by Skyhigh SecurityTechBag Intel Page

Skyhigh CASB

Your staff use far more cloud apps than IT ever approved. Company data shouldn’t leave through the ones nobody checked — Skyhigh CASB rates the cloud services your people use, scans sanctioned apps such as Microsoft 365 and Salesforce by API, and controls uploads, downloads and logins inline through forward and reverse proxies.

API scanning plus forward and reverse proxy40,000+ cloud services risk-ratedQuote; per user, pooled or unlimited

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price; partners quote Shadow IT and sanctioned-app licences per user
Quote
Modes
API scanning for sanctioned apps, with forward and reverse proxy for inline control
API + proxy
Analysts
Gartner’s 2025 SSE Magic Quadrant, after Visionary in 2024; named in the 2026 edition, no quadrant given
Niche (2025)
India
The status page lists Mumbai Proxy and DLP PoPs, and India can be chosen for log storage
Mumbai PoPs

Quick answer

Skyhigh CASB governs cloud apps two ways: API connections scan what already sits in sanctioned apps such as Microsoft 365, Box and Salesforce, and forward and reverse proxies control uploads, downloads and logins as they happen. A registry of 40,000+ cloud services risk-scores shadow IT. It is quoted per user through partners, with Mumbai PoPs and India as a selectable log-storage location. Read more ↓ Show less ↑
Part 01 · Orient

The Skyhigh Security platform family

This page covers Skyhigh CASB — Shadow IT discovery plus sanctioned-app control, pooled or unlimited. The rest:

Quick facts

30-second orientation
Product
Cloud access security broker: API scanning plus forward- and reverse-proxy control of SaaS
Maker
Skyhigh Security, California; owned by STG (legal entity Musarubra US LLC); CEO Vishal Rao
Status
Sold as its own SKUs or inside SSE suites; Shadow IT from SSE Essential, unlimited apps from Advanced
Price
Not published; quoted per user through partners, which carry all of Skyhigh’s sales
Licence
Shadow IT (C02); sanctioned apps Pooled per user per app, or Unlimited (C63) per user
Coverage
40,000+ cloud services rated on 75+ attributes; API integration for 40 apps
Data
DLP in every SKU; EDM/IDM and OCR are add-ons; sanctioned data kept 100 days by default
Analysts
Gartner SSE MQ: Visionary 2024, Niche Player 2025, named in 2026; first of eight in 2026 Advanced SSE
India
Mumbai Proxy and DLP PoPs; India a selectable log-storage location; office in Bangalore
In India via
TechBag — app inventory, mode planning, quote in INR with GST, a sanctioned-app pilot
Part 02 · Learn

Understand CASB before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a cloud access security broker?

A CASB sits between your people and their cloud apps, finding which ones are used and controlling what data goes into them.

Firewall logs and app admin settings vs Skyhigh CASB — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionFirewall logs and app admin settingsSkyhigh CASB
Knowing which apps are usedFirewall logs and guessworkA risk-scored registry of 40,000+ services
Files already shared publiclyFound when a customer complainsAPI scans of the sanctioned tenant
Uploads to personal accountsBlocked by domain, or not at allControlled in flight by forward or reverse proxy
Devices you do not manageFull access or noneReverse-proxy policy at the app sign-in
Evidence for an auditScreenshots from each admin consoleIncidents in one tenant, 100 days or 12 months
What it is NOT—A firewall, a published price, or API depth for every app

The cheapest test is API-only: connect one Microsoft 365 or Google Workspace tenant, block nothing, and read what is already shared.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What every cloud service is scored on

Registry

Skyhigh cloud registry

More than 40,000 cloud services, each assessed on over 75 risk attributes, so the apps your users reach are ranked by risk rather than simply listed as shadow IT.

02
Where data at rest is scanned

API

Out-of-band API connections

API integrations for 40 apps, Microsoft 365, Box, Salesforce and Slack among them, read stored files, sharing and settings without sitting in the user’s traffic path.

03
How activity is controlled in flight

Proxy

Forward and reverse proxy

A forward proxy governs managed devices on their way to any app; a reverse proxy fronts a sanctioned app’s sign-in, the usual route to devices you do not manage.

04
Where policy and incidents meet

Tenant

Skyhigh Cloud tenant

One console holds DLP, behaviour analytics, malware and posture rules for both modes; sanctioned data stays 100 days by default, or 12 months on a paid plan.

A registry that rates every cloud service — then API scans at rest and forward or reverse proxies in flight.

Part 03 · Evaluate

Nine capabilities. Discover, control, protect.

Skyhigh CASB finds the cloud apps in use, scans the approved ones by API and controls activity in flight.

Discover
Shadow IT

40,000+ services, risk-scored

Each cloud service is rated on more than 75 attributes, so an unvetted file-sharing site ranks well above an audited, known one.

Discover
Sanctioned apps

API scans of stored data

API integrations reach 40 apps, including Microsoft 365, Google Workspace, Box, Dropbox, ServiceNow and Zoom, to scan what is stored.

Discover
Posture

SaaS settings checked

Misconfiguration monitoring flags risky settings in connected SaaS tenants, such as open sharing defaults, before data is exposed.

Control
Inline

Forward and reverse proxy

Uploads, downloads and logins are allowed, blocked or coached in flight, through a forward proxy or a reverse proxy at the app sign-in.

Control
UEBA

Behaviour, not only rules

User and entity behaviour analytics baseline normal activity and flag outliers such as mass downloads, mapped to MITRE ATT&CK.

Control
GenAI

Shadow AI, found and fenced

Inline DLP covers more than 1,900 AI apps, and API-mode DLP reaches Microsoft 365 Copilot and ChatGPT Enterprise directly.

Protect
DLP

One DLP engine in every SKU

DLP comes with every licence; exact and indexed document match (EDM/IDM) and OCR for images are bought as separate add-ons.

Protect
Malware

Sandboxing in the CASB

Sandboxing is part of the CASB’s threat protection, and malware findings sit in the same incident view as DLP and UEBA alerts.

Protect
Retention

Evidence kept for a year

Sanctioned-app data stays 100 days by default; the Extended Sanctioned Data Plan keeps 12 months and lifts the incident cap to 7M.

See it, don’t just read it

Watch Skyhigh CASB in action

Two 2024 overviews of shadow IT control and data protection, plus 2023 demos of API and reverse-proxy deployment and of Google Drive protection. All from Skyhigh’s official channel.

Skyhigh Security (official)·Overview, July 2024

Skyhigh CASB - Monitor and Regulate Access to Cloud Apps

How discovery and risk ratings turn unknown cloud apps into ones you can allow, restrict or block.

Skyhigh Security (official)·Overview, July 2024

Skyhigh CASB - Control Over Data and Cloud Activity From Any Source

Data and activity control across sanctioned apps, whichever device or network the user starts from.

Skyhigh Security (official)·Demo, September 2023

API and Reverse Proxy Deployments with Skyhigh CASB

A 2023 look at the two deployment modes side by side: scanning by API and controlling sessions by reverse proxy.

Skyhigh Security (official)·Demo, May 2023

Skyhigh Cloud Access Security Broker for Google Drive

A 2023 walkthrough of CASB policy applied to one sanctioned app, Google Drive, end to end.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Skyhigh CASB

Company data now lives in other people’s apps. Skyhigh CASB watches it there and on the way in.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Both halves of CASB, one policy console

Inline and API CASB answer different questions: one stops an upload as it happens, the other finds what was uploaded last year. Skyhigh sells both, proxies plus API integration for 40 apps, with one DLP engine, so a rule written once applies in flight and at rest.

02

Licensing that follows the apps you approve

Shadow IT discovery is its own SKU (C02). Sanctioned apps are then licensed Pooled, per user per app, or Unlimited (C63), per user across any app. Governing only Microsoft 365 and Salesforce need not mean paying for unlimited coverage.

03

Data protection with an analyst score

Gartner’s 2024 Critical Capabilities for SSE gave Skyhigh the highest score in the Protect Data use case, and the 2026 edition ranked it first of eight vendors in Advanced SSE at 4.2/5, with 4.06/5 for SaaS and AI Enablement.

04

Where it stops

There is no public price, and Skyhigh sells only through partners. It was a Niche Player in Gartner’s 2025 SSE Magic Quadrant. API depth covers 40 apps, not every SaaS tool, Cloud SWG alone carries no CASB licence, and no Indian customer is named.

The idea
API scanning plus inline proxy control
The reach
40,000+ services rated, 40 API apps
The price
Quote; per user, pooled or unlimited
Proof, not promises

The numbers behind the platform

40000+ services
in Skyhigh’s cloud registry, each risk-rated on more than 75 attributes
— Vendor
40 apps
with API integration for scanning sanctioned data at rest, per Skyhigh’s CASB page
— Vendor
100 days
default retention for sanctioned-app data; 12 months with the Extended Sanctioned Data Plan
— Vendor
1900+ AI apps
covered by inline DLP for generative AI, beside API DLP for Copilot and ChatGPT Enterprise
— Vendor
#1 of 8
Skyhigh’s rank in the Advanced SSE use case of Gartner’s 2026 Critical Capabilities, at 4.2/5
— Analyst
7M incidents
the incident cap on the Extended Sanctioned Data Plan, up from 2M by default
— Vendor

What your Skyhigh CASB rollout looks like

Week 1Model

Read the shadow IT report

Route a pilot group through the Skyhigh gateway and let the registry rank the cloud services in use, before any policy.

Week 2Decide

Choose the sanctioned apps

List the apps you will govern, then weigh Pooled per-app licensing against Unlimited before the partner quotes.

Week 3Pilot

Connect APIs, report only

Connect Microsoft 365 or Google Workspace by API, scan existing files and sharing links, and only report on findings.

Month 2Prove

Switch on inline control

Add forward or reverse proxy for one app, coach users before blocking, and fix any app flows that break on the way.

Month 3Commit

Set retention and exports

Decide whether 100 days of sanctioned data is enough, add the extended plan if not, and schedule incident exports.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
64+ reviews*
83% would recommend
Shadow IT discovery4.4
DLP depth4.4
Inline control4.2
API coverage4.0
Ease of setup3.6
5★
45%
4★
35%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“The first shadow IT report ranked hundreds of apps by risk, and the personal file-sharing sites at the top were what we blocked first.”
Information Security Manager
BFSI
Insurance
“API scanning found customer spreadsheets shared publicly from OneDrive long before we bought it. Inline alone would never have seen them.”
Data Protection Officer
Insurance
Manufacturing
“Pooled licensing suited us: we govern Microsoft 365 and Salesforce only, so paying for unlimited sanctioned apps made no sense yet.”
IT Procurement Lead
Manufacturing
IT Services
“The reverse proxy covers contractors on their own laptops. Expect a few broken app flows while you tune it, and test each one.”
Cloud Security Engineer
IT Services
Healthcare
“We export CASB incidents every month, because the default 100 days of sanctioned-app data is shorter than our auditors ask for.”
Compliance Head
Healthcare
Retail
“Strong DLP, but the console takes learning, and the partner quote took three rounds before EDM was itemised on its own line.”
Head of IT
Retail
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud access security broker market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag CASB Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Skyhigh CASBThis page

Quoted per user via partners; Pooled or Unlimited apps.

Grid 02 · The architecture

Enforcement Modes × Data Depth

The grid nobody publishes — how many ways a CASB can reach cloud apps vs how deeply it inspects the data inside them.

Deep but narrow reachFull multimode CASBsLight add-onsWide but shallower
Skyhigh CASBThis page

API plus forward and reverse proxy; EDM, IDM and OCR.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Skyhigh CASB vs the CASB field

Against Netskope CASB, Microsoft Defender for Cloud Apps, Zscaler CASB, Forcepoint CASB and Palo Alto SaaS Security — on modes, app coverage, price, DLP, retention and India.

DimensionSkyhigh CASBNetskope CASBMicrosoft Defender for Cloud AppsZscaler CASBForcepoint CASBPalo Alto SaaS Security
What it isMultimode CASBNetskope One moduleMicrosoft’s SaaS guardCASB in Zscaler SSEData-first CASBNGFW-native CASB
Deployment modesAPI + forward + reverseAPI, forward, reverseAPI + reverse proxyInline + API, no reverseAPI, reverse, forwardInline in NGFW + API
App risk catalogue40,000+ services80,000+ apps (CCI)33,000+ appsRisk score per app800,000+ apps claimed400+ categories
API connectors40 API appsCount not published27 app connectorsCount not publishedMajor suites namedCount not published
Pricing modelPer user, by app scopePer user, in a bundlePer user, in a suitePer user, by editionPer user, quotedSeparate subscriptions
Published entry priceNot published~$15+ bundled$12/user/month (suite)~$6–12 reportedNot publishedNot published
Included vs add-onEDM/IDM, OCR extraBundle decidesPurview labels nativeEditions decideInline and API in oneThree licences
Data protectionEDM, IDM, OCRAI/ML DLP enginesPurview-driven DLPEDM, IDM, OCRShared Forcepoint DLPEnterprise DLP
Threats and UEBAUEBA, sandbox, ATT&CKUEBA, sandboxingUEBA in Defender XDRSandbox, at-rest scansThreat remediationWildFire analysis
Posture and AI appsSSPM + 1,900 AI appsSSPM, GenAI riskSSPM + app governanceSSPM includedCompliance mappingCompliance reports
Retention and limits100 days, 12 mo optionNot publishedUp to 180 daysNot publishedNot publishedSized by log service
India presenceMumbai PoPs, India logs8 Indian data centresNo India for core data4 Indian citiesMumbai region, 5 edges4 Indian locations
Lock-in and exitData gone in ~30 daysPlatform pullMicrosoft-centredTied to the ZIA pathDLP policy couplingNeeds PAN in the path
Best fitSkyhigh web estatesDeep multimode CASBMicrosoft 365 estatesZscaler ZIA estatesForcepoint DLP usersPalo Alto firewall shops
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Skyhigh CASB if…

  • ✓You need API scanning of sanctioned apps and inline control of uploads, governed by one DLP policy
  • ✓You govern only a few sanctioned apps and want Pooled licensing per app instead of paying for unlimited coverage
  • ✓Your web traffic already runs through a Skyhigh gateway, on-premises or in the cloud, and CASB should share its policy

Compare alternatives if…

  • ✓Your estate is Microsoft-only and Entra ID plus Purview already set policy — Defender for Cloud Apps comes in the Defender Suite
  • ✓You want Indian data centres and a management plane in Mumbai documented up front — Netskope documents both
  • ✓Your firewalls are Palo Alto — SaaS Security enforces inline in the firewall path without a separate proxy

Do not expect…

  • ✓A published price, or a direct sale outside the partner channel
  • ✓API connections for every SaaS tool — Skyhigh lists 40 apps
  • ✓Top-tier SSE quadrant status: Skyhigh sat among the Niche Players in Gartner’s 2025 SSE report

Skyhigh CASB is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does ungoverned cloud app use cost you?

Drag the sliders (employees using cloud apps; security staff-hour cost). Estimates model the security team’s time per user each year spent finding unapproved apps, reviewing public sharing links and handling cloud-data incidents, at an assumed 1.5 hours per user a year, with 70% of it removed by risk-scored discovery, API scanning and inline policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cloud-app oversight cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Skyhigh publishes no CASB price and sells only through partners. Licensing is per user: CASB Shadow IT (C02) covers discovery and risk scoring, and sanctioned apps are licensed Pooled, per user per app, or Unlimited (C63), per user across any app. Advanced DLP (EDM/IDM), OCR and the Extended Sanctioned Data Plan are add-ons. SSE Essential includes Shadow IT and SSE Advanced the unlimited tier. TechBag maps your apps first, then quotes in INR with GST.

CASB Shadow IT (C02)

Best for finding and ranking unapproved apps

  • Registry of 40,000+ cloud services
  • 75+ risk attributes per service
  • Included in SSE Essential and up

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Sanctioned apps: Pooled or Unlimited

Best for API and inline control of approved apps

  • Pooled: per user, per sanctioned app
  • Unlimited (C63): per user, any app
  • Unlimited bundled in SSE Advanced

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
App scope

How many sanctioned apps will you govern? Pooled licensing is per user per app; Unlimited (C63) covers any app.

2
API coverage

Is each sanctioned app among the 40 with Skyhigh API integration? If not, inline control is its only cover.

3
Inline mode

Which apps need a forward proxy for managed devices, and which a reverse proxy to reach unmanaged ones?

4
DLP depth

Do you need exact or indexed document match, or OCR for images? All are add-ons; get each itemised in the quote.

5
Retention

Is 100 days of sanctioned data enough for your auditors, or do you need the 12-month Extended Sanctioned Data Plan?

6
India

Will log storage be set to India, and which Indian PoPs — Mumbai, Bangalore or Noida — will your users reach?

7
Agents

If inline control relies on Client Proxy, are laptops on 4.9.x? Version 4.8.x reached end of life on 1 May 2026.

8
Suite or SKU

Would SSE Essential (Shadow IT) or SSE Advanced (unlimited apps) cost less than CASB SKUs plus a gateway?

FAQ

Questions buyers ask

Skyhigh CASB is the cloud access security broker from Skyhigh Security. It rates the cloud services your users reach against a registry of 40,000+, scans sanctioned apps such as Microsoft 365 by API, and controls uploads, downloads and logins inline by forward and reverse proxy.

Ready to evaluate Skyhigh CASB?

List your sanctioned apps and check them against the 40 API integrations first, or let a TechBag advisor plan the modes, compare pooled and unlimited licensing and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.