This content is currently locked.

Your current Info-Tech Research Group subscription does not include access to this content. Contact your account representative to gain access to Premium SoftwareReviews.

Contact Your Representative
Or Call Us:
+1-888-670-8889 (US/CAN) or
+1-703-340-1171 (International)

Skyhigh Security SSE Platform: Hybrid Enforcement, Browser-Native AI Controls, and Integrated Data Security Posture

Technology Note By: Carlos Rivera, Info-Tech Research Group

Executive Summary

Security service edge (SSE) entered the market as a cloud-delivered inspection layer, an architectural response to the collapse of the perimeter and the migration of work to software as a service (SaaS). The dominant assumption baked into first-generation SSE platforms was that traffic worth inspecting travels from a remote user to the cloud, and that routing everything through a vendor's points of presence (PoP) is an acceptable cost of protection. Both assumptions are breaking down. Regulated enterprises increasingly refuse to route sensitive traffic through American cloud service providers. Cost-sensitive organizations are discovering that full cloud-based inspection of 100% of traffic is expensive enough to become a budgetary objection. And the emergence of AI-native applications (particularly those that communicate over WebSockets rather than inspectable HTTP) has exposed a structural gap that proxy-based architectures cannot close from the cloud.

Skyhigh Security announced three platform extensions at RSAC 2026 that address these breakdowns directly. The first is a unified hybrid management console that lets organizations run the full SSE stack on-premises, in the cloud, or across both simultaneously, with traffic routing decisions made at the organization's discretion rather than defaulting to cloud inspection. The second is Enterprise Browser Controls, a browser-agnostic JavaScript injection approach that extends data loss prevention and AI traffic governance into the browser session without requiring an enterprise browser deployment. The third is an integrated data security posture management capability, bundled at a base tier for all customers, that combines CASB-sourced data-at-rest visibility with inline proxy-sourced data-in-motion visibility to produce a 360-degree sensitive data risk picture.

Taken together, the three announcements represent a coherent argument that SSE should be an enforcement platform that follows the user and the data rather than a cloud routing service that users route through. The argument is well constructed and addresses real friction that first-generation SSE customers are encountering. The product is best suited to organizations in regulated industries operating hybrid infrastructure, Skyhigh Security customers looking to consolidate from point solutions, and security teams whose primary concerns center on AI data leakage and the cost efficiency of cloud-only inspection. It is less suited to organizations that have already committed deeply to a competing SSE platform, those whose compliance posture does not require on-premises traffic inspection, and those whose primary agentic AI risk is agent action drift rather than data movement.

Product Overview

Skyhigh Security's SSE platform is an integrated stack combining secure web gateway (SWG), cloud access security broker (CASB), data loss prevention (DLP), remote browser isolation (RBI), and zero trust network access (ZTNA) under a unified policy engine. The company has invested materially in data classification and DLP capabilities over more than a decade, a legacy from its McAfee Enterprise heritage, and positions data protection as the differentiating layer above the access controls that all SSE platforms provide.

The three announcements at RSAC 2026 extend the existing platform rather than introducing a new product category. Hybrid management addresses the deployment architecture. Enterprise Browser Controls address the AI traffic inspection gap. Data security posture management (DSPM) addresses the posture and governance layer. None requires replatforming for existing Skyhigh customers; each is layered on top of existing SSE infrastructure. For organizations not yet on the Skyhigh platform, the announcements are most coherently evaluated as a package. The differentiated value of each individual component is harder to isolate from the integrated architecture.

Features and Capabilities

Core Features

Hybrid SSE with Unified Cloud Management

Hybrid enforcement with centralized management. Organizations can run the SSE stack, SWG, ZTNA, and Browser Security on dedicated hardware appliances or software VMs in on-premises data centers today. CASB, DLP, and RBI are available today as cloud services, unified with the on-premises capabilities under a single console for policy, administration, alerting, and logging/reporting; Skyhigh has stated a roadmap to bring these three capabilities to on-premises deployment as well. Policy is authored once and pushed to all enforcement points regardless of location. Traffic routing decisions are made per user group or per traffic type: an organization might choose to inspect 60% of traffic on-premises and route the remaining 40% to cloud inspection, with the cost profile and compliance implications of each path visible at policy time.

Local enforcement without hairpinning. The enforcement point for a given user's traffic is the point closest to where that traffic originates. A remote user's traffic is enforced at the cloud PoP nearest to them. An employee on-premises has their traffic enforced at the local appliance. This eliminates the latency and cost associated with backhauling on-premises traffic to a cloud inspection node. Backhauling has been an endemic problem in first-generation ZTNA deployments; local enforcement maintains the same security posture across both contexts, a hallmark of a software defined perimeter (SDP) solution.

Zero trust for private applications becomes practical on-premises. The same local-enforcement architecture also makes it operationally practical to extend zero trust controls to private applications and internal resources for on-premises users, guarding against unauthorized discovery or access, including from AI agents operating on the internal network. Few organizations enable zero trust for on-premises traffic today, because hairpinning that traffic to a cloud-based enforcement point has historically added enough cost and latency to make the control impractical at scale. Local, on-premises enforcement removes that barrier.

Platform and OS coverage. The client agent supports Windows, macOS, iOS, Android, Linux, and ARM-based systems, a coverage profile that reflects the shift toward ARM silicon in enterprise endpoints.

Enterprise Browser Controls

Browser-agnostic JavaScript injection. Enterprise Browser Controls are delivered as JavaScript injected into the browser session as traffic passes through the SSE proxy. Because the injection occurs at the proxy layer rather than inside a proprietary browser runtime, the controls apply to any browser – including Chrome, Edge, Firefox, AI-native browsers such as Perplexity's browser – without requiring organizations to standardize on an enterprise browser product or manage browser version compatibility across their SaaS application estate.

AI and WebSocket traffic governance. Many AI applications, Microsoft Copilot being the prominent example, communicate over WebSockets rather than standard HTTP. WebSocket traffic is opaque to proxy-based inspection; you cannot parse session content at the proxy for a persistent WebSocket connection. Enterprise Browser Controls move enforcement to the point of origin, the browser session itself, so DLP policy can be applied to clipboard pastes, prompt submissions, and file uploads into AI applications regardless of the underlying transport protocol. A user pasting sensitive content into a Copilot prompt encounters the same policy enforcement as one uploading a document to a sanctioned cloud storage service.

Bring your own device (BYOD) and unmanaged device coverage. Because the controls are delivered via the proxy layer rather than an endpoint agent or browser extension, they apply to unmanaged devices accessing corporate resources through the proxy, including contractors, guest workers, and BYOD users, without requiring any software installation on the unmanaged endpoint. Third-party access to private applications is handled via reverse proxy with optional RBI layered on top; the third party accesses a rendered browser session in which they can see and interact with content but cannot download, print, or exfiltrate it.

Watermarking and visual DLP. Browser controls include the ability to inject visible watermarks into rendered content. Content viewed through a browser session carries a watermark traceable to the session and user, which remains visible even in a photograph of the screen. This falls short of a full enterprise digital rights management implementation: It does not provide encryption or access revocation outside the browser session. It does extend accountability to scenarios where download prevention alone is insufficient.

Integrated Data Security Posture Management (DSPM)

360-degree sensitive data visibility. Skyhigh's DSPM capability combines two data sources that most pure-play DSPM vendors cannot access simultaneously: CASB application programming interface (API) connectors that scan data at rest in sanctioned SaaS applications (SharePoint, Box, Salesforce, and others) and the inline proxy that observes data in motion across cloud and on-premises traffic. The combination produces a single risk picture that identifies where sensitive data lives, who has access to it, how it is moving, and what contextual risk factors apply to it.

Risk-contextualized classification. DSPM risk scoring draws on more than sensitivity alone. User risk scores from the platform's user and entity behavior analytics (UEBA) capability feed into the data risk calculation: a financial projection document accessed by a high-risk user reads as a different risk posture than the same document in a routine workflow. SaaS security posture management signals feed in as well: A SharePoint instance misconfigured as publicly writable elevates the risk of all sensitive data within it, even data that would otherwise be classified as low risk given its location. The integration avoids the false-negative problem where sensitive data is correctly identified but incorrectly assessed as safe because its repository context is not evaluated.

Bundled base tier with volume-based expansion. Base DSPM functionality is included with all Skyhigh SSE customers at no additional license cost, subject to a data volume cap. The cap is sized to deliver meaningful visibility within the first month of deployment, enough for a security team to identify material risks and establish a baseline posture, rather than as a demonstration-only sample. Organizations whose data volumes exceed the cap are offered volume expansion packs. Customers already licensed for CASB or advanced DLP automatically inherit the classification work they have already done in those products; DSPM consumes the existing classification rules and fingerprinting configurations rather than requiring re-instrumentation.

From discovery to enforcement: closed-loop remediation. DSPM findings feed a governance mechanism Skyhigh documentation refers to as “Closed-Loop Remediation” (also described simply as “governance”), which connects CASB-based discovery and risk scoring to inline policy enforcement at the SWG, proxy, or firewall layer. Administrators define service groups in CASB, either manually or dynamically, using rules keyed to risk attributes such as unfavorable IP-ownership terms or a recent breach disclosure, and the Cloud Connector publishes each group as a dynamic URL list that on-premises or edge SWG policies reference directly. As newly discovered shadow-IT services or changing risk scores update a service group, the corresponding SWG policy updates automatically, blocking or presenting a coaching/warning page to the user without an administrator maintaining a separate block list. A related capability, Granular Closed-Loop Remediation, extends this model to organizations running an external enterprise DLP: rather than a single blanket action, the external DLP can direct Skyhigh to apply a specific remediation, report only, quarantine, delete, or encrypt, on a per-policy basis. Skyhigh positions this discovery-to-enforcement loop as the mechanism that operationalizes DSPM insight rather than leaving it as a reporting-only exercise; as with any vendor-documented capability, the specific configuration steps and supported actions are worth confirming against current Skyhigh documentation at time of evaluation, since SSE platform features continue to evolve.

Differentiating Features

Cost architecture as a competitive lever. Pure-play SSE vendors charge for cloud-based inspection regardless of traffic volume, with costs scaling linearly as inspection services stack: proxy, CASB, DLP, and RBI each add cost. Organizations that already operate on-premises infrastructure can, with Skyhigh's hybrid architecture, run the full SSE stack on that infrastructure for a portion of their traffic, materially reducing the cloud inspection volume they pay for. The positioning is explicit: Displacing Zscaler and Netskope on total cost of ownership for hybrid-infrastructure customers is a stated go-to-market motion.

Data protection depth as an inherited advantage. Skyhigh’s DLP and data classification capabilities predate its SSE positioning and reflect more than a decade of dedicated investment. Advanced techniques, including exact data match, indexed document match, ML-based classification, and fingerprinting, are available within the same policy engine that governs SSE enforcement. This means DLP sophistication is not bolted onto an access platform; it is native to it. The DSPM capability inherits this depth directly.

Security posture that follows the user. The architectural argument underlying all three announcements is that security posture should be tied to the user, not to the network location of the user. The same policy framework applies whether the user is remote, on-premises, or on a managed device in a branch office. First-generation ZTNA implementations typically provided strong enforcement for remote users and fell back to implicit trust for on-premises users on the same network. Skyhigh's hybrid architecture is explicitly designed to close that gap.

Analyst Perspective

The most consistent criticism I hear from organizations that have deployed first-generation SSE platforms is that the cost model is not what they anticipated and the on-premises gap is not what they were told would exist. These are related problems. Cloud-only inspection means every byte of on-premises traffic has to travel to a cloud PoP and back, which adds latency, adds cost, and in regulated industries, particularly outside the United States, creates data sovereignty objections that some organizations are not willing to resolve in favor of the vendor. The hybrid enforcement announcement directly addresses both the cost and the sovereignty objection. The architectural concept itself predates this announcement. What Skyhigh has added is bringing it under a unified management console with consistent policy, which is where the operational complexity has historically lived.

Enterprise Browser Controls is the announcement I find most technically interesting. The WebSocket inspection gap is real and growing. As AI applications increasingly communicate over persistent WebSocket connections rather than discrete HTTP requests, proxy-based DLP loses coverage over exactly the traffic category that represents the most consequential data leakage risk in most organizations' current threat model: employees pasting sensitive content into AI productivity tools. The JavaScript injection approach is architecturally clever because it sidesteps the enterprise browser adoption problem entirely. Enterprise browser vendors face an application compatibility surface area problem: When a SaaS vendor updates their application, the enterprise browser has to validate compatibility before customers can use the new version. Skyhigh's approach is immune to that problem because the controls live in the proxy layer rather than in a proprietary browser runtime. The browser-agnostic claim reflects a genuine architectural choice rather than a marketing label.

The DSPM positioning is the one I would probe most carefully in a procurement conversation. The 360-degree visibility story is compelling, but it depends on how much of the infrastructure is already running through Skyhigh’s proxy and CASB connectors. An organization with significant traffic flowing through a competing SSE platform will get only partial visibility from Skyhigh DSPM, limited to the traffic Skyhigh can see. The value of the bundled base tier is also contingent on the organization’s existing data classification maturity; customers who have invested in DLP classification with Skyhigh will inherit that work immediately, while net-new customers are starting from baseline. Neither caveat negates the value proposition, but both affect the timeline to material value realization.

The broader competitive argument the company is making – that first-generation SSE deployments are underutilized that organizations have checked the VPN-replacement box without actually deploying the inspection and classification capabilities they paid for – resonates with what I hear in advisory conversations. A significant cohort of organizations has Zscaler or Netskope deployed in a configuration that amounts to remote access with minimal inspection enabled. The argument that a platform with cost-optimized hybrid enforcement, browser-native AI controls, and bundled data posture management is a better answer to that installed base than doubling down on the original platform is a legitimate one. Whether it is persuasive in a given sales conversation will depend heavily on how much switching friction the customer has accumulated and whether the economics hold up under scrutiny.

Conclusions and Fit Guidance

Strong Fit

Organizations in regulated industries with hybrid infrastructure. Financial services, healthcare, and public sector organizations, particularly those outside the United States, face data sovereignty requirements that cloud-only inspection cannot satisfy. Skyhigh's hybrid architecture lets them retain on-premises traffic inspection while managing policy from a unified console. The argument is strongest where an existing on-premises infrastructure investment can absorb a portion of the inspection load, reducing both cloud inspection cost and data residency risk.

Organizations whose primary AI data risk is employee prompt behavior. If the threat model centers on employees pasting sensitive content into AI productivity tools, particularly tools that communicate over WebSockets, Enterprise Browser Controls addresses the gap that proxy-based inspection cannot close. This is a concrete and present risk for most knowledge-worker organizations; it does not require speculative AI threat modeling to be worth addressing.

Existing Skyhigh customers expanding into AI governance and data posture. For organizations already running Skyhigh for SSE, all three announcements extend existing infrastructure. DSPM inherits existing DLP classification work. Browser controls layer on top of the existing proxy. Hybrid management consolidates what may already be a mixed on-premises and cloud deployment. The switching cost is low; the incremental value is high relative to what they are already paying.

Organizations evaluating SSE platforms for the first time. Buyers entering the SSE market without an existing platform commitment should evaluate Skyhigh's total-cost-of-ownership argument seriously, particularly if they operate hybrid infrastructure. The first-generation SSE vendors offer mature cloud inspection platforms; Skyhigh's differentiation is the flexibility to not route everything through those platforms as well as the data protection depth that comes with its DLP heritage.

Organizations operating legacy on-premises SWG deployments. Organizations with a mature on-premises SWG policy set built up over years, with granular category rules, custom exceptions, and established change-management processes, face a real cost in abandoning that investment for a cloud-only platform. Skyhigh's hybrid architecture lets these organizations keep their on-premises appliances and existing policy logic in place while incrementally adding the CASB, DLP, RBI, and ZTNA capabilities that are available today as cloud services, all managed from the same console as the on-premises SWG. This is a modernization path rather than a replatforming decision, and it is worth evaluating against the alternative of migrating the existing on-premises policy set to a competing cloud-only vendor.

No Fit or Requires Augmentation

Organizations deeply committed to a competing SSE platform. The switching costs associated with replatforming an SSE deployment, including policy migration, agent redeployment, and integration rework, are substantial. The DSPM and Browser Controls announcements are compelling, but not at the cost of a full platform migration for organizations where the existing platform is working adequately. The more relevant question for those organizations is whether their existing vendor's roadmap for hybrid enforcement and AI traffic governance is credible.

Organizations whose primary agentic AI risk is autonomous action drift. All three announcements address data movement risk: what data an employee or agent can see, move, or exfiltrate. Organizations whose threat model is primarily centered on what AI agents do, such as privilege escalation, unauthorized transactions, and chained actions that drift outside their original authorization, need an identity-grounded enforcement layer, not an SSE platform. Skyhigh addresses the data dimension well; it does not address the action dimension.

Organizations seeking an EDRM solution. Enterprise digital rights management (persistent encryption, access revocation outside the browser session, policy enforcement on documents after they leave the organization's boundary) is not what Skyhigh delivers natively. The watermarking capability in Browser Controls is a partial answer to the post-exfiltration accountability use case; it is not a substitute for EDRM. Skyhigh integrates with Microsoft Information Protection and Seclore for organizations that need full EDRM, but that integration requires a separate procurement and the associated budget justification.

The SSE market is in its second architectural generation, and the questions that are driving the replacement cycle, such as cost efficiency of cloud-only inspection, on-premises enforcement gaps, AI traffic opacity, and data posture visibility, are all questions that Skyhigh's RSAC announcements address coherently. The strongest version of the case for Skyhigh rests on a different premise than platform maturity – Zscaler and Netskope have deeper cloud deployment history. Instead, the argument is that the architectural assumptions baked into those platforms are the source of the friction that the market is now experiencing, and that Skyhigh has built the hybrid, browser-native, data-first alternative to them. Whether that case is persuasive in a given organization will depend on how much of that friction they are actually feeling, and how willing they are to act on it.

Latest Technology Notes

All Technology Notes
Visit our IT’s Moment: A Technology-First Solution for Uncertain Times Resource Center
Over 100 analysts waiting to take your call right now: +1 (703) 340 1171