Why Fly-Direct Is Becoming the Default SSE Architecture in 2026

Why Fly-Direct Is Becoming the Default SSE Architecture in 2026

The short answer

SSE is built one of two ways. Cloud-backhaul routes user traffic to a vendor data center for inspection. Fly-direct inspects on the device and sends traffic straight to its destination. For most of the last decade, cloud-backhaul was the default. In 2026 that is changing: fly-direct is becoming the default because the workforce is distributed, AI has moved risk to the endpoint, and the backhaul detour no longer buys anything it used to.

This is not a feature race. It is an architecture shift, the same kind the industry already went through once when security moved from appliances to the cloud. The move now is from the cloud proxy to the device.

The default was set for a world that no longer exists

Cloud-backhaul solved a real problem. In the appliance era, remote and branch traffic hauled back to a headquarters firewall. Vendors moved that inspection into their own clouds, closer and more scalable than a box in a closet. The design assumed users clustered near a point of presence (PoP), and in 2015 they did.

That assumption is the load-bearing wall of the entire cloud-proxy model, and it has quietly failed. People work on laptops, at home, in transit, and across continents. When the user is not near a PoP, the detour to reach one becomes the slowest part of the connection. The default architecture is optimized for a workplace most companies no longer have.

Three shifts pushing fly-direct to the front

1. The workforce is permanently distributed

Backhaul latency scales with distance from a PoP. Near a node the detour is roughly 40 to 80 ms per request. Far from one it is 150 to 400 ms, and through a filtered or congested path it is higher and less predictable. Multiply that across the dozens of requests a page makes and the thousands an app makes in a session, and the compounded effect is an internet that feels slow, worst for exactly the remote and international staff you most need productive.

Fly-direct removes the detour because inspection runs on the endpoint. Protection travels with the user, identical whether they are on the corporate network, at home, or on hotel Wi-Fi. See SSE for remote and hybrid workforces.

2. AI moved the risk to the endpoint

The sensitive data leaving your organization used to be a file uploaded to a website, something a cloud proxy could see. Now it is a prompt pasted into ChatGPT desktop, a snippet sent from an IDE, an autonomous agent acting on company data. A model that only sees what routes through a browser or a cloud proxy misses a growing share of it.

Fly-direct inspects at the point traffic leaves the machine, whatever app produced it. dope.security layers Dopamine DLP to catch PII, PCI, PHI, and IP in prompts and uploads, and Cloud Application Control to restrict AI tools to your enterprise tenant. That is structurally hard for a cloud proxy and impossible for a browser extension. See why in the CISO's guide to AI governance.

3. The privacy and residency bill came due

To inspect encrypted traffic, someone has to decrypt it. In cloud-backhaul, that decryption happens inside the vendor's cloud, so your corporate plaintext exists in third-party infrastructure at the moment of inspection, sometimes in another jurisdiction. Regulated teams in healthcare, finance, and government increasingly treat that as a real exposure, not an accepted cost.

Fly-direct decrypts on the endpoint the user already controls. The plaintext never leaves the machine to be read. That is a cleaner data-residency story, and it is one reason the model holds up under strict compliance.

Cloud-backhaul vs fly-direct, side by side

What you care about Cloud-backhaul Fly-direct
Speed for remote users Detour on every request No network detour, up to 4x faster
AI visibility What routes through the proxy Browser, desktop apps, IDEs, scripts
Data residency Decrypted in vendor cloud Decrypted on the device
Restricted regions Hop can degrade or fail Keeps working
Time to deploy Weeks to quarters Days to weeks via MDM

"Modern default" is a claim, so here is the evidence

Calling fly-direct the modern default is only worth saying if deployments back it. They do.

A Fortune 100 company scaled the fly-direct agent from 900 to more than 18,000 devices in a matter of weeks, averaging around 3,000 per week, deploying silently via Intune. Outreach Health, a healthcare organization with 34 offices, secured 99% of its fleet in one week and cut web-access IT tickets 70% in 90 days. Greylock Partners moved off a legacy SSE and signed in 27 days. Another Cisco Umbrella customer migrated 2,000 machines in two days. The City of Visalia, a 700-plus-user municipality, adopted fly-direct so protection followed its mobile workforce off-network.

None of those organizations stood up a forwarding architecture. There was nothing to route, because the inspection lives on the device.

What this means if you are buying SSE this year

The practical takeaway is to make architecture the first question in an evaluation, not the last. Before comparing feature checklists, ask where the product inspects: on the device, or in a vendor cloud. That single answer sets your latency, your privacy posture, your reliability in hard geographies, and your deployment effort.

Then weight the decision to your workforce and your risk. The more remote and international your users, and the more AI is central to your exposure, the more fly-direct pays off. If your users cluster near points of presence and you want all enforcement in a network cloud, cloud-backhaul is still a defensible choice, with the trade-offs above.

For the full architectural breakdown, see the SSE architecture guide. If you are replacing a specific incumbent, start with the best Zscaler alternatives or top Netskope alternatives.

Frequently asked questions

What is the modern SSE architecture? Fly-direct: inspecting traffic on the endpoint rather than backhauling it to a vendor data center. It removes the latency detour, keeps data local, and sees AI traffic at the source.

Why is fly-direct becoming the default in 2026? Because the workforce is distributed, AI moved sensitive-data risk to the endpoint, and the privacy cost of decrypting corporate traffic in a vendor cloud is no longer acceptable to many teams. Cloud-backhaul was optimized for an office-centric world that has changed.

Is cloud-backhaul obsolete? No. It still suits teams whose users cluster near points of presence and who want all enforcement in a network cloud. It is just no longer the automatic choice for a hybrid, remote, or international workforce.

Does fly-direct sacrifice central control? No. Management, policy, and analytics stay in one cloud console with real-time policy push. Only the inspection of live traffic moves to the device.

How disruptive is switching to fly-direct? Usually less than a cloud-to-cloud migration, because you remove the forwarding layer rather than rebuild it. Rollouts of thousands of devices in days are common.

See it in action

Want to see why fly-direct is becoming the default on your own devices? Start a free trial or book a 20-minute demo at dope.security.

SSE
SSE
Thought Leadership
Thought Leadership
SASE
SASE
back to blog Home