Citrix & VDI ยท Citrix SecurSpaces
Give employees, contractors and AI coding agents a ready-to-code cloud workspace where source code, credentials and IP never leave your security perimeter. Developers keep their favourite IDEs, security keeps control, and Citrix cut its own cost per developer by more than 60%.
Citrix SecurSpaces is Citrix's cloud development environment (CDE) platform, formerly Secure Developer Spaces and, before Citrix acquired it in December 2024, Strong Network. It hosts container-based developer workspaces that keep source code, secrets and data inside a controlled perimeter instead of on laptops.
Each workspace is pre-configured with the right toolchain and governed by your identity, network and audit policies. The same controls apply to human developers and to AI coding agents. Workspaces are fully containerized Linux environments that are provisioned in seconds. There's no desktop streaming, so they stay responsive even on poor networks.
Shipping high-end laptops to every developer and contractor is costly, and each one holds your IP, tokens and credentials.
Heavy desktops don't fit modern DevOps toolchains, containers or platform engineering workflows.
Agentic coding tools can read repositories, run commands and call external models. Without a sandbox, that's a new path for data leakage.
Results from Citrix's own rollout of SecurSpaces across its global engineering teams. Read the Citrix case study โ Your results depend on team size and your current setup, and an Altanora pilot measures them in your environment.
VS Code, JetBrains Gateway, Cursor and Windsurf, or a browser-based IDE and terminal.
Pre-built workspace templates mean new hires and contractors code on day one.
Light, medium or heavy profiles to match the job, from everyday coding to large builds.
GitHub, GitLab, Bitbucket and Azure DevOps; OCI registries such as JFrog, ACR and ECR; HashiCorp Vault and Azure Key Vault.
AI coding agents run in isolated workspaces under the same control plane as your developers, with no lateral movement onto your network.
Workspace LLM traffic routes only to approved model endpoints: self-hosted, private cloud or approved third party.
You decide which models, repositories and data each AI tool can reach.
AI interactions are logged and subject to the same egress controls as everything else.
| Control | What it does |
|---|---|
| Code and secrets stay central | Source, tokens and data never land on local devices |
| Exfiltration protection | Blocks data exfiltration, credential leaks and unauthorized code entry without interrupting developers |
| Identity | SSO via SAML, OIDC or Microsoft/Google OAuth, with MFA and SCIM provisioning |
| Data loss prevention | Native DLP, plus ingress and egress filtering |
| Access control | Role-based access control per workspace and project |
| Governance and cost control | Admins set security policies and see resource use per workspace, with DevSecOps best practices enforced |
| Audit | Event log catalogue, streamed to your SIEM in Common Event Format |
| Secure ingress | NetScaler (recommended) with public or private certificate authorities |
| Option | Where it runs | Best for |
|---|---|---|
| Altanora-hosted | Altanora's SecurSpaces-ready Azure environment | The fastest start, with onboarding in about 30 minutes |
| Citrix-managed (SecurSpaces Flex) | Citrix-operated Azure, billed with Citrix Platform Flex credits | Low operational burden and consumption billing |
| Your cloud | Your AWS EKS, Azure AKS or Google Cloud Kubernetes | Production-representative control in your own tenancy |
| On-premises or air-gapped | Your data centre on Kubernetes or Red Hat OpenShift | Strict data residency or no internet egress |
Give external developers access in minutes without shipping or securing laptops.
Move engineering teams off expensive high-end laptops.
Let teams use AI coding tools with approved models only.
Finance, healthcare, defence and government, including air-gapped builds.
As a Citrix Preferred Services Partner, Altanora runs a structured SecurSpaces pilot. Pilots can be funded by Citrix, subject to Citrix approval. Most run 4 to 6 weeks.
Pick two or three use cases, the deployment model and measurable success criteria.
Connect your identity provider, repositories, registries, secrets, certificates and SIEM.
Configure the use cases and onboard a pilot developer group, with the optional AI module.
Evidence against your success criteria, plus a recommendation on the path to production.
Citrix acquired Strong Network in December 2024. The platform became Citrix Secure Developer Spaces and is now Citrix SecurSpaces.
Yes. They can use VS Code, JetBrains Gateway, Cursor, Windsurf, or a browser IDE and terminal.
Yes. Agents run in sandboxed workspaces, and the AI Gateway restricts which models they can call.
Yes. It runs on-premises on Kubernetes or OpenShift, with offline licensing and mirrored images.
VDI streams a full desktop. SecurSpaces gives developers lightweight, container-based workspaces built for code, CI/CD and AI tooling. Many organizations use both.
In Citrix's own rollout, SecurSpaces cut total cost of ownership by more than 60% per user compared with traditional VDI or high-spec laptops. New developers onboard in minutes instead of days, and IT manages every environment from a single control plane, with no image building or patching.
Pilots can be funded by Citrix, subject to Citrix approval. Altanora handles the application with Citrix for you.
Start with a pilot on your real repositories and security controls. Pilots can be Citrix-funded, subject to Citrix approval.
Request a SecurSpaces Pilot