Your Isolated Workstation is Just One Swipe Away.
Choose the only Type 1 hypervisor running multiple
isolated environments locally without UX compromise.
Sure, you can let your employees juggle devices
Or you can let them switch between isolated environments with a single swipe.




Employees resent clunky IT.
Yours will thank you.
Isolate with
Full Performance
Most virtualization platforms promise isolation but trade it for performance.
With YS::Desktop, isolation and performance finally work on the same team. By separating CPU cores dedicated to the hypervisor and virtual machines, and applying hypervisor-level encryption, the solution prevents side-channel and auxiliary attacks without slowing anything down.




Manage Everything
Centrally
In large organizations, IT teams drown in the complexity of multiple systems, isolated networks, and half-controlled endpoints.
YS::Desktop changes that. Instead of managing disconnected machines, you manage one unified platform built around Security Domains that make every VM visible, governed, and compliant by design.
Central Management Console
Corporate Domain
Development Domain
Restricted Domain
Overcome network
Constraints
IP address management and system segmentation should no longer limit your teams' productivity
With YS::Desktop, you choose between two operating modes: NAT, which assigns one IP per workstation, and Bridge, which enables native IP access. VLANs are fully supported and fit right into your existing infrastructure.Your Static IPs stay compatible with legacy PLCs.
NAT Mode

VLAN Support

Bridge Mode



Ready to isolate
Without Compromise?
Live walkthrough by specialists who've solved this for teams like yours.
Our latest Blog Posts
Frequently Asked Questions
The French Cybersecurity Agency (ANSSI) has published a guide on multi-environment workstations outlining the security requirements for virtualizing NP and DR environments.
We are 100% compliant with the guide's requirements, which we intend to demonstrate through certification.
Additionally, our type of solution is referenced in the ANSSI guide on sensitive and restricted system architectures (rule 52-) and in the ANSSI guide for secure SI administration (rule 9-).
To run the solution, the hardware requirements are: 32 GB of RAM, an Intel vPro Enterprise Gen 12+ processor, a 512 GB NVMe SSD, and a TPM 2.0 module.
YS::Desktop is a Type 1 hypervisor, it is the first system to boot on the machine, which means the workstation's disk must be completely wiped. Our goal is to integrate with our customers' existing processes, so we offer several deployment options, including network server deployment via PXE or HTTPboot, as well as USB-based deployment.
The solution is administered through a full administration console: the YAC. You can deploy it wherever you choose. Kerys Software has no visibility into your console or your configurations.
The YAC (administration console) exposes several APIs that workstations call to check for available updates (pull mode).







