Your internet access has to pass through a proxy. It shouldn’t have to be someone else’s cloud — SafeSquid Secure Web Gateway is an Indian-built proxy you run on your own Linux server, VM or cloud instance — TLS inspection, identity rules and DLP, with every log on a disk you place.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers SafeSquid Secure Web Gateway — SafeSquid’s one product, with its add-ons.
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy you run yourself that every browser goes through, so web traffic can be decrypted, filtered and logged on your side.
What consolidation actually replaces, dimension by dimension.
| Dimension | A bare proxy box with IP lists | SafeSquid Secure Web Gateway |
|---|---|---|
| HTTPS traffic | Passed through unread, or hand-configured | Intercepted or tunnelled per rule, TLS 1.0–1.3 |
| Who gets what | IP address lists in a config file | Users and groups from AD, LDAP or Kerberos |
| Sensitive uploads | Nothing reads them on the way out | DLP add-on reading text, images and Office files |
| Log history | Rotated away when the disk fills | 30 days local by default, forwarded for longer |
| A second gateway | A copy kept in step by hand | A cluster that syncs policy and certificates |
| What it is NOT | — | A cloud service, a roaming agent or a CASB |
The cheapest test is the free licence: build one gateway on a spare VM, send a single team through it for two weeks, and read the logs.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
An SMP-aware proxy on x86_64 Linux takes each request in explicit, transparent, reverse, proxy-chain, TCP-proxy or WCCP mode and applies your policy before it goes upstream.
A rule either tunnels a CONNECT request or intercepts its TLS; then SqScan, ClamAV, external parsers or an ICAP server examine content, and DLP analysers read what leaves.
DNSBL lookups, homograph detection, GeoIP rules and DNS-tunnelling checks run inside the gateway, and its bundled BIND can sit in your clients’ resolution path if you choose.
The cloud-linked portal issues activation keys, custom categories, roaming VPN settings and policy backups; where SafeSquid hosts it is not documented, so ask if residency matters.
A proxy daemon on a Linux server you own — TLS, content and DNS checks inline, with a portal for keys and categories.
SafeSquid is a web proxy you host yourself, so the traffic and the logs never leave your control.
Policy keys on user, group, source network, destination, time of day, application and transfer size, all in one rule set.
Users authenticate locally or through PAM, LDAP or Active Directory, with Kerberos single sign-on for domain-joined PCs.
Application signatures, login controls and social-media limits work beside enforced SafeSearch and YouTube restrictions.
Each CONNECT is tunnelled or intercepted by policy across TLS 1.0 to 1.3; a 2026 build moved to OpenSSL 3.5+ for post-quantum work.
The built-in SqScan engine, ClamAV, external parsers and any ICAP server you run can examine a download before the browser gets it.
Text and image analysers, true-MIME fingerprints and archive explosion; regex now reaches Office files, OCR is in beta. A paid add-on.
Explicit, transparent, reverse, proxy-chain, TCP-proxy and WCCP modes; WCCP itself is one of the premium feature subscriptions.
Active-active or active-standby clusters keep policy, categories and certificates in step across the gateways you operate.
SIEM-ready logs are kept 30 days on local disk by default; send them to syslog, a SIEM, S3 or Azure Blob to hold them longer.
Building a gateway from the Appliance Builder ISO, plus two dated demos of SafeSearch enforcement and an earlier release.
Building a gateway from the Appliance Builder ISO, the install route SafeSquid recommends today.
A 2012 demo of forcing SafeSearch at the gateway, shown in the old interface of an earlier release.
A 2014 walk-through of an earlier release, from when the product took the SafeSquid SWG name.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
SafeSquid Labs builds it in India, and it runs only on servers you control. CERT-In’s guidelines for government bodies ask that clients reach the internet through a proxy; here the proxy, its decrypted traffic and its logs all stay on hardware you place, in India if you put it there.
Register for a key, install the Appliance Builder ISO and you have a proxy with HTTPS inspection and custom policy on a licence with no time limit. The commercial plan adds the URL categorisation database, real-time threat feeds, 365-day cloud backup and email support.
It runs as an explicit, transparent, reverse or chained proxy, a TCP proxy or over WCCP, so it slots in behind an existing firewall. Users come from Active Directory, LDAP or PAM with Kerberos sign-on, and ICAP, SNMP and a REST interface connect it to the tools you run.
No cloud service and no roaming agent: remote users return over a VPN, with a paid add-on for Windows laptops only. There is no CASB, no price list today and no named customer. Free-tier category rules match nothing, and you size, patch and harden every server yourself.
Estimate peak concurrent connections per office and match them to SafeSquid’s sizing rows, from 400 up to 8,000 a server.
Register for an activation key, install the Appliance Builder ISO on a VM, change any default password and set the CA.
Point one office at the proxy, join it to Active Directory, turn on TLS interception and record every bypass you need.
Pick named users, connections or CPU hours, activate categories and threat feeds, then cluster a second gateway.
Forward logs to your SIEM or storage for 180 days, and decide how remote staff return: WireGuard or the Roaming add-on.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We proved the whole design on the free licence first, then found category rules did nothing until the subscription was active.”
“Kerberos sign-on meant users never saw a login prompt, and the rules finally named people instead of IP ranges.”
“The inspection team wanted web logs on our own servers for 180 days. We forwarded them to the SIEM and that closed the point.”
“An Appliance Builder install on a spare server took an afternoon, most of it spent pushing our interception certificate to PCs.”
“DLP flagged spreadsheets with account numbers going to personal mail sites. We had to buy it as an add-on, but it earned its place.”
“Sales staff on Macs get nothing off-site; the roaming add-on is for Windows laptops only, so plan remote cover separately.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the self-hosted secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Small Indian vendor; several builds in 2026.
The grid nobody publishes — how easily you can start (free tier, self-serve download, public price) vs how deeply the gateway inspects web traffic.
Free tier, self-serve download; TLS, DLP add-on, no CASB.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Fortinet FortiProxy, Skyhigh SWG On-Prem, Symantec Edge SWG, Kaspersky Web Traffic Security and Zscaler Internet Access — on deployment, TLS, remote users, price, add-ons, scale, patching and India.
| Dimension | SafeSquid Secure Web Gateway | Fortinet FortiProxy | Skyhigh Secure Web Gateway On-Prem | Symantec Edge SWG | Kaspersky Web Traffic Security | Zscaler Internet Access |
|---|---|---|---|---|---|---|
| What it is | Indian self-hosted proxy | Fortinet’s on-site proxy | Formerly McAfee gateway | ProxySG, renamed | Proxy + ICAP gateway | Cloud-only proxy |
| Deployment | ISO, image or tarball | Appliance or yearly VM | E/F boxes or a VM | Box, VA or private cloud | VM image or DEB | Nothing to install |
| TLS inspection | TLS 1.0–1.3, by rule | Full, hardware offload | Full, 4096-bit RSA | Full, SSL offload | Full, four modes | Full, in Zscaler’s cloud |
| Off-network users | VPN back; Windows add-on | No client | Only with cloud SWG | Via Cloud SWG | No roaming agent | Client Connector |
| Cloud and hybrid | Your nodes, synced | FortiSASE sold apart | 12.2 yes, 13.0 not yet | Universal Policy | No cloud side | The cloud is the policy |
| Cloud app control | Inline app control | Inline CASB | Inline only | Inline; CloudSOC for API | No CASB | Inline and API |
| Threat protection | SqScan, ClamAV, ICAP | AV, IPS, sandbox bundled | DLP in, sandbox extra | Content Analysis | Malware, phishing, files | Sandbox, DLP, RBI |
| Pricing model | Annual, three bases | Box + 500-seat lots | Per user, partner-led | Per user, boxes extra | Per user, banded | Per user, by edition |
| Published entry price | Free tier; then quote | Not published | Not published | Quote; UK MSRP £56.25 | Not published | ~$6–12/user/month |
| Included vs add-on | DLP, roaming extra | DLP, RBI optional | Anti-malware extra | Suite in, hardware out | In Total Security | Editions add depth |
| Hardware and scale | 400–8,000 connections | 6,000–60,000 users | Sized by appliance | Sized by S210/S410 | 20 nodes, 757 Mbps | 500B+ transactions/day |
| Lifecycle and patching | Several 2026 builds | Exploited admin flaws | Dated EOLs | 7.3 ends ~Dec 2026 | Supported to Sept 2027 | Nothing to patch |
| India and logs | Your servers, 30 days | On your hardware | Your site, India logs | Your racks; Indian PoPs | Your servers; KSN out | Four Indian cities |
| Best fit | Proxy-mandated offices | Fortinet-standard sites | Ex-McAfee estates | ProxySG estates | Kaspersky estates | No proxy boxes at all |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
SafeSquid Secure Web Gateway is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the gateway; admin-hour cost). Estimates model administrator time spent on hand-edited proxy rules, unblock requests and log pulls at an assumed 1.5 hours per user a year, with 70% of it removed by identity-based policy and searchable logs. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: SafeSquid’s pricing page now returns 404, and commercial subscriptions are quoted yearly by named users, concurrent connections or CPU hours, paid by PayPal or wire. An archived August 2024 page put commercial use under US$9 per user a year — history, not today’s price. A free licence with no time limit runs the proxy without URL categories or threat feeds. TechBag quotes in INR with GST.
Best for labs and proving the design
Best for a broader rollout
Best for production gateways
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your peak count of concurrent connections, and which row of SafeSquid’s sizing guide does each server meet?
Will the quote count named users, concurrent connections or CPU hours, and which fits how your offices browse?
Do you need URL categories and live threat feeds? The free tier has neither, so category rules match nothing.
Are DLP, Roaming, Log Aggregator and WCCP itemised in the quote, or will you discover them as extras later?
How do staff off the network come back: WireGuard, or the Windows-only Roaming add-on? Nothing is documented for macOS or phones.
Where will 180 days of logs live for CERT-In: a bigger local disk, your SIEM, or S3 or Azure Blob in an Indian region?
Has the cloud image’s default administrator password been changed, and who patches the Linux host and kernel?
Activation, categories and policy backups go through SafeSquid’s portal, whose hosting is undocumented. Is that acceptable?
Model your users and admin time first, or let a TechBag advisor size the servers and scope a pilot that sends one office through the gateway.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.