Your branches backhaul to a proxy and your VPN opens the whole network. One per-user platform should replace both — iboss Zero Trust SASE runs web filtering, CASB, ZTNA, DLP and SD-WAN on a containerised gateway of your own, delivered from 100+ PoPs — Mumbai and Delhi among them — or from your own data centre.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers iboss Zero Trust SASE — the Core, Advanced and Complete packages. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Network and security delivered from the cloud as one service: web gateway, private access and SD-WAN under one policy.
What consolidation actually replaces, dimension by dimension.
| Dimension | Backhauled proxies and a VPN | iboss Zero Trust SASE |
|---|---|---|
| Branch internet traffic | Backhauled to the head-office proxy | Sent straight to the nearest iboss gateway |
| HTTPS inspection | Partial, to spare the appliance | Unlimited decryption included in the platform |
| Remote access | A VPN that opens the whole network | Per-app ZTNA, from the Advanced package |
| Branch hardware | Router, firewall and proxy at each site | SD-WAN and an SE-170 gateway under one policy |
| Who shares the gateway | Every tenant on the same proxies | A containerised gateway and IPs of your own |
| What it is NOT | — | A published price, a Gartner Leader, or documented India residency |
The cheapest test is the 30-day proof of concept: one office and its roaming users, full HTTPS decryption, and the logs checked at the end.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Every tenant is given a dedicated containerised gateway, so processing is isolated in software and never mixed with others’ traffic; dedicated egress IPs cost nothing extra.
iboss lists 57 data centres, Mumbai and Delhi included, plus cloud-extended points for 100+ in all; the same containers also run in-country, on-premises or air-gapped.
The Cloud Connector agent covers six operating systems; sites steer by GRE or IPsec, WCCP, explicit proxy or PAC file, and network connectors run on AWS, Docker or VMware.
Reporting nodes keep logs and telemetry inside a chosen jurisdiction and stream events to a SIEM live; a reseller schedule shows the reporting licence sold separately.
A containerised gateway per customer — run in iboss’s cloud, a chosen country, your data centre or an air-gapped site.
iboss Zero Trust SASE gives every customer its own gateway, and sells the platform in three packages.
Each customer runs on a dedicated containerised gateway, so its traffic is processed apart and never co-mingled with other tenants.
Full HTTPS inspection is part of the platform; iboss charges no extra licence fee however much encrypted traffic is opened.
The entry package filters the web by URL category, adds DNS security and device posture checks, and decrypts HTTPS throughout.
Advanced adds malware sandboxing and threat feeds to the gateway; Complete layers an intrusion prevention system over both.
From Advanced, the Cloud Connector opens per-app tunnels only after anti-malware, firewall and disk-encryption checks pass.
One agent, the Cloud Connector, covers laptops, phones and shared Chromebooks across all six major operating systems.
SD-WAN comes with Advanced, and the SE-170 branch gateway hands a whole office’s traffic to the platform’s policies.
Offices can send traffic by GRE or IPsec tunnel, WCCP, ITD, F5, explicit proxy or a PAC file, without new hardware.
Core carries basic CASB, Advanced inspects SaaS inline, and Complete adds AI-powered CASB with out-of-band API scanning.
Complete brings advanced DLP and OCR for text in images; Purview integration and Exact Data Match are sold as add-ons.
Browser isolation streams a risky page as pixels, keeping its code off the endpoint; it is an add-on in every package.
Entra SSO, Defender for Cloud Apps, Sentinel forwarding and tenant restrictions pinned to your dedicated IP addresses.
The SE-170 branch gateway that brings SD-WAN into the platform, and using data labels to stop data loss. Both from iboss’s official channel, November 2024.
How the SE-170 branch gateway brings an office’s SD-WAN and internet traffic into the iboss platform.
Driving iboss data-loss rules from sensitivity labels, the DLP depth that arrives with the Complete package.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most cloud gateways are shared. iboss gives each customer its own containerised gateway, isolated in software, plus dedicated IP addresses at no extra charge. Microsoft tenant restrictions and Entra conditional access can pin to those fixed IPs, so SaaS sign-ins only succeed through your gateway.
iboss includes unlimited SSL decryption: full HTTPS inspection with no licence for the volume opened. Its comparison page sets this, per-customer containers and built-in SD-WAN against Zscaler; those are iboss’s claims, so measure throughput in the 30-day proof of concept.
Core covers web filtering, DNS security, HTTPS decryption and basic CASB. Advanced brings ZTNA, SD-WAN and sandboxing; Complete then layers AI-powered CASB, DLP with OCR, and IPS. Each step upgrades one per-user licence, and the gateways can run in-country, on-premises or air-gapped.
Every package is quoted, and the required reporting licence is sold separately. Gartner rated iboss a Niche Player in its 2025 SSE Magic Quadrant. ZTNA starts at Advanced, DLP at Complete, isolation is always extra, and agentless access, log retention and Indian residency are undocumented.
Map who needs only web filtering (Core), who needs private apps or SD-WAN (Advanced) and who handles regulated data (Complete).
Get in writing which gateway and reporting node serve Indian users, where their logs are stored, and for how many days.
Put one office and a group of roaming users through the Mumbai or Delhi data centre with full HTTPS decryption switched on.
Point Entra conditional access and tenant restrictions at your dedicated egress IPs, then move CASB rules from monitor to block.
On Advanced or Complete, move private apps behind ZTNA, stream logs to your SIEM, and switch off the old proxy and VPN.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Fixed egress IPs of our own let us lock our Microsoft 365 tenant to the gateway. Personal accounts stopped working that day.”
“The old proxy could only decrypt a slice of our traffic. Now all of it is inspected, and nobody argued about a decryption licence.”
“Starting on Core kept the first quote small. Moving up to Advanced for ZTNA later was a contract change, not a new rollout.”
“Chromebooks in our training centres ruled out two vendors. The Cloud Connector covered them along with the Windows laptops.”
“Ask how many days of logs you get before you sign. Retention was not written down, and our auditors want 180 days.”
“Capable platform, but the separate reporting licence surprised finance, and India residency answers came slowly.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SASE and SSE market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only per user; reporting licence sold apart.
The grid nobody publishes — where the gateways can run, India and air-gapped sites included, vs how many network and security functions one licence covers.
Cloud, in-country, own DC or air-gapped; SD-WAN in Advanced.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler, Netskope One, Palo Alto Prisma Access, Skyhigh SSE and Cloudflare One — on deployment, modules, price, add-ons, scale, inspection, private access, logs, India and support.
| Dimension | iboss Zero Trust SASE | Zscaler ZIA + ZPA | Netskope One SSE Platform | Palo Alto Prisma Access | Skyhigh Security Service Edge | Cloudflare One |
|---|---|---|---|---|---|---|
| What it is | SASE in three packages | Internet + private pair | Converged SSE platform | Cloud firewall as SSE | SSE in three suites | Zero Trust on a CDN |
| Deployment | Cloud, hybrid, air-gap | Cloud only | Cloud, NewEdge | GlobalProtect to cloud | Cloud plus on-prem | Cloud, WARP |
| Modules covered | Eight functions, one SKU | Broad, split in two | SSE set, SD-WAN apart | ZTNA, SWG, firewall | Data-led SSE set | SSE plus Magic WAN |
| Pricing model | Per user, by package | Per user, by edition | Per user, per module | Per user, yearly quote | Per user, via partners | Free tier, then per user |
| Published entry price | Quote; UK reseller £16 | ~$6–12 reported | ~$15+ reported | Not listed | Partner pricebook | $7/user/month |
| Included vs add-on | ZTNA from Advanced | Three subscriptions | DEM is extra | SaaS Security extra | ZTNA extra below top | Depth on Enterprise |
| Scale and network | 100+ PoPs, 4,000+ orgs | 150+ data centres | 100+ NewEdge DCs | 100+ locations | 145+ PoPs | 330+ cities |
| Inspection depth | Unlimited TLS, sandbox | Inline proxy benchmark | Tenant-aware inspection | App-ID and WildFire | Emulation sandbox | Paid plans inspect TLS |
| Private app access | ZTNA from Advanced | ZPA, own subscription | Client and clientless | ZTNA 2.0 bundled | In Complete, or add-on | Access, free to 50 |
| Log retention | No day count published | 6 months, then SIEM | 90 days default | 1 year included | 100 days; 365 extra | 30-day HTTP logs |
| India PoPs and logs | Mumbai, Delhi DCs | Indian DCs; logs unclear | 8 DCs, Mumbai plane | Mumbai since 2021 | 3 cities, India logs | 6 Indian cities |
| Support | 24x7 via reseller tier | 24x7 on paid plans | Three support levels | 24/7 with Premium | Partner-led | 24/7 for Enterprise |
| Lock-in and exit | Your DC or air-gapped | Cloud-only commitment | Modules move together | PAN policy model | Hybrid for good | No term to start |
| Best fit | Sovereign, hybrid SASE | All-in cloud at scale | Data-led, residency set | NGFW shops going remote | Hybrid proxy estates | Price-first teams |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
iboss Zero Trust SASE is one of 22 SASE & SSE products TechBag carries. The SASE & SSE guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users on the platform; engineer-hour cost). Estimates model engineer time spent running separate web proxies, VPN concentrators and branch boxes — rule changes, capacity tickets and backhaul faults — at an assumed 1.5 hours per user a year, with 70% of it removed by one cloud platform. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. iboss publishes no rates: Zero Trust Core, Advanced and Complete are licensed per user per year, and ten add-ons — browser isolation, SSPM+DSPM, Exact Data Match and digital experience management among them — are priced on top. The only public reference is a UK reseller’s G-Cloud 15 schedule (January 2026): Core from £16 per user per year for Europe-hosted service, reporting licence extra, minimum orders applying. It is not an iboss list price and does not cover India. TechBag scopes the package first, then gets the quote itemised in INR with GST.
Best for web security, then private apps
Best for a broader rollout
Best where regulated data leaves the building
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Who needs only web and DNS filtering (Core), ZTNA and SD-WAN (Advanced), or DLP and OCR (Complete)?
Is the reporting licence on the quote? A UK reseller’s schedule says it is required and sold separately.
iboss publishes no retention period: will the contract state 180 days for CERT-In, or will logs stream to your SIEM?
Which iboss data centre, Mumbai or Delhi, serves your users, and can a reporting node be placed in India?
Do contractors need browser-only access? Agentless ZTNA is not documented, so test it in the proof of concept.
Which add-ons do you need: browser isolation, SSPM+DSPM, Exact Data Match or digital experience management?
Are any on-prem gateways older than 10.2.0.160, which fixed CVE-2024-3378, a medium login-portal XSS?
Is the quote per user per year, in INR with GST, with package, add-ons, reporting and support tier itemised?
Count your users and branches first, or let a TechBag advisor pick the package, chase the Indian log answers and plan retention for CERT-In.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.