration. Service instability should also halt testing.

Do not pivot beyond approved scope. Do not test unrelated accounts. Do not increase load casually. Do not collect extra proof.

Contact the program through its official channel. RFC 9116 can help locate that channel. Verify any redirect carefully. The current policy defines that program's boundary.

Send a concise reproducible report. Describe impact without exaggeration. Separate observation from inference. Mark untested theories clearly.

  1. 01

    Stop the test.

    Cease activity after sufficient evidence. Preserve approved records only.

  2. 02

    Protect encountered data.

    Avoid further access or copying. Follow immediate notification requirements.

  3. 03

    Use the official channel.

    Follow the published policy or disclosure file. Use its authorized contact or portal.

  4. 04

    Report reproducible facts.

    Include scope, environment, steps, impact, evidence, and safe remediation ideas.

  5. 05

    Coordinate later disclosure.

    Follow program timelines and written disclosure rules. Keep communications documented.

SourcesUnited States Department of JusticeRFC EditorNIST

Use one final preflight checklist.

The final decision should feel boring. Authorization is documented. Scope is exact. Evidence handling is already arranged.

The chosen tool should match requirements. Shield should cover temporary browsing only. Dedicated labs should cover deeper analysis. Persistent workspaces should preserve required evidence.

Review browser protections too. Chromium uses operating-system sandbox controls. Exact assurances vary by platform. Off-device placement remains a separate property.

Repeat this review for every engagement. Policies can expire or change. Systems can leave scope. Reporting contacts can also change.

  • Authorization evidence is current.
  • Every target remains in scope.
  • Every planned method remains allowed.
  • Test accounts are explicitly approved.
  • Data rules cover expected evidence.
  • Stop conditions have named owners.
  • The environment matches required tooling.
  • The reporting path remains current.

SourcesNISTUnited States Department of JusticeChromiumLegba

FAQs.

References

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06
  7. 07
  8. 08

Keep exploring

Try it on the next page you do not trust

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.

Free for 30 days. No card required.

Ghost. A private route for your browser. Shield. An isolated browser, off your device. Close the tab. The session is destroyed.