01 · DNS
The query hits your gateway first.
Name resolution goes through the gateway you already route through. Bad destinations can be refused before a connection is ever opened.
- Enforced on your self-hosted gateways
- No separate filtering appliance
Secure Web Gateway
DNS-layer web filtering by domain, category and identity, on the gateways you already route through. Enterprise adds a host-level forward proxy. Same policy. No TLS inspection.
How filtering decides
01 · DNS
Name resolution goes through the gateway you already route through. Bad destinations can be refused before a connection is ever opened.
02 · CATEGORY
Curated threat and category feeds sit next to tenant domain lists. A gambling rule and a malware feed use the same engine.
03 · IDENTITY
The verdict includes the user and their group from your IdP. Engineering can reach GitHub while a contractor cannot.
04 · VERDICT
The decision is enforced inline and logged. Enterprise can apply the same host-level policy on the HTTP forward proxy.
Two enforcement paths
DNS-layer filtering is the default. Enterprise can send web traffic through a host-level proxy on the gateway. Neither path inspects TLS today.
Business and above
Filter by domain, category and identity before a connection starts. This is the SWG most teams turn on first.
Enterprise
A host-level HTTP forward proxy on the gateway. CONNECT and plain HTTP use the same content-filter policy as DNS.
One policy plane fans out to every app, gateway and user. No duplicated rules, no drift between tools. Change a policy in one place and it's live everywhere.
Audit trail
Allow or block, who and what, when and why. Every enforcement decision is written to a tamper-evident audit trail and retained on your terms. Built for the questions auditors actually ask.
Plans
DNS-layer filtering ships with Security on Business. The host-level proxy is Enterprise. Same policy plane, no migration.
For small teams getting started with zero trust access.
For growing teams who need more control and visibility.
For organizations with advanced security and compliance needs.
Full feature breakdown on the pricing page →
Better together
Security runs on the Pulse Network, and Network is included in every tier, including yours. The policy plane that enforces your traffic also routes it, with managed gateways, egress and DNS built in.