Request for Information Secure Enterprise Browser Solution

Agency: State Government of Wisconsin
State: Wisconsin
Type of Government: State & Local
NAICS Category:
  • 541511 - Custom Computer Programming Services
  • 541512 - Computer Systems Design Services
  • 541519 - Other Computer Related Services
Posted Date: Jun 4, 2026
Due Date: Jun 12, 2026
Solicitation No: Request for Information Secure Enterprise Browser Solution
Original Source: Please Login to View Page
Contact information: Please Login to View Page
Bid Documents: Please Login to View Page
Solicitation Reference #: Request for Information Secure Enterprise Browser Solution
Title: Request for Information
Secure Enterprise Browser Solution
Available Date: 5/22/2026
Due Date: 6/12/2026 2:00:00 PM
Are faxed Bids acceptable? No
Are e-mailed bids acceptable? No
Bid Synopsis:

Request for Information

Secure Enterprise Browser Solution

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned.  Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions regarding the RFI are due on May 27, 2026. Email questions to Caleb.Hall@wisc.edu.

Agency Contact: Julie Yapp

Documents:
Amendment 1 RFI-SEB 5.21.26.docx
6/4/2026
RFI-SEB 5.21.26.docx
5/22/2026
NIGP Codes
Code Description
20811 Application Software, Microcomputer
20836 Data Processing Software, Microcomputer
92005 Application, Infrastructure, Hosting and Cloud Computing Services
92014 Applications Software (For Minicomputer Systems)
92045 Software Maintenance/Support
Revision History5/22/2026 3:06:16 PM - Julie Yapp: Due date for questions added to synopsis per agent's request - MW

Attachment Preview

Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

Questions concerning this RFI should be directed via email to UW Madison Purchasing Manager Caleb Hall

RFI Issued Date: May 21, 2026

Questions Due: May 27, 2026

RFI Due Date: June 4, 2026 by 2:00 PM CT

Email questions and completed RFI responses to

Request for Information (RFI): Secure Enterprise Browser Solution

1. Introduction and Purpose

The University of Wisconsin-Madison (UW-Madison, UW, or the University), a public R1 research institution, is soliciting information regarding a Secure Enterprise Browser (SEB) solution. Our environment is characterized by a highly decentralized "hub-and-spoke" administrative model. We require a solution that secures web-based workflows, protects sensitive research data, meets contractual and regulatory requirements, and simplifies access to internal resources while respecting the autonomy of the 150+ departments on campus.

2. Scope of Requirements

The university seeks a solution that provides a managed browser environment (either as a standalone browser or an enterprise-managed extension) to enforce security policies at the application layer.

Key Objectives:

Hierarchical Governance: Ability for Central IT to set "Global Guardrails" while delegating granular policy control to departmental IT leads.

Data Protection: Robust Data Loss Prevention (DLP) to protect intellectual property, FERPA, FedRAMP (Moderate), CUI, HIPAA data.

Zero Trust Integration: Alignment with Zero Trust Architecture (ZTA) by providing identity-aware access to web applications without traditional Virtual Private Networks (VPNs).

3. Technical and Functional Requirements

3.1 Administrative Hierarchy and Federated Access

The solution must support a multi-tenant or multi-tier administrative structure.

Centralized Oversight: Central Cybersecurity must be able to push mandatory, non-overridable policies (e.g., "All departments must disable 3rd-party cookies on financial sites").

Delegated Administration: Individual departments (e.g., School of Medicine, College of Engineering) must have scoped administrative consoles to manage department-specific settings.

Policy Inheritance: Describe how your solution handles policy conflicts between central and departmental levels (e.g., most restrictive vs. specific override).

Granularity for Users: Is the browser able to distinguish between a student login and a staff/faculty login? Are we able to apply different policy sets?

3.2 Security and Policy Management

Extension Management: Capabilities to allowlist/blocklist extensions per department.

DLP Controls: Granular control over printing, clipboard (copy/paste), file uploads/downloads, and screen capture based on the sensitivity of the URL or data classification tagging.

Threat Protection: Built-in phishing protection, malware sandboxing, and real-time URL filtering.

Visibility: Centralized logging of security events with the ability to export data to a Security Information and Event Management (SIEM) solution (e.g., Sentinel, Elastic Search).

Containment: Natively built into the product and offers additional containment options in the event of an incident

3.3 Identity and Access Management (IAM)

Federated Identity: Seamless integration with Security Assertion Markup Language (SAML 2.0), OpenID Connect (OIDC), and Entra ID.

Just-in-Time Provisioning and Deprovisioning: Automated user onboarding based on directory groups.

Contextual Access: Ability to vary browser security posture based on user location, device health, or network origin.

4. Vendor Questionnaire

Please provide detailed responses to the following questions:

A. General Questions

Introduce your organization.

Identify contact name(s), telephone numbers(s), and email address(es) for questions we might have concerning this information and the products and services you offer.

List any relevant websites for your company and its products including support, training, and consulting.

Describe your product(s) and services strategy, including markets served. We are particularly interested in knowing if you serve the higher educational community. How long has your company been providing these types of products and services?

Identify or describe your top five customers and provide a paragraph describing the relevant products they use. We are particularly interested in your higher educational customers; describe your company's experience with university clients of a similar size or government clients of similar size and complexity, including experience working with federally regulated research spaces to meet security requirements. Provide contacts if possible.

Describe your development roadmap over the next three years. Where do you see your organization from a products and services standpoint five years from now?

How and how often do you work to understand user needs to iteratively improve your products and services?

What is your release schedule and how are major releases coordinated with customers?

Describe the location of your data centers and/or platform provider. Please confirm whether any persistent UW data would be maintained outside the United States.

Is any session content decrypted or stored by your company? If so, please describe.

Does your solution require an on-premises connector or gateway to proxy the traffic, or is it handled via a cloud-based POP (Point of Presence)? If so, describe.

Does Zero-Trust / Private Access require opening ports on the perimeter firewall? If so, please describe.

Does your platform have any safeguards to prevent agents from manually altering or fabricating data? If so, please describe.

Does your platform allow the ability to disable Developer Tools? If so, please describe.

Does your platform allow for custom branding? If so, please describe.

Does your platform support Application Streaming? If so, please describe.

Does your platform enforce domain-bound credentials? If so, please describe.

Describe your application status/availability monitoring and auditing capabilities; what Service Level Agreements (SLAs) are available?

What external systems do you support for logging, monitoring and auditing?

What are your patching and maintenance philosophies?

Can content inspection be disabled for specific departments or data classes? If so, please describe.

Are there known incompatibilities with common research or teaching platforms? If so, please describe.

What support tiers are offered, and are they available 24x7?

What is the escalation path for critical security or availability issues?

Does your solution support access to non-HTTP/S protocols such as Secure Shell (SSH) and Remote Desktop Protocol (RDP)? If so, please describe how this access is provided.

Does your solution support RDP over TLS and SSH-2? Are there limitations on terminal emulation or display resolution? If so, please describe.

Can your solution restrict or audit specific actions such as copy/paste, local file transfers, and printing during an active SSH or RDP session? If so, please describe.

Does your solution provide full session recording (video) or searchable command-line auditing for SSH sessions? If so, please describe.

What is the average time a zero day bug patch is released is your product patched and deployed? Is updating your solution automated or requires Admin to push the update?

What is the strategy for handling AI (artificial intelligence) browsing agents?

Does the presence of another SEB vendor's product on an endpoint crate any conflicts, limitations, or unsupported scenarios for the installation, functionality, or performance of your solution? If so, please provide details and recommended remediation steps.

Does your solution support coexistence with other SEB products, or is exclusive installation required? If so, please describe.

Describe whether the proposed solution functions fully as a standalone offering or whether it is optimized to work as part of a larger product suite. Identify any required, recommended, or optional companion products and explain their roles.

Do you sign Business Associate Agreements?

B. Governance & Multi-Tenancy

How does your platform support a "parent-child" organizational structure for policy management? Are there any limitations on the number of child organizations?

Can a departmental administrator be restricted from seeing the data or policies of another department but still see policies applied from the central administrator? If so, please describe.

Describe the process for a central administrator to audit the policies set by a departmental administrator.

C. Deployment & Compatibility

Does your solution require a proprietary browser, or is it an overlay for existing browsers (Chrome/Edge)? If so, please describe.

How does the solution handle managed vs. unmanaged (BYOD) devices, common in a research environment?

Is the local cache encrypted, and can it be remotely wiped upon session termination?

What is your product's impact on end-user performance and site compatibility? What is your product's maximum latency threshold?

Does your solution require administrative level access for installation? If so, please describe.

What Operating Systems are supported?

Does your solution perform hygiene/compliance checks on the device? How often are posture checks performed? If so, please describe.

Does your platform offer an API for scripting? If so, what capabilities can be completed via scripting?

Does your platform support any IdP? Can users and groups from providers be imported into the application? If so, please describe.

How does your platform handle credential injection or "passwordless" access? Can it integrate with an existing Vault/PAM (Privileged Access Management) solution to prevent credentials from ever reaching the endpoint?

Does your platform support x-forwards-host (e.g., can a user log into the Browser with credentials from Identity Provider (IdP) A, while also login into an application using credentials from IdP B)?

Describe how to configure a web application to restrict access to only be allowed from your product

How often do policy enforcement updates refresh?

Does your solution use or support AI? If so, can the AI components be audited or blocked based on a user's group membership?

What level of day-to-day administration is required (FTE estimate at scale)?

What onboarding and training resources are provided for admins?

How does your solution handle 'nested' inspection? Are there specific configurations required to prevent performance degradation when running alongside existing campus-wide SSL/TLS inspection engines?

Does the solution support local discovery protocols (like mDNS) to allow the browser to interact with locally connected lab equipment or printers on the same subnet?

D. Research & Compliance

How does your solution assist in meeting regulatory compliance standards such as NIST 800-53, NIST 800-171, or Cybersecurity Maturity Model Certification (CMMC) requirements for research enclaves?

Can DLP policies be triggered based on specific "Data Classifications" recognized by the browser? If so, please describe.

Does the browser isolate work profiles from personal profiles?

How does the solution manage, audit, and 'sandbox' browser extensions to prevent malicious data exfiltration?

E. Accessibility

Do your products and/or services conform to the World Wide Web Consortium (W3C) Web Content Accessibility Guidelines, version 2.1 ("WCAG 2.1") at the conformance levels A and AA, and Section 508?

Has the product been tested with assistive technologies (AT)? If so, which AT were used? Who did the testing? What was the testing methodology? What were the results?

How is accessibility built into your quality assurance workflow? If you roll out upgrades of the product, how do you ensure that upgrades will not break accessibility?

Are there known accessibility issues with your products or tools? If so, what are they? What are the work-arounds for users of assistive technology? What is the plan to address these issues?

How should accessibility barriers be communicated to you and how does your company respond to such issues?

5. Submission Instructions

Send via email a completed response by 2:00 p.m. June 4, 2026 to:

Caleb Hall, Purchasing Manager

UW Madison

caleb.hall@.edu

Include in your response:

An executive summary of the solution.

Detailed responses to the Section 4 Questionnaire, including references requested in 4.A.5

A description of your pricing structure and licensing model(s) with specific costs and figures, including support / maintenance tiers, optional modules, and other add-ons. Include details on licensing options for various user populations (e.g., students, faculty, staff, campus affiliates, and external collaborators).

6. Anticipated Timeline

The anticipated schedule for this RFI process is as follows:

RFI Issued May 21, 2026

Questions Due May 27, 2026

Information Due by June 4, 2026 2:00PM (CDT)

The University reserves the right to modify this schedule.

7. Questions

Questions regarding this RFI should be submitted via email by May 27, 2026 at 2:00 pm (CDT) to:

Caleb Hall, Purchasing Manager

UW Madison

8. Disclaimer

This Request for Information is issued for informational and planning purposes only. It does not

constitute a solicitation for proposals and does not obligate the University to issue a subsequent procurement document or enter into any agreement. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.

The University reserves the right to:

* Modify or cancel this RFI at any time

* Request additional information from respondents

* Conduct interviews with respondents

* Use information received to structure a future procurement process

The University is not responsible for any costs incurred by respondents in preparing responses to this RFI.

This page summarizes the opportunity, including an overview and a preview of the attached documents.
* Disclaimer: This website provides information about bids, requests for proposals (RFPs), or requests for qualifications (RFQs) for convenience only and does not serve as an official public notice. Individuals who wish to respond to or inquire about bids, RFPs, or RFQs should contact the relevant government department directly.

Sign-up for a Free Trial, Government Bid Alerts

With Free Trial, you can:

You will have a full access to bids, website, and receive daily bid report via email and web.

Try One Week FREE Now

See Also

Solicitation Reference #: Required 2026-UW-01377-RFP Title: Energy Management Software Available Date: 6/30/2026 Due

State Government of Wisconsin

Bid Due: 8/11/2026

Project: Airport Wireless Local Area Network and Distributed Antenna System Ref. #: RFP-2026-007

Milwaukee County

Bid Due: 9/03/2026

CONTRACT NUMBER: 8820 CONTRACT: Euclid Ave, Birch Ave Recon Percentage of Contract Completed:

City of Madison

Bid Due: 9/24/2026

Solicitation Reference #: 2026-GRBALL-01355-RFB Title: UW-Green Bay Campus Calendar Software Available Date: 7/14/2026

State Government of Wisconsin

Bid Due: 8/14/2026