Website Whitelisting
- Allow access only to approved websites and domains
- Everything outside the allowlist stays unreachable
Turn Android smartphones and tablets into secure web kiosks. Allow approved websites, block unwanted URLs and restrict browser controls remotely from LimaxLock.
A secure kiosk browser restricts Android devices to approved websites and web applications, while preventing access to unauthorized URLs, browser settings and the device functions around them.
The secure browser is the web side of device lockdown: it pairs with kiosk lockdown and full Android MDM, works alongside mobile application management, and turns POS and frontline devices into single-purpose web terminals.
The allowlist, the browser interface and the way it behaves are all part of one profile — set once in the console, enforced on every device that carries it.
Website whitelisting on Android is allow-by-exception: you list the sites that are permitted and everything else is denied by default. Add a URL, choose whether subdomains come with it, and apply the list to a device group.
Same device, same browser, two very different outcomes. An approved address opens your web application; anything outside the allowlist never loads at all.
Point the device at the URL that does the job, and let the browser own the screen. The site launches on boot, fills the display and comes back on its own after a reboot or a power cut.
Every control is a policy setting, not a device setting — so what an admin configures in the console is precisely what the user gets on the device.
Which device runs which browser profile, pointed at which website, and whether it is online right now — the whole browsing estate in one table.
Your web app is already the product. Give it a URL, a browser configuration and a device group, and it ships to the fleet as a dedicated Android experience — no native build required.
A locked-down device is only as closed as its browser. These are the restrictions that keep the open web from being the exit door.
Every navigation is resolved against the allowlist. Anything outside it never loads.
Paired with kiosk mode, the browser is the session — leaving it takes an admin.
Stop files landing on shared devices you did not put there.
Configuration is set by policy, not by whoever is holding the device.
Back, forward, refresh and outbound links are available only if you allow them.
Chrome and any other installed browser are blocked, so there is one way to the web.
The same secure browser, pointed at a different address — that is usually the only difference between one deployment and the next.
pos.company.com
Product catalogues, web-based POS and customer-facing portals on the shop floor.
order.restaurant.com
Self-service ordering and digital menus that never wander off the ordering page.
checkin.clinic.com
Patient check-in and approved clinical web portals on shared waiting-room tablets.
exams.school.edu
Exam portals and a short list of approved learning sites — nothing else opens.
inventory.company.com
Browser-based inventory and logistics apps on rugged handhelds and scanners.
guest.hotel.com
Guest check-in and self-service portals in lobbies and on room tablets.
Approved websites can sit on the device like apps. Users tap the one they need and land straight in it — no address to type, and nowhere else to go.
Built around managed Android deployments, not a desktop tool ported sideways.
Change approved websites and browser behaviour without touching a device.
Secure browsing and dedicated-device lockdown are the same product, not two.
Browsers sit beside apps, kiosk profiles and devices in a single dashboard.
Ready to lock browsing to your approved sites?
Start your 14-day free trial — no credit card required.
Enter the approved URLs or web application the device should be able to reach.
Choose full-screen, address bar, navigation and download behaviour for the profile.
Apply the browser profile to a device, a group or the whole fleet.
Push the secure browsing experience over the air and manage it from the console.
A secure kiosk browser is a locked-down web browser for managed devices. It opens only the websites on an admin-defined allowlist, runs full-screen with browser controls hidden, and is configured remotely — turning a device into a single-purpose web terminal instead of an open window onto the internet.
An Android kiosk browser is the same idea applied to Android phones, tablets, rugged handhelds and POS terminals. LimaxLock's kiosk browser runs on enrolled Android devices, enforces the website allowlist on the device itself, and is managed from the same console as the rest of your Android fleet.
Enroll the device in LimaxLock, add the approved URLs to the browser profile, and apply that profile to the device or group. The secure browser then resolves every navigation against the allowlist: approved sites load, everything else is blocked. Changing the list later is a console edit, not a site visit.
Website whitelisting is an allow-by-exception model: instead of listing the sites to block, you list the sites that are permitted and everything else is denied by default. It is the safer model for dedicated devices, because a site nobody anticipated is blocked automatically rather than reachable until someone notices.
Yes. You can block specific websites outright, or use the allowlist so that anything not explicitly approved is already blocked. Because other browsers are blocked at app level, there is no second browser to fall back on.
Yes. Single-website kiosk mode boots the tablet straight into one URL, full-screen, and reloads it after a crash or a power cut — the web equivalent of single-app kiosk mode, and the usual setup for check-in pages, dashboards and digital signage.
Yes. Full-screen mode renders the page edge to edge with no address bar, tabs or menus, so a web application looks and behaves like a native kiosk app rather than a website someone opened in a browser.
Not on their own. Running the secure browser as the kiosk app means the browser is the session: the home and recents keys, the status bar and Android settings are all blocked, and leaving kiosk mode requires an admin password or a one-time exit code.
Yes. Add or remove URLs in the browser profile and the change rolls out over the air to every device on that profile. No recall, no re-enrollment and no hands on the hardware.
Yes. The address bar can be shown, hidden or locked per profile. Hiding it removes the most obvious way off the allowlist and makes the device read as a purpose-built terminal instead of a browser.
Yes — that is one of the most common reasons to use it. Point the browser profile at your web app, turn on full-screen, hide the address bar and restrict navigation, and the app becomes a dedicated Android experience without anyone building a native app.
Kiosk mode locks the device — it decides which apps can run and blocks the launcher, settings and system keys. A kiosk browser locks the web — it decides which websites can load and which browser controls exist. Most dedicated web deployments use both: kiosk mode makes the browser the only app, and the browser allowlist decides where it may go.
Create secure web kiosks, control website access and manage browser policies remotely with LimaxLock — start your 14-day free trial, no credit card required.
14-day free trial•No credit card required•Set up in minutes