Security / Secure Web Gateway

Secure Web Gateway

Filter the destination.
Keep the identity.

DNS-layer web filtering by domain, category and identity, on the gateways you already route through. Enterprise adds a host-level forward proxy. Same policy. No TLS inspection.

DNS on Business · host-level proxy on Enterprise · one policy plane
8
Curated filter feeds
2
Enforcement paths
1
Policy plane
0
Extra appliances

How filtering decides

The destination is judged before the connection starts.

01 · DNS

The query hits your gateway first.

Name resolution goes through the gateway you already route through. Bad destinations can be refused before a connection is ever opened.

  • Enforced on your self-hosted gateways
  • No separate filtering appliance

02 · CATEGORY

Feeds and your own lists.

Curated threat and category feeds sit next to tenant domain lists. A gambling rule and a malware feed use the same engine.

  • Eight curated feeds
  • Allow and deny lists you own

03 · IDENTITY

Who asked, not just what they asked for.

The verdict includes the user and their group from your IdP. Engineering can reach GitHub while a contractor cannot.

  • SSO / SCIM identity on the request
  • Group- and role-aware rules

04 · VERDICT

Allow or block, then write it down.

The decision is enforced inline and logged. Enterprise can apply the same host-level policy on the HTTP forward proxy.

  • Tamper-evident audit trail
  • Same policy for DNS and proxy

Two enforcement paths

Same policy. Different depth.

DNS-layer filtering is the default. Enterprise can send web traffic through a host-level proxy on the gateway. Neither path inspects TLS today.

Business and above

DNS-layer

Filter by domain, category and identity before a connection starts. This is the SWG most teams turn on first.

  • Domain and category rules
  • Curated threat feeds
  • Identity-aware verdicts

Enterprise

Full proxy

A host-level HTTP forward proxy on the gateway. CONNECT and plain HTTP use the same content-filter policy as DNS.

  • Host-level policy, not URL path
  • No TLS inspection yet
  • Same identity inputs as DNS
Easy to manage

Write it once. Enforce it everywhere.

One policy plane fans out to every app, gateway and user. No duplicated rules, no drift between tools. Change a policy in one place and it's live everywhere.

One policy plane Web filtering + firewall + access Version controlled
ACCESS POLICY one rule payments-api internal-wiki ci-runner s3-store admin-panel

Audit trail

Every decision, on the record.

Allow or block, who and what, when and why. Every enforcement decision is written to a tamper-evident audit trail and retained on your terms. Built for the questions auditors actually ask.

Tamper-evident chain Retention you control Evidence-ready
audit-trail · live recording
09:42:01 dana@acme · blocked domain block
09:42:03 eng-payments · payments-api allow
09:42:05 unmanaged host · internal-db block
09:42:08 sso:okta · admin-panel · mfa allow
09:42:11 guest-wifi · category: gambling block
09:42:14 ci-runner · s3-store allow

Questions teams actually ask

Is PulseHA a secure web gateway?
Yes. PulseHA Security includes a DNS-layer secure web gateway from Business, with a host-level forward proxy on Enterprise. Both paths use one identity-aware policy.
Is this a full proxy SWG with TLS inspection?
Not yet. The Enterprise proxy evaluates the destination host. TLS inspection, URL-path rules and malware scanning are not in this release.
Which plan includes SWG?
DNS-layer filtering ships on Business and Enterprise. The full host-level proxy is Enterprise only. Core includes the network, not SWG.

Plans

SWG unlocks at Business.

DNS-layer filtering ships with Security on Business. The host-level proxy is Enterprise. Same policy plane, no migration.

Core

For small teams getting started with zero trust access.

  • Full Network product
  • DNS-layer web filtering
  • Firewall & access policies

Enterprise

For organizations with advanced security and compliance needs.

  • Everything in Business
  • Posture & trust score enforcement
  • Custom audit retention & SLAs

Full feature breakdown on the pricing page →

Better together

Network comes with every plan.

Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.

  • You already have it. Network ships in every plan.
  • One policy model across network and security.
  • Application-aware routing and enforcement, together.
Explore Network