Your proxies sit at head office and your people don’t. Web policy shouldn’t depend on where they log in — Skyhigh Secure Web Gateway decrypts and inspects web traffic in Skyhigh’s cloud PoPs, on appliances you keep on site, or both under one policy, with an emulation sandbox, DLP and — in Cloud SWG Advanced — isolation of risky sites included.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Secure Web Gateway — Cloud SWG and Cloud SWG Advanced, including hybrid rights to on-site and virtual appliances. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy in the cloud inspects every web request from offices and laptops, and appliances on site can enforce the same rules locally.
What consolidation actually replaces, dimension by dimension.
| Dimension | A head-office proxy and VPN backhaul | Skyhigh Secure Web Gateway |
|---|---|---|
| Where web traffic is inspected | Only at head office, via VPN backhaul | The nearest PoP, or your own appliance |
| Laptops at home | Unfiltered unless the VPN is up | Client Proxy sends them to the cloud gateway |
| Unknown sites | Allowed or blocked outright | Isolated in a remote browser (Advanced) |
| Uploads to AI tools | Invisible inside HTTPS | Decrypted and checked by DLP inline |
| Where logs live | On the proxy’s own disks | Selectable region, India included |
| What it is NOT | — | A CASB, a Linux client, or a published price |
The cheapest test is one branch: tunnel it to an Indian PoP, put ten laptops on Client Proxy, and read a week of logs before you buy.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sites send web traffic over IPsec or GRE tunnels to a primary and a secondary PoP; the Global Routing Manager, a DNS-based service, picks the closest pair.
Skyhigh Client Proxy forwards traffic from Windows and macOS laptops; Mobile Client covers iOS and Android phones, pushed through Microsoft Intune or Workspace ONE.
The PoP decrypts SSL, checks URL and application risk, runs files through Gateway Anti-Malware’s ML emulation sandbox and applies DLP before a page reaches the user.
The Cloud SWG licence also covers on-premises SWG and virtual appliances on KVM or SVP, so head-office traffic can be inspected locally under the same policy.
Tunnels and Client Proxy into Indian and global PoPs — with on-site appliances enforcing the same policy where you keep them.
Skyhigh Secure Web Gateway inspects every web request in a cloud PoP or on your own appliance, under one policy.
Branch routers and firewalls tunnel to Skyhigh over IPsec or GRE, with a secondary PoP ready if the primary drops.
Client Proxy keeps Windows and macOS laptops on the cloud gateway from home or hotel; version 4.9.0 fixed three 2024 CVEs.
Mobile Client 4.2.1 supports Android 15–16 and iOS 15–18, 26 and 27, deployed through Intune or Workspace ONE.
SSL decryption exposes what is inside HTTPS, so URL, application-risk and coaching rules act on real content, not just domains.
Gateway Anti-Malware emulates unknown files with machine learning inline; Skyhigh says it adds 19.5% protection over plain AV.
DNS security flags tunnelling, generated domains and newly registered domains, answering with a block page, NXDOMAIN or sinkhole.
Cloud SWG Advanced opens uncategorised and risky sites in remote browser isolation at no extra charge; Full Isolation is per seat.
Secure Browser Controls govern uploads, text paste, downloads, the clipboard, printing and the context menu in Chrome, Edge, Firefox or Safari.
DLP is in every licence and watches prompts and uploads to more than 1,900 AI apps inline, ChatGPT and Claude among them.
Secure Browser Controls (2026), protection from unknown threats (2024), and two 2023 demos of risk-based app coaching and tenant restrictions. All from Skyhigh Security’s official channel.
The browser ruleset that limits uploads, pasting, printing and the clipboard, whichever browser a user opens.
How the gateway handles files and sites it has never seen, from emulation to isolation.
A 2023 demo of blocking cloud apps by risk score and warning users with a coaching page instead.
A 2023 demo of letting staff into the company’s own cloud tenant while keeping personal tenants out.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
A Cloud SWG licence also entitles you to on-premises SWG and to virtual appliances on KVM or SVP, and hybrid mode manages both from one policy. Head office can keep inspecting locally while roaming staff go to the nearest PoP. Forcepoint, Fortinet and Broadcom also sell both forms; Skyhigh is one of few.
Cloud SWG Advanced sends uncategorised and risky sites to remote browser isolation at no added cost. Skyhigh says no other vendor bundles risky-web RBI into its web security this way. Isolating every site is Full Isolation, licensed per seat, with use measured in three 12-hour buckets and overuse tolerated to 115%.
Skyhigh’s status page lists SWG PoPs in Bangalore and Noida and proxy and DLP PoPs in Mumbai, checked in October 2026. India is one of eight log-storage locations you can select. Web logs are kept 100 days by default, or a year with the SSE Data Retention Add-on, which gets you to CERT-In’s 180 days.
There is no public price. Cloud SWG is not a CASB: Shadow IT discovery starts at SSE Essential. Skyhigh documents no Linux client, and Client Proxy 4.8.x reached end of life on 1 May 2026. The 13.0 on-prem release, still limited availability, leaves out cloud policy sync. Gartner placed Skyhigh a Niche Player in 2025.
Count users, list offices and any on-site proxies, and decide between Cloud SWG and Cloud SWG Advanced for isolation.
Select India as the log-storage location and decide whether CERT-In’s 180 days means the retention add-on or an export.
Bring one branch in over IPsec or GRE, roll out the SSL certificate, and watch the Bangalore, Noida or Mumbai PoP it lands on.
Deploy Client Proxy 4.9 on Windows and macOS, push Mobile Client through Intune, and test coaching pages on real users.
Bring existing 12.2.x appliances or new virtual ones into hybrid mode, then retire rules that now live in one cloud policy.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We kept our two proxy appliances at head office and moved field sales to the cloud PoPs. One policy covers both.”
“Risky-web isolation came with Cloud SWG Advanced, so uncategorised sites stopped being a ticket for us every week.”
“Choosing India as the log location settled a question our auditors had raised about where web history was stored.”
“Tenant restrictions let staff into our Microsoft 365 tenant while personal accounts got blocked. That was the win.”
“We had to move every laptop off Client Proxy 4.8 before May 2026. Plan the upgrade window before you sign.”
“Strong engine, but the console takes time to learn and we needed a partner just to get a price in front of finance.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the secure web gateway market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Niche Player in 2025; first in Gartner’s 2026 Advanced SSE use case.
The grid nobody publishes — how many places the gateway can enforce and keep its logs, India included, vs how much it inspects inside each request.
Cloud, appliances and VMs on one policy; India log storage; risky-web RBI.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Internet Access, Netskope Next Gen SWG, Forcepoint Web Security, Palo Alto Prisma Access and Cloudflare One Gateway — on deployment, steering, roaming, inspection, isolation, CASB, price, India PoPs and logs.
| Dimension | Skyhigh Secure Web Gateway | Zscaler Internet Access | Netskope Next Gen SWG | Forcepoint Web Security | Palo Alto Prisma Access | Cloudflare One Gateway |
|---|---|---|---|---|---|---|
| What it is | Cloud + hybrid SWG | Cloud proxy | Per-instance proxy | DLP-led cloud SWG | Cloud firewall SSE | DNS + HTTP gateway |
| Deployment options | Cloud, on-prem or both | Cloud service | Cloud, in a platform | Cloud, agent, on-prem | Cloud-delivered | Cloud edge only |
| How traffic arrives | Tunnels, GRM, client | Tunnels, agent, PAC | Client and tunnels | Tunnels, PAC, SmartEdge | GlobalProtect, IPsec | WARP, DNS, tunnels |
| Roaming devices | Win, macOS, mobile | Client Connector | Netskope Client | SmartEdge, mobile app | GlobalProtect | WARP client |
| Inspection and threats | SSL + emulation sandbox | Full TLS; sandbox up | Full TLS, own engine | Full HTTPS, two engines | Full TLS, WildFire | Full TLS at $7 |
| Browser isolation | Risky-web RBI included | Edition or add-on | RBI in the platform | $32 add-on | Separate licence | Enterprise tier |
| CASB and DLP | DLP yes; CASB later | Inline + API, by edition | CASB at its core | Inline DLP; API extra | CASB and DLP extra | Both; Enterprise depth |
| Pricing model | Per user, via partners | Per user, by edition | Per user, platform | Per user, yearly | Users and bandwidth | Free, then per user |
| Published entry price | Not published | ~$6–12/user/mo | Not published | $55/user/yr | Quote only | $7/user/mo after 50 |
| Included vs add-on | GAM and DLP in | Depth by edition | Module by module | API CASB, RBI extra | Services as lines | Enterprise for depth |
| India PoPs | Bangalore, Noida, Mumbai | Four Indian cities | Eight Indian DCs | Mumbai + 5 edge cities | Four Indian locations | Six Indian cities |
| Log retention and location | 100 days; India option | 180 days | Get it in writing | 30 days, US East | Not verified here | HTTP logs 30 days |
| Minimum and scale | No minimum printed | Enterprise-sized deals | Not published | 500-user minimum | No floor published | Starts at one user |
| Best fit | Hybrid, India logs | Inspect every session | Per-tenant SaaS rules | Forcepoint DLP shops | Strata NGFW estates | List price, wide India |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Skyhigh Secure Web Gateway is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users behind the gateway; security staff-hour cost). Estimates model the staff time spent cleaning up web-borne malware, handling blocked-site tickets and maintaining head-office proxies at an assumed 1.5 hours per user a year, with 70% of it removed by cloud inspection, isolation and one policy. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no price for Cloud SWG or Cloud SWG Advanced, and its pricebooks sit behind a partner login. Both are quoted per user a year through partners; Full Isolation is counted per seat, and service providers can buy pay-go. Advanced adds risky-web isolation at no extra charge, while Full Isolation, Private Access, Cloud Firewall, OCR, EDM/IDM DLP and 365-day log retention are add-ons. TechBag counts your users and sites first, then quotes in INR with GST.
Best for web inspection in the cloud and on site
Best for a broader rollout
Best for estates with risky, uncategorised browsing
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Cloud SWG or Cloud SWG Advanced? Only Advanced includes risky-web isolation; Full Isolation is per seat on top.
Do you need Shadow IT discovery or API CASB? Neither is in Cloud SWG; both start at the SSE suites.
Will you select India as the log-storage location, and is that choice recorded in the order and the tenant?
Is 100 days enough, or does CERT-In’s 180-day rule mean buying the SSE Data Retention Add-on or exporting to a SIEM?
Are all laptops Windows or macOS? Skyhigh documents no Linux client; plan another route for Linux desks.
Is every laptop past Client Proxy 4.8.x, which reached end of life on 1 May 2026 and had three 2024 CVEs?
Will on-site appliances stay on 12.2.x? The 13.0 limited-availability build lacks cloud policy sync.
Does the partner quote list SKU codes (MVW or MVW-ADV), add-ons and the user count, in INR with GST?
Count your users, offices and on-site proxies first, or let a TechBag advisor pick the edition, set India as the log location and itemise the partner quote in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.