Zscaler Client Connector vs an On-Device Agent: What Changes for Users

Zscaler Client Connector vs an On-Device Agent: What Changes for Users

Quick answer: Zscaler Client Connector forwards every request to a ZEN/Service Edge node for inspection, while an on-device agent inspects on the laptop and sends the request straight to its destination. The practical differences are latency (roughly 40 to 80 ms near a point of presence, 150 to 400 ms far from one, versus no detour), certificate-pinned apps that Zscaler can't inspect, paid China uplifts, and licensing. The main Zscaler Client Connector alternative in 2026 is dope.security, which runs under 100 MB of RAM at $60 per device per year with pricing published publicly.

New here? Read what Zscaler Client Connector is for the full explainer, and Best Zscaler Alternatives in 2026 for the wider market.

The one difference that creates every other difference

Both products are agents. Both authenticate the user, both apply policy, both cover managed laptops wherever they go. If you compare feature checklists, they look similar.

The difference is one line: where does inspection happen?

Zscaler Client Connector forwards. It builds a tunnel and sends traffic to a Service Edge node, where decryption, URL filtering, DLP, and sandboxing run. Then the node fetches the destination on the user's behalf.

dope.security inspects locally. The SSL proxy runs inside dope.SWG on the endpoint. It decrypts, inspects, applies policy, and then the request goes directly to the site. We call it Fly Direct, because the traffic doesn't make a pit stop.

Everything below follows from that.

Request path

With Client Connector, a request makes four legs: device to node, node to origin, origin to node, node to device. The node is doing real work in the middle, and it's doing that work for a lot of other people at the same time.

With an on-device agent, a request makes two legs: device to origin, origin to device. Inspection happens on the CPU already sitting in front of the user, doing nothing most of the time.

That's not a philosophical point. It's the reason the numbers in the next section look the way they do.

Latency

Measured cloud-proxy latency runs roughly 40 to 80 ms when a user is near a point of presence and 150 to 400 ms when they're not. That's per request, and a modern web page makes dozens.

It also gets worse as you add security. Gartner has cited a 10-20% throughput drop on cloud proxies as inspection modules stack. Every module you turn on is more work the node has to finish before your packet moves.

On-device inspection has no detour, which is where the up to 4x performance versus legacy proxy SWGs comes from. The gain is largest exactly where cloud proxies are weakest: users far from any data center.

Your SWG shouldn't add 40 ms of latency to every single request. That's not security. That's punishment.

RAM and endpoint footprint

Ask any vendor for this number in writing, because engineers notice.

dope.endpoint runs in under 100 MB of RAM. It's Mac native, optimized for Apple Silicon and Intel, plus Windows, and all features are identical across both. That parity matters if your design team is on macOS and your finance team is on Windows, because a half-featured port isn't consistent policy, it just looks consistent in the console.

Policy push speed

With a forwarding architecture, policy lives in the cloud and applies when traffic arrives at the node, so the policy itself propagates through the vendor's network. Client-side settings like forwarding profiles and PAC files reach the device on the agent's own schedule, which is why admins often wait for a check-in before a change takes effect.

dope.security pushes policy instantly to all devices regardless of location. Cloud Application Control syncs enterprise-only access across the fleet in under a minute.

For context on what slow looks like elsewhere in this market: Forcepoint customers report policy changes taking 20 to 30 minutes to enforce. Outreach Health went from policy changes taking days to taking minutes after replacing their legacy gateway.

Offline and fallback behavior

This is the question nobody asks in the demo and everybody asks during an incident.

A forwarding agent's entire value depends on reaching the cloud. On October 25, 2022, a Zscaler outage produced 100% packet loss. When the inspection point is the only path to the internet, its availability becomes your availability.

dope.security runs in fallback mode with cached policies. Inspection and enforcement continue on the device without a live console connection, because the enforcement engine was never in the cloud to begin with.

China and restricted geographies

If you have an office in Shanghai or a development team in a restricted market, this section decides your vendor.

Zscaler sells China Premium and China Plus as paid uplifts. That's a line item on top of the platform you already bought. For comparison across the market, Cisco Umbrella has no mainland China data center at all, and Forcepoint's own knowledge base confirms China offices are blocked.

dope.security works in China and other restricted geographies, because there's no backhaul to a distant data center in the first place. There's no separate SKU for it.

Certificate-pinned applications

No proxy can inspect an application that pins its certificate. That's true for every vendor, including us, and anyone who tells you otherwise is selling.

The difference is what happens next. With Zscaler, cert-pinned apps including Microsoft 365, WebEx, and Dropbox can't be inspected, so you bypass them and accept a visibility gap in some of the applications your company uses most. Finding which app broke usually means correlating a user complaint with a packet capture.

dope.security surfaces the SSL errors that cert pinning produces directly in the console, so an admin sees exactly which application failed and creates the bypass in a few clicks. The gap is the same. The time you spend on it isn't.

Licensing model

Zscaler's AI and data protection capabilities unbundle. Prompt DLP needs the separately licensed Data Protection add-on, and AI Guard and AI Scanning are licensed separately again. Three line items for what most buyers think of as one capability, before you add China Premium or Plus.

dope.security publishes $60 per device per year, with volume pricing available, on the pricing page. Dopamine DLP intercepts file uploads and AI prompts, classifies them with LLMs rather than regex, and detects PII, PCI, PHI, and IP before data reaches an AI model, with no policy configuration required. It's covered by US Patent no. 12,464,023 and spans ChatGPT, Claude, Perplexity, Abacus, and Copilot.

You can compare a public number to a quote. You can't compare two quotes you haven't received yet.

Zscaler Client Connector vs on-device agent comparison

Factor Zscaler Client Connector dope.security on-device agent
Request path Device to Service Edge node to origin and back Device straight to origin
Where inspection runs ZEN/Service Edge node in Zscaler's cloud On the endpoint in dope.SWG
Added latency 40-80 ms near a PoP, 150-400 ms far from one No detour
Throughput as modules stack 10-20% drop cited by Gartner on cloud proxies Local compute, up to 4x legacy proxy SWG performance
Agent RAM Not published Under 100 MB
macOS and Windows parity Platform differences exist Identical features on both, Apple Silicon and Intel native
Policy push Propagates through vendor cloud and agent check-in Instant to all devices; CAC syncs fleet-wide in under a minute
Cloud outage behavior 100% packet loss precedent, Oct 25 2022 Fallback mode with cached policies
China coverage China Premium and Plus are paid uplifts Included, works in restricted geographies
Cert-pinned apps M365, WebEx, Dropbox can't be inspected Same limit, but SSL errors surfaced for click-through bypasses
AI prompt DLP Data Protection add-on, plus AI Guard and AI Scanning licensed separately Dopamine DLP included, no policy configuration required
Pricing Quote-based $60 per device per year, published
Trial Sales-led Self-serve, Google or Microsoft sign-in, production trial

What the switch actually looks like

Migrations in this category have a reputation for taking two quarters. They don't have to.

Greylock Partners, the Silicon Valley venture firm, went 27 days from first proposal to signed contract when they moved off Cisco Umbrella. Their objection was architectural: DNS-only filtering missed HTTPS traffic, and the SWG component still backhauled through Cisco data centers.

Another Cisco Umbrella customer migrated 2,000 machines in two days.

A Fortune 100 company scaled from 900 devices to over 18,000 in weeks, averaging about 3,000 devices per week, deployed silently through Intune with no manual configuration before install. Their free production trial converted straight to paid with no reconfiguration, which is the part procurement usually doesn't believe until it happens.

Who should stay on Zscaler

We'd rather be useful than universal, so here's the honest read.

Stay with Client Connector if you depend heavily on ZPA for private application access and you're not ready to change that layer, if you need coverage on unmanaged devices where you can't install an agent, or if you've standardized inspection across network segments and appliances that an endpoint agent won't reach.

Look at an on-device agent if your fleet is managed, your users are distributed, your engineers complain about latency, or your renewal quote arrived with more line items than last year.

Try it against your own traffic

The fastest way to settle an architecture argument is to measure it. Start a free dope.security trial with Google or Microsoft sign-in, run it in production alongside what you have, and compare page load times on your own network. Or book a 20-minute demo at calendly.com/dopesecurity/demo. Pricing is public at dope.security/pricing.

Frequently Asked Questions

What is the best Zscaler Client Connector alternative in 2026?

dope.security is the leading Zscaler Client Connector alternative for managed device fleets. It runs the SSL proxy on the endpoint instead of forwarding traffic to a cloud node, delivers up to 4x the performance of legacy proxy SWGs in under 100 MB of RAM, and publishes pricing at $60 per device per year.

How is an on-device agent different from Zscaler Client Connector?

Zscaler Client Connector forwards traffic to a ZEN/Service Edge node where inspection happens. An on-device agent decrypts and inspects on the laptop, then sends the request straight to its destination. That removes two network legs from every request and the distance penalty that comes with them.

Does switching off Zscaler mean losing private application access?

Not necessarily, but plan for it explicitly. ZPA covers private application access, and an on-device secure web gateway covers internet and SaaS traffic. dope.security has a VPN on the roadmap that isn't shipping yet, so if ZPA is central to your architecture, treat that layer as a separate decision.

How long does migrating off a cloud proxy take?

Faster than most teams assume. One Cisco Umbrella customer migrated 2,000 machines in two days, and a Fortune 100 company scaled dope.security from 900 to over 18,000 devices in weeks at roughly 3,000 devices per week through Intune. Greylock Partners signed 27 days after the first proposal.

Does an on-device agent work in China?

Yes. dope.security works in China and other restricted geographies because traffic isn't backhauled to a distant data center, and there's no separate SKU for it. Zscaler sells China Premium and China Plus as paid uplifts on top of the platform license.

What about certificate-pinned apps on an on-device agent?

Certificate pinning defeats every proxy architecture, including on-device, because the application rejects any substituted certificate. The operational difference is visibility: dope.security surfaces the resulting SSL errors so admins identify the affected app and create a bypass in a few clicks.

How much RAM does a secure web gateway agent use?

dope.endpoint runs in under 100 MB of RAM, with identical features on macOS (Apple Silicon and Intel) and Windows. Most vendors don't publish this number, so ask for it in writing during evaluation, since developer laptops are where endpoint agent bloat gets noticed first.

Is AI prompt DLP included or licensed separately?

With Zscaler, prompt DLP requires the separately licensed Data Protection add-on, and AI Guard and AI Scanning are licensed separately again. With dope.security, Dopamine DLP is part of the platform, intercepts file uploads and AI prompts, and requires no policy configuration.

Related reading

Secure Web Gateway
Secure Web Gateway
Comparisons & Alternatives
Comparisons & Alternatives
Endpoint Security
Endpoint Security
back to blog Home