Exam & lockdown browser

The exam browser that speaks SEB — byte for byte.

Vajra is a secure, Linux-first lockdown browser that produces the exact same Config Key as Safe Exam Browser. Your LMS accepts it unchanged — no server-side configuration, no second admin console.

Chromium 144 Moodle · Inspera · Cirrus · SEB Server Linux · macOS · Windows

Accepted, unchanged, by any LMS configured for Safe Exam Browser

Moodle Inspera Cirrus SEB Server + any SEB-aware LMS
The gap

Safe Exam Browser never shipped for Linux.

Whole computer labs run on Linux and Chromebooks. For high-stakes exams, they’ve had no compliant lockdown browser at all — only Windows and macOS.

The official Safe Exam Browser is Windows and macOS only. Institutions standardised on Linux desktops, managed Chromebooks, or thin clients are forced into spare Windows machines, BYOD exceptions, or simply weaker, unverifiable exam conditions.

Vajra closes the gap without asking the LMS to change. It computes the same SHA-256 Config Key SEB does — over the same canonical settings, with the version string excluded by design — so the exam server can’t tell the difference. Get the canonicalisation right to the byte and the Linux client is indistinguishable to the LMS.

And it goes further than a key: a real Wayland kiosk holds exactly one surface, and a client-integrity scan blocks virtual machines and remote sessions before the exam starts.

01 — Capabilities

A lockdown browser, proven at the layer that matters.

Not a checklist of process kill-lists — security enforced at the compositor and verified against the published SEB spec.

CONFIG KEY

Byte-identical SEB keys

Computes the Config Key and Browser Exam Key exactly as Safe Exam Browser does — anchored on the published reference vectors. The LMS accepts it with zero server-side change.

verified against SEB spec
WAYLAND KIOSK

One surface, nothing else

A forked Cage Wayland compositor enforces a single fullscreen window. Screenshots, screencast portals and VT switching are denied at the compositor — not patched over a browser.

proven on real GPU hardware
POSTURE

Integrity checked before launch

Reads /proc and /sys directly to detect virtual machines, screen-capture pipelines and active SSH/RDP/VNC sessions. A VM or live remote session blocks the exam.

VM · remote · screencast
.SEB FILES

Takes the file straight from the LMS

Reads password-encrypted .seb configs out of the box — RNCryptor v3, the exact scheme SEB uses, validated against its published test vectors. Plist and JSON too.

AES-256 · PBKDF2 · HMAC
CROSS-PLATFORM

Linux-first, not Linux-only

The lockdown build leads on Linux and Chromebooks — the platforms no one else serves — with macOS and Windows builds from the same hardened Chromium 144 core.

Linux · macOS · Windows
CONSOLE

One console when you scale

The same product carries an admin console for fleets — enrolment, policy and posture reporting — so exam delivery and enterprise browsing live under one identity, not two stacks.

unified control plane
02 — How it works

Download the .seb, run one command, sit the exam.

No LMS plugin to install. No server-side change. The handshake is the standard SEB handshake.

Export from your LMS

Configure the quiz for Safe Exam Browser and download the .seb — encrypted or not.

Vajra computes the key

It decrypts the config and derives the Config Key byte-for-byte — the same value SEB-Windows or SEB-macOS would produce.

Posture gate

The client-integrity scan runs. A virtual machine or an active remote session stops the launch right here.

Kiosk launch

The browser opens inside a locked Wayland surface and sends the SEB request headers. The LMS verifies the hash and lets the candidate in.

03 — The facts

Specific, measured, and honest.

Everything here is grounded in the build and its tests — not roadmap.

Engine
144Chromium, hardened
Config Key
SHA-256byte-identical to SEB
.seb crypto
RNCryptor v3AES-256 · PBKDF2 · HMAC
Lockdown
Waylandsingle-surface kiosk
LMS
4+Moodle, Inspera, Cirrus, SEB Server
Posture
VM · remoteblocked before launch
Platforms
3Linux · macOS · Windows
Server change
Nonestandard SEB handshake
Measured, not marketed

Local-mode is the latency guarantee.

High-stakes, typing-heavy exams need the browser on the candidate’s machine. That’s the build we lead with — sub-90 ms input, fully offline-capable, no streaming variables.

We also measured cloud pixel-streaming end-to-end on real GPU hardware and we’ll tell you exactly where it works: in-region only. We publish the floor instead of pretending it isn’t there.

Local mode — input latency< 90 ms · GO
Cloud floor (in-region, ≤ 35 ms RTT)~104 ms p95
Cloud, cross-regionno-go (stated)
Measured onNVIDIA L4 · NVENC
04 — Beyond exams

The same engine, hardened for work.

When you need a secure browser for the workforce, Vajra is already that browser — managed from the same console.

Exam lockdown and enterprise browsing are the same problem at different stakes: hold a known-good surface, enforce policy, and prove the endpoint is trustworthy. Vajra runs both from one identity graph — no parallel admin stack, no second agent.

  • Data-loss preventionClipboard, print, download and screenshot controls, with watermarking for sensitive surfaces.
  • Zero-trust accessContinuous device-posture checks and risk-adaptive access — degrade or step up instead of all-or-nothing.
  • SIEM / SOAR integrationOCSF-compliant telemetry forwarded to your SOC — sessions, DLP events and threats, severity-tagged.
Get started

Sit your first exam on Linux this week.

Grab the validation build, point it at a real Moodle quiz, and watch the LMS accept it like any other Safe Exam Browser. No plugin, no server change.