Live Workshop: Zero Trust SWG with SafeSquid ·

Register Now

Modern attacks hide inside trusted web sessions.

Destination trust is no longer enough. SafeSquid is a Layer 7 intelligence platform that judges every request on identity, content, destination, and behaviour inside the live session.

IBMTata Consultancy ServicesWiproSafran GroupThomson ReutersAonBell CanadaMotorolaO2ValeoHughesKonkan RailwayIBMTata Consultancy ServicesWiproSafran GroupThomson ReutersAonBell CanadaMotorolaO2ValeoHughesKonkan RailwayIBMTata Consultancy ServicesWiproSafran GroupThomson ReutersAonBell CanadaMotorolaO2ValeoHughesKonkan RailwayIBMTata Consultancy ServicesWiproSafran GroupThomson ReutersAonBell CanadaMotorolaO2ValeoHughesKonkan Railway

Four doors your gateway already holds open.

SaaS, cloud files, APIs, and AI tools carry business activity and hidden risk through the same encrypted channels, and the risk looks exactly like normal work. You are probably on your second or third security product by now, and the risk still arrives through the same four doors.

Sanctioned traffic

Malware arrives inside the apps you already approve.

Payloads ride Google Drive, Dropbox, and sanctioned SaaS APIs, while stolen tokens and hijacked sessions look exactly like a normal login. It's all encrypted, so most gateways stop looking.

Gateway allow-listencrypted · authenticated · persistent
  • drive.google.comAllowed
    invoice_Q3.zip → macro dropperMalware inside
  • dropbox.comAllowed
  • api.slack.comAllowed
  • login.microsoftonline.comAllowed
Contents not inspectedencrypted end-to-end

Trusted destinations

A good reputation is easy to borrow.

Trusted clouds and CDNs double as malware hosting and command infrastructure, fresh domains, redirects, and lookalike sites slip past every blocklist by design, and covert DNS channels quietly carry data out.

Reputation enginedestination trust
  • cdn.jsdelivr.netclean
    allowed
  • storage.googleapis.comclean
    allowed
  • login-m1crosoft.comHosting C2
    registered 2h ago
DNS exfil
dGhp.a3fk.leak.example — resolved

The browser

Attacks land after your gateway has already said yes.

JavaScript, WebAssembly, and DOM manipulation run past the reach of perimeter controls, extensions widen the blast radius of one bad page, and uploads, forms, and the clipboard move data both ways, unsupervised.

https://app.vendor.comAllowed by gateway
gateway visibility ends here
  • DOM manipulationexecutes post-allow
  • JavaScriptexecutes post-allow
  • WebAssemblyexecutes post-allow
  • Extensions (12 installed)camera · mic · filesystem
uploads · downloads · forms · clipboardunsupervised

Compromised user

Trust granted at login lasts all day, even in the wrong hands.

A hijacked account keeps every privilege the real user had, sensitive files leave through channels the policy explicitly allows, and nothing re-checks the session until the damage is done.

priya@corp — authenticated 09:12Trusted
Session trustnever re-checked
09:1212:0014:3017:00
  • 09:12login — mfa ok
  • 11:47token replayed · new ASNAllow
  • 11:52bulk download 1.2 GB → allowAllow
Policy verdict: trusted sessionprivileges intact

Then generative AI poured fuel on all four doors.

AI accelerates productivity. It also accelerates risk, through the same sessions your perimeter already approves.

exploit completion compressed · detect/respond too late

chatgpt & llms ·copilots & agents ·ai saas apps ·code generators ·file sharing ·browser extensions ·shadow saas ·chatgpt & llms ·copilots & agents ·ai saas apps ·code generators ·file sharing ·browser extensions ·shadow saas ·

Zero Trust was supposed to be the answer to all of this.

What you bought as “Zero Trust” is not Zero Trust.

The industry sells a three-step model: check identity, approve the destination, then trust the session. That is a login screen.

the model they sold

false
01void

Identity

Verify once, at login.

Nothing re-checks the session after.

02void

Destination

Approve by reputation.

The address is judged. Never the content.

03void

Session

Trust indefinitely.

Trust at 9 am is an open door at 5 pm.

as defined

Never trust. Always verify. Continuously. Every request, every payload, every time.

Where existing solutions still fail.

They clear the URL. They never see the session.

One platform for every web interaction.

Secure Web Gateway, Remote Browser Isolation, one shared core.

It reads every transaction at Layer 7, where identity, content, destination, and behaviour are all visible. The Secure Web Gateway is its hero component, built for Zero Trust from first principles rather than retro-fitted from a web cache. Remote Browser Isolation is a separate component, included at no extra cost. Every module shares one memory pool, and you can download it and run it today.

ObserveUnderstandGovern

every gap above, answered

01Destination approvalEvery payload inspected in-session; risky sites rendered in full isolation.Remote Browser Isolation
02Static rulesContextual policies that adapt per request, in real time.Parallel processors
03Operational blind spotsFull HTTPS inspection on every session. Nothing needs bypassing.Multi-threaded core
04Fragmented contextParallel engines correlating identity, content, and behaviour on one decision.Parallel processors

The architecture is the part that stays durable.

Features come and go with each threat cycle. Three things underneath do not: an open architecture you can inspect and extend, a multi-threaded core, and isolation built into the same product.

Multi-threaded core

Full inspection without copying data between processes.

Legacy gateways copy data between processes and wait for each one to finish. SafeSquid threads share a single memory pool, so every inspection engine reads the same bytes the others already have.

0ms2ms4ms6ms8ms
0 copies
0 wait
thread · ssl inspect
thread · content scan
thread · policy check

Parallel processors

A neural network for traffic.

Every engine runs on the same data at once, over shared memory instead of isolated checks. Identity, content, behaviour, and policy fuse into one coordinated decision per transaction.

Processor queueSafeSquid
  • ssl.inspect()EDGE
  • content.scan()PROD
  • policy.evaluate()PROD
  • threat.correlate()CORE
Fused into one verdict0.4ms · shared mem

Remote Browser Isolation

Risky pages render in containment.

The page is rendered inside SafeSquid and the endpoint receives pixels. Isolation ships with the platform, not as a separate line item.

Isolated sessions

pixel stream only

2001000
76
JS blockedDownloads scannedIsolation active● live

Inside SafeSquid, every request is inspected, profiled, and enforced.

This is the decision path a single web transaction takes before anything reaches your network or the open web.

01HTTPS Inspection

Open the encrypted session

HTTPS is decrypted at the perimeter so headers, payload, and destination are visible instead of guessed from a URL allow-list.

02Profile & risk decision

Bind identity, content, destination, and behaviour

SafeSquid scores every opened session against a live profile before a control is chosen.

  • Identity
  • Content
  • Destination
  • Behaviour
03Enforce

Apply the right control

Block, sanitize, or isolate. The control matches the risk, so a session is never denied outright by default.

  • Block
  • Sanitize
  • Isolate / RBI

The browser runs at your perimeter.

Remote Browser Isolation runs the session on SafeSquid instead of on the endpoint. Only a sanitized pixel stream and scanned downloads reach the user. Included at no extra cost.

Browser Runtime

login.microsoftonline.com/common/oauth2
Sign in
Injected Script

Use your work or school account to access Acme Corp

Email, phone, or Skype
Password
Scripts
Rasterized
Credentials
Destroyed

ISOLATED

Trusted Endpoint

pixel-stream · reconstructed
Sign in

Rendered pixels only. No active content crossed the boundary.

Next
VerifiedSanitizedChecksum OK

Active content terminates in containment. Only rendered pixels and sanitized files reach the endpoint.

Lightweight

Runs on standard infrastructure with no dedicated hardware.

Scalable

SMP-aware architecture scales from small teams to enterprise-wide deployments.

Fully customizable

Open architecture for tailored isolation policies that match your security posture.

Access & privilege management

Seamless authentication and granular privilege controls for isolated sessions.

VDI integration

Optional virtual desktop infrastructure for complete endpoint isolation.

Enterprise control

Your team owns every policy and configuration.

what enters your enterprise

  • Pixel stream of the rendered page
  • Explicitly approved downloads, scanned first

what never reaches the endpoint

  • No JavaScript, DOM, or plugins
  • No zero-day browser exploits
  • No drive-by downloads or redirects

Users browse normally. No VPN, no agent, no workflow change.

Supporting services stay off the live path.

Inline is where traffic flows through SafeSquid. These services inform, report, and assist. None of them sit in the user's request path.

cloud

Threat intelligence

Cloud intel feeds the decision. It is a feed, never a choke point on the wire.

out-of-band

Reporting & analytics

Reads logs after the fact, out of band, so it never delays user traffic.

beta

AI (beta)

Assistive today. Filtering stays in the SafeSquid core.

Twenty years at the perimeter of the hardest networks.

0+

years proven

0+

installations

0M+

users secured

0

rbi surcharge

Data exfiltration prevention — secure web gateway blocking credential theft
Safran Group (Aviation)

Zero data exfiltration incidents post-deployment

Aerospace and defence manufacturer deployed SafeSquid across global facilities, replacing a legacy UTM stack. Full HTTPS inspection maintained for 10,000+ users.

Built through two decades of real threats.

SafeSquid wasn't designed in a boardroom. Each change came out of an attack, a deployment, or a failure mode in production.

2004Origins

SafeSquid founded

Initial release as proxy-chain filtering layer.

2007Scale

First enterprise deployments

Multi-process proxy limitations confirmed at scale.

2009Architecture

Multi-threaded rewrite

Shared memory pool enables real-time context.

2013Scale

HTTPS inspection at scale

10,000+ concurrent sessions validated.

2017Intelligence

Security Correlation Engine

Neural-net profiling. Fused decision per transaction.

2019Differentiator

RBI bundled free

Pixel streaming at perimeter. Included at no extra cost.

2024Today

SafeSquid SWG current gen

2,000+ installations. 20M+ users secured.

Stop inspecting the perimeter.
Start controlling it.

Free guided pilot. No lock-in. No per-user RBI surcharge.