BBTI Browser is a privacy-first browser built by Blake Burns Technologies Inc. Designed for users who demand visibility and control over their web security, it ships a full-featured browsing experience alongside an integrated Web Application Firewall (WAF) and Runtime Application Self-Protection (RASP) engine — capabilities typically reserved for enterprise server infrastructure, now running client-side on your desktop.
Security at Its Core
Every page load and outbound request is scanned in real time against a comprehensive ruleset derived from OWASP's Core Rule Set (CRS). BBTI Browser detects and optionally blocks the most dangerous web attack categories before they reach your system:
XSS (Cross-Site Scripting) — inline event handlers, javascript: URIs, base64 payloads, DOM manipulation attempts
SQL Injection — UNION SELECT attacks, tautology injections, stacked queries, time-based blind SQLi
SSRF (Server-Side Request Forgery) — private IPv4 ranges, loopback addresses, AWS and GCP metadata endpoints
LFI / RFI — path traversal sequences, PHP stream wrappers, remote file inclusion via URL parameters
RCE (Remote Code Execution) — shell command injection, PowerShell obfuscation, command substitution
SSTI (Server-Side Template Injection) — Jinja2, Twig, Java EL expression probes
Malicious Downloads — executable and script file type blocking before download begins
Session Fixation — detection of session IDs exposed in URLs
The RASP engine injects a lightweight monitoring script into every page before content loads, intercepting fetch, XMLHttpRequest, and WebSocket calls to catch attack payloads in outbound request bodies — providing a second layer of defence beyond URL inspection alone.
Browsing Features
BBTI Browser covers everything you expect from a modern browser. Multi-tab support lets you open, switch, and close tabs freely while each tab preserves its full live session — no reloads when switching. The address bar tracks URL changes accurately across both traditional page loads and single-page applications that use history.pushState, replaceState, and hash-based routing, so the address bar is always in sync.
Design
The interface uses a dark, minimal aesthetic built for long browsing sessions. The layout is fully responsive across window sizes — from compact laptop windows to wide ultrawide displays — and re-renders fluidly as the window is resized. A persistent WAF badge in the address bar gives you constant confirmation that protection is active.
BBTI Browser is built and maintained by Blake Burns Technologies Inc., a federally incorporated Canadian technology company.