Your data rules stop at the browser. Every upload to an unsanctioned site skips them — Forcepoint Web Security decrypts web traffic and applies your Forcepoint DLP rules to every upload, enforced on the laptop or in Forcepoint’s cloud, with edge sites in five Indian cities.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Forcepoint Web Security — the secure web gateway on Forcepoint Data Security Cloud. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy that decrypts web traffic and applies the same DLP rules your endpoints and email already use.
What consolidation actually replaces, dimension by dimension.
| Dimension | A URL filter plus a separate DLP proxy | Forcepoint Web Security |
|---|---|---|
| Data leaving by browser | Invisible unless a separate DLP proxy is chained in | Checked inline with Forcepoint DLP classifiers |
| Laptops off the network | VPN back to the office, or no filtering at all | SmartEdge agent enforces policy on the device |
| Personal AI accounts | Block the whole AI site, or allow every account | Corporate tenant allowed, personal tenant blocked |
| Branch offices | A web appliance in every site to patch | GRE, IPsec or PAC file to the cloud proxy |
| Log evidence | Appliance logs held wherever the box sits | 30 days in US East; export for 180 days |
| What it is NOT | — | A DNS filter, an API CASB, or a small-office product |
The cheapest test is monitor mode: send one office and fifty agent laptops through it for two weeks and read what it would have blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Branch sites send web traffic over GRE or IPsec tunnels, or through a PAC file, to Forcepoint’s cloud proxy, which decrypts, scans and applies policy before forwarding it.
On Windows 10 and 11 and macOS the agent enforces policy locally and calls the cloud only for unseen URLs or files to scan; users cannot remove it without an admin.
One console sets web, cloud-app and private-app policy and reuses DLP patterns across them; web and proxy logs stay 30 days in Forcepoint’s US East data centre.
The datasheet cites over 300 PoPs on AWS; India gets a Mumbai region and five edge cities, and virtual PoPs localise content for 110 countries.
A cloud proxy for offices and an on-device agent for laptops — one DLP-aware policy, with Indian edge sites.
Forcepoint Web Security is a proxy gateway that treats every web upload as a DLP decision.
The SmartEdge agent enforces web policy on Windows and macOS wherever the user is, and the user cannot stop or uninstall it.
Branches reach the cloud proxy over GRE or IPsec tunnels, or a PAC file, so guests and unmanaged devices are filtered too.
Forcepoint Mobile, the client for Web Security, brings the same cloud policy to managed iOS and Android devices.
HTTPS is decrypted for inspection, while connection rules can let banking or health sites pass through without decryption.
Uploads, web forms and cloud storage are checked inline with the same classifiers Forcepoint DLP applies to endpoints and email.
Files are scanned by CrowdStrike or Bitdefender engines; risky sites can open in remote browser isolation, an add-on.
Tenant-based rules let the company’s ChatGPT or Claude account through while blocking a personal account on the same site.
Custom categories accept full directory paths, so one section of a large site can be blocked while the rest stays open.
Daily browsing quotas and time-of-day rules allow social or shopping sites in breaks instead of banning them outright.
Blocking personal AI tenants while allowing the corporate one, protecting iOS and Android devices, and setting browsing quotas.
A corporate Claude tenant is allowed while a personal account on the same service is blocked in the same session.
Mobile profiles for iOS and Android, then an AI upload, a phishing link and a malicious QR code stopped on an iPhone.
Time-of-day rules and per-category browsing quotas, configured in Data Security Cloud and reset each midnight.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Forcepoint built its name on data loss prevention, and the gateway shows it. Uploads, web forms and cloud storage are checked inline with the classifiers Forcepoint DLP uses on endpoints and email, so one data policy covers the browser too. Forrester’s Q1 2024 SSE Wave scored the platform 4.6 of 5 on data protection, tied for the top mark.
The SmartEdge agent applies policy on the device and asks the cloud only about URLs it has not seen recently and files that need scanning. Ordinary browsing goes straight to the site, which Forcepoint says keeps throughput near the line rate. Offices without agents tunnel to the cloud proxy instead, so guests are covered as well.
Forcepoint lists a Mumbai cloud region and local edge data centres in Bangalore, Chennai, Hyderabad, Mumbai and New Delhi to cut latency for Indian users. Its retention policy, though, keeps web and proxy logs for 30 days in a US East data centre. CERT-In expects 180 days of logs, so plan a SIEM export from day one.
It is a proxy with no DNS-layer tier, so there is no cheap floor for unmanaged devices on your resolver. The agent runs only on Windows and macOS. API scanning of data already in SaaS needs Cloud App Security, a separate licence. The Marketplace listing sets a 500-user minimum, which rules out small offices. Forcepoint documents no handling of DNS-over-HTTPS.
Confirm you clear the 500-user floor, then split users into agent laptops, tunnelled offices and mobile devices.
List apps that pin certificates and the banking or health sites you will not decrypt, before any policy goes live.
Put one office and fifty laptops on the gateway, log without blocking, and review what would have been stopped.
Apply your Forcepoint DLP policies to uploads, allow the corporate AI tenant, and block personal accounts on it.
Export web logs before the 30-day window closes, so CERT-In’s 180 days and audit requests are covered.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We already ran Forcepoint DLP, so the web channel picked up our Aadhaar and PAN rules without rewriting a single policy.”
“Allowing the company ChatGPT tenant while blocking personal logins settled a six-month argument with our legal team.”
“The agent on laptops felt quicker than our old cloud proxy, because routine browsing no longer took a detour abroad.”
“Thirty days of logs was not enough for our auditors. We stream everything to the SIEM now; set that up before go-live.”
“Quotas worked better than blocks. Staff get twenty minutes of shopping sites at lunch and complaints stopped.”
“Our 300-seat branch office fell under the 500-user minimum, so the quote took a custom package and extra weeks.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
$55 per user a year on AWS Marketplace; 500-user minimum.
The grid nobody publishes — how many ways traffic can reach the control (sites, agents, mobile, DNS) vs how deeply it protects data on the web.
Tunnels, PAC, agent, mobile, on-prem; inline DLP and tenant control.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Internet Access, Netskope Next Gen SWG, Cisco Umbrella, Cloudflare One Gateway and FortiSASE — on layer, steering, TLS, CASB, price, minimums, India and logs.
| Dimension | Forcepoint Web Security | Zscaler Internet Access | Netskope Next Gen SWG | Cisco Umbrella | Cloudflare One Gateway | FortiSASE |
|---|---|---|---|---|---|---|
| What it is | Data-centric cloud SWG | Inline cloud proxy | Instance-aware proxy | DNS layer, then SIG | Zero Trust web gateway | SASE for Fortinet shops |
| Enforcement layer | Proxy only | Proxy only | Proxy only | DNS + proxy | DNS + HTTP + network | DNS + proxy |
| Traffic steering | Tunnels, PAC or agent | Client or tunnels | Client or tunnels | Resolver change first | WARP or tunnels | FortiClient or FortiGate |
| Off-network devices | Windows, macOS, mobile | Roaming agent | Roaming agent | Roaming module | WARP client | FortiClient |
| TLS inspection | Full, agent certificates | Full | Full | Selective | Full, on the $7 tier | Full |
| CASB mode | Inline; API extra | Inline + API | Inline + API | API-based | Inline + API | Inline |
| Data protection (DLP) | Inline DLP built in | Edition or add-on | In Netskope One | SIG tiers only | Deeper at Enterprise | Check the bundle |
| Pricing model | Per user, 12 months | Per user, by edition | Platform, per user | Per user, four tiers | Free, then per user | Per user, by bundle |
| Published entry price | $55/user/yr | ~$6–12/user/mo | Not published | $2.25–6.50/user/mo | Free, then $7/user/mo | Quote; UK list from £78 |
| Included vs add-on | RBI and API CASB extra | Data features extra | Modules of a platform | Proxy at SIG only | Depth at Enterprise | Rises with the tier |
| Smallest estate | 500-user minimum | Not published | Not published | No floor printed | Free to 50 users | From 50 users |
| India PoPs | Mumbai + 5 edge cities | Four Indian cities | Eight Indian DCs | Mumbai and Chennai | Six cities named | Not documented |
| Log retention | 30 days, US East | 180 days | Ask in writing | 30-day search | 30 days for HTTP | 30 days at most |
| Best fit | DLP-led web control | Deepest inspection | Per-tenant SaaS control | A cheap DNS floor | Public price, wide India | FortiGate estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Forcepoint Web Security is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the gateway; admin-hour cost). Estimates model administrator time spent on unblock requests, separate web and DLP policies and log pulls at an assumed 1.5 hours per user a year, with 70% of it removed by one data-aware gateway. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Forcepoint’s AWS Marketplace listing suggests $55 per user a year for Web Security Edition on a 12-month term, with a 500-user minimum and add-ons such as selective browser isolation ($32), a dedicated egress IP ($75) and 12-month reporting ($2) per user. forcepoint.com prints no price. TechBag checks the seat floor, then quotes in INR with GST.
Best for estates of 500 users or more
Best for a broader rollout
Best for DLP-led, regulated estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do you have 500 or more users to license? Below that, ask Forcepoint for a custom package before you compare prices.
Which users get the SmartEdge agent, which offices use GRE, IPsec or a PAC file, and which phones need Forcepoint Mobile?
Can you push a certificate to PAC-file sites, and which pinned apps and private sites must bypass decryption?
What covers devices with no agent and no tunnel? This gateway has no DNS layer, so decide on one separately.
Is inline control enough, or do you need API scanning of files already in SaaS, which is a separate licence?
Where will logs live after 30 days in US East? CERT-In asks for 180 days, and its FAQ Q37 names proxy-server logs.
Does SEBI CSCRF apply? Guidelines 4.b and 4.c name proxy servers and web filters; map each to a policy here.
Running the on-prem line? CVE-2025-2274, a stored XSS through 8.5.6, is fixed in 8.5.7; confirm your version.
Model your seats and admin time first, or let a TechBag advisor scope a monitor-mode pilot with one office and fifty laptops.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.