Talk to us
by Skyhigh SecurityTechBag Intel Page

Skyhigh Security Service Edge

Your web proxy, CASB and VPN each keep their own rules. Your data policy shouldn’t live in three places — Skyhigh Security Service Edge puts web gateway, CASB, DLP, isolation and private access under one policy, enforced in Skyhigh’s cloud PoPs — Bangalore, Noida and Mumbai included — and on the on-prem gateways you already run.

One policy, cloud and on-premPoPs in Bangalore, Noida and MumbaiQuote-only per user, through partners

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price for any suite or SKU; partners quote per user per year
Quote
Analysts
Advanced SSE use case, Gartner Critical Capabilities 2026, scoring 4.2/5; a Niche Player in the 2025 MQ
#1 of 8
India
Bangalore, Noida and Mumbai on the status page (October 2026); India is a log-storage option
3 PoP cities
Logs
Default for web-access logs; 365 days needs the SSE Data Retention Add-on
100 days

Quick answer

Skyhigh Security Service Edge bundles a secure web gateway, CASB, DLP and browser isolation into Essential, Advanced and Complete suites; Complete adds Private Access and Cloud Firewall. One policy covers cloud PoPs and on-prem gateways. It is quote-only through partners, per user. Gartner placed it first of eight for Advanced SSE (Critical Capabilities, 2026). PoPs sit in Bangalore, Noida and Mumbai, and logs can be stored in India. Read more ↓ Show less ↑
Part 01 · Orient

The Skyhigh Security platform family

This page covers Skyhigh Security Service Edge — the Essential, Advanced and Complete suites. The rest:

Quick facts

30-second orientation
Product
Converged SSE: web gateway, CASB, DLP, isolation, private access and cloud firewall on one console
Maker
Skyhigh Security (legal entity Musarubra US LLC), owned by Symphony Technology Group; CEO Vishal Rao
History
Launched by STG on 21 March 2022 as the McAfee Enterprise SSE business, carved out and renamed
Suites
Essential, Advanced and Complete; Skyhigh still sells individual SKUs alongside them
Price
Quote-only through partners, per user per year; Full Isolation is counted in seats
Analysts
Gartner SSE MQ: Visionary 2024, Niche Player 2025, named in 2026; Critical Capabilities 2026: first of eight, Advanced SSE
Clients
Skyhigh Client Proxy for Windows and macOS; Skyhigh Mobile Client for Android and iOS
Logs
Web logs kept 100 days by default, or 365 days with the SSE Data Retention Add-on
India
Office in Bangalore; status page lists PoPs in Bangalore, Noida and Mumbai; India log storage selectable
In India via
TechBag — suite sizing, partner quote in INR with GST, log-retention plan for CERT-In
Part 02 · Learn

Understand security service edge before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a security service edge?

Web gateway, CASB, DLP and private access delivered as one service, so one policy follows the user wherever they work.

Separate proxy, CASB and VPN boxes vs Skyhigh SSE — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSeparate proxy, CASB and VPN boxesSkyhigh Security Service Edge
Rules for web, SaaS and private appsThree consoles, three rulebooksOne MOWGLI policy, written once
On-prem web proxiesRipped out, or left running unmanagedKept as an enforcement plane under the cloud policy
Risky websitesBlocked outright, or allowed blindOpened in isolation, included in every suite
Staff using AI toolsUnknown apps, pasted data1,900+ AI apps under inline DLP
Web logsOn a box, overwritten when the disk fills100 days in the cloud, India selectable; 365 with an add-on
What it is NOT—A published price, a documented Linux client, or an MQ Leader

The cheapest test is one office in hybrid mode: join its gateway to the cloud policy, move its roaming users to Client Proxy, and compare.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where every rule is written

Policy

MOWGLI Unified Policy Engine

Skyhigh’s “author once, enforce everywhere” model: one policy for web, cloud apps, data and private apps, pushed to the cloud and to on-prem gateways alike.

02
Where roaming and branch traffic is inspected

Cloud

SSE Cloud points of presence

Client Proxy, IPsec or GRE tunnels carry traffic to a PoP picked by the DNS-based Global Routing Manager; Skyhigh cites 145+ PoPs as of March 2026.

03
Where traffic stays inside your network

On-prem

Secure Service Gateway and SWG appliances

Appliances or VMs enforce locally from a cached policy that survives internet brownouts, and hand traffic to cloud DLP, isolation and AI security when needed.

04
How internal apps are reached

Private apps

Private Access Connector

In the Complete suite, a connector VM beside each app dials out to the Private Access Gateway in the PoPs, so no inbound firewall port is opened.

One MOWGLI policy — enforced in Skyhigh’s cloud PoPs and on on-prem gateways that keep working through an outage.

Part 03 · Evaluate

Twelve capabilities. See, protect, connect.

Skyhigh SSE writes one policy for web, cloud apps, data and private apps, and enforces it in the cloud and on-prem.

See
Registry

40,000+ cloud services rated

The cloud registry scores over 40,000 services on 75+ risk attributes, so shadow IT is ranked by risk, not just listed.

See
Shadow IT

Discovery in every suite

CASB Shadow IT is part of Essential, Advanced and Complete; Advanced adds unlimited sanctioned SaaS apps under CASB control.

See
DNS

Tunnels and fresh domains

DNS security flags tunnelling and exfiltration, DGA names and newly registered domains, answering with a block page or sinkhole.

See
UEBA

Behaviour, mapped to ATT&CK

User and entity behaviour analytics flag unusual cloud activity, with incidents mapped to MITRE ATT&CK tactics.

Protect
Web gateway

Decrypt and detonate

The gateway decrypts TLS and runs unknown files through the Gateway Anti-Malware emulation sandbox inline.

Protect
DLP

One DLP for every channel

DLP ships in every SKU and applies across web, cloud apps and private apps; EDM/IDM matching and OCR are add-ons.

Protect
GenAI

1,900+ AI apps covered

Inline DLP covers over 1,900 AI applications, and API-mode DLP reaches Microsoft 365 Copilot and ChatGPT Enterprise.

Protect
Isolation

Risky sites, opened safely

Risky-web isolation is included in all three suites; Full Isolation for every session is a per-seat add-on.

Connect
ZTNA

Private apps, no VPN

Private Access checks device posture and identity, then brokers per-app access; unmanaged devices get read-only isolated access.

Connect
FWaaS

Non-web traffic too

Cloud Firewall takes non-HTTP traffic over a WireGuard tunnel from Client Proxy and runs deep packet inspection.

Connect
Hybrid

Keep the on-prem gateways

Appliances and VMs from the on-prem gateway line enforce the same policy as the cloud, with a virtual appliance entitlement in each suite.

Connect
Browser

Controls inside any browser

Secure Browser Controls govern uploads, downloads, clipboard, print and context menus in Chrome, Edge, Firefox or Safari.

See it, don’t just read it

Watch Skyhigh SSE in action

How Skyhigh SSE grew around data protection, building a sanctioned-app DLP policy, and governing AI tools and copilots. All from Skyhigh’s official channel, 2024–2026.

Skyhigh Security (official)·Video, June 2025

The Evolution of Skyhigh SSE and Frictionless Data Protection

How the SSE platform grew around data protection, from Skyhigh’s own channel.

Skyhigh Security (official)·How-to, August 2026

Create a Sanctioned DLP Policy | Skyhigh SSE

A walk-through of building a DLP policy for a sanctioned cloud application in the SSE console.

Skyhigh Security (official)·Video, June 2025

AI Security: Visibility, Risk, and Zero Trust Policies

Seeing which AI tools staff use, rating their risk, and setting policy for them.

Skyhigh Security (official)·Video, December 2024

Skyhigh Security for AI Copilots

Skyhigh’s approach to data exposure through AI copilots such as Microsoft 365 Copilot.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Skyhigh Security Service Edge

Web, cloud and private apps each got their own box. Skyhigh SSE puts them under one policy.

Here’s what genuinely sets it apart — and exactly where it stops.

01

One policy for cloud and on-prem gateways

Most SSE services assume every packet goes to their cloud. Skyhigh’s Hybrid Mesh lets on-prem appliances and VMs enforce the same MOWGLI policy as its PoPs, from a local cache that survives an internet outage. Estates with years of on-prem web proxies can move users to the cloud gradually rather than in one cut-over.

02

Data protection is the centre, not an add-on

DLP ships in every SKU and follows data across web, sanctioned SaaS, private apps and over 1,900 AI applications. Gartner’s 2026 Critical Capabilities ranked Skyhigh first of eight vendors in the Advanced SSE use case, scoring 4.2/5, and the 2024 edition gave it the highest score for Protect Data.

03

Indian PoPs and Indian log storage

The status page lists Skyhigh PoPs in Bangalore, Noida and Mumbai (checked October 2026), and India is one of eight log-storage locations an admin can select. Skyhigh describes its DPDP offering as compliance-ready; that is its own claim, so map your obligations to its controls before relying on it.

04

Where it stops

Every suite is quote-only through partners. Gartner moved Skyhigh from Visionary in 2024 to Niche Player in 2025, and Skyhigh states no quadrant for 2026. Web logs default to 100 days, short of CERT-In’s 180 without the add-on. Private Access and Cloud Firewall are only bundled in Complete, and no Linux client is documented.

The idea
One policy, cloud and on-prem
The residency
Indian PoPs; India log storage selectable
The price
Quote-only per user, through partners
Proof, not promises

The numbers behind the platform

145+ PoPs
points of presence Skyhigh reported worldwide in March 2026, across 60+ countries
— Vendor
40000+ services
cloud services in the registry, each rated on more than 75 risk attributes
— Vendor
1900+ AI apps
AI applications inline DLP can inspect, including ChatGPT, Claude and DeepSeek
— Vendor
100 days
default retention for web-access logs in the Skyhigh cloud; 365 with the add-on
— Vendor
3 India PoPs
cities on the status page in October 2026: Bangalore, Noida and Mumbai
— Vendor
#1 of 8
in the Advanced SSE use case of Gartner’s 2026 Critical Capabilities, scoring 4.2/5
— Analyst

What your Skyhigh SSE rollout looks like

Week 1Model

Map traffic and gateways

List on-prem proxies, branch links, roaming users and sanctioned SaaS, and decide which suite each requirement points to.

Week 2Decide

Pick India for logs

Set the log-storage location to India in a trial tenant, then size retention against CERT-In’s 180 days before quoting.

Week 4Pilot

Pilot one office hybrid

Join one site’s on-prem gateway to the cloud policy and move its roaming users to Client Proxy on the Indian PoPs.

Month 2Prove

Turn on DLP and AI rules

Start DLP and the AI-app rules in monitor mode, review a fortnight of incidents, then switch the clear ones to block.

Month 3Commit

Add private apps and firewall

If you bought Complete, deploy Private Access Connectors next to internal apps and route non-web traffic to Cloud Firewall.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
61+ reviews*
82% would recommend
Data protection4.5
Hybrid deployment4.3
Cloud app visibility4.3
Ease of administration3.7
Value for money3.8
5★
45%
4★
35%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We kept our on-prem gateways in the head office and put branches on the cloud PoPs. One policy, and nobody noticed the switch.”
Network Security Lead
BFSI
Pharmaceuticals
“The registry risk scores turned a list of 600 unknown apps into a short list of 30 we actually had to decide on.”
Information Security Manager
Pharmaceuticals
Insurance
“Choosing India for log storage settled the residency question in our audit committee faster than anything else.”
Chief Information Security Officer
Insurance
IT Services
“AI-app DLP caught source code going into a public chatbot in week one. That alone justified the Advanced suite.”
Head of IT Security
IT Services
NBFC
“Budget for the retention add-on up front. 100 days is not enough for our auditors, and we found out late.”
IT Compliance Manager
NBFC
Manufacturing
“Strong product, but the console has many corners and the partner quote took three rounds to get line items right.”
IT Infrastructure Head
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the security service edge market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Security Service Edge Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Skyhigh Security Service EdgeThis page

Quote-only per user through partners; no public price.

Grid 02 · The architecture

Enforcement Reach × Data Depth

The grid nobody publishes — where a service can enforce and keep its logs, India included, vs how deeply it protects data in web, SaaS and AI traffic.

Cloud-only data specialistsHybrid and data-deepNetwork-first edgesWide but lighter
Skyhigh Security Service EdgeThis page

Cloud plus on-prem on one policy; India PoPs and log storage.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Skyhigh SSE vs the security service edge field

Against Zscaler, Netskope One, Palo Alto Prisma Access, Cisco Secure Access and Cloudflare One — on deployment, modules, price, add-ons, scale, data depth, log retention, India and support.

DimensionSkyhigh Security Service EdgeZscaler ZIA + ZPANetskope One SSE PlatformPalo Alto Prisma AccessCisco Secure AccessCloudflare One
What it isConverged SSE suitesTwo-part SSEOne-client SSE platformFirewall-grade SSEUmbrella-rooted SSEZero Trust suite
DeploymentCloud, hybrid, on-premCloud serviceCloud, one clientCloud, GlobalProtectCloud, Secure ClientCloud, WARP client
Modules coveredSWG, CASB, ZTNA, FW, RBIFull set, two productsSWG, CASB, ZTNA, DLPZTNA 2.0, SWG, FW, DLPNine services in oneGateway, Access, CASB
Pricing modelPer user, by suitePer user, by editionPer user, by modulePer user per yearEssentials / AdvantageFree, then per user
Published entry priceNot published~$6–12/user/month~$15+/user/monthQuote onlyQuote only$7/user/month
Included vs add-onSuite decides; add-onsZPA and ZDX extraModules add upCASB and ADEM extraTier decidesEnterprise for depth
Scale and network145+ PoPs (vendor)150+ data centres100+ NewEdge DCs100+ locationsCount not confirmed330+ cities
Threat and data depthSandbox, DLP, isolationFull inline proxyInstance-aware CASBWildFire, App-IDTalos intelligenceDeeper on Enterprise
SaaS and AI apps40,000+ apps, 1,900 AICASB by editionInline + API, by tenantSaaS Security add-onCloudlock lineageAPI CASB, Enterprise DLP
Log retention100 days; 365 add-on6 months, then SIEM90 days, extendable1 year with logging7, 14 or 30 days30 days for HTTP
India PoPs and logs3 cities, India logs4 India cities8 DCs, Mumbai plane4 India locationsCities not documented6 India cities
SupportThrough partners8x5 free, 24x7 paidBasic, Premium, PlusPremium for 24/7Included in tiers24/7 on Enterprise
Lock-in and exitOn-prem stays an optionNo firewall estatePlatform commitmentTied to PAN policyCisco EA gravityStart free, leave easily
Best fitHybrid, data-led estatesCloud-only at scaleData protection firstPalo Alto estatesCisco-standard shopsPrice-first starters
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Skyhigh SSE if…

  • ✓You run on-prem web gateways today and want cloud SSE under the same policy, not a forced cut-over
  • ✓Data protection drives the project: DLP across web, SaaS, private apps and 1,900+ AI apps in one engine
  • ✓Web logs must be stored in India and you want PoPs in Bangalore, Noida and Mumbai

Compare alternatives if…

  • ✓You want a price before a sales call — Cloudflare One publishes $7 per user a month
  • ✓A Gartner SSE Leader is a board requirement — Zscaler, Netskope and Palo Alto held that position in 2025
  • ✓You need eight Indian data centres and an in-country management plane — Netskope documents both

Do not expect…

  • ✓A public price for any suite or SKU
  • ✓Private Access or Cloud Firewall below the Complete suite without paying for add-ons
  • ✓More than 100 days of web logs without the SSE Data Retention Add-on

Skyhigh Security Service Edge is one of 22 SASE & SSE products TechBag carries. The SASE & SSE guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does running three security policies cost you?

Drag the sliders (users protected; security admin-hour cost). Estimates model admin time spent keeping separate web, cloud-app and remote-access policies in step, and chasing incidents across their consoles, at an assumed 1.5 hours per user a year, with 70% of it removed by one policy and one console. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual policy-administration cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Skyhigh publishes no price for any suite or SKU, the pricebook sits behind a partner login, and every sale goes through a partner. Suites are licensed per user per year: Essential, Advanced and Complete, with individual SKUs still available. Full Isolation is an add-on counted in seats; OCR and EDM/IDM DLP are add-ons on every suite; Private Access and Cloud Firewall are add-ons below Complete; 365-day log retention is the SSE Data Retention Add-on. TechBag scopes the suite first, then gets the quote itemised in INR with GST.

SSE Essential or Advanced

Best for web, SaaS and data protection

  • Web gateway, DLP and risky-web isolation
  • Advanced adds unlimited sanctioned SaaS apps
  • Private Access and Cloud Firewall as add-ons

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

SSE Complete

Best for replacing VPN and branch firewalls too

  • Everything in Advanced
  • Private Access (ZTNA) and Cloud Firewall included
  • Full Isolation still a per-seat add-on

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Suite fit

Do you need sanctioned SaaS under API control (Advanced), or Private Access and Cloud Firewall too (Complete)?

2
Hybrid

Which on-prem gateways stay? Note that SWG 13.0 is Limited Availability and cannot yet sync policy to the cloud.

3
Log retention

Web logs default to 100 days; will you buy the 365-day add-on or export to a SIEM to keep CERT-In’s 180 days?

4
Data location

Has the admin set India as the log-storage location, and is that written into the order form?

5
AI use

Which AI tools do staff use today, and should DLP block, coach or only log uploads to them?

6
Clients

Are all devices Windows, macOS, Android or iOS? No Linux client is documented, and Client Proxy 4.8.x is end-of-life.

7
Isolation

Is risky-web isolation enough, or do some users need Full Isolation seats, which are a separate add-on?

8
Quote

Does the partner quote list suite, users, add-ons and term, in INR with GST, against the same scope as rival quotes?

FAQ

Questions buyers ask

It is Skyhigh’s converged SSE platform: a secure web gateway, CASB, DLP and remote browser isolation, with Private Access (ZTNA) and Cloud Firewall in the top suite. One policy engine enforces in Skyhigh’s cloud PoPs and on on-prem gateway appliances or VMs, all run from a single console.

Ready to evaluate Skyhigh SSE?

Count users and on-prem gateways first, or let a TechBag advisor map your requirements to a suite, set India log storage and plan retention for CERT-In.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.