Blocking every unknown site breeds tickets; allowing them invites malware. Isolation lets users open them safely — Skyhigh Remote Browser Isolation runs risky web pages in a throwaway cloud browser and streams users only a live image — risky-site isolation bundled with Cloud SWG Advanced and the SSE suites, full isolation bought per seat.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Remote Browser Isolation — Risky Web mode and the per-seat Full Isolation add-on. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The web page runs in a remote, throwaway browser, and the user sees only a live picture of it.
What consolidation actually replaces, dimension by dimension.
| Dimension | Block risky sites, raise tickets | Skyhigh Remote Browser Isolation |
|---|---|---|
| An uncategorised site | Blocked until someone raises a ticket | Opened in isolation under Risky Web |
| Code from a phishing page | Runs in the user’s own browser | Runs in a cloud container that is discarded |
| Copying data out | Nothing between the page and the clipboard | Clipboard kept in-session or blocked by rule |
| Screenshots and printouts | Free to print or capture | Print and Windows capture blocked; pages watermarked |
| Who pays for full isolation | Everyone, or no one | Seats bought only for high-risk users |
| What it is NOT | — | A standalone product, or a published price |
The cheapest test is Risky Web on a pilot group: isolate uncategorised sites for two weeks and count the unblock tickets that stop arriving.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Two rule sets in the SWG web policy decide: Risky Web judges a site by reputation and URL category, while Full Isolation follows your lists of domains, IPs, categories or all traffic.
Traffic passes from a cloud SWG PoP to an RBI master controller, whose VM manager starts a session container; the site’s code executes there and is thrown away afterwards.
The user’s own browser gets a real-time interactive picture of the page over WebSocket; every hop uses TLS 1.3 with a hybrid post-quantum key exchange by default since June 2025.
Full Isolation seats are tracked across three 12-hour buckets; VIP users can hold reserved seats, and you choose whether over-limit sites are blocked or opened unisolated.
Policy picks the session — the page runs in a throwaway cloud container and only a live image reaches the user.
Skyhigh Remote Browser Isolation runs the web page in Skyhigh’s cloud so its code never runs on the user’s device.
Uncategorised and unverified sites are isolated by default instead of refused, so a new domain no longer means a help-desk ticket.
Isolate all traffic, or lists of domains, IPs, URL categories and risk levels, plus every site that has no URL category at all.
Named domains can be isolated when a user reaches them from a page that is already isolated; the option is off by default.
Copying and pasting can be unrestricted, kept inside the isolated session or blocked, with character caps in Full Isolation.
Allow or block file uploads and downloads for all domains with exceptions; file types are recognised by their extensions.
Block Ctrl+P, Save as PDF and Windows screen capture, and stamp the user’s name or email diagonally across isolated pages.
Pages can be made read-only, cookies kept off the device and the built-in RBI password manager switched off for everyone.
An on-prem or Hybrid Mesh SWG forwards chosen sessions to the cloud by next-hop proxy on port 8081, where they are isolated.
Since SSE 6.8.2 in June 2025, each RBI link uses the X25519MLKEM768 hybrid key exchange, with nothing for admins to set.
Two Cyber60 talks from Skyhigh’s official channel, recorded in October and November 2025 — discussions of why isolation matters, not product demos.
A short talk on why isolating the browser matters more as AI tools and agents spend their time on the open web.
A talk weighing a managed enterprise browser against remote isolation for big estates; a discussion, not a product demo.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Risky Web is part of Cloud SWG Advanced and all three SSE suites, so uncategorised and low-reputation sites open in isolation instead of being blocked. Skyhigh calls itself the only vendor including risky-web RBI at no extra charge — its own claim, though its packaging table bears out the inclusion.
Full Isolation is licensed in seats, not for the whole workforce. Someone active at least once a day keeps a seat, use may run to 115% of what you bought, and VIPs can have seats held for them. Buy seats for finance, executives or researchers; Risky Web covers everyone else.
Isolation also governs what leaves the page: clipboard limits, upload and download rules, print and screen-capture blocks, read-only pages and watermarks. Skyhigh says its DLP reaches into isolated sessions, so pasting card or personal data can be stopped, from the same web policy tree.
Not sold alone, and no public price. Pixel streaming wants 25 Mbps and under 40 ms latency, with about five tabs open. Full Isolation plus the HTTPS Decryption rule set breaks Word and Excel online. There are two RBI talks but no demo, and the PoP rendering Indian sessions is undocumented.
Confirm whether your SKU is Cloud SWG Advanced or an SSE suite, which already carries Risky Web, before buying seats.
Run speed tests at each office against Skyhigh’s 25 Mbps, 40 ms and 7 ms marks, and fix the weakest branch links.
Enable Risky Web for a pilot group, bypass streaming and web-meeting categories, and verify with a test such as nopixels.com.
Buy Full Isolation seats for finance, executives or researchers, mark VIPs, and decide whether over-limit sites are blocked.
Set clipboard caps, upload and download rules, print blocking and watermarks, then review the browser isolation dashboard.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Turning on Risky Web cut our tickets for unblocking new domains sharply, and it was already in our SSE suite, so no new PO.”
“We bought Full Isolation seats only for the treasury team. The 36-hour seat window meant shift workers kept theirs.”
“Watermarks plus print blocking on our vendor portal stopped screenshots doing the rounds on messaging groups.”
“Branch links under 25 Mbps felt sluggish in isolation. Check the speed test numbers before you roll it out wide.”
“Word and Excel online broke under Full Isolation until we took HTTPS Decryption off for them; read the restriction note.”
“Our on-prem gateways send risky sessions to the cloud through the next-hop rule, so isolation came without new hardware.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the browser isolation market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Risky Web bundled; Full Isolation seats quoted.
The grid nobody publishes — how much you can control inside an isolated session vs how much of the user's traffic and apps can be isolated.
Clipboard caps, print and capture blocks, watermarks; web plus Private Access.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Zero Trust Browser, Netskope RBI, Cloudflare Browser Isolation, Menlo Secure Cloud Browser and Forcepoint RBI — on rendering, licensing, price, data controls, India and exit.
| Dimension | Skyhigh Remote Browser Isolation | Zscaler Zero Trust Browser | Netskope Remote Browser Isolation | Cloudflare Browser Isolation | Menlo Secure Cloud Browser | Forcepoint Remote Browser Isolation |
|---|---|---|---|---|---|---|
| What it is | SSE isolation service | Isolation for ZIA | RBI in Netskope One | Cloudflare One add-on | Specialist cloud browser | RBI with file CDR |
| Deployment | Cloud, plus hybrid | Zero Trust Exchange | NewEdge cloud | Cloudflare network | Cloud, no agent | Cloud, on-prem, hybrid |
| Rendering method | Pixel stream | Safe pixel streaming | Pixel stream | Vector rendering (NVR) | DOM mirroring (ACR) | Pixels or clean DOM |
| What gets isolated | Risky or chosen sites | Web, SaaS, private apps | Depends on licence | Sites picked by policy | Sessions in the cloud | Full or Selective |
| Pricing model | Per seat, quoted | Add-on to ZIA | Platform add-on | Add-on to a plan | Products × users | Per-user add-on |
| Published entry price | Not published | Add-on not priced | Not published | Base $7; add-on quoted | Estimator only | $32 per user |
| Included vs add-on | Risky Web bundled | Separate add-on | Two RBI licences | Add-on only | DLP sold apart | Full vs Selective tier |
| Seat and scale limits | Seats, 115% buffer | Not published | Not published | 50 free base users | Not published | 500-user minimum |
| Data controls in session | Clipboard, print, marks | Clipboard, print, files | Files and form POSTs | Six session controls | Clean content; DLP extra | CDR and clipboard rules |
| Unmanaged devices | Via Private Access, CAI | Agentless BYOD access | Not stated | Clientless by URL | Nothing to install | Any HTML5 browser |
| Platform integration | SWG, CASB, ZTNA, DLP | ZIA, ZPA, data suite | Next Gen SWG policy | Gateway and Access | Own platform | ONE, SD-WAN, NGFW, DLP |
| India presence | 3 PoP cities, India logs | 4 India node cities | 8 Indian data centres | 6 India PoP cities | Mumbai PoP, global logs | 5 India edge cities |
| Lock-in and exit | Tied to Skyhigh SWG | Tied to ZIA | Tied to Netskope One | Tied to Gateway | Separate vendor | Best inside Forcepoint |
| Best fit | Skyhigh SWG estates | ZIA customers | Netskope One estates | Cloudflare One users | Isolation-first buyers | Forcepoint DLP estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no browser isolation guide yet, so Skyhigh Remote Browser Isolation sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (users who browse risky or uncategorised sites; staff-hour cost). Estimates model time lost to unblock requests, blocked research and cleaning up after web-borne malware, at an assumed 1.5 hours per user a year, with 70% of it removed by isolating those sites instead of blocking them. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no price: Risky Web isolation comes with Cloud SWG Advanced and the Essential, Advanced and Complete SSE suites, while Full Isolation is the UCEFI add-on, licensed in seats and sold through partners; the pricebook needs a partner login. TechBag checks what your licence already covers, sizes the seats, then quotes in INR with GST.
Best for isolating uncategorised and risky sites
Best for a broader rollout
Best for high-risk users and chosen sites
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Does your current SKU include Risky Web, meaning Cloud SWG Advanced or an SSE suite, or is it plain Cloud SWG?
How many people truly need every site isolated? Price Full Isolation seats for them, not for the whole headcount.
Do your offices meet 25 Mbps down, 40 ms latency and 7 ms jitter? Pixel streaming suffers on weaker links.
Will Word and Excel online run under Full Isolation? With HTTPS Decryption on, Skyhigh says they break.
Which clipboard, upload, download, print and watermark settings will each user group get inside isolation?
If you run on-prem SWG, is the next-hop proxy to the cloud on port 8081 set, with the RBI domains not decrypted?
Ask in writing which PoP renders isolated sessions for Indian users, and set the log storage location to India.
TechBag does not have a browser isolation guide yet, so weigh the five rivals in the table above directly.
Check whether your current Skyhigh licence already covers Risky Web, or let a TechBag advisor size Full Isolation seats and test your branch links.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.