Your web proxy, CASB and VPN each keep their own rules. Your data policy shouldn’t live in three places — Skyhigh Security Service Edge puts web gateway, CASB, DLP, isolation and private access under one policy, enforced in Skyhigh’s cloud PoPs — Bangalore, Noida and Mumbai included — and on the on-prem gateways you already run.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Skyhigh Security Service Edge — the Essential, Advanced and Complete suites. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Web gateway, CASB, DLP and private access delivered as one service, so one policy follows the user wherever they work.
What consolidation actually replaces, dimension by dimension.
| Dimension | Separate proxy, CASB and VPN boxes | Skyhigh Security Service Edge |
|---|---|---|
| Rules for web, SaaS and private apps | Three consoles, three rulebooks | One MOWGLI policy, written once |
| On-prem web proxies | Ripped out, or left running unmanaged | Kept as an enforcement plane under the cloud policy |
| Risky websites | Blocked outright, or allowed blind | Opened in isolation, included in every suite |
| Staff using AI tools | Unknown apps, pasted data | 1,900+ AI apps under inline DLP |
| Web logs | On a box, overwritten when the disk fills | 100 days in the cloud, India selectable; 365 with an add-on |
| What it is NOT | — | A published price, a documented Linux client, or an MQ Leader |
The cheapest test is one office in hybrid mode: join its gateway to the cloud policy, move its roaming users to Client Proxy, and compare.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Skyhigh’s “author once, enforce everywhere” model: one policy for web, cloud apps, data and private apps, pushed to the cloud and to on-prem gateways alike.
Client Proxy, IPsec or GRE tunnels carry traffic to a PoP picked by the DNS-based Global Routing Manager; Skyhigh cites 145+ PoPs as of March 2026.
Appliances or VMs enforce locally from a cached policy that survives internet brownouts, and hand traffic to cloud DLP, isolation and AI security when needed.
In the Complete suite, a connector VM beside each app dials out to the Private Access Gateway in the PoPs, so no inbound firewall port is opened.
One MOWGLI policy — enforced in Skyhigh’s cloud PoPs and on on-prem gateways that keep working through an outage.
Skyhigh SSE writes one policy for web, cloud apps, data and private apps, and enforces it in the cloud and on-prem.
The cloud registry scores over 40,000 services on 75+ risk attributes, so shadow IT is ranked by risk, not just listed.
CASB Shadow IT is part of Essential, Advanced and Complete; Advanced adds unlimited sanctioned SaaS apps under CASB control.
DNS security flags tunnelling and exfiltration, DGA names and newly registered domains, answering with a block page or sinkhole.
User and entity behaviour analytics flag unusual cloud activity, with incidents mapped to MITRE ATT&CK tactics.
The gateway decrypts TLS and runs unknown files through the Gateway Anti-Malware emulation sandbox inline.
DLP ships in every SKU and applies across web, cloud apps and private apps; EDM/IDM matching and OCR are add-ons.
Inline DLP covers over 1,900 AI applications, and API-mode DLP reaches Microsoft 365 Copilot and ChatGPT Enterprise.
Risky-web isolation is included in all three suites; Full Isolation for every session is a per-seat add-on.
Private Access checks device posture and identity, then brokers per-app access; unmanaged devices get read-only isolated access.
Cloud Firewall takes non-HTTP traffic over a WireGuard tunnel from Client Proxy and runs deep packet inspection.
Appliances and VMs from the on-prem gateway line enforce the same policy as the cloud, with a virtual appliance entitlement in each suite.
Secure Browser Controls govern uploads, downloads, clipboard, print and context menus in Chrome, Edge, Firefox or Safari.
How Skyhigh SSE grew around data protection, building a sanctioned-app DLP policy, and governing AI tools and copilots. All from Skyhigh’s official channel, 2024–2026.
How the SSE platform grew around data protection, from Skyhigh’s own channel.
A walk-through of building a DLP policy for a sanctioned cloud application in the SSE console.
Seeing which AI tools staff use, rating their risk, and setting policy for them.
Skyhigh’s approach to data exposure through AI copilots such as Microsoft 365 Copilot.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most SSE services assume every packet goes to their cloud. Skyhigh’s Hybrid Mesh lets on-prem appliances and VMs enforce the same MOWGLI policy as its PoPs, from a local cache that survives an internet outage. Estates with years of on-prem web proxies can move users to the cloud gradually rather than in one cut-over.
DLP ships in every SKU and follows data across web, sanctioned SaaS, private apps and over 1,900 AI applications. Gartner’s 2026 Critical Capabilities ranked Skyhigh first of eight vendors in the Advanced SSE use case, scoring 4.2/5, and the 2024 edition gave it the highest score for Protect Data.
The status page lists Skyhigh PoPs in Bangalore, Noida and Mumbai (checked October 2026), and India is one of eight log-storage locations an admin can select. Skyhigh describes its DPDP offering as compliance-ready; that is its own claim, so map your obligations to its controls before relying on it.
Every suite is quote-only through partners. Gartner moved Skyhigh from Visionary in 2024 to Niche Player in 2025, and Skyhigh states no quadrant for 2026. Web logs default to 100 days, short of CERT-In’s 180 without the add-on. Private Access and Cloud Firewall are only bundled in Complete, and no Linux client is documented.
List on-prem proxies, branch links, roaming users and sanctioned SaaS, and decide which suite each requirement points to.
Set the log-storage location to India in a trial tenant, then size retention against CERT-In’s 180 days before quoting.
Join one site’s on-prem gateway to the cloud policy and move its roaming users to Client Proxy on the Indian PoPs.
Start DLP and the AI-app rules in monitor mode, review a fortnight of incidents, then switch the clear ones to block.
If you bought Complete, deploy Private Access Connectors next to internal apps and route non-web traffic to Cloud Firewall.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We kept our on-prem gateways in the head office and put branches on the cloud PoPs. One policy, and nobody noticed the switch.”
“The registry risk scores turned a list of 600 unknown apps into a short list of 30 we actually had to decide on.”
“Choosing India for log storage settled the residency question in our audit committee faster than anything else.”
“AI-app DLP caught source code going into a public chatbot in week one. That alone justified the Advanced suite.”
“Budget for the retention add-on up front. 100 days is not enough for our auditors, and we found out late.”
“Strong product, but the console has many corners and the partner quote took three rounds to get line items right.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the security service edge market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only per user through partners; no public price.
The grid nobody publishes — where a service can enforce and keep its logs, India included, vs how deeply it protects data in web, SaaS and AI traffic.
Cloud plus on-prem on one policy; India PoPs and log storage.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler, Netskope One, Palo Alto Prisma Access, Cisco Secure Access and Cloudflare One — on deployment, modules, price, add-ons, scale, data depth, log retention, India and support.
| Dimension | Skyhigh Security Service Edge | Zscaler ZIA + ZPA | Netskope One SSE Platform | Palo Alto Prisma Access | Cisco Secure Access | Cloudflare One |
|---|---|---|---|---|---|---|
| What it is | Converged SSE suites | Two-part SSE | One-client SSE platform | Firewall-grade SSE | Umbrella-rooted SSE | Zero Trust suite |
| Deployment | Cloud, hybrid, on-prem | Cloud service | Cloud, one client | Cloud, GlobalProtect | Cloud, Secure Client | Cloud, WARP client |
| Modules covered | SWG, CASB, ZTNA, FW, RBI | Full set, two products | SWG, CASB, ZTNA, DLP | ZTNA 2.0, SWG, FW, DLP | Nine services in one | Gateway, Access, CASB |
| Pricing model | Per user, by suite | Per user, by edition | Per user, by module | Per user per year | Essentials / Advantage | Free, then per user |
| Published entry price | Not published | ~$6–12/user/month | ~$15+/user/month | Quote only | Quote only | $7/user/month |
| Included vs add-on | Suite decides; add-ons | ZPA and ZDX extra | Modules add up | CASB and ADEM extra | Tier decides | Enterprise for depth |
| Scale and network | 145+ PoPs (vendor) | 150+ data centres | 100+ NewEdge DCs | 100+ locations | Count not confirmed | 330+ cities |
| Threat and data depth | Sandbox, DLP, isolation | Full inline proxy | Instance-aware CASB | WildFire, App-ID | Talos intelligence | Deeper on Enterprise |
| SaaS and AI apps | 40,000+ apps, 1,900 AI | CASB by edition | Inline + API, by tenant | SaaS Security add-on | Cloudlock lineage | API CASB, Enterprise DLP |
| Log retention | 100 days; 365 add-on | 6 months, then SIEM | 90 days, extendable | 1 year with logging | 7, 14 or 30 days | 30 days for HTTP |
| India PoPs and logs | 3 cities, India logs | 4 India cities | 8 DCs, Mumbai plane | 4 India locations | Cities not documented | 6 India cities |
| Support | Through partners | 8x5 free, 24x7 paid | Basic, Premium, Plus | Premium for 24/7 | Included in tiers | 24/7 on Enterprise |
| Lock-in and exit | On-prem stays an option | No firewall estate | Platform commitment | Tied to PAN policy | Cisco EA gravity | Start free, leave easily |
| Best fit | Hybrid, data-led estates | Cloud-only at scale | Data protection first | Palo Alto estates | Cisco-standard shops | Price-first starters |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Skyhigh Security Service Edge is one of 22 SASE & SSE products TechBag carries. The SASE & SSE guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users protected; security admin-hour cost). Estimates model admin time spent keeping separate web, cloud-app and remote-access policies in step, and chasing incidents across their consoles, at an assumed 1.5 hours per user a year, with 70% of it removed by one policy and one console. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. Skyhigh publishes no price for any suite or SKU, the pricebook sits behind a partner login, and every sale goes through a partner. Suites are licensed per user per year: Essential, Advanced and Complete, with individual SKUs still available. Full Isolation is an add-on counted in seats; OCR and EDM/IDM DLP are add-ons on every suite; Private Access and Cloud Firewall are add-ons below Complete; 365-day log retention is the SSE Data Retention Add-on. TechBag scopes the suite first, then gets the quote itemised in INR with GST.
Best for web, SaaS and data protection
Best for a broader rollout
Best for replacing VPN and branch firewalls too
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do you need sanctioned SaaS under API control (Advanced), or Private Access and Cloud Firewall too (Complete)?
Which on-prem gateways stay? Note that SWG 13.0 is Limited Availability and cannot yet sync policy to the cloud.
Web logs default to 100 days; will you buy the 365-day add-on or export to a SIEM to keep CERT-In’s 180 days?
Has the admin set India as the log-storage location, and is that written into the order form?
Which AI tools do staff use today, and should DLP block, coach or only log uploads to them?
Are all devices Windows, macOS, Android or iOS? No Linux client is documented, and Client Proxy 4.8.x is end-of-life.
Is risky-web isolation enough, or do some users need Full Isolation seats, which are a separate add-on?
Does the partner quote list suite, users, add-ons and term, in INR with GST, against the same scope as rival quotes?
Count users and on-prem gateways first, or let a TechBag advisor map your requirements to a suite, set India log storage and plan retention for CERT-In.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.