What Is Cato Networks? Cato SASE, Explained for Device-First Teams
.jpeg)
Cato Networks is one of the few security vendors that started as a network company and stayed proud of it. Its pitch is simple and ambitious: replace your MPLS, your branch firewalls, and your remote access VPN with one global cloud, and get security as part of the package. That pitch has made Cato a Gartner Leader and one of the most valuable private companies in the space. If you are already weighing vendors, our head-to-head on Cato Networks vs Zscaler is the fastest way in. This post answers the question underneath it: what Cato actually is, how it works, and who it is built for.
The short answer
Cato Networks is a SASE company, headquartered in Tel Aviv, that runs its own global private backbone of more than 85 points of presence. Sites connect through Cato Socket appliances, cloud workloads through vSockets, and remote users through the Cato Client. All traffic is inspected in Cato's cloud by a single-pass engine that handles firewall, secure web gateway, IPS, CASB, DLP, and more. Cato is a network company that sells security as a property of its backbone. Licensing is built around site bandwidth and regional user counts, with security add-ons that must cover the whole licensed capacity, so a device-first workforce with little WAN to fix ends up buying a backbone it barely uses. dope.security takes the opposite approach, inspecting traffic on the device and sending it direct.
That is a testable claim. Count how many of your people sit in branches that need SD-WAN, and how many work from laptops on home and hotel networks. The ratio tells you which architecture you are paying for.
What is Cato Networks?
Cato was founded in 2015 by Shlomo Kramer, who remains CEO, and Gur Shatz. Kramer previously co-founded Check Point and Imperva, which helps explain why Cato has never been shy about taking on incumbents. The company has raised about $1.1 billion in total, including a $359 million Series G in June 2025 at a valuation above $4.8 billion, later extended to $409 million.
Cato reported more than $350 million in annual recurring revenue for 2025, and Israeli business outlet CTech reported $415 million as of July 2026. Cato remains private, and its leadership has said it has not stopped planning an IPO.
On the analyst side, Cato announced on July 31, 2026 that it was named a Leader in the 2026 Gartner Magic Quadrant for SASE Platforms, its third consecutive year as a Leader. Coverage of the report in SDxCentral noted Gartner's cautions as well, including pricing that runs higher than others in the market.
How Cato Networks works
Cato's architecture has three parts, and they only make full sense together.
- The backbone. Cato operates a private global network of more than 85 PoPs, connected by its own backbone rather than the public internet between them.
- SPACE, the single-pass engine. Inside each PoP, the Single Pass Cloud Engine runs firewall as a service, secure web gateway, IPS, CASB, DLP, remote browser isolation, ZTNA, and anti-malware in one pass over each flow. In March 2026 Cato announced Neural Edge, which puts NVIDIA GPUs inside PoPs to run AI inspection inline.
- The edges. Physical sites connect with Cato Socket appliances, cloud sites with vSocket, and third-party equipment over IPsec. Remote users run the Cato Client, and Cato also offers a browser extension, an enterprise browser, and a clientless portal for access.
For remote users, the model is a tunnel to the cloud. Cato's documentation says the Cato Client connects to the optimal PoP based on location plus live latency and packet-loss measurements, and inspection happens there. It also notes that a client pinned to a specific PoP disconnects rather than failing over if that PoP goes down. If you want the background on why these architectures exist, SASE vs SSE architecture explains where each draws the line.
Does Cato add latency for remote users?
For sites, Cato's backbone can genuinely beat the public internet between offices, and that is the core of its value. For a laptop on home Wi-Fi reaching a SaaS app, the picture is different. The request goes up a tunnel to a Cato PoP, gets inspected, and then heads to the destination. A good backbone optimizes the middle of the trip. It does not remove the first leg.
Measured cloud-proxy latency typically runs 40 to 80 milliseconds near a point of presence and 150 to 400 milliseconds when users are far from one, and modern SaaS pages chain dozens of requests. We lay out the arithmetic in the latency math behind cloud proxy SWGs and what the detour does to real work in the backhaul bottleneck.
How much is the detour costing you? Run the Fly-Direct Speed Test to measure your real round-trip latency and compare a cloud PoP detour with inspection on the device. See how dope.security's Fly-Direct Secure Web Gateway removes the stopover, or book a 20-minute demo to see it live.
The takeaway: a private backbone speeds up the middle of the trip, while on-device inspection removes the trip.
What Cato does well
Credit where it is due. Cato has earned its reputation.
- WAN consolidation. If you are retiring MPLS and branch firewalls across dozens of sites, one vendor for SD-WAN and security is a real simplification.
- One console, built as one product. Cato built its platform rather than stitching together acquisitions, and G2 reviewers consistently praise the single management interface.
- Single-pass inspection. Running every engine in one pass is a clean design that avoids some of the stacking penalties of multi-module proxies.
- Customer satisfaction. Cato's own 2025 announcement cited a 4.7 out of 5 rating on Gartner Peer Insights from more than 275 reviews, and reviewers frequently call support responsive.
Where Cato falls short in 2026
Most of the trade-offs trace back to one fact: Cato is priced and architected around the network.
Licensing follows sites and capacity
Cato's current product catalog licenses sites by bandwidth, through bandwidth pools or per-site bandwidth, and licenses users as ZTNA users per region group. Security capabilities such as Threat Prevention, Advanced Threat Prevention, CASB, DLP, and AI Security are Premium Security add-ons. The catalog states that Threat Prevention, Advanced Threat Prevention, CASB, and DLP must cover the total licensed capacity, so you cannot buy them for a subset of sites or users. That is coherent for a network-first buyer. For a mostly remote company, it means the bill is shaped by a backbone and capacity model rather than by the laptops you are trying to protect. Reviewers on G2 and AWS Marketplace echo this, with recurring comments that licensing and bandwidth upgrades are expensive, especially for smaller teams.
Remote users still ride a tunnel
Every Cato Client connection terminates in a PoP, which is where inspection happens. Some reviewers report client disconnects and reconnects, and one reported needing to block DNSSEC for macOS users. Like every cloud inspection model, certificate-pinned apps break under TLS inspection and have to be bypassed, which Cato's own best-practice guide acknowledges. We explain why in certificate pinning and SSL inspection.
China works, within the rules
Cato documents its China design clearly. China PoPs egress in-country through a local gateway, so the Great Firewall still applies, and using a non-China PoP to get around it violates Cato's master services agreement. Cato also states that browser access, the browser extension, the enterprise browser, and remote browser isolation are not supported in China, and that global bandwidth for China sites is more expensive than regional bandwidth.
AI security is new and licensed separately
Cato acquired Aim Security in September 2025 and made Cato AI Security generally available on March 17, 2026, covering employee use of public AI tools, homegrown AI apps, and guardrails for agents. It is a serious investment. It is also an add-on, priced per user, sitting in the PoP. The hard AI test is the same for everyone: allow the corporate ChatGPT workspace, block personal ChatGPT on the same domain, and read the prompt before it leaves. We walk through it in how to block personal ChatGPT while keeping the corporate account.
Cato Networks vs dope.security: the head-to-head
Both platforms protect remote users. They start from different problems. Here is the comparison, line by line.
- What it is built to fix. Cato is built to replace the WAN and branch security stack. dope.security is built to secure the device wherever it works, with no network redesign.
- Where inspection happens. Cato inspects traffic in its PoPs after the Cato Client or a Socket tunnels it there. dope.security inspects traffic on the device with an on-device SSL inspection proxy.
- Network path for remote users. Cato routes client traffic to the optimal PoP and across its backbone. dope.security flies direct to the destination, with up to 4x performance over legacy proxy SWGs.
- Licensing shape. Cato licenses site bandwidth and ZTNA users, with security add-ons that must cover total capacity. dope.security needs no site appliances or bandwidth pools, and runs SWG, CASB Neural, and Dopamine DLP under one dope.console.
- AI tenant control. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to corporate tenants and blocks personal logins on the same domain.
- DLP for prompts and uploads. Dopamine DLP intercepts file uploads and AI prompts on the device and classifies them with large language models through zero-retention OpenAI APIs, covering ChatGPT, Claude, Perplexity, Abacus, and Copilot.
- Footprint. The dope.security agent is Mac native and Windows and uses less than 100 MB of RAM.
For the wider field, see our Cato Networks alternatives guide and our roundup of SASE vendors in 2026. If branch security is part of your plan, our SD-WAN security guide covers how the two problems fit together.
Do you need Cato, or just the SSE piece?
If you run many branches, are retiring MPLS, and want one vendor for networking and security, Cato is a strong choice and deserves a serious evaluation. If most of your people work from laptops, your offices are small or shrinking, and the real problem is web security, AI governance, and data loss on those laptops, you are buying a network to solve a device problem.
That second profile is common in the 250 to 5,000 employee range, and it is where a device-first gateway fits. Deployment is measured in days, not quarters. Greylock Partners went from first proposal to signed contract in 27 days, and a Fortune 100 company scaled from 900 to more than 18,000 devices in weeks.
The bottom line on Cato Networks
Put simply: Cato is an excellent answer to a network question, and its security comes attached to a backbone and a capacity-based license, so companies whose people mostly work off the network pay for infrastructure they barely touch while every remote request still tunnels to a PoP. If you want web security, AI tenant control, and DLP to run on the laptop and send traffic straight to its destination, that is what dope.security was built to do. Explore the Fly-Direct Secure Web Gateway or book a 20-minute demo and we will run the personal ChatGPT test live.
Frequently Asked Questions
What does Cato Networks do?
Cato Networks provides a cloud-delivered SASE platform that combines SD-WAN and network security on its own global private backbone. Sites connect through Cato Socket appliances, cloud workloads through vSockets, and remote users through the Cato Client, and all traffic is inspected in Cato's PoPs by its Single Pass Cloud Engine.
Is Cato Networks SASE or SSE?
Cato is a SASE platform, meaning it combines networking (SD-WAN and its backbone) with security service edge capabilities such as secure web gateway, CASB, DLP, and ZTNA. Cato's catalog also lists SSE site bandwidth licensing. dope.security focuses on the SSE side, delivered from the device.
How is Cato Networks licensed?
Cato's product catalog licenses sites by bandwidth and users as ZTNA users per region group. Security capabilities such as Threat Prevention, CASB, DLP, and AI Security are Premium Security add-ons, and Cato states that several of them must cover the total licensed capacity. Gartner's 2026 cautions, as reported by SDxCentral, included higher pricing than others in the market.
How many PoPs does Cato Networks have?
Cato states that its backbone includes more than 85 PoPs worldwide. Remote users connect to the optimal PoP based on location and live latency and packet-loss measurements. dope.security does not route web traffic through PoPs for inspection because inspection runs on the device.
Does Cato Networks work in China?
Yes, with conditions Cato documents. China PoPs egress in-country, so the Great Firewall still applies, and using a non-China PoP to bypass it violates Cato's MSA. Cato also lists browser access, the browser extension, the enterprise browser, and remote browser isolation as unsupported in China, and global bandwidth for China sites costs more than regional bandwidth.
What is the best Cato Networks alternative for remote workforces?
For organizations whose main goal is protecting laptops that work from anywhere rather than rebuilding the WAN, dope.security is a strong alternative. It runs an on-device SSL inspection proxy with no PoPs in the data path, Cloud Application Control for AI tenants, and Dopamine DLP, all under one console, and it deploys through standard device management such as Intune.



