What Is Zscaler? How It Works, What It Costs, and Where the Cloud Proxy Model Breaks (2026)
.jpeg)
Zscaler is a cloud security company whose products (Zscaler Internet Access, Zscaler Private Access, Zscaler Digital Experience and the Zscaler Client Connector agent) all work the same way: traffic leaves the device, travels to a Zscaler data center called the Zero Trust Exchange, gets inspected there, and continues to the internet or a private app. That detour is the product. It is also the thing a buyer is really choosing, because once inspection can run on the device itself, the feature list stops being the difference. dope.security runs the Secure Web Gateway, CASB and DLP on the endpoint and lets traffic fly direct, which is why it shows up on so many Zscaler shortlists.
If you landed here because someone in a meeting said "we should look at Zscaler" and you nodded along, this is the explainer. It covers what Zscaler actually sells, how the architecture works, what it costs, where it is strong, and where its own documentation says it struggles. If you are already past the "what is it" stage and comparing options, our ranked list of the best Zscaler alternatives in 2026 and the full Zscaler review pick up where this leaves off.
What is Zscaler, in one paragraph?
Zscaler is a publicly traded (NASDAQ: ZS) security vendor founded in 2007 and headquartered in San Jose, California. It sells a cloud-delivered Security Service Edge (SSE) platform. Instead of putting a firewall or proxy appliance in your office, Zscaler puts the proxy in its own data centers and routes your users through them. Gartner has placed Zscaler in the Leaders quadrant of the SSE Magic Quadrant every year the report has existed, and it is the vendor most large enterprises name first when they say "zero trust."
The one-line version: Zscaler is a very large, very mature cloud proxy. Everything else in this article is a consequence of that sentence.
What does Zscaler sell? The four products that matter
Zscaler's catalog is long, but four names cover almost every conversation.
Zscaler Internet Access (ZIA)
ZIA is the Secure Web Gateway. It handles URL filtering, malware scanning, SSL inspection, cloud firewall, sandboxing and, with the right add-on, data loss prevention and CASB for traffic headed to the open internet and SaaS apps. When people say "we run Zscaler," they usually mean ZIA. It is the product that competes with dope.SWG.
Zscaler Private Access (ZPA)
ZPA is the zero trust network access (ZTNA) product, positioned as a VPN replacement. Instead of dropping a user onto the corporate network, ZPA brokers a connection to one specific private application through the Zscaler cloud. We break down the split between the two flagship products in ZIA vs ZPA.
Zscaler Digital Experience (ZDX)
ZDX is monitoring. It measures the user's experience from the device through Zscaler to the application, which exists in part because customers needed a way to prove whether the Zscaler hop was the reason a page felt slow.
Zscaler Client Connector
Client Connector (formerly Zscaler App or "Z App") is the agent installed on every laptop and phone. It does not inspect traffic. Its job is to forward traffic to the nearest Zscaler enforcement node. The distinction matters, and we cover it in Zscaler Client Connector vs an on-device agent.
How does Zscaler work?
Every Zscaler product runs on the same pattern. The Client Connector on the device (or a GRE or IPsec tunnel from an office router) forwards traffic to the closest Zscaler point of presence, historically called a ZEN and now a Service Edge. That node terminates the connection, decrypts TLS if inspection is enabled, applies your policy, re-encrypts, and forwards the request to its destination. The response comes back the same way. Zscaler operates 150 or more of these nodes globally and peers with major cloud providers to keep the hop as short as possible.
That design solved a real problem in 2008. Backhauling traffic from branch offices to a headquarters proxy was slow and expensive, and moving the proxy to a cloud that was closer to users than HQ was a clear improvement. What the design cannot do is remove the hop. It can only move it. Every request your users make still goes device, then Zscaler, then destination, then back through Zscaler, all day.
The alternative pattern, which dope.security uses, is to run the proxy on the device itself. The dope.endpoint agent performs SSL inspection, URL filtering, Cloud Application Control and Dopamine DLP locally, in under 100 MB of RAM, and then sends the request straight to its destination with no intermediate data center. Policy still comes from a single cloud console (dope.console) and pushes to devices in seconds, but the traffic path has one fewer stop.
What does the Zscaler hop cost in latency?
Zscaler's own positioning talks about peering and proximity, and near a Service Edge the added round trip is modest. The issue is what happens as modules stack and users move. Customers report [Sentiment] that latency compounds two to three times as SSL inspection, DLP and sandboxing are layered on the same request path, and Gartner's research has cited [Documented] a 10 to 20 percent throughput drop from cloud proxy SSE inspection in general. Users far from a Service Edge, in APAC especially, draw the short straw. We worked through the arithmetic in the cloud proxy latency math and in the backhaul bottleneck.
Measure the detour yourself: the Fly-Direct Speed Test times your real round-trip latency in the browser and shows what a cloud proxy hop would add to common apps. See how Fly Direct removes the hop, or book a 20-minute demo and we will run it on your network.
Takeaway: a cloud proxy adds a fixed detour to every request; on-device inspection adds none, so your existing latency is your load time.
Is Zscaler reliable? What the incident history says
Zscaler is engineered for scale and most days it is invisible. The pattern worth knowing is that its largest incidents were self-inflicted. On October 25, 2022, an internal maintenance change caused 100 percent packet loss for customers routed through affected nodes [Documented]. On January 19, 2025, another significant disruption hit the same week Cisco Umbrella had its own DNS failover incident [Documented]. Because every user is routed through the shared control plane, a problem in one Service Edge is a problem for every customer on it at once, and admins lose dashboards and logs during the incident they most need them. The full timeline is in Zscaler outage history and the control plane problem.
The architectural contrast: with enforcement on the device, a cloud incident cannot take inspection offline. dope.endpoint keeps enforcing cached policy if it loses contact with dope.console, and there is no shared node for your traffic to be stuck behind.
What breaks with Zscaler? SSL inspection and the agent
Three categories of friction show up in Zscaler's own support documentation and in customer reports.
- Certificate-pinned apps. Zscaler cannot inspect traffic from apps that pin their certificates, which includes parts of Microsoft 365, WebEx and Dropbox, so admins maintain bypass lists that create blind spots [Documented]. Developer tooling such as Docker, Python package managers and Git also breaks until the Zscaler root certificate is installed in each tool's trust store [Documented]. Our guide to certificate pinning and SSL inspection explains why this is harder for a cloud proxy than for an on-device one.
- Agent resource use. Zscaler publishes guidance on high-CPU threads and memory leaks in Client Connector, and on the 60-second hangs users experience when the client re-establishes its tunnel after a network change [Documented].
- Deployment weight. PAC files, forwarding profiles, app profiles, certificate exception lists and per-region node selection all need to be right before ZIA behaves. Global rollouts commonly run two to four months and most mid-market teams end up with a dedicated Zscaler admin [Sentiment].
dope.security's approach to the first problem is worth a sentence: because inspection happens on the device, a pinned-app failure shows up as an SSL error notification in the console and the admin adds a bypass in a few clicks. A Fortune 100 customer cited that feature as one of the reasons it scaled from 900 to over 18,000 devices in a matter of weeks, a story told in the 18,000-device deployment write-up.
How much does Zscaler cost?
Zscaler does not publish a price list. Pricing is per user, per year, in stacked editions (Business, Transformation and above) with add-ons for data protection, sandboxing, browser isolation and AI controls. Renewals are where customers feel it: an August 2025 analysis by NPI Financial found some core SKUs priced 35 percent or more above prior-year levels [Documented]. At 2,000 users on a full stack, annual contracts commonly land between $250,000 and $400,000 before professional services. We keep a current breakdown in Zscaler pricing in 2026.
Two line items catch buyers off guard. First, China: Zscaler sells access from mainland China as a separate China Premium or China Plus uplift [Documented]; see does Zscaler work in China. Second, AI governance: inspecting prompts to ChatGPT or Claude for sensitive data requires the Data Protection add-on, and the AI Guard and AI Scanning capabilities are licensed separately again [Documented]. The stack is itemized in what Zscaler AI governance actually costs.
Zscaler vs dope.security: the architectural comparison
The clearest way to understand Zscaler is to put it next to the design it did not choose. Each line below pairs the Zscaler behavior with the dope.security behavior.
- Where inspection happens: Zscaler decrypts and inspects in a Service Edge data center; dope.security decrypts and inspects on the device in the dope.endpoint agent.
- Traffic path: Zscaler routes device to Service Edge to destination and back on every request; dope.security sends traffic from the device straight to the destination with no intermediate hop.
- Failure mode: a Zscaler Service Edge or control-plane incident affects every user routed through it simultaneously; dope.security enforcement is local, with cached policy if the console is unreachable.
- Agent footprint: Zscaler Client Connector is a steering agent with published high-CPU and memory-leak guidance; dope.endpoint is the inspection engine itself and runs in under 100 MB of RAM, with up to 4x performance over legacy proxy SWGs.
- Console: Zscaler spreads ZIA, ZPA, ZDX and data protection across products and editions; dope.security runs SWG, CASB Neural, Dopamine DLP and Cloud Application Control from one console built from scratch.
- AI governance: Zscaler sells prompt DLP and AI controls as add-ons on top of the proxy; dope.security ships three-layer AI governance natively, from Shadow IT discovery to SWG policy to CAC tenant control, with Dopamine DLP (US Patent 12,464,023) classifying prompts on the device through zero-retention APIs.
- China: Zscaler charges a China uplift; dope.security works in China with no paid uplift because there is no data center the traffic has to reach first.
- Deployment: Zscaler rollouts commonly run months; dope.security customers such as Outreach Health reached 99 percent device coverage in one week and cut web-access tickets 70 percent in 90 days.
Who is Zscaler for, and who should look elsewhere?
Zscaler is a sound choice for large enterprises with dedicated security engineering teams, budget for professional services, users concentrated near Service Edges, and a board that wants a name it recognizes. It is a poorer fit for the 250 to 5,000 employee company with a distributed workforce, a lean IT team, employees in China or APAC, and a renewal cycle that keeps climbing. If that second description sounds familiar, the complete guide to replacing Zscaler covers the migration path, and this healthcare displacement story shows what it looked like for one organization.
The bottom line on what Zscaler is
Zscaler is the company that proved the perimeter could live in the cloud, and it built the most complete cloud proxy in the market to prove it. What it never did is question whether the proxy needed to be somewhere else at all. Every ZIA, ZPA and ZDX capability exists to make the trip through the Zero Trust Exchange safe, fast enough and observable. dope.security started from the opposite premise: put the proxy on the device, skip the trip, and keep the controls. If you want to see the difference on your own laptops, start a free trial or book a 20-minute demo.
Frequently Asked Questions
Is Zscaler a VPN?
No. Zscaler Private Access (ZPA) is marketed as a VPN replacement, but it works differently: instead of putting the user on the corporate network, it brokers access to individual applications through the Zscaler cloud. Zscaler Internet Access (ZIA) is not a VPN either; it is a cloud proxy that inspects internet-bound traffic. dope.security takes the proxy off the network path entirely by running inspection on the device.
Is Zscaler a firewall?
ZIA includes a cloud firewall module, but Zscaler is better described as a Secure Web Gateway and Security Service Edge platform than as a firewall. It inspects web and SaaS traffic at layer 7, which is what a firewall at the office edge cannot see once users leave the building. Our explainer on secure web gateway vs firewall draws the line.
Does Zscaler slow down the internet?
It can, because every request makes a round trip to a Zscaler Service Edge before reaching its destination. Near a node the added latency is modest; far from one, or with SSL inspection, DLP and sandboxing stacked, customers report it compounding. dope.security adds no network detour because inspection runs on the device, so page load time is governed by the user's own connection.
What is the Zero Trust Exchange?
The Zero Trust Exchange is Zscaler's name for its global network of inspection data centers and the policy engine that runs in them. Every Zscaler product forwards traffic into it. It is the reason Zscaler can enforce one policy everywhere, and also the reason a control-plane incident affects every customer at once.
Can Zscaler control personal ChatGPT while allowing the corporate tenant?
Yes, but it requires the proxy plus SSL inspection plus the Data Protection add-on to inject the tenant header, and prompt-content DLP is licensed separately again. dope.security does the same allow-corporate, block-personal control on the device through Cloud Application Control, with Dopamine DLP inspecting prompt content, and no add-on SKU. The walkthrough is in how to block personal ChatGPT.
How is Zscaler deployed on endpoints?
Through the Zscaler Client Connector agent, typically pushed by an MDM such as Intune or Jamf, plus a root certificate for SSL inspection and PAC or forwarding profiles that tell the client where to send traffic. dope.endpoint deploys the same way through MDM, but there are no forwarding profiles or node selection to configure because traffic does not go anywhere before the internet. A Fortune 100 customer pushed it silently through Intune at roughly 3,000 devices per week.


.jpeg)
.jpeg)
.jpeg)

