{"api_version":"provider-public/1.0.0","provider":{"id":"provider:zscaler","slug":"zscaler","display_name":"Zscaler, Inc. (trading and profile display name: Zscaler)","provider_types":["technology_vendor"],"primary_geographies":[]},"revision":{"id":"revision:44562c0b5225f88ac0275492","dataset_version":"sha256-0f697fc7fc4690bb","editorial_revision":"unreviewed-import","reviewed_at":"2026-09-01T20:20:11.364Z"},"editorial":{"overview":"Zscaler is the vendor that effectively created the SSE category, and it’s still the one most competitors get measured against when it comes to sheer scale and security depth - the Zero Trust Exchange runs across 150+ data centres, processes over 400 billion transactions a day, and holds FedRAMP High authorisation for ZIA and ZPA (other SASE-class vendors also hold FedRAMP High or equivalent for their own components). If you’re a security-first buyer looking to retire VPN concentrators and stitch SWG, CASB, DLP and ZTNA together under one console, Zscaler is one of the most proven single-vendor routes to get there. Where it’s less straightforward is on the networking side and on price: there’s no owned private backbone underneath it (it leans on internet peering rather than Cato-style middle-mile infrastructure), the SD-WAN/branch story is newer and less mature than the core security stack, and the tiered per-user pricing model can escalate fast once ZDX, workload licensing and Data Protection add-ons come into play - all worth mapping out early rather than discovering at renewal.","page_title":"Zscaler, Inc. (trading and profile display name: Zscaler) SD-WAN and SASE profile","meta_description":"Z caler i  the vendor that effectively created the SSE category, and it’   till the one mo t competitor  get mea ured again t when it come  to  heer  cale "},"products":[{"id":"product:8d6aee31f6dfb811b8d504de","name":"AI Security / GenAI Security","category":"AI application and data-security module","delivery_relationship":"native","target_buyer":"Security/compliance teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:zscaler:14","evidence:zscaler:16"]},{"id":"product:dee0f7343c1fee04168d94d0","name":"Data Fabric for Security","category":"Security data aggregation / unified vulnerability management","delivery_relationship":"native","target_buyer":"SecOps/vulnerability management teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:zscaler:10"]},{"id":"product:b242eba6b38e6b9328c36e3e","name":"Risk360","category":"Cyber risk quantification","delivery_relationship":"native","target_buyer":"CISO/risk teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:zscaler:13"]},{"id":"product:74b675b539e0a00c04f3f30c","name":"Zero Trust Branch","category":"SD-WAN / branch connectivity","delivery_relationship":"native","target_buyer":"Branch/site buyers","delivery_model":"Hardware appliance or VM, cloud-managed","status":"current","evidence_source_ids":[]},{"id":"product:bfb3f277c179768ae6a72fa8","name":"Zero Trust Exchange","category":"Converged SSE/SASE platform","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"product:1cb99a2537fbd91fbad9fb72","name":"Zscaler Client Connector","category":"Endpoint agent","delivery_relationship":"native","target_buyer":"Remote/mobile users","delivery_model":"Client-based","status":"current","evidence_source_ids":[]},{"id":"product:1ad19faebc8600e9504db93b","name":"Zscaler Deception","category":"Deception technology","delivery_relationship":"native","target_buyer":"Security teams","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":["evidence:zscaler:53"]},{"id":"product:d4833ba4be7b9469d8889c1f","name":"Zscaler Digital Experience","category":"Digital experience monitoring (DEM)","delivery_relationship":"native","target_buyer":"IT operations/helpdesk","delivery_model":"Cloud-delivered, add-on","status":"current","evidence_source_ids":[]},{"id":"product:d85af107f2e7cef691f00f97","name":"Zscaler Internet Access","category":"Secure web gateway, inline CASB, DLP, cloud firewall","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":[]},{"id":"product:d6e6f1ae09b9ae1583f8a31a","name":"Zscaler Private Access","category":"Zero Trust Network Access (ZTNA)","delivery_relationship":"native","target_buyer":"All buyers","delivery_model":"Cloud-delivered","status":"current","evidence_source_ids":[]}],"capabilities":[{"id":"capability:54a99cd24f948cd54441e7ed","capability_code":"ai_assistant_copilot","label":"AI assistant/copilot","category":"ai_automation","support_state":"unknown","qualification":"Marketing language ('AI-driven', '5 trillion daily signals') is broad - Netify should ask Zscaler to name the specific assistant product rather than accept the general claim at face value, applying the same standard used for Cato.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:13"]},{"id":"capability:1e00288e514f542a4271ae80","capability_code":"ai_data_protection_controls","label":"AI data protection controls","category":"ai_automation","support_state":"requires_confirmation","qualification":"Same as above","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:15","evidence:zscaler:23"]},{"id":"capability:4d113f0070c6c89844dfdb24","capability_code":"anomaly_detection","label":"Anomaly detection","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth of the ML methodology not disclosed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3cb5e216486f4b70c463d65e","capability_code":"automated_policy_recommendation","label":"Automated policy recommendation","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:eb79ab6727be98d1333bf8b4","capability_code":"automated_remediation","label":"Automated remediation","category":"ai_automation","support_state":"requires_confirmation","qualification":"Full auto-remediation (without human action) not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:541075189d29c693b2ca8a38","capability_code":"capacity_path_optimisation","label":"Capacity/path optimisation","category":"ai_automation","support_state":"requires_confirmation","qualification":"Applies at the last-mile/ISP level, not a private middle-mile network","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:04301e73a96ba8cec37c7c81","capability_code":"configuration_generation","label":"Configuration generation","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:6b612a0ad918428dfc7b68ef","capability_code":"digital_experience_diagnostics","label":"Digital experience diagnostics","category":"ai_automation","support_state":"requires_confirmation","qualification":"Same third-party sourcing caveat as above","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:f53411e0560889a0c658647d","capability_code":"generative_ai_application_controls","label":"Generative AI application controls","category":"ai_automation","support_state":"requires_confirmation","qualification":"Depth/accuracy of AI-traffic classification not independently tested","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:11","evidence:zscaler:16"]},{"id":"capability:b56a2374730094d370a5d653","capability_code":"natural_language_querying","label":"Natural-language querying","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:d04e4163b1b723d7a10c493b","capability_code":"report_summarisation","label":"Report summarisation","category":"ai_automation","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3fb1ecc8cec56f9ec0339eb6","capability_code":"root_cause_analysis","label":"Root-cause analysis","category":"ai_automation","support_state":"requires_confirmation","qualification":"The '98% faster' and 'auto-reroute' claims are relayed via a third-party summary and not independently verified against a primary Zscaler source","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:6389dd0769e3454fceb37645","capability_code":"threat_detection_classification","label":"Threat detection/classification","category":"ai_automation","support_state":"requires_confirmation","qualification":"'5 trillion daily signals' is a vendor-originated scale claim relayed by a partner, not independently audited","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:13"]},{"id":"capability:0033ff436ecaf8334fbe445d","capability_code":"user_entity_behaviour_analytics","label":"User/entity behaviour analytics","category":"ai_automation","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:625c3c3eafd17365c7255258","capability_code":"cap_5g_lte_support","label":"5G/LTE support","category":"architecture","support_state":"requires_confirmation","qualification":"Zscaler Cellular is referenced as a named product area in secondary financial-data commentary, but not independently confirmed via a primary Zscaler product page in this pass","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:048c29de1c3c3032a88dfc95","capability_code":"application_identification","label":"Application identification","category":"architecture","support_state":"requires_confirmation","qualification":"Native - DNS requests for ZPA application segments are forwarded distinctly from other DNS resolution","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:5eb268d92c72b06280590eda","capability_code":"branch_lan_wlan_integration","label":"Branch LAN/WLAN integration","category":"architecture","support_state":"unknown","qualification":"Unknown","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:e1f0bb3f605ee8ada4bda96b","capability_code":"brownfield_migration_support","label":"Brownfield migration support","category":"architecture","support_state":"supported","qualification":"Evidenced via case study - Baker & Baker adopted SD-WAN alongside ZIA when its MPLS contract expired, implying a supported migration path from legacy WAN","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17"]},{"id":"capability:de96550bcfcccbf57c417ef5","capability_code":"dynamic_path_selection","label":"Dynamic path selection","category":"architecture","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct capability in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:0e0fba692b1c329471e379a3","capability_code":"edge_form_factors","label":"Edge form factors","category":"architecture","support_state":"unknown","qualification":"Physical hardware appliance (plug-and-play, standard gigabit Ethernet, AC power) or virtual machine","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:0d7317b1474fcc9dc0c1c4c5","capability_code":"forward_error_correction_packet_duplication","label":"Forward error correction / packet duplication","category":"architecture","support_state":"requires_confirmation","qualification":"Not confirmed in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:62ffd65923a3cac488b0d6c3","capability_code":"high_availability","label":"High availability","category":"architecture","support_state":"unknown","qualification":"Unknown at the branch-hardware level in sources reviewed; the cloud platform itself is inherently multi-data-centre redundant given 160+ data centres globally","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:f7d9ec3c4fa7d3cf53f573ad","capability_code":"leo_satellite_support","label":"LEO satellite support","category":"architecture","support_state":"unknown","qualification":"Unknown","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:be19b48bdf37ef053cdd8d6b","capability_code":"local_internet_breakout","label":"Local internet breakout","category":"architecture","support_state":"requires_confirmation","qualification":"Native, by design - traffic is tunnelled directly to the nearest Zscaler cloud data centre via DTLS (ZIA) or TLS (ZPA), which is itself a direct-to-cloud breakout model","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:50c4e880ac89f84114317b71","capability_code":"qos_and_traffic_engineering","label":"QoS and traffic engineering","category":"architecture","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct Zero Trust Branch capability in sources reviewed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:47c0eb12522d343223cf9bb6","capability_code":"segmentation_vrf_capability","label":"Segmentation / VRF capability","category":"architecture","support_state":"unknown","qualification":"Unknown","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:6542906a0068c73c05634a2f","capability_code":"supported_wan_underlays","label":"Supported WAN underlays","category":"architecture","support_state":"not_supported","qualification":"Broadband/internet implied as the primary underlay; no MPLS-coexistence capability found in sources reviewed","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:ec6cdc511f7c987fb79ba8fa","capability_code":"virtual_cloud_edge_support","label":"Virtual/cloud edge support","category":"architecture","support_state":"requires_confirmation","qualification":"Yes - deployable as a VM in customer data centres","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3a091742ca3bef3ea5f92d2d","capability_code":"zero_touch_provisioning","label":"Zero-touch provisioning","category":"architecture","support_state":"requires_confirmation","qualification":"Native - described as plug-and-play with a TPM 2.0 chip for secure device authentication on connect","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:0d11c38d325ebb6c80231ddc","capability_code":"application_aware_routing","label":"Application-aware routing","category":"core_capabilities","support_state":"requires_confirmation","qualification":"Depth of routing logic beyond DNS-based segment forwarding not fully detailed in sources reviewed","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3efbeaf14c722bdaf2db1adf","capability_code":"casb_api","label":"CASB - API","category":"core_capabilities","support_state":"requires_confirmation","qualification":"Not confirmed as distinct from inline CASB or from SaaS Security capability in Table 3's 'SaaS security posture' row","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:cf38bc05ddbca3f46f6f511b","capability_code":"casb_inline","label":"CASB - inline","category":"core_capabilities","support_state":"requires_confirmation","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:04c7db112455b456be8a6530","capability_code":"cloud_firewall_cloud_network_security","label":"Cloud firewall / cloud network security","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:18"]},{"id":"capability:6a9a5604389a3a1066547045","capability_code":"dns_security","label":"DNS security","category":"core_capabilities","support_state":"requires_confirmation","qualification":"General web/DNS filtering is plausible given ZIA's scope, but a distinct DNS security product/feature was not independently confirmed","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:dc99ae8c92661dcb696b299b","capability_code":"data_loss_prevention","label":"Data loss prevention","category":"core_capabilities","support_state":"supported","qualification":"Full DLP capability may require Transformation/Unlimited tier - verify at quoting stage","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:14","evidence:zscaler:53"]},{"id":"capability:bdac58e65f090a563382354d","capability_code":"digital_experience_monitoring","label":"Digital experience monitoring","category":"core_capabilities","support_state":"requires_confirmation","qualification":"Requires separate ZDX licence","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:8d7429d071726d1b8e8322ce","capability_code":"firewall_as_a_service","label":"Firewall as a Service","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:18"]},{"id":"capability:52feec34a7c7957cf52be7e6","capability_code":"multi_cloud_networking","label":"Multi-cloud networking","category":"core_capabilities","support_state":"supported","qualification":"Depth of multi-cloud on-ramp capability sourced only via a third-party blog in this pass","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:59"]},{"id":"capability:38b7cf148d97ac4da3ce7305","capability_code":"sd_wan","label":"SD-WAN","category":"core_capabilities","support_state":"supported","qualification":"Newer and less independently documented than the core SSE stack; Gartner positions Zscaler as a Visionary (not Leader) in the SASE MQ specifically because of this","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:8"]},{"id":"capability:86c6c079ed9307a3fdd3bef5","capability_code":"saas_security_posture","label":"SaaS security posture","category":"core_capabilities","support_state":"supported","qualification":"Depth beyond Microsoft 365/Copilot not independently confirmed","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:15"]},{"id":"capability:6179f5d77a29f7012f567774","capability_code":"secure_web_gateway","label":"Secure web gateway","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"capability:773a14773800412afafc05b9","capability_code":"threat_intelligence","label":"Threat intelligence","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:13"]},{"id":"capability:8ba6db780b6eee7fe9ecd259","capability_code":"wan_optimisation","label":"WAN optimisation","category":"core_capabilities","support_state":"requires_confirmation","qualification":"Zscaler's proxy-cloud architecture does not appear to include backbone-based WAN optimisation the way backbone-first vendors do - consistent with having no owned private backbone","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:802a3a738b3f636b7a52587b","capability_code":"ztna","label":"ZTNA","category":"core_capabilities","support_state":"supported","qualification":"None identified","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:60"]},{"id":"capability:a1d5ae2a253a761a334b9b1c","capability_code":"clientless_access","label":"Clientless access","category":"remote_access","support_state":"supported","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"capability:a753622df4406d8dda3b549d","capability_code":"contractors_third_parties","label":"Contractors/third parties","category":"remote_access","support_state":"supported","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19"]},{"id":"capability:5d46dc8c420349b39c520f12","capability_code":"managed_laptops","label":"Managed laptops","category":"remote_access","support_state":"supported","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"capability:fa1ef5b7385bb5b838f35449","capability_code":"mobile_devices","label":"Mobile devices","category":"remote_access","support_state":"supported","qualification":"None identified","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"capability:c46f38c44f66170533cf3674","capability_code":"privileged_access","label":"Privileged access","category":"remote_access","support_state":"supported","qualification":"Tier-gated (Transformation, not Business)","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:53"]},{"id":"capability:9bf193827832fc93f759aabc","capability_code":"remote_browser_isolation","label":"Remote browser isolation","category":"remote_access","support_state":"supported","qualification":"Tier-gated rather than universally included","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:53"]},{"id":"capability:beea61b25c12de13090b5c8e","capability_code":"remote_browser_isolation","label":"Remote browser isolation","category":"remote_access","support_state":"supported","qualification":"Tier-gated rather than universally included","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:53"]},{"id":"capability:156cca746032007e724ccb5f","capability_code":"unmanaged_byod_devices","label":"Unmanaged/BYOD devices","category":"remote_access","support_state":"supported","qualification":"Depth of BYOD-specific policy control not independently confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"capability:c030c02d2cf6e0ad04a72bb1","capability_code":"vdi_environments","label":"VDI environments","category":"remote_access","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3dbc6a18b89487b08219458b","capability_code":"application_performance","label":"Application performance","category":"reporting_analytics","support_state":"supported","qualification":"Requires ZDX licence","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:6"]},{"id":"capability:34a3fc3c7d54b828b08ec556","capability_code":"compliance_reporting","label":"Compliance reporting","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:c7e6da9ac90cd2b474a3c715","capability_code":"custom_reports","label":"Custom reports","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:3282e56783ef3daab0b2674d","capability_code":"dlp_events","label":"DLP events","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:c716d915ff462372b9c27791","capability_code":"executive_dashboard","label":"Executive dashboard","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:ddbff3e1560a4263a1eaf744","capability_code":"network_health","label":"Network health","category":"reporting_analytics","support_state":"supported","qualification":"Requires ZDX licence","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:335ce9cc1c081ab73cbfc38d","capability_code":"raw_log_access","label":"Raw log access","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:46"]},{"id":"capability:9c93dad89a8d641554e82c0f","capability_code":"remote_user_experience","label":"Remote-user experience","category":"reporting_analytics","support_state":"supported","qualification":"Requires ZDX licence","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:6"]},{"id":"capability:5d666f8b4fc5ea4a8750ecc2","capability_code":"sla_reporting","label":"SLA reporting","category":"reporting_analytics","support_state":"requires_confirmation","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:38"]},{"id":"capability:da6ab17085d6acc00fd2a67f","capability_code":"scheduled_reports","label":"Scheduled reports","category":"reporting_analytics","support_state":"unknown","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"capability:628528c56892ece59f1cc932","capability_code":"security_events","label":"Security events","category":"reporting_analytics","support_state":"supported","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:10"]},{"id":"capability:207fe941747f23dbf4bd89e1","capability_code":"site_and_circuit_performance","label":"Site and circuit performance","category":"reporting_analytics","support_state":"supported","qualification":"Requires ZDX licence","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"capability:0c07830984addef329820dbc","capability_code":"threat_reporting","label":"Threat reporting","category":"reporting_analytics","support_state":"supported","qualification":"Not confirmed","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:10"]},{"id":"capability:7c7d8f5ab06e734d19563d21","capability_code":"user_experience","label":"User experience","category":"reporting_analytics","support_state":"supported","qualification":"Requires ZDX licence","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]}],"geographies":[{"id":"geographies:89a8c4ffc6c2282318637fd1","geography":"Africa coverage","delivery_type":"Unknown - not itemised in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - not itemised in sources reviewed | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - same treatment as Cato's equivalent row.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:47aedc02d20f2e1a90003c8a","geography":"Asia-Pacific coverage","delivery_type":"Unknown in named-country detail - general 'six continents' and 'most countries' claims imply presence but no specific APAC country/city list was found in this pass","delivery_relationship":"unknown","qualification":"Unknown in named-country detail - general 'six continents' and 'most countries' claims imply presence but no specific APAC country/city list was found in this pass | Unknown | Not specified in detail | No named APAC data centres found | Not found in a Tier 1-2 source in this pass | Low | Evidence gap - worth checking Zscaler's own data-centre location page directly for a country-level breakdown before advising APAC-heavy buyers.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:93fb42189c0739e7cdf3c4b2","geography":"Carrier interconnects","delivery_type":"Zscaler 'peers with hundreds of ISPs and cloud service providers in major internet exchanges around the world'","delivery_relationship":"owned","qualification":"Zscaler 'peers with hundreds of ISPs and cloud service providers in major internet exchanges around the world' | Direct | Global | Specific carrier/exchange names not disclosed | Zscaler press material (2019, reaffirmed in later releases) | Medium | Standard practise for a cloud-native security vendor; nothing unusual to flag.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:9eaa2c0a95b6f916d265c35b","geography":"China coverage","delivery_type":"Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed","delivery_relationship":"unknown","qualification":"Unknown - no China-specific data-centre or licensed-PoP detail found in sources reviewed | Unknown | Not specified | No named China presence found, in contrast to Cato's explicit Beijing/Shanghai/Shenzhen PoPs | Not found in a Tier 1-2 source in this pass | Low | A genuine point of comparison for multinational buyers with China-inclusive estates - do not assume parity with Cato's specific China story.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:5410d98498ed393739e3163c","geography":"Data residency choices","delivery_type":"Confirmed - dedicated logging planes in six countries as of March 2026, expanding to Canada, with fully isolated control, data and logging planes by design","delivery_relationship":"owned","qualification":"Confirmed - dedicated logging planes in six countries as of March 2026, expanding to Canada, with fully isolated control, data and logging planes by design | Direct | Six named-count countries (specific names not given in the source), expanding to Canada | Exact list of the six countries not itemised in the source reviewed | 12 Mar 2026 | High | A well-evidenced, architecturally serious data-sovereignty story - genuinely stronger and more specific than what was found for Cato's equivalent Private PoP-based approach.","confidence":"high","verified_date":"2026-03-12T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:20d478958a6cfb85fe7618b3","geography":"Latin America coverage","delivery_type":"Unknown - not itemised in sources reviewed, though the 'present in most countries' claim implies some presence","delivery_relationship":"unknown","qualification":"Unknown - not itemised in sources reviewed, though the 'present in most countries' claim implies some presence | Unknown | Not specified | No named data centres found | Not found in a Tier 1-2 source in this pass | Low | Do not infer specific coverage from the general 'most countries' claim - ask directly.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:239efd3fbb41423aa2de297c","geography":"Middle East coverage","delivery_type":"Confirmed - active data-centre expansion in Saudi Arabia announced July 2025, described as part of a broader Middle East growth strategy","delivery_relationship":"owned","qualification":"Confirmed - active data-centre expansion in Saudi Arabia announced July 2025, described as part of a broader Middle East growth strategy | Direct | Saudi Arabia (named); wider Middle East implied | Other specific Middle East countries not itemised | 1 Jul 2025 | High | Better-evidenced than Cato's Middle East coverage (which was a total gap in that profile) - a fair point of comparison to make to buyers with Middle East estates.","confidence":"high","verified_date":"2025-07-01T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:7ba2c25f8b31086f211c542e","geography":"Private backbone","delivery_type":"Not present - Zscaler's architecture relies on internet peering and cloud-provider interconnects rather than an owned, SLA-backed private backbone","delivery_relationship":"unknown","qualification":"Not present - Zscaler's architecture relies on internet peering and cloud-provider interconnects rather than an owned, SLA-backed private backbone | N/A | N/A | This is a genuine architectural characteristic, not an evidence gap | Ongoing (platform architecture) | High | The single clearest, most consequential architectural difference from Cato in this entire comparison - Netify should present this plainly rather than softening it.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:5fd01e4cf0397dba069ed77f","geography":"Public cloud on-ramps","delivery_type":"AWS, Azure, GCP peering/integration referenced across multiple sources (Baker & Baker on Azure; Zscaler Workload Segmentation for multi-cloud)","delivery_relationship":"owned","qualification":"AWS, Azure, GCP peering/integration referenced across multiple sources (Baker & Baker on Azure; Zscaler Workload Segmentation for multi-cloud) | Direct | Wherever those hyperscalers have regions | Depth of on-ramp architecture (dedicated interconnects vs standard peering) not fully detailed | 22 Jul 2026 | Medium-High | Strong multi-hyperscaler story, evidenced by named customer deployments rather than marketing claims alone.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:131dff3ecaa9c4b7e6f4be79","geography":"SD-WAN gateways / cloud gateways","delivery_type":"Delivered from the same global data-centre infrastructure as the security edges - no separate SD-WAN-only gateway network identified","delivery_relationship":"owned","qualification":"Delivered from the same global data-centre infrastructure as the security edges - no separate SD-WAN-only gateway network identified | Direct | Same as above | None identified | Ongoing (platform architecture) | Medium | Consistent with a converged-platform design, though Zscaler's SD-WAN maturity is genuinely newer (see Table 4).","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"geographies:c310ac33437703a061e4007e","geography":"Security PoPs / service edges","delivery_type":"160+ data centres globally as of March 2026 (earlier press material from 2019-2021 cited 150+, showing steady growth over time)","delivery_relationship":"owned","qualification":"160+ data centres globally as of March 2026 (earlier press material from 2019-2021 cited 150+, showing steady growth over time) | Direct (Zscaler-owned/operated cloud) | Six continents, present in most countries | Full country-by-country list not found in sources reviewed | High | Zscaler's data-centre count is, like Cato's PoP count, an actively growing figure - cite with the publication date rather than as a fixed spec.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:34","evidence:zscaler:35","evidence:zscaler:36"]},{"id":"geographies:d02d5b551ed0c653d261616f","geography":"Sovereign/regional service options","delivery_type":"Government Cloud (ZGC) confirmed as a distinct FedRAMP High authorised offering, separate from the commercial cloud","delivery_relationship":"owned","qualification":"Government Cloud (ZGC) confirmed as a distinct FedRAMP High authorised offering, separate from the commercial cloud | Direct | United States (federal/government cloud) | Sovereign offerings for non-US regions (e.g. EU sovereign cloud) not found in sources reviewed | 22 Jul 2026 | Medium-High | Strong for US federal buyers specifically; UK/EU-equivalent sovereign offerings should be asked about directly rather than assumed to exist on the same basis.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"service_models":[{"id":"service_models:00f30496d201960f526f76e5","model":"other","support_state":"supported","qualification":"Yes | Zero Trust Branch hardware | Appliance → Zscaler cloud | Cloud console | Distributed branch estates | Low (per Zscaler's own claims) | See Table 4 - newer capability than the core security stack | Real, but with thinner independent evidence than Cato's equivalent, retail-proven branch rollout story.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:03a0e7ccfa4fcc17a8a083f0","model":"other","support_state":"requires_confirmation","qualification":"Confirmed at Premium Support Advanced/Advanced Plus tiers - 'a designated resource to help you execute your digital transformation' | Per tier | Not specified | Premium tier | N/A | Not separately quantified | Concrete, named ('Focal Support', dedicated resource) - good evidence quality.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:41","evidence:zscaler:42"]},{"id":"service_models:05ca29794b6f625f747734f0","model":"other","support_state":"unknown","qualification":"Same tiered structure as configuration management | Per tier | N/A | Premium tier | Shared | Not separately quantified | Same as above | Same as above.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:0894ea6e22c0ff4a5d2417e1","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed | Presumably Admin Portal/API | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap - flag for direct vendor follow-up.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:12348f44e4bf668ddb6d6063","model":"other","support_state":"supported","qualification":"Native - Zscaler Technical Assistance Centre (ZTAC) operates the cloud platform | 24x7x365 | Not itemised by location | Included as part of the platform service | Customer configures policy; Zscaler operates the underlying cloud | P1 (Urgent) initial response as fast as 15 minutes on premium tiers, 30 minutes on Standard | Well-documented, specific SLA figures rather than a vague 'we have a NOC' claim - a genuine strength of the primary-source evidence available for Zscaler.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:39","evidence:zscaler:40"]},{"id":"service_models:12c3551aac0cce4472cf0a83","model":"other","support_state":"supported","qualification":"Native - MDR is a named, SLA-backed service | 24x7 (implied) | Not itemised by location | Premium/add-on | N/A | 10-minute notification SLA | zscaler.com SLA & Support legal page | One of the best-evidenced managed-service claims in this profile, with a specific contractual SLA rather than a vague marketing figure.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:1f3ec589a039881a6aad972f","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct customer-facing SOC service in sources reviewed, though Managed Detection and Response (MDR) exists as a named service with its own SLA | 24x7 for MDR (implied by a 10-minute notification SLA) | Not itemised by location | MDR appears to be a premium/add-on service | Not fully detailed | MDR Response Time Agreement: customer notified within 10 minutes of a Zscaler analyst confirming a threat | zscaler.com SLA & Support legal page | The 10-minute MDR notification SLA is a specific, credible, contractually-stated commitment - stronger evidence than a marketing claim of '24x7 SOC'.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:1f75b0218a179c0232290fe8","model":"other","support_state":"supported","qualification":"Yes | Zero Trust Branch VM | VM → nearest Zscaler data centre | Cloud console | Data centres wanting to avoid physical hardware | Low | Deploy as VM image | Reasonable option for virtualised data-centre estates.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:27bd7ba5038025ea42ab979f","model":"other","support_state":"supported","qualification":"Yes | Zscaler Client Connector | Client → Zscaler cloud | Cloud console | Managed-device remote/hybrid workforce | Low | N/A | Zscaler's most mature, longest-standing deployment pattern.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:306cd1df909cb174aa30c356","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct capability in sources reviewed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | See Table 6 - no equivalent to Cato's MSASE partner platform was found for Zscaler in this pass.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:3370e1af07670e4f4a0338b1","model":"other","support_state":"supported","qualification":"Yes, as branch CPE only, not a self-contained on-prem product | Zero Trust Branch hardware appliance | Appliance → nearest Zscaler data centre via DTLS/TLS | Cloud console | Branch offices | Low (zero-touch provisioning) | Plug-and-play install per Zscaler's own reference architecture | Same 'thin edge into the cloud' pattern seen across SASE vendors - the appliance is an on-ramp, not an independent security boundary.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:364ae7ae71c6fff297e2ccda","model":"other","support_state":"supported","qualification":"Yes | Browser-based ZPA access | Browser → Zscaler cloud | Cloud console | BYOD, contractors | Low | N/A | See Table 5.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:3a33e2360971f7bc17c1b9d2","model":"other","support_state":"supported","qualification":"Available at higher support tiers (Premium Support Advanced/Advanced Plus include 'Focal Support' and a designated resource) | Per tier | N/A | Premium tier | Shared, depending on tier purchased | Not separately quantified beyond the tiered SLA table | A genuinely tiered, well-documented support structure rather than a single flat offering.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:42"]},{"id":"service_models:3a7913dfb8b21dc23fff0f0e","model":"other","support_state":"supported","qualification":"Native via MDR | 24x7 (per MDR SLA) | N/A | Premium/add-on | Depends on MDR being purchased | 10-minute notification SLA (see above) | zscaler.com SLA & Support legal page | Concrete, contractual SLA - one of the better-evidenced specific commitments in this entire profile.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:4c1eb6005c89031f26ab88a6","model":"other","support_state":"unknown","qualification":"Not applicable in the same sense as an SD-WAN/backbone vendor, given Zscaler does not manage a private middle mile (see Table 7) | N/A | N/A | N/A | N/A | N/A | N/A | This row is structurally different for Zscaler than for a backbone-based vendor - not a gap, but an architectural non-applicability worth stating plainly.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:52ae11fb19e243724bdb06c4","model":"other","support_state":"requires_confirmation","qualification":"Unknown in detail; role-based access is documented for end-user application access (Mindbody case study) but administrator-level RBAC was not separately confirmed | Presumably Admin Portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Do not conflate the well-evidenced end-user role-based access with administrator-level RBAC, which wasn't separately confirmed.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19"]},{"id":"service_models:5dfe820271181a78d9d7b4e7","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed | Presumably Admin Portal | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in public sources reviewed | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:6367e652fe30261aa7ac36d8","model":"other","support_state":"supported","qualification":"Native | 24x7 | N/A (cloud service) | Included for platform; MDR is the premium security-monitoring tier | N/A | See above | Same as above | N/A","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:6acb4a66bd4dcb3f8f2ddef4","model":"other","support_state":"unknown","qualification":"Implied via Customer Success team engagement at Premium Support tiers, though not itemised as a distinct professional-services SKU in sources reviewed | N/A | N/A | Premium tier engagement | N/A | N/A | zscaler.com Premium Support data sheets | Less concretely evidenced as a standalone PS product than Cato's AWS Marketplace-listed Managed Deployment package - worth asking Zscaler directly for a PS-specific data sheet.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:73356d7ad19916e982f5c984","model":"other","support_state":"unknown","qualification":"Cloud-based admin console setup; branch hardware is plug-and-play per Zscaler's own reference architecture | Zscaler Admin Portal | General IT/network admin per case study evidence | Zero-touch provisioning for Zero Trust Branch hardware | Low, per multiple customer case studies describing fast, straightforward rollouts | None significant identified in sources reviewed | Consistently described as low-effort across independent case studies, similar in tone to Cato's equivalent evidence.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19"]},{"id":"service_models:770ee67a0e02d1591a5a656b","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed for Zero Trust Branch appliance RMA/replacement terms | Not found | Not found | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - matters for branch-heavy buyers doing hardware rollouts, same caveat as flagged for Cato.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:78c49e9ff4fa689588a06f67","model":"other","support_state":"unknown","qualification":"Zscaler Client Connector install or browser-based clientless route | Admin Portal + Client Connector | End-user self-install typical of this category | Not itemised | Not itemised | Not itemised | General platform pages | Standard for the category; no distinctive evidence found either way.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:7eb7f4377d823f03fb4a1a53","model":"other","support_state":"requires_confirmation","qualification":"Confirmed - 'Support Case Reviews, Operational Reviews' listed as part of the base support offering, expanding at higher tiers to include 'Business Continuity Plan', 'Configuration Audit' and 'Service Resiliency Audit' | Per tier | Not specified | Included at base, expands with tier | N/A | Not separately quantified | Specific, itemised list of review types - stronger evidence than a generic 'we do reviews' claim.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:44"]},{"id":"service_models:80cd3ec34cfab77180495d2b","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct named service in sources reviewed | Not confirmed | N/A | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | Evidence gap - flag for direct vendor follow-up.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:8bc13fc299c6d97bf46750b9","model":"other","support_state":"supported","qualification":"Yes | Mix of Client Connector, clientless, Zero Trust Branch | Mixed | Cloud console, unified | Most real-world enterprise estates | Moderate | Case studies (Baker & Baker, AutoNation) show phased adoption starting with ZIA/ZPA and adding further modules over time | A realistic, evidenced pattern - customers typically start with the security core and expand rather than deploying the whole platform at once.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:a76bb2be2105d57b40ce0558","model":"other","support_state":"unknown","qualification":"Cloud-delivered updates for the platform are automatic by design (SaaS model); Zero Trust Branch appliance firmware lifecycle not detailed in sources reviewed | N/A for cloud platform | Not confirmed for appliance firmware specifically | Automatic for cloud platform | Low for cloud platform; appliance firmware cadence not confirmed | Not confirmed for appliances | General SaaS/platform architecture pages | Reasonable to assume low burden for the cloud platform given the SaaS model; appliance-specific patch cadence should be verified directly for hardware-heavy branch buyers.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:acc20472d1fd029ab479c797","model":"other","support_state":"supported","qualification":"Native via Zscaler Workload Segmentation / Cloud Connector | Cloud Connector for AWS/Azure/GCP | Cloud workload → Zscaler cloud | Cloud console | Multi-cloud/hybrid enterprises | Not fully detailed | Evidence for this row sourced mainly via a third-party blog (see Table 3) | Directionally credible but less independently evidenced than the branch/client deployment models.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:b54279a0c01c887b81b5781c","model":"other","support_state":"unknown","qualification":"Not clearly documented as a distinct model in sources reviewed | Not confirmed | - | - | Not confirmed | Not confirmed | Not confirmed | Zscaler's support-tier structure (Table 8) implies varying degrees of Zscaler involvement, but a formal 'co-managed' service model distinct from support tiers was not found - flag as a gap rather than assume it doesn't exist.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:b6c438d9f8858b0f28b21b37","model":"other","support_state":"unknown","qualification":"ZDX Network Intelligence (added October 2025) has Client Connector probe every 5 minutes for latency/jitter/packet loss and uses AI to pinpoint ISP bottlenecks and auto-reroute | ZDX dashboards within Admin Portal | Reduced specialist requirement implied by AI-assisted diagnostics | AI-assisted correlation and auto-rerouting | Positioned as low-effort | Depends on ZDX licence being active | A genuinely specific, dated product update (not generic 'AI-powered' language) - though sourced via a third-party report rather than a primary Zscaler product page in this pass, worth a follow-up citation to Zscaler's own ZDX release notes.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:9"]},{"id":"service_models:c15e47f5cfe9240de0be0e29","model":"other","support_state":"requires_confirmation","qualification":"Not confirmed as a distinct Zscaler-delivered managed-service offering in sources reviewed; delivered primarily through partners/MSSPs in the broader market rather than as a named Zscaler product | Not confirmed | - | - | Buyers wanting full outsourcing | Not confirmed | Not confirmed | Unlike Cato's explicit Managed SASE / MSASE partner programme, no equivalent named Zscaler-delivered managed-service product was found in this pass - worth asking directly if a buyer needs this.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:c54dc22546a4d98a8ce89ce5","model":"other","support_state":"unknown","qualification":"Unknown - not found in sources reviewed as a distinct MSP/multi-tenant capability | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not confirmed | Not found in a Tier 1-2 source in this pass | In contrast to Cato's explicit MSASE multi-tenant partner platform, no equivalent named Zscaler capability was found - flag as a genuine evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:ec2c2a446356d7673ee65b7d","model":"other","support_state":"unknown","qualification":"Ship Zero Trust Branch hardware, plug-and-play connect via TPM 2.0-authenticated tunnel | Admin Portal (remote) | No on-site specialist required per the reference architecture description | Zero-touch | Low, per Zscaler's own documentation, though not independently proven at the operational scale Cato's Ulta Beauty case study demonstrates | No large-scale, metric-rich branch-rollout case study was found in this pass (in contrast to Cato's Ulta Beauty story) | help.zscaler.com Zero Trust Branch reference architecture | The mechanism is well documented, but Zscaler lacks an equivalent to Cato's Ulta Beauty proof point - a fair, specific gap to flag rather than assume away.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:f1dc6245f84dd0e0039bd0e1","model":"other","support_state":"supported","qualification":"Yes | Zscaler cloud (Zero Trust Exchange) | Via nearest Zscaler data centre | Centralised, cloud console | All customers - core delivery model | Low | N/A - default | The default and only real operating model for the security stack, consistent with Zscaler's proxy-cloud architecture.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"service_models:fd3926ad32cf736ed6669f72","model":"other","support_state":"unknown","qualification":"Centralised policy engine covering ZIA/ZPA/ZDX from one console | Zscaler Admin Portal | Not itemised in detail | Not itemised | Not itemised | Not itemised | General platform pages | Insufficient specific evidence to grade granularly - flagged as a gap rather than assumed easy based on general marketing.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"compliance":[{"id":"compliance:03eb72e1c82bbd2fae8a0ac9","framework":"DORA relevance","scope":"N/A","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed | N/A | Not confirmed | EU financial services | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - relevant to Netify's financial-services sector suitability assessment (Table 14).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:1224065172e261fcaa0d630a","framework":"Data residency","scope":"Wherever the sovereignty architecture is deployed","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Confirmed - isolated control/data/logging planes by design, with dedicated logging planes in six countries and expansion to Canada announced | Wherever the sovereignty architecture is deployed | Zscaler's data-sovereignty architecture (unnamed as a discrete product, described as a platform-wide capability) | Six named-count countries (not itemised by name in the source), expanding to Canada | 22 Jul 2026 | One of the stronger, more technically specific data-residency stories in this profile - genuinely differentiated evidence, not just marketing language.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:34"]},{"id":"compliance:51fe0537cd836cb9b78a4f6b","framework":"Encryption/key management","scope":"Government Cloud confirmed; commercial cloud not separately detailed","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Partial - FIPS 140-2 validated cryptographic modules confirmed for the Government Cloud specifically; general commercial-cloud encryption/key-management detail not itemised in sources reviewed | Government Cloud confirmed; commercial cloud not separately detailed | FIPS 140-2 Level 1 validated cryptographic modules (Government Cloud) | None identified | 22 Jul 2026 | FIPS validation for the Government Cloud is credible and specific; Netify should ask directly whether the same validation extends to the commercial cloud before assuming parity.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:33"]},{"id":"compliance:2817bc7349eaaa1a85667487","framework":"FedRAMP","scope":"US federal government","support_state":"unknown","expiry_or_review_date":null,"qualification":"Authorized - High and Moderate baselines, both JAB and Agency authorizations referenced across ZIA, ZPA and ZDX; also GovRAMP Authorized | US federal government | FedRAMP High ATO (JAB), FedRAMP Moderate; DoD IL5 (ZPA) and IL4 Provisional Authorization referenced for Zscaler Government Cloud; DoD Approved Products List | US federal/government | 22 Jul 2026 | A major, extensively documented differentiator - very few SASE/SSE-class vendors clear FedRAMP High, and Zscaler's evidence here is unusually deep (multiple primary press releases and dedicated public-sector pages).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:25","evidence:zscaler:28","evidence:zscaler:32"]},{"id":"compliance:92dff0b5972512080333e2f7","framework":"GDPR","scope":"Platform/company","support_state":"supported","expiry_or_review_date":null,"qualification":"Compliant (self-attested), supported by a documented data-sovereignty architecture | Platform/company | Isolated control/data/logging planes; dedicated logging planes in six countries as of March 2026 | EU/UK relevant | 22 Jul 2026 | Better-evidenced than a bare self-attestation - the isolated-plane architecture is a specific, technical data-sovereignty mechanism, not just a policy statement.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:34"]},{"id":"compliance:cd43a36da78aa246517e76ff","framework":"HIPAA","scope":"N/A","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Not separately confirmed via a dedicated attestation in sources reviewed, though healthcare is listed among served industries | N/A | Not confirmed as a formal attestation | US healthcare-relevant | Not found in a Tier 1-2 source in this pass | Do not assume a formal HIPAA attestation exists just because healthcare is listed as a served industry - a genuine distinction Netify should hold Zscaler to the same standard on as any other vendor.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"compliance:d18aa6a2dad37c455189b369","framework":"ISO 27001","scope":"Platform/company ISMS, following ISO/IEC 27002:2013 best practise","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified | Platform/company ISMS, following ISO/IEC 27002:2013 best practise | ISO 27001 certificate; ISO 27017 (cloud security) and ISO 27018 (cloud privacy) also referenced | None identified | 22 Jul 2026 | Consistently repeated across multiple primary Zscaler pages - high confidence.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:24","evidence:zscaler:27","evidence:zscaler:30","evidence:zscaler:31"]},{"id":"compliance:8596c4a5b21bfc33b5a56677","framework":"Logging/auditability","scope":"Platform, especially sovereignty-relevant deployments","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Confirmed at an architectural level - dedicated, isolated logging planes distinct from control and data planes, described as ensuring 'sensitive data never leaves its required jurisdiction' | Platform, especially sovereignty-relevant deployments | Isolated logging plane architecture | Six named-count countries, expanding to Canada | 22 Jul 2026 | A genuinely distinctive architectural claim (separate logging plane as a first-class architectural layer) rather than a generic 'we keep logs' statement.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:34"]},{"id":"compliance:fda9113bca37060dc51b7508","framework":"NHS DSPT relevance","scope":"N/A","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed | N/A | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap - directly relevant to Netify's UK healthcare-sector buyers; ask directly rather than infer from US healthcare positioning.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:987fddf915823b69b93eafb7","framework":"NIS2 relevance","scope":"N/A","support_state":"unknown","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed | N/A | Not confirmed | EU | Not found in a Tier 1-2 source in this pass | Not found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:babf2cab9f273df6bc8e0768","framework":"PCI DSS","scope":"N/A","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Not confirmed in sources reviewed | N/A | Not confirmed | N/A | Not found in a Tier 1-2 source in this pass | Not found | In contrast to Cato's explicit PCI-DSS Level 1 claim, no equivalent Zscaler PCI-DSS statement was found - flag as a genuine evidence gap for payment-handling buyers rather than assume parity.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"compliance:b8cf11895d62998df30f341d","framework":"SOC 2","scope":"Platform","support_state":"unknown","expiry_or_review_date":null,"qualification":"Certified (Type II) | Platform | SOC 2 Type II report, audited annually by a third party | None identified | 22 Jul 2026 | Confirmed across multiple primary Zscaler pages, including a specific note that it's audited annually.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:26"]},{"id":"compliance:1130bc69da2ebfc1466fce08","framework":"UK public sector frameworks","scope":"UK","support_state":"requires_confirmation","expiry_or_review_date":null,"qualification":"Unknown - not found in sources reviewed; a third-party review (not independently corroborated) separately claims Cyber Essentials Plus, but this was not confirmed on Zscaler's own compliance pages in this pass | UK | Not confirmed | UK | Not found in a Tier 1-2 source in this pass | This is a direct, important follow-up question for Netify's UK-focused work - do not repeat the Cyber Essentials Plus claim as fact until it's confirmed on a primary Zscaler source.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:7"]}],"integrations":[{"id":"integrations:2b625b1bb9a8d3f92ee34bd0","integration_name":"AWS","integration_type":"Cloud","delivery_relationship":"native","qualification":"Cloud | Native (Cloud Connector; also marketplace-listed pricing editions) | Bidirectional (connectivity + optional Marketplace billing) | Not specified | AWS Marketplace listings referenced by third-party pricing analysis | Medium | Directionally confirmed but sourced mainly via third-party summaries in this pass rather than a direct AWS Marketplace visit - worth a primary-source follow-up.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:51","evidence:zscaler:59"]},{"id":"integrations:9a0b3b6b27ad2a02568a71ea","integration_name":"Active Directory","integration_type":"Identity","delivery_relationship":"unknown","qualification":"Identity | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:4cb35cba697d50d54ced37d7","integration_name":"CrowdStrike","integration_type":"EDR","delivery_relationship":"partner","qualification":"EDR | Native, deeply documented - three-way Okta/CrowdStrike/Zscaler alliance, plus a dedicated Zscaler Operations Technology Partners entry ('CrowdStrike integrates with Zscaler to provide threat intelligence and automation') | Bidirectional (Zscaler reads CrowdStrike Falcon Zero Trust Assessment device-posture scores; threat intel shared both ways) | Not specified | Formal joint deployment guide, hands-on integration lab (WWT ATC), and a dedicated Okta/CrowdStrike/Zscaler business-development guide (Feb 2024) all found | High | Unusually well-documented - four independent pieces of evidence (alliance blog, partner page, formal guide, hands-on lab) for a single integration.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:13","evidence:zscaler:48","evidence:zscaler:49","evidence:zscaler:50"]},{"id":"integrations:ce46e4135e861b20f91e68c3","integration_name":"Google Cloud","integration_type":"Cloud","delivery_relationship":"unknown","qualification":"Cloud | Referenced generically alongside Google Workspace integration | Not detailed | Not specified | Not detailed | zscaler.com Operations Technology Partners page | Medium | Present but not independently detailed to the same depth as the Azure evidence.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:685dc403f2c0bed309211512","integration_name":"Google Workspace","integration_type":"Identity/productivity","delivery_relationship":"unknown","qualification":"Identity/productivity | Referenced generically ('Google and Zscaler provide secure, fast access to... Google Drive and Gmail') | Not detailed | Not specified | Not detailed | zscaler.com Operations Technology Partners page | Medium | Confirmed present but with less depth than the Okta alliance.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:841a09c9def3b067dc2ba053","integration_name":"Intune","integration_type":"MDM/UEM","delivery_relationship":"unknown","qualification":"MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:cca23f5b7cf3f24f919aa786","integration_name":"Jamf","integration_type":"MDM/UEM","delivery_relationship":"unknown","qualification":"MDM/UEM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - relevant to verify given Apple-heavy enterprise estates.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:22ce4951a0331d679bdb74c0","integration_name":"Microsoft 365","integration_type":"Productivity/SaaS","delivery_relationship":"native","qualification":"Productivity/SaaS | Native - specifically documented for Microsoft Copilot misconfiguration scanning and CASB-based permission management | Zscaler monitors/secures M365 and Copilot traffic and configuration | Not specified | Detailed in a dedicated blog post on securing Copilot specifically | High | Genuinely detailed, current integration (Copilot-specific), not just a generic 'works with Office 365' claim.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:15"]},{"id":"integrations:95d165aaa3ae9611dd1ce6f1","integration_name":"Microsoft Azure","integration_type":"Cloud","delivery_relationship":"native","qualification":"Cloud | Native - confirmed in production via the Baker & Baker case study (ZPA securing private apps running on Azure) | Bidirectional | Not specified | Not detailed further | High | Confirmed via a named customer's real production use, stronger evidence than a generic capability claim.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17"]},{"id":"integrations:a93cdc6df3cd84bdadfba7e9","integration_name":"Microsoft Defender","integration_type":"EDR","delivery_relationship":"unknown","qualification":"EDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - CrowdStrike is clearly the best-documented EDR partner; Defender-specific integration wasn't found in this pass.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:10048a22fd63275bb0366c64","integration_name":"Microsoft Entra ID","integration_type":"Identity","delivery_relationship":"unknown","qualification":"Identity | Not separately itemised from general IdP integration claims in sources reviewed (Okta is the specifically documented IdP) | Unknown | Not specified | Not detailed | Not found as a distinct integration in this pass | Low | Do not assume Entra ID parity with the well-documented Okta integration without direct confirmation.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:15b721e8d97965565119705a","integration_name":"Microsoft Sentinel","integration_type":"SIEM","delivery_relationship":"unknown","qualification":"SIEM | Not separately itemised as a distinct Sentinel integration in sources reviewed, though general SIEM/TIP integration claims exist | Unknown | Not specified | Not detailed | zscaler.com Operations Technology Partners page (general SIEM/TIP language, not Sentinel-specific) | Low-Medium | Do not assume a Sentinel-specific integration is documented to the same depth as CrowdStrike/Okta without direct confirmation.","confidence":"low_medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:4a6f68b33711e3a587271e24","integration_name":"Okta","integration_type":"Identity","delivery_relationship":"native","qualification":"Identity | Native, deeply documented - a three-way Okta/CrowdStrike/Zscaler alliance with a joint deployment guide | Bidirectional (Zscaler reads Okta identity/device-trust context; policies act on it) | Not specified | Formal joint Business Development Guide and deployment guide published | High | One of the best-evidenced integrations in this entire profile - a formal three-way alliance with named joint collateral, not just a listed logo.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:47","evidence:zscaler:48","evidence:zscaler:50"]},{"id":"integrations:b6a7cbd19109a88bf6b440a7","integration_name":"Palo Alto Cortex","integration_type":"SIEM/XDR","delivery_relationship":"unknown","qualification":"SIEM/XDR | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:053530cdb444f9cdbddc6096","integration_name":"REST API","integration_type":"Platform API","delivery_relationship":"partner","qualification":"Platform API | Implied by the existence of formal partner integrations (Okta, CrowdStrike) and third-party threat-intel feeds (Anomali, Recorded Future, Cyware, EclecticIQ via TIP integration) | Bidirectional | Not specified | Not detailed as a standalone developer product in sources reviewed | zscaler.com Operations Technology Partners page (TIP integrations) | Medium | API existence is a reasonable inference from the documented integrations, but a standalone API/developer portal page wasn't independently confirmed in this pass.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:2b2f4bfad89ff2bfb235a1a8","integration_name":"SCIM/SAML/OIDC","integration_type":"Identity federation","delivery_relationship":"unknown","qualification":"Identity federation | SAML confirmed via the Okta/CrowdStrike joint guide ('Online help for configuring SAML 2.0 for Zscaler') | Bidirectional (auth) | Not specified | Documented in the joint deployment guide | Medium-High | SAML is explicitly confirmed; SCIM/OIDC support is a reasonable inference from standard IdP integration practise but wasn't separately itemised by name.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:50"]},{"id":"integrations:a1c6a4805861f34de3d830e4","integration_name":"ServiceNow","integration_type":"ITSM","delivery_relationship":"unknown","qualification":"ITSM | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - do not assume ITSM integration exists without confirmation.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:6cf64d1a364f08694edf4fec","integration_name":"Splunk","integration_type":"SIEM","delivery_relationship":"unknown","qualification":"SIEM | Confirmed via a named public-sector deployment architecture (Red River Zero Trust Accelerator combines AWS, CrowdStrike, Okta, Splunk and Zscaler) | Zscaler → Splunk (implied) | Not specified | Part of a validated, field-tested reference architecture for public sector/regulated industries | AWS Marketplace listing - Red River Zero Trust Accelerator | Medium-High | Evidenced via a named, validated reference architecture rather than a generic 'integrates with Splunk' claim.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:470051f7d99a5c80abd719aa","integration_name":"Syslog","integration_type":"Log export","delivery_relationship":"unknown","qualification":"Log export | Not separately itemised in sources reviewed | Unknown | Not specified | Not detailed | Not found | Low | Evidence gap - reasonable to assume given SIEM integrations exist, but not independently confirmed.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"integrations:9adcddce0c0b785b4943c27e","integration_name":"Terraform","integration_type":"Infrastructure-as-code","delivery_relationship":"unknown","qualification":"Infrastructure-as-code | Unknown - not found in sources reviewed | - | - | - | Not found | Low | Evidence gap - worth checking Zscaler's developer/API documentation directly.","confidence":"low","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"sector_evidence":[{"id":"sector_evidence:abfb11deb0f444ac8b0d39db","sector":"Education","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:e210778f541f45ef424b07a1","sector":"Energy/utilities","suitability_state":"unknown","named_evidence":"NOV (oilfield services/energy, 27,500 users, global remote-access rollout during COVID-19)","case_study_strength":"strong","qualification":"Conditional fit | Global remote-access capability plausibly relevant | Not assessed | NOV (oilfield services/energy, 27,500 users, global remote-access rollout during COVID-19) | Global distributed workforce use case well evidenced | Single case study, but a genuinely substantial, named, metric-rich one | NOV is a strong, credible case study for this sector specifically - a real enterprise-scale (27,500-user) deployment with a clear before/after narrative.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:21"]},{"id":"sector_evidence:74d85f1beff1c4a2ad558228","sector":"Financial services","suitability_state":"not_supported","named_evidence":"None found in this research pass","case_study_strength":"none","qualification":"Conditional - no PCI-DSS or DORA evidence found in this pass, in contrast to Cato's explicit PCI-DSS Level 1 | DLP, CASB plausibly relevant | Not confirmed | None found in this research pass | N/A | No named financial-services case study or PCI-DSS attestation found | A genuine, specific gap relative to Cato's profile on this exact point - flag it plainly rather than assume parity.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:50c6472b30f92374ae3a117a","sector":"Government/public sector","suitability_state":"unknown","named_evidence":"CSC (public-sector case study, VPN-to-Zero-Trust productivity gains)","case_study_strength":"strong","qualification":"Strong fit, extensively evidenced | FedRAMP High/Moderate, DoD IL5, GovRAMP, CJIS, CMMC Level 2 | FedRAMP High/Moderate, GovRAMP Authorized, CJIS, CMMC Level 2, DoD IL4/IL5 | CSC (public-sector case study, VPN-to-Zero-Trust productivity gains) | Zscaler Government Cloud is a distinct FedRAMP High authorised offering | US-federal-specific; UK/EU public-sector framework listings not found in this pass | By far the best-evidenced sector in this entire profile - genuinely strong, multi-source, dated evidence. The clear standout differentiator versus Cato, which had no equivalent public-sector compliance depth.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:20"]},{"id":"sector_evidence:5f4b87fc27ce81adbf8bef48","sector":"Healthcare/NHS","suitability_state":"not_supported","named_evidence":"None found in this research pass","case_study_strength":"none","qualification":"Conditional - US healthcare listed as a served industry, but no formal HIPAA attestation or NHS DSPT evidence found | DLP, ZTNA, CASB plausibly relevant | Healthcare listed as served industry (company FAQ); no HIPAA/NHS DSPT confirmation found | None found in this research pass | N/A | No named healthcare case study or formal healthcare-specific compliance attestation found | Do not claim healthcare/NHS suitability beyond 'lists healthcare as a served industry' without a supporting case study or direct compliance confirmation.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:1"]},{"id":"sector_evidence:719cca8370c71a556a203ffa","sector":"Hospitality","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"sector_evidence:d8826292592031c9bb116f42","sector":"Manufacturing","suitability_state":"unknown","named_evidence":"Baker & Baker (food manufacturing)","case_study_strength":"strong","qualification":"Conditional fit | SD-WAN/branch capability plausibly relevant | Not assessed | Baker & Baker (food manufacturing) | N/A | Single case study, not deeply metric-rich beyond the ransomware-reduction claim | Some evidence exists but is thinner than the retail/public-sector case studies.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17"]},{"id":"sector_evidence:3c3eb5011725769d066e17fe","sector":"Professional services","suitability_state":"unknown","named_evidence":"Mindbody (business software/services company)","case_study_strength":"strong","qualification":"Conditional fit | Not assessed | Not assessed | Mindbody (business software/services company) | N/A | Single case study, not sector-specific in focus | Some evidence exists but isn't a deep sector-specific case.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19"]},{"id":"sector_evidence:92c70b3a2f8b3ab50cade597","sector":"Retail","suitability_state":"unknown","named_evidence":"AutoNation (retail/automotive dealerships), Baker & Baker (food manufacturing/retail supply)","case_study_strength":"strong","qualification":"Good fit, evidenced | SD-WAN/ZIA for distributed sites, M365 security | Not assessed | AutoNation (retail/automotive dealerships), Baker & Baker (food manufacturing/retail supply) | Multi-site retail benefits from ZIA's direct-to-cloud model avoiding centralised backhaul | US-centric case evidence; UK/EU retail-specific case studies not found in this pass | Reasonably well evidenced via AutoNation specifically, though not as singularly strong as Cato's Ulta Beauty story.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17","evidence:zscaler:18"]},{"id":"sector_evidence:0f0c938559a0669576bdc14e","sector":"Transport/logistics","suitability_state":"unknown","named_evidence":"None found","case_study_strength":"none","qualification":"Unknown - not assessed | Not assessed | Not assessed | None found | N/A | No case study found | Evidence gap.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"case_studies":[{"id":"case_studies:51264e0632241d066dd5a9d5","customer_type":"Named - AutoNation","named_customer":null,"sector":"Retail (automotive dealerships)","geography":"United States","estate":"Not quantified; Multiple retail and corporate locations","outcome":"Eliminated ~500 GB/month of unwanted P2P traffic (named-executive quote); improved Microsoft 365 performance enterprise-wide","quantified_result":"Eliminated ~500 GB/month of unwanted P2P traffic (named-executive quote); improved Microsoft 365 performance enterprise-wide","qualification":"Named - AutoNation | Retail (automotive dealerships) | United States | Not quantified | Multiple retail and corporate locations | Needed a cloud-based security stack to support Microsoft 365 rollout and control unauthorised P2P traffic consuming bandwidth | ZIA, Cloud Sandbox, Bandwidth Control | Cloud-delivered, direct-to-cloud with ZIA peering with Microsoft in 150+ data centres | Microsoft 365, AWS, Azure | Eliminated ~500 GB/month of unwanted P2P traffic (named-executive quote); improved Microsoft 365 performance enterprise-wide | High - named customer, named CISO (Athanasiou), specific bandwidth metric | A concrete, quantified operational outcome (500 GB/month) rather than a vague efficiency claim - good evidence quality.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"case_studies:924cfa5c151d774202c20aff","customer_type":"Named - NOV (National Oilwell Varco)","named_customer":null,"sector":"Energy (oilfield services)","geography":"Global (150+ years of operating history, described as a global energy-industry supplier)","estate":"27,500 users; Not quantified (global distributed enterprise)","outcome":"Leadership able to commit that all 27,500 users could work remotely on short notice - a specific, dated (2020 pandemic-era), verifiable capability claim","quantified_result":"Leadership able to commit that all 27,500 users could work remotely on short notice - a specific, dated (2020 pandemic-era), verifiable capability claim","qualification":"Named - NOV (National Oilwell Varco) | Energy (oilfield services) | Global (150+ years of operating history, described as a global energy-industry supplier) | 27,500 users | Not quantified (global distributed enterprise) | Needed to secure a globally distributed enterprise and enable work-from-anywhere, which proved fortuitous when COVID-19 required an immediate, complete remote-work pivot | ZPA, Zscaler Identity Proxy, Okta (identity), SentinelOne DataSet (log management/threat hunting) | Client-based remote access (ZPA) reducing data-centre traffic | Okta, SentinelOne | Leadership able to commit that all 27,500 users could work remotely on short notice - a specific, dated (2020 pandemic-era), verifiable capability claim | High - named customer, named executive (Philips), specific user count and a clearly dated real-world stress test | Genuinely the strongest case study Zscaler has for the 'remote-user-heavy organisation' suitability claim (Table 15) - real scale, a real crisis stress-test, and a named source.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"case_studies:9adb53e52b98a300362d6d8a","customer_type":"Named - Baker & Baker","named_customer":null,"sector":"Food manufacturing","geography":"Not specified (implied European/international given Zscaler customer profile)","estate":"Not quantified; Not quantified","outcome":"Ransomware incidents dropped from ~10/month to zero in the weeks and months immediately following deployment (named-executive quote)","quantified_result":"Ransomware incidents dropped from ~10/month to zero in the weeks and months immediately following deployment (named-executive quote)","qualification":"Named - Baker & Baker | Food manufacturing | Not specified (implied European/international given Zscaler customer profile) | Not quantified | Not quantified | MPLS contract expiry prompted a rethink of connectivity and security; averaging ~10 ransomware incidents per month prior to Zscaler | ZIA, ZPA, SD-WAN | Hybrid - SD-WAN for connectivity, ZIA/ZPA for security, Azure and data-centre application access via ZPA | Microsoft Azure | Ransomware incidents dropped from ~10/month to zero in the weeks and months immediately following deployment (named-executive quote) | High - named customer, named executive (Erler), specific before/after metric | A genuinely strong, specific security outcome - the kind of concrete before/after figure that's more persuasive to a buyer than general marketing language.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"evaluations":[{"id":"evaluations:0a1ace7f53df118c5e596b47","evaluation_type":"summary","finding":"Commercial reality | No public pricing; multiple independent third-party analyses converge reasonably well on per-user ranges (roughly $140-390/user/year combined ZIA+ZPA depending on tier) and describe a real risk of 30-100% cost escalation from common add-ons - directionally useful for budget conversations but not authoritative. | Table 16 | Medium (convergent third-party sourcing - stronger than a single anecdote, still not primary-sourced) | Use as a rough planning signal with buyers, always routing to a direct Zscaler quote for real numbers, exactly as advised for Cato's equivalent finding.","buyer_implication":"Use as a rough planning signal with buyers, always routing to a direct Zscaler quote for real numbers, exactly as advised for Cato's equivalent finding.","qualification":"No public pricing; multiple independent third-party analyses converge reasonably well on per-user ranges (roughly $140-390/user/year combined ZIA+ZPA depending on tier) and describe a real risk of 30-100% cost escalation from common add-ons - directionally useful for budget conversations but not authoritative. | Table 16 | Medium (convergent third-party sourcing - stronger than a single anecdote, still not primary-sourced) | Use as a rough planning signal with buyers, always routing to a direct Zscaler quote for real numbers, exactly as advised for Cato's equivalent finding.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:0bdc55b6acd5d7ed4849c8dd","evaluation_type":"summary","finding":"Reporting reality | Strong specifically around ZDX (network/application/user experience, AI-assisted root-cause diagnostics); weaker or unconfirmed on executive dashboards, compliance reporting, and scheduled/custom reporting, which weren't found in sources reviewed. | Table 10 | Medium | Present the ZDX strength specifically rather than imply comprehensive reporting maturity across the board - same approach used for Cato's equivalent finding.","buyer_implication":"Present the ZDX strength specifically rather than imply comprehensive reporting maturity across the board - same approach used for Cato's equivalent finding.","qualification":"Strong specifically around ZDX (network/application/user experience, AI-assisted root-cause diagnostics); weaker or unconfirmed on executive dashboards, compliance reporting, and scheduled/custom reporting, which weren't found in sources reviewed. | Table 10 | Medium | Present the ZDX strength specifically rather than imply comprehensive reporting maturity across the board - same approach used for Cato's equivalent finding.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:0e8f6f582713390cc62d3fd2","evaluation_type":"summary","finding":"Security & Analytics | FedRAMP High + DoD IL5 authorisation, a Data Fabric for Security pulling from 150+ third-party sources, and deep native AI processing trillions of daily signals behind detection, remediation and digital-experience diagnostics. | ZIA and ZPA started life as related-but-separate products and still carry some of that history in licensing and console structure; higher-value DLP, analytics and AI capability is frequently gated behind Transformation/Unlimited tiers rather than the entry tier.","buyer_implication":null,"qualification":"FedRAMP High + DoD IL5 authorisation, a Data Fabric for Security pulling from 150+ third-party sources, and deep native AI processing trillions of daily signals behind detection, remediation and digital-experience diagnostics. | ZIA and ZPA started life as related-but-separate products and still carry some of that history in licensing and console structure; higher-value DLP, analytics and AI capability is frequently gated behind Transformation/Unlimited tiers rather than the entry tier.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:10a70d689932be6ee55d43ec","evaluation_type":"summary","finding":"Large enterprise | Strong fit | NOV (27,500 users), AutoNation (large multi-site retailer) demonstrate enterprise-scale deployment | Requires internal or partner-supported operational ownership at scale | Enterprise-tier (Transformation/Unlimited) pricing likely, with meaningful cost escalation from add-ons per multiple independent third-party analyses | Well evidenced at the large end, comparable in evidence quality to Cato's Ulta Beauty story, via NOV specifically.","buyer_implication":null,"qualification":"Strong fit | NOV (27,500 users), AutoNation (large multi-site retailer) demonstrate enterprise-scale deployment | Requires internal or partner-supported operational ownership at scale | Enterprise-tier (Transformation/Unlimited) pricing likely, with meaningful cost escalation from add-ons per multiple independent third-party analyses | Well evidenced at the large end, comparable in evidence quality to Cato's Ulta Beauty story, via NOV specifically.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:18","evidence:zscaler:21"]},{"id":"evaluations:12caacff3cc966553e668305","evaluation_type":"summary","finding":"Firewall consolidation | Evidenced via AutoNation: 'full packet inspection firewall' replaced prior approach, eliminating unwanted P2P traffic | Existing firewall rules translated into ZIA policy | IT/security team | Not itemised | Not quantified | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real-world evidence exists via a named customer, though process detail (e.g. rule-migration tooling) wasn't found - same caveat applied to Cato's equivalent row.","buyer_implication":null,"qualification":"Evidenced via AutoNation: 'full packet inspection firewall' replaced prior approach, eliminating unwanted P2P traffic | Existing firewall rules translated into ZIA policy | IT/security team | Not itemised | Not quantified | Policy translation errors during cutover (not specifically addressed in the source) | Not detailed | Real-world evidence exists via a named customer, though process detail (e.g. rule-migration tooling) wasn't found - same caveat applied to Cato's equivalent row.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:13f84f9f9315f797ef417b04","evaluation_type":"summary","finding":"SME | Conditional fit | Entry-level AWS Marketplace editions exist (e.g. a 50-user Business edition), but overall commercial evidence points toward mid-market/enterprise economics and per-user tier structures that reward scale | Minimal internal skills needed for the security core; branch/SD-WAN less proven at small scale | Smaller AWS Marketplace-listed editions give SMEs a concrete entry point, though pricing still climbs quickly with add-ons per third-party analysis | SMEs have a clearer self-serve entry point via Marketplace editions than was found for Cato, though the same tier-escalation caution applies once add-ons are needed.","buyer_implication":null,"qualification":"Conditional fit | Entry-level AWS Marketplace editions exist (e.g. a 50-user Business edition), but overall commercial evidence points toward mid-market/enterprise economics and per-user tier structures that reward scale | Minimal internal skills needed for the security core; branch/SD-WAN less proven at small scale | Smaller AWS Marketplace-listed editions give SMEs a concrete entry point, though pricing still climbs quickly with add-ons per third-party analysis | SMEs have a clearer self-serve entry point via Marketplace editions than was found for Cato, though the same tier-escalation caution applies once add-ons are needed.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:51"]},{"id":"evaluations:142d9e3f2b88ed67a815360a","evaluation_type":"summary","finding":"Deployment & Ops | Massive global footprint (160+ data centres on six continents) with documented, tiered support SLAs (P1 response as fast as 15 minutes on premium tiers) and a mature Zero Trust Branch reference architecture that's largely plug-and-play hardware. | No owned private backbone - traffic relies on internet peering and cloud interconnects rather than a dedicated, SLA-backed middle mile, so performance is more exposed to public internet variability than backbone-based competitors like Cato.","buyer_implication":null,"qualification":"Massive global footprint (160+ data centres on six continents) with documented, tiered support SLAs (P1 response as fast as 15 minutes on premium tiers) and a mature Zero Trust Branch reference architecture that's largely plug-and-play hardware. | No owned private backbone - traffic relies on internet peering and cloud interconnects rather than a dedicated, SLA-backed middle mile, so performance is more exposed to public internet variability than backbone-based competitors like Cato.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:166a409157cfea144af723ff","evaluation_type":"summary","finding":"When would Netify recommend looking elsewhere? (mandatory) | When a buyer specifically wants a private, SLA-backed backbone as the architectural core of their SASE deployment; when a buyer needs a large, already-proven branch/retail rollout track record at Ulta-Beauty-like scale; when a buyer needs pre-verified PCI-DSS, HIPAA, or UK/EU regulated-sector compliance out of the box; or when a buyer wants a single converged console replacing their existing security stack rather than a best-of-breed addition to it. | Synthesis of Tables 4, 7, 13, 15, 17 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","buyer_implication":"Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","qualification":"When a buyer specifically wants a private, SLA-backed backbone as the architectural core of their SASE deployment; when a buyer needs a large, already-proven branch/retail rollout track record at Ulta-Beauty-like scale; when a buyer needs pre-verified PCI-DSS, HIPAA, or UK/EU regulated-sector compliance out of the box; or when a buyer wants a single converged console replacing their existing security stack rather than a best-of-breed addition to it. | Synthesis of Tables 4, 7, 13, 15, 17 | Medium-High | Each trigger is tied to a specific, evidenced gap rather than a generic 'consider alternatives' hedge.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:20c2734e211b4cc3c078c83a","evaluation_type":"summary","finding":"Global multinational | Good fit, with coverage caveats | 160+ data centres, present in most countries, active regional expansion (e.g. Saudi Arabia) | Needs Netify/buyer to verify specific-country data-centre coverage, since named-country detail is thin outside North America, Europe and the Middle East (see Table 7) | Custom enterprise pricing | Table 7 findings | The architecture supports multinational buyers well, but - same caution as for Cato - don't assume complete country-level coverage without checking Zscaler's own current data-centre map.","buyer_implication":null,"qualification":"Good fit, with coverage caveats | 160+ data centres, present in most countries, active regional expansion (e.g. Saudi Arabia) | Needs Netify/buyer to verify specific-country data-centre coverage, since named-country detail is thin outside North America, Europe and the Middle East (see Table 7) | Custom enterprise pricing | Table 7 findings | The architecture supports multinational buyers well, but - same caution as for Cato - don't assume complete country-level coverage without checking Zscaler's own current data-centre map.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:236a06592fc01cf782c3b27b","evaluation_type":"summary","finding":"Lean IT team | Good fit | Cloud-delivered, SaaS-model platform reduces on-prem hardware/patch burden; case studies (UST, Mindbody) describe reduced operational overhead | None significant for the security core; branch/SD-WAN operational maturity less proven | Support-tier upgrades (Premium, Premium Advanced) available to further reduce internal burden | Well evidenced for the security/access side; less proven for branch operations specifically, consistent with the pattern seen throughout this profile.","buyer_implication":null,"qualification":"Good fit | Cloud-delivered, SaaS-model platform reduces on-prem hardware/patch burden; case studies (UST, Mindbody) describe reduced operational overhead | None significant for the security core; branch/SD-WAN operational maturity less proven | Support-tier upgrades (Premium, Premium Advanced) available to further reduce internal burden | Well evidenced for the security/access side; less proven for branch operations specifically, consistent with the pattern seen throughout this profile.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19","evidence:zscaler:22"]},{"id":"evaluations:2b68c1b25f53cfb306f8c867","evaluation_type":"summary","finding":"Commercials | Concrete, vendor-published price anchors exist via AWS Marketplace listings, giving buyers something real to plan a budget against even without a public list price. | No public list pricing; multiple independent third-party analyses describe steep step-ups between Business, Transformation and Unlimited tiers, and warn that ZDX, workload licensing and Data Protection add-ons can each add 30-100% to a baseline ZIA+ZPA quote.","buyer_implication":null,"qualification":"Concrete, vendor-published price anchors exist via AWS Marketplace listings, giving buyers something real to plan a budget against even without a public list price. | No public list pricing; multiple independent third-party analyses describe steep step-ups between Business, Transformation and Unlimited tiers, and warn that ZDX, workload licensing and Data Protection add-ons can each add 30-100% to a baseline ZIA+ZPA quote.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:2d0d6775bfda64d43f6e61e0","evaluation_type":"summary","finding":"Support/service reality | A credible, unusually well-documented tiered support structure (Standard through Premium Support Advanced Plus) with specific, contractual SLA figures (P1 response as fast as 15 minutes; MDR 10-minute notification) sourced directly from Zscaler's own data sheets. | Table 8 | High | One of the better-evidenced operational areas in this whole profile - genuinely strong primary-source material.","buyer_implication":"One of the better-evidenced operational areas in this whole profile - genuinely strong primary-source material.","qualification":"A credible, unusually well-documented tiered support structure (Standard through Premium Support Advanced Plus) with specific, contractual SLA figures (P1 response as fast as 15 minutes; MDR 10-minute notification) sourced directly from Zscaler's own data sheets. | Table 8 | High | One of the better-evidenced operational areas in this whole profile - genuinely strong primary-source material.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:2e75d1eb2108d665c607a744","evaluation_type":"summary","finding":"Sector fit | US federal/public sector is by a wide margin the best-evidenced sector; retail and energy have credible single case studies; healthcare, financial services, education, hospitality, transport and manufacturing all lack the same depth of evidence found for the public-sector claim. | Table 14 | High for public sector; Medium for retail/energy; Low for other sectors | Do not extend the strong public-sector evidence into an assumption of equally strong healthcare/financial-services fit - those need separate verification.","buyer_implication":"Do not extend the strong public-sector evidence into an assumption of equally strong healthcare/financial-services fit - those need separate verification.","qualification":"US federal/public sector is by a wide margin the best-evidenced sector; retail and energy have credible single case studies; healthcare, financial services, education, hospitality, transport and manufacturing all lack the same depth of evidence found for the public-sector claim. | Table 14 | High for public sector; Medium for retail/energy; Low for other sectors | Do not extend the strong public-sector evidence into an assumption of equally strong healthcare/financial-services fit - those need separate verification.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:32978698de2bd912fed84dc6","evaluation_type":"summary","finding":"Regulated organisation | Strong fit for US federal/public sector specifically; conditional for other regulated sectors | FedRAMP High/Moderate, DoD IL5, GovRAMP, CJIS, CMMC Level 2 all confirmed for US government; PCI-DSS, HIPAA attestation, and UK/EU frameworks (NHS DSPT, DORA, NIS2) not confirmed | Buyer must independently verify sector-specific compliance status directly with Zscaler for anything outside US federal/public sector | Not assessed | Table 13 findings | A genuinely bifurcated picture: exceptionally strong for US federal/public sector, materially less evidenced for UK/EU-regulated sectors and for PCI-DSS/HIPAA specifically - don't let the federal strength imply blanket regulated-sector coverage.","buyer_implication":null,"qualification":"Strong fit for US federal/public sector specifically; conditional for other regulated sectors | FedRAMP High/Moderate, DoD IL5, GovRAMP, CJIS, CMMC Level 2 all confirmed for US government; PCI-DSS, HIPAA attestation, and UK/EU frameworks (NHS DSPT, DORA, NIS2) not confirmed | Buyer must independently verify sector-specific compliance status directly with Zscaler for anything outside US federal/public sector | Not assessed | Table 13 findings | A genuinely bifurcated picture: exceptionally strong for US federal/public sector, materially less evidenced for UK/EU-regulated sectors and for PCI-DSS/HIPAA specifically - don't let the federal strength imply blanket regulated-sector coverage.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:38e817cdbecf93d70b58bed3","evaluation_type":"summary","finding":"What implementation challenges should buyers expect? (mandatory) | Expect a genuine need to map tier-to-feature detail carefully before committing, since advanced DLP, browser isolation and privileged access all appear to be gated to Transformation/Unlimited tiers rather than universally included. Expect total cost to grow meaningfully once ZDX, workload licensing and Data Protection add-ons are factored in - multiple independent analyses describe 30-100% uplifts from these. Branch-heavy buyers should expect to pilot Zero Trust Branch carefully given the thinner independent evidence base relative to the core security stack. | Tables 3, 5, 16, 17 | Medium-High | Each expectation is traceable to a specific finding elsewhere in this profile, not a generic caution.","buyer_implication":"Each expectation is traceable to a specific finding elsewhere in this profile, not a generic caution.","qualification":"Expect a genuine need to map tier-to-feature detail carefully before committing, since advanced DLP, browser isolation and privileged access all appear to be gated to Transformation/Unlimited tiers rather than universally included. Expect total cost to grow meaningfully once ZDX, workload licensing and Data Protection add-ons are factored in - multiple independent analyses describe 30-100% uplifts from these. Branch-heavy buyers should expect to pilot Zero Trust Branch carefully given the thinner independent evidence base relative to the core security stack. | Tables 3, 5, 16, 17 | Medium-High | Each expectation is traceable to a specific finding elsewhere in this profile, not a generic caution.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:399755d8cb34221075d1f8af","evaluation_type":"summary","finding":"Scope & Boundaries | Very mature, long-standing SSE feature depth - Zscaler has been named a Gartner Secure Web Gateway Leader ten times running - spanning SWG, inline and API CASB, DLP, ZTNA and browser isolation. | Zscaler is fundamentally a security company that added branch/SD-WAN later (Zero Trust Branch, Zscaler Cellular), the reverse emphasis of a networking-first vendor - branch-heavy buyers should weigh that history against vendors built backbone-first from day one.","buyer_implication":null,"qualification":"Very mature, long-standing SSE feature depth - Zscaler has been named a Gartner Secure Web Gateway Leader ten times running - spanning SWG, inline and API CASB, DLP, ZTNA and browser isolation. | Zscaler is fundamentally a security company that added branch/SD-WAN later (Zero Trust Branch, Zscaler Cellular), the reverse emphasis of a networking-first vendor - branch-heavy buyers should weigh that history against vendors built backbone-first from day one.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:3a75867496d37d3190b846ec","evaluation_type":"summary","finding":"Procurement watch-out | Several compliance claims relevant to UK/EU buyers specifically (Cyber Essentials Plus, NHS DSPT, NIS2, DORA) were found via only a single, uncorroborated third-party review, or not found at all | UK/EU regulated-sector buyers cannot currently get a fully evidenced compliance answer from public sources alone and must request direct confirmation | Most relevant to Netify's UK healthcare, financial-services, and public-sector audiences specifically | Table 13 findings | Medium | A direct, practical follow-up item - mirrors the equivalent gap flagged for Cato, and equally important to close before this profile supports a high-stakes UK regulated-sector recommendation.","buyer_implication":"UK/EU regulated-sector buyers cannot currently get a fully evidenced compliance answer from public sources alone and must request direct confirmation","qualification":"Several compliance claims relevant to UK/EU buyers specifically (Cyber Essentials Plus, NHS DSPT, NIS2, DORA) were found via only a single, uncorroborated third-party review, or not found at all | UK/EU regulated-sector buyers cannot currently get a fully evidenced compliance answer from public sources alone and must request direct confirmation | Most relevant to Netify's UK healthcare, financial-services, and public-sector audiences specifically | Table 13 findings | Medium | A direct, practical follow-up item - mirrors the equivalent gap flagged for Cato, and equally important to close before this profile supports a high-stakes UK regulated-sector recommendation.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:3adb4292e3e6344d5d489836","evaluation_type":"summary","finding":"Deployment reality | Fast and well-evidenced on the security/remote-access side (Mindbody's 'five times faster than VPN' claim, NOV's rapid pandemic-era scale-up); genuinely less proven on the branch/SD-WAN side given the absence of a large-scale rollout case study. | Table 9, 17, 18 | Medium-High | Set expectations differently for the security core versus the branch/networking side - they're not equally mature.","buyer_implication":"Set expectations differently for the security core versus the branch/networking side - they're not equally mature.","qualification":"Fast and well-evidenced on the security/remote-access side (Mindbody's 'five times faster than VPN' claim, NOV's rapid pandemic-era scale-up); genuinely less proven on the branch/SD-WAN side given the absence of a large-scale rollout case study. | Table 9, 17, 18 | Medium-High | Set expectations differently for the security core versus the branch/networking side - they're not equally mature.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:3e1202d4f2a14c8d7b5bce00","evaluation_type":"summary","finding":"MPLS to SD-WAN migration | Evidenced via Baker & Baker: MPLS contract expiry triggered adoption of SD-WAN alongside ZIA for internet/SaaS security | Existing MPLS circuits retired at contract end rather than coexisting mid-transition (in contrast to Cato's explicit coexistence capability) | IT team, per case study | Not itemised | Not quantified | Less gradual than Cato's documented MPLS-coexistence model - potentially a harder cutover point | Not detailed in sources reviewed | A real migration scenario is evidenced, but the mechanism (contract-expiry-triggered switch) is less flexible than a purpose-built coexistence feature - a fair, specific point of comparison.","buyer_implication":null,"qualification":"Evidenced via Baker & Baker: MPLS contract expiry triggered adoption of SD-WAN alongside ZIA for internet/SaaS security | Existing MPLS circuits retired at contract end rather than coexisting mid-transition (in contrast to Cato's explicit coexistence capability) | IT team, per case study | Not itemised | Not quantified | Less gradual than Cato's documented MPLS-coexistence model - potentially a harder cutover point | Not detailed in sources reviewed | A real migration scenario is evidenced, but the mechanism (contract-expiry-triggered switch) is less flexible than a purpose-built coexistence feature - a fair, specific point of comparison.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:49da1828cebc529dc10309f7","evaluation_type":"summary","finding":"Questions Netify still cannot verify | PCI-DSS and HIPAA attestation status; UK Cyber Essentials Plus and NHS DSPT/NIS2/DORA relevance; exact tier-to-feature mapping for DLP, browser isolation and privileged access; Zero Trust Branch hardware charging model; a large-scale, metric-rich branch rollout case study; and whether any Zscaler-delivered (as opposed to partner-delivered) fully-managed service exists. | Synthesis of Tables 4, 6, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Zscaler briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent list in the Cato profile.","buyer_implication":"This list should drive the next follow-up (a direct Zscaler briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent list in the Cato profile.","qualification":"PCI-DSS and HIPAA attestation status; UK Cyber Essentials Plus and NHS DSPT/NIS2/DORA relevance; exact tier-to-feature mapping for DLP, browser isolation and privileged access; Zero Trust Branch hardware charging model; a large-scale, metric-rich branch rollout case study; and whether any Zscaler-delivered (as opposed to partner-delivered) fully-managed service exists. | Synthesis of Tables 4, 6, 13, 16 | N/A - explicitly unresolved | This list should drive the next follow-up (a direct Zscaler briefing or partner conversation) before this profile is considered fully closed out, in exactly the same spirit as the equivalent list in the Cato profile.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:4ad451b35ed923099be37be6","evaluation_type":"summary","finding":"Cloud-first organisation | Good fit | Multi-cloud on-ramps (AWS, Azure, GCP) evidenced via Baker & Baker (Azure) specifically | None significant identified | Not itemised | Solid, evidenced by a real production deployment rather than platform-page claims alone.","buyer_implication":null,"qualification":"Good fit | Multi-cloud on-ramps (AWS, Azure, GCP) evidenced via Baker & Baker (Azure) specifically | None significant identified | Not itemised | Solid, evidenced by a real production deployment rather than platform-page claims alone.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17"]},{"id":"evaluations:4d2f66bb4bfa8e98e42c91a8","evaluation_type":"summary","finding":"Merger/acquisition integration | Referenced via the Zscaler-on-Zscaler case study describing the SPLX acquisition, where ZIA and DLP policies were deployed within five days of deal close | Not itemised beyond the five-day timeframe | Not itemised | Zscaler's own internal security team ('customer zero') | Five days from deal close to ZIA + DLP policy deployment (specific, dated) | Not itemised | Not detailed | A genuinely specific, dated, quantified M&A integration example - better evidence than Cato's equivalent row, which relied on general marketing-page positioning rather than a named scenario.","buyer_implication":null,"qualification":"Referenced via the Zscaler-on-Zscaler case study describing the SPLX acquisition, where ZIA and DLP policies were deployed within five days of deal close | Not itemised beyond the five-day timeframe | Not itemised | Zscaler's own internal security team ('customer zero') | Five days from deal close to ZIA + DLP policy deployment (specific, dated) | Not itemised | Not detailed | A genuinely specific, dated, quantified M&A integration example - better evidence than Cato's equivalent row, which relied on general marketing-page positioning rather than a named scenario.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:51c2e3a9899d93b009d8cb2e","evaluation_type":"summary","finding":"Biggest operational concern | Tier-to-feature opacity combined with documented add-on cost escalation creates real risk of buyers under-scoping their initial quote and facing a larger-than-expected bill once DLP, browser isolation, ZDX or workload licensing are actually needed. | Table 16, 19 | Medium | Netify should proactively flag this to buyers during the shortlist conversation rather than let it surface as a surprise at renewal.","buyer_implication":"Netify should proactively flag this to buyers during the shortlist conversation rather than let it surface as a surprise at renewal.","qualification":"Tier-to-feature opacity combined with documented add-on cost escalation creates real risk of buyers under-scoping their initial quote and facing a larger-than-expected bill once DLP, browser isolation, ZDX or workload licensing are actually needed. | Table 16, 19 | Medium | Netify should proactively flag this to buyers during the shortlist conversation rather than let it surface as a surprise at renewal.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:53234a2b13ebcf75b2bafd4d","evaluation_type":"summary","finding":"Highly distributed branch estate | Conditional fit | Zero Trust Branch exists and is architecturally sound, but lacks an equivalent to Cato's large-scale, metric-rich branch-rollout proof point (e.g. Ulta Beauty) | Zero-touch provisioning documented at the mechanism level, not proven at large operational scale in the evidence found | Site-based licensing implications not itemised | help.zscaler.com Zero Trust Branch reference architecture | This is the clearest area where Cato currently has a stronger evidence base than Zscaler - a fair, specific point to make to a branch-heavy buyer rather than assuming parity.","buyer_implication":null,"qualification":"Conditional fit | Zero Trust Branch exists and is architecturally sound, but lacks an equivalent to Cato's large-scale, metric-rich branch-rollout proof point (e.g. Ulta Beauty) | Zero-touch provisioning documented at the mechanism level, not proven at large operational scale in the evidence found | Site-based licensing implications not itemised | help.zscaler.com Zero Trust Branch reference architecture | This is the clearest area where Cato currently has a stronger evidence base than Zscaler - a fair, specific point to make to a branch-heavy buyer rather than assuming parity.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:54c1c8a99dcc4ec9e3f54424","evaluation_type":"summary","finding":"Compliance & Footprint | Exceptionally well-documented US federal and public-sector credentials - FedRAMP High/Moderate, GovRAMP, CJIS, CMMC Level 2 - alongside broad ISO 27001/27017/27018/27701 and SOC 2 Type II coverage. | UK- and region-specific certifications (Cyber Essentials Plus, NHS DSPT relevance) were found via only a single third-party review in this pass and are not independently confirmed on Zscaler's own compliance pages - don't assume coverage without asking directly.","buyer_implication":null,"qualification":"Exceptionally well-documented US federal and public-sector credentials - FedRAMP High/Moderate, GovRAMP, CJIS, CMMC Level 2 - alongside broad ISO 27001/27017/27018/27701 and SOC 2 Type II coverage. | UK- and region-specific certifications (Cyber Essentials Plus, NHS DSPT relevance) were found via only a single third-party review in this pass and are not independently confirmed on Zscaler's own compliance pages - don't assume coverage without asking directly.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:5b619991e634f3b3ef7a4945","evaluation_type":"summary","finding":"Limitation | SD-WAN/branch capability (Zero Trust Branch) is real but has materially thinner independent evidence than the core security stack - no large-scale, metric-rich branch-rollout case study equivalent to Cato's Ulta Beauty story was found | Branch-heavy buyers should not assume the same maturity/proof-point depth on the networking side as on the security side | Affects highly distributed branch/retail buyers most | Table 4, 15, 17 findings | Medium-High | A fair, specific, well-evidenced gap rather than a vague impression - worth stating to buyers directly rather than softening.","buyer_implication":"Branch-heavy buyers should not assume the same maturity/proof-point depth on the networking side as on the security side","qualification":"SD-WAN/branch capability (Zero Trust Branch) is real but has materially thinner independent evidence than the core security stack - no large-scale, metric-rich branch-rollout case study equivalent to Cato's Ulta Beauty story was found | Branch-heavy buyers should not assume the same maturity/proof-point depth on the networking side as on the security side | Affects highly distributed branch/retail buyers most | Table 4, 15, 17 findings | Medium-High | A fair, specific, well-evidenced gap rather than a vague impression - worth stating to buyers directly rather than softening.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:64aa7bcd0e89fce46ea75306","evaluation_type":"summary","finding":"Global branch rollout | Zero Trust Branch reference architecture describes plug-and-play hardware install, but no large-scale, metric-rich branch rollout case study (comparable to Cato's Ulta Beauty story) was found in this pass | Existing branch network/Wi-Fi infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Unproven at Cato-Ulta-Beauty-scale in the evidence available | Not detailed | The clearest, most specific gap in Zscaler's evidence base relative to Cato - worth being direct about this with buyers who need branch-rollout proof points specifically.","buyer_implication":null,"qualification":"Zero Trust Branch reference architecture describes plug-and-play hardware install, but no large-scale, metric-rich branch rollout case study (comparable to Cato's Ulta Beauty story) was found in this pass | Existing branch network/Wi-Fi infrastructure to integrate or replace | Not itemised | Not itemised | Not quantified | Unproven at Cato-Ulta-Beauty-scale in the evidence available | Not detailed | The clearest, most specific gap in Zscaler's evidence base relative to Cato - worth being direct about this with buyers who need branch-rollout proof points specifically.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:710f2040e2a415bde7d7c3c7","evaluation_type":"summary","finding":"VPN to ZTNA migration | Evidenced via Baker & Baker and Mindbody: both explicitly describe eliminating VPNs in favour of ZPA | Existing VPN concentrator/client footprint retired | IT team | Not itemised | Mindbody: 'ZPA deploys five times more quickly than traditional VPN solutions' (customer quote) | Not itemised | Not detailed | This is Zscaler's best-evidenced migration scenario by a clear margin - two independent named customers specifically describing VPN elimination, with a concrete relative-speed claim from one of them.","buyer_implication":null,"qualification":"Evidenced via Baker & Baker and Mindbody: both explicitly describe eliminating VPNs in favour of ZPA | Existing VPN concentrator/client footprint retired | IT team | Not itemised | Mindbody: 'ZPA deploys five times more quickly than traditional VPN solutions' (customer quote) | Not itemised | Not detailed | This is Zscaler's best-evidenced migration scenario by a clear margin - two independent named customers specifically describing VPN elimination, with a concrete relative-speed claim from one of them.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:8f59e1e58c9869f5c538b724","evaluation_type":"summary","finding":"Multi-vendor SASE integration | Well evidenced, in a different direction than Cato - Zscaler's strongest partner alliances (Okta, CrowdStrike) are explicitly built around being one best-of-breed component in a multi-vendor security architecture, not a single converged replacement for it | IdP and EDR already in place | Not itemised | Formal joint deployment guides and a hands-on integration lab | Not quantified | N/A | N/A | Worth stating plainly in the Netify View: Zscaler is, by design and by its strongest evidenced partnerships, genuinely well-suited to buyers wanting a best-of-breed multi-vendor stack - the reverse of Cato's positioning on this exact scenario.","buyer_implication":null,"qualification":"Well evidenced, in a different direction than Cato - Zscaler's strongest partner alliances (Okta, CrowdStrike) are explicitly built around being one best-of-breed component in a multi-vendor security architecture, not a single converged replacement for it | IdP and EDR already in place | Not itemised | Formal joint deployment guides and a hands-on integration lab | Not quantified | N/A | N/A | Worth stating plainly in the Netify View: Zscaler is, by design and by its strongest evidenced partnerships, genuinely well-suited to buyers wanting a best-of-breed multi-vendor stack - the reverse of Cato's positioning on this exact scenario.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:903ebdbaf35121d3ee58f483","evaluation_type":"summary","finding":"Where does it fall behind competitors? (mandatory) | No owned private backbone, which is a genuine architectural gap against backbone-first SASE vendors like Cato for buyers prioritising predictable site-to-site WAN performance; SD-WAN/branch maturity and proof points are materially thinner than the security stack; and PCI-DSS/HIPAA attestations, which some competitors publish explicitly, were not found for Zscaler in this pass. | Tables 4, 7, 13, 15, 17 | Medium-High | Named specifically and evidenced, not a generic hedge - Netify can state these gaps with real confidence.","buyer_implication":"Named specifically and evidenced, not a generic hedge - Netify can state these gaps with real confidence.","qualification":"No owned private backbone, which is a genuine architectural gap against backbone-first SASE vendors like Cato for buyers prioritising predictable site-to-site WAN performance; SD-WAN/branch maturity and proof points are materially thinner than the security stack; and PCI-DSS/HIPAA attestations, which some competitors publish explicitly, were not found for Zscaler in this pass. | Tables 4, 7, 13, 15, 17 | Medium-High | Named specifically and evidenced, not a generic hedge - Netify can state these gaps with real confidence.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:967f35fd422c3b24bd1fcef1","evaluation_type":"summary","finding":"Strength | Unmatched US federal/public-sector compliance depth - FedRAMP High, DoD IL5, GovRAMP, CJIS, CMMC Level 2, serving 14 of 15 US Cabinet-level agencies | Removes a major procurement blocker for US federal and regulated public-sector buyers that most SASE/SSE competitors can't clear | Best: US federal/state/local government. Less relevant: buyers with no US federal/government exposure | High | This is Zscaler's single clearest, most defensible differentiator in the entire profile.","buyer_implication":"Removes a major procurement blocker for US federal and regulated public-sector buyers that most SASE/SSE competitors can't clear","qualification":"Unmatched US federal/public-sector compliance depth - FedRAMP High, DoD IL5, GovRAMP, CJIS, CMMC Level 2, serving 14 of 15 US Cabinet-level agencies | Removes a major procurement blocker for US federal and regulated public-sector buyers that most SASE/SSE competitors can't clear | Best: US federal/state/local government. Less relevant: buyers with no US federal/government exposure | High | This is Zscaler's single clearest, most defensible differentiator in the entire profile.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:25","evidence:zscaler:28"]},{"id":"evaluations:99f85c04407139b0ebff8e41","evaluation_type":"summary","finding":"Limitation | No owned private backbone - the architecture relies on internet peering and cloud interconnects rather than an SLA-backed middle mile | Buyers wanting Cato-style predictable, backbone-based performance across a distributed estate should weigh this architectural difference directly, not assume parity | Affects distributed multi-site buyers most; less relevant to buyers whose primary need is internet/SaaS security rather than site-to-site WAN performance | Table 7 findings | High | The single most consequential architectural fact in this whole profile - should be stated plainly and early to any buyer comparing Zscaler against a backbone-first vendor.","buyer_implication":"Buyers wanting Cato-style predictable, backbone-based performance across a distributed estate should weigh this architectural difference directly, not assume parity","qualification":"No owned private backbone - the architecture relies on internet peering and cloud interconnects rather than an SLA-backed middle mile | Buyers wanting Cato-style predictable, backbone-based performance across a distributed estate should weigh this architectural difference directly, not assume parity | Affects distributed multi-site buyers most; less relevant to buyers whose primary need is internet/SaaS security rather than site-to-site WAN performance | Table 7 findings | High | The single most consequential architectural fact in this whole profile - should be stated plainly and early to any buyer comparing Zscaler against a backbone-first vendor.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:a0d16e2db2465b2c129732ad","evaluation_type":"summary","finding":"Questions to ask before recommending it | 1) Which Table 3 capabilities (advanced DLP, browser isolation, privileged remote access) are actually included at the buyer's target tier, versus requiring Transformation or Unlimited? 2) What would ZDX, workload licensing, and Data Protection add-ons realistically add to the buyer's total cost at their expected scale? 3) Can Zscaler confirm PCI-DSS, HIPAA, Cyber Essentials Plus, and NHS DSPT-relevant status directly, given none were independently confirmed in this pass? 4) For branch-heavy buyers specifically, can Zscaler provide a large-scale reference deployment comparable in evidence depth to what competitors can show? | Synthesis of Tables 3, 5, 13, 16, 17 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Zscaler.","buyer_implication":"A direct, reusable question set for Netify's advisory conversations with buyers considering Zscaler.","qualification":"1) Which Table 3 capabilities (advanced DLP, browser isolation, privileged remote access) are actually included at the buyer's target tier, versus requiring Transformation or Unlimited? 2) What would ZDX, workload licensing, and Data Protection add-ons realistically add to the buyer's total cost at their expected scale? 3) Can Zscaler confirm PCI-DSS, HIPAA, Cyber Essentials Plus, and NHS DSPT-relevant status directly, given none were independently confirmed in this pass? 4) For branch-heavy buyers specifically, can Zscaler provide a large-scale reference deployment comparable in evidence depth to what competitors can show? | Synthesis of Tables 3, 5, 13, 16, 17 | High | A direct, reusable question set for Netify's advisory conversations with buyers considering Zscaler.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:adf09477ebba2329751bc2fd","evaluation_type":"summary","finding":"Mid-market | Good fit | Sweet spot implied by several case studies (Mindbody, UST) describing mid-sized, distributed organisations | Low - case studies show non-specialist IT teams managing rollouts successfully | Business-tier pricing likely applies; volume discounts documented above 1,000 users per third-party analysis (a reported 34-35% discount threshold) | Reasonably well evidenced by multiple mid-sized case studies.","buyer_implication":null,"qualification":"Good fit | Sweet spot implied by several case studies (Mindbody, UST) describing mid-sized, distributed organisations | Low - case studies show non-specialist IT teams managing rollouts successfully | Business-tier pricing likely applies; volume discounts documented above 1,000 users per third-party analysis (a reported 34-35% discount threshold) | Reasonably well evidenced by multiple mid-sized case studies.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:19","evidence:zscaler:22","evidence:zscaler:53"]},{"id":"evaluations:b4c93de252480c940432153e","evaluation_type":"summary","finding":"Biggest operational advantage | Demonstrated ability to support a rapid, large-scale shift to secure remote access under real-world pressure, evidenced concretely via NOV's 27,500-user COVID-19-era pivot rather than just claimed in the abstract. | Table 15, 17, 18 | High | Directly quotable with the specific NOV figures for credibility.","buyer_implication":"Directly quotable with the specific NOV figures for credibility.","qualification":"Demonstrated ability to support a rapid, large-scale shift to secure remote access under real-world pressure, evidenced concretely via NOV's 27,500-user COVID-19-era pivot rather than just claimed in the abstract. | Table 15, 17, 18 | High | Directly quotable with the specific NOV figures for credibility.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:b939dbeb8597de8084f89cf9","evaluation_type":"summary","finding":"Procurement watch-out | PCI-DSS and HIPAA attestations, both explicitly confirmed for Cato in that profile, were not found for Zscaler in this research pass despite healthcare being listed as a served industry | Payment-handling and healthcare buyers should not assume compliance parity with competitors that do explicitly publish these attestations | Most relevant to retail/payments and healthcare buyers specifically | Table 13 findings | Medium | A specific, comparative finding worth surfacing directly - this is exactly the kind of vendor-to-vendor compliance gap Netify's comparison tool exists to catch.","buyer_implication":"Payment-handling and healthcare buyers should not assume compliance parity with competitors that do explicitly publish these attestations","qualification":"PCI-DSS and HIPAA attestations, both explicitly confirmed for Cato in that profile, were not found for Zscaler in this research pass despite healthcare being listed as a served industry | Payment-handling and healthcare buyers should not assume compliance parity with competitors that do explicitly publish these attestations | Most relevant to retail/payments and healthcare buyers specifically | Table 13 findings | Medium | A specific, comparative finding worth surfacing directly - this is exactly the kind of vendor-to-vendor compliance gap Netify's comparison tool exists to catch.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:c074a5b4b3f52460e47e793a","evaluation_type":"summary","finding":"When would Netify recommend it? (mandatory) | When a buyer needs FedRAMP High/DoD IL5-level government assurance; when a buyer's primary pain point is legacy VPN/firewall-appliance elimination and internet/SaaS/private-app security specifically; or when a buyer wants to add best-of-breed SSE into an existing security stack (particularly one already built around Okta and/or CrowdStrike, given the depth of that specific alliance). | Synthesis of Tables 12, 13, 15, 17 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","buyer_implication":"A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","qualification":"When a buyer needs FedRAMP High/DoD IL5-level government assurance; when a buyer's primary pain point is legacy VPN/firewall-appliance elimination and internet/SaaS/private-app security specifically; or when a buyer wants to add best-of-breed SSE into an existing security stack (particularly one already built around Okta and/or CrowdStrike, given the depth of that specific alliance). | Synthesis of Tables 12, 13, 15, 17 | High | A clear, actionable recommendation trigger set for Netify's comparison tool to apply directly.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:c4a95f03934d5416e757af4e","evaluation_type":"summary","finding":"Limitation | Commercial opacity plus documented tier-escalation risk - no public pricing, and multiple independent third-party analyses describe steep step-ups between Business/Transformation/Unlimited tiers with 30-100% cost increases from common add-ons (ZDX, workload licensing, Data Protection) | Buyers risk under-budgeting if they scope only the entry tier without accounting for the add-ons they'll likely need | Affects all buyer sizes, though the absolute cost impact is largest for large enterprises with big user/workload counts | Table 16 findings | Medium (convergent across multiple independent third-party sources) | The convergence across several independent pricing analyses makes this a reasonably confident finding despite the lack of primary-source pricing - Netify should flag the tier-escalation risk proactively rather than waiting for a buyer to discover it at quoting.","buyer_implication":"Buyers risk under-budgeting if they scope only the entry tier without accounting for the add-ons they'll likely need","qualification":"Commercial opacity plus documented tier-escalation risk - no public pricing, and multiple independent third-party analyses describe steep step-ups between Business/Transformation/Unlimited tiers with 30-100% cost increases from common add-ons (ZDX, workload licensing, Data Protection) | Buyers risk under-budgeting if they scope only the entry tier without accounting for the add-ons they'll likely need | Affects all buyer sizes, though the absolute cost impact is largest for large enterprises with big user/workload counts | Table 16 findings | Medium (convergent across multiple independent third-party sources) | The convergence across several independent pricing analyses makes this a reasonably confident finding despite the lack of primary-source pricing - Netify should flag the tier-escalation risk proactively rather than waiting for a buyer to discover it at quoting.","confidence":"medium","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:c60343a23b7699dd8543c373","evaluation_type":"summary","finding":"Mature NetOps/SecOps team | Good fit, with a caveat | Deep, formally documented integrations (Okta, CrowdStrike) support a mature best-of-breed toolchain approach | Mature teams may find the still-separate ZIA/ZPA console history less unified than a platform designed as one product from day one | Not assessed | Table 12 findings | Worth noting candidly: Zscaler's strength is genuinely deep point-integration into an existing security stack (Okta/CrowdStrike alliance) rather than replacing that stack with a single converged console the way Cato pitches itself.","buyer_implication":null,"qualification":"Good fit, with a caveat | Deep, formally documented integrations (Okta, CrowdStrike) support a mature best-of-breed toolchain approach | Mature teams may find the still-separate ZIA/ZPA console history less unified than a platform designed as one product from day one | Not assessed | Table 12 findings | Worth noting candidly: Zscaler's strength is genuinely deep point-integration into an existing security stack (Okta/CrowdStrike alliance) rather than replacing that stack with a single converged console the way Cato pitches itself.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:cb3b58b242a035ffd1d2df29","evaluation_type":"summary","finding":"Strength | Genuinely mature, long-standing SSE stack (10x Gartner SWG MQ Leader) with a well-evidenced VPN-elimination migration story | Buyers retiring legacy VPN/proxy infrastructure get a proven, widely-adopted replacement path | Best: security-first enterprises with a VPN/firewall-appliance-heavy legacy estate. Less relevant: buyers without significant legacy VPN debt | High | Two independently named customers specifically describing VPN elimination is good, concrete evidence.","buyer_implication":"Buyers retiring legacy VPN/proxy infrastructure get a proven, widely-adopted replacement path","qualification":"Genuinely mature, long-standing SSE stack (10x Gartner SWG MQ Leader) with a well-evidenced VPN-elimination migration story | Buyers retiring legacy VPN/proxy infrastructure get a proven, widely-adopted replacement path | Best: security-first enterprises with a VPN/firewall-appliance-heavy legacy estate. Less relevant: buyers without significant legacy VPN debt | High | Two independently named customers specifically describing VPN elimination is good, concrete evidence.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:17","evidence:zscaler:19"]},{"id":"evaluations:cb59309fdd693d6b0d6355b1","evaluation_type":"summary","finding":"AI reality | A genuinely evidenced, actively-developing set of specific AI functions (Data Fabric threat correlation, ZDX AI diagnostics, agentic-AI guardrails) sits inside broader 'AI-driven' marketing language that extends further than what's independently confirmed for every claimed function. | Table 11 | Medium-High | Represent the narrower, evidenced AI feature set in buyer-facing content rather than the full marketing scope - consistent with the standard applied throughout this profile.","buyer_implication":"Represent the narrower, evidenced AI feature set in buyer-facing content rather than the full marketing scope - consistent with the standard applied throughout this profile.","qualification":"A genuinely evidenced, actively-developing set of specific AI functions (Data Fabric threat correlation, ZDX AI diagnostics, agentic-AI guardrails) sits inside broader 'AI-driven' marketing language that extends further than what's independently confirmed for every claimed function. | Table 11 | Medium-High | Represent the narrower, evidenced AI feature set in buyer-facing content rather than the full marketing scope - consistent with the standard applied throughout this profile.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:cfb193c11a7f266e3c0924c9","evaluation_type":"summary","finding":"Co-managed transition | Not documented as a distinct migration scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - consistent with the broader finding that Zscaler doesn't appear to have a named co-managed service model (see Table 6).","buyer_implication":null,"qualification":"Not documented as a distinct migration scenario in sources reviewed | Not itemised | Not itemised | Not itemised | Not quantified | Not itemised | Not detailed | Evidence gap - consistent with the broader finding that Zscaler doesn't appear to have a named co-managed service model (see Table 6).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:d0750d67501d3ae9c5ce3922","evaluation_type":"summary","finding":"Strength | Specific, current, well-evidenced AI investment - Data Fabric for Security, ZDX AI diagnostics, and a June 2026 agentic-AI security launch with 11 named Technology Alliance Partners | Buyers with active or planned agentic-AI/GenAI initiatives get security controls that are demonstrably being actively developed, not just marketed | Best: organisations rolling out GenAI/agentic AI tools who need governance controls now. Less relevant: buyers with no near-term AI-security need | Medium-High | One of the more concretely dated, named AI announcements found across this entire research pass - a genuine signal of active investment, not just AI-washing.","buyer_implication":"Buyers with active or planned agentic-AI/GenAI initiatives get security controls that are demonstrably being actively developed, not just marketed","qualification":"Specific, current, well-evidenced AI investment - Data Fabric for Security, ZDX AI diagnostics, and a June 2026 agentic-AI security launch with 11 named Technology Alliance Partners | Buyers with active or planned agentic-AI/GenAI initiatives get security controls that are demonstrably being actively developed, not just marketed | Best: organisations rolling out GenAI/agentic AI tools who need governance controls now. Less relevant: buyers with no near-term AI-security need | Medium-High | One of the more concretely dated, named AI announcements found across this entire research pass - a genuine signal of active investment, not just AI-washing.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:12"]},{"id":"evaluations:db9a03cc67b8a761e45365a2","evaluation_type":"summary","finding":"Remote-user-heavy organisation | Strong fit, Zscaler's core strength | Client Connector, clientless access, ZDX all mature; NOV's 27,500-user remote pivot during COVID-19 is a strong, dated proof point | Requires ZDX licence for full experience visibility | User licensing is Zscaler's primary commercial model | Arguably Zscaler's single best-evidenced suitability claim in the whole profile - this is the core use case the platform was built for.","buyer_implication":null,"qualification":"Strong fit, Zscaler's core strength | Client Connector, clientless access, ZDX all mature; NOV's 27,500-user remote pivot during COVID-19 is a strong, dated proof point | Requires ZDX licence for full experience visibility | User licensing is Zscaler's primary commercial model | Arguably Zscaler's single best-evidenced suitability claim in the whole profile - this is the core use case the platform was built for.","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":["evidence:zscaler:21"]},{"id":"evaluations:e195e1c222e4c21af4e9a0f0","evaluation_type":"summary","finding":"Most credible differentiator | The combination of FedRAMP High/DoD IL5 authorisation with a decade-plus-mature, independently-validated SSE stack - very few competitors clear the compliance bar and have the platform maturity to match it simultaneously. | Tables 3, 13 | High | This is the single sentence Netify's comparison engine could most confidently quote for Zscaler specifically.","buyer_implication":"This is the single sentence Netify's comparison engine could most confidently quote for Zscaler specifically.","qualification":"The combination of FedRAMP High/DoD IL5 authorisation with a decade-plus-mature, independently-validated SSE stack - very few competitors clear the compliance bar and have the platform maturity to match it simultaneously. | Tables 3, 13 | High | This is the single sentence Netify's comparison engine could most confidently quote for Zscaler specifically.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:e3961f456bb12f1bab93c5d2","evaluation_type":"summary","finding":"Where does it stand out? (mandatory) | FedRAMP High/DoD IL5 government authorisation that very few SASE-class competitors clear; a decade-plus-mature SSE stack (10x Gartner SWG Leader) with well-evidenced VPN-elimination case studies; and a specific, actively-dated AI security investment (agentic AI guardrails launched June 2026 with 11 named partners). | Tables 3, 11, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated evidence rather than generic marketing language.","buyer_implication":"These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated evidence rather than generic marketing language.","qualification":"FedRAMP High/DoD IL5 government authorisation that very few SASE-class competitors clear; a decade-plus-mature SSE stack (10x Gartner SWG Leader) with well-evidenced VPN-elimination case studies; and a specific, actively-dated AI security investment (agentic AI guardrails launched June 2026 with 11 named partners). | Tables 3, 11, 13, 19 | High | These are the claims Netify can make most confidently and specifically to buyers, each backed by named, dated evidence rather than generic marketing language.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:e4e993bd95a637cb94c38cf0","evaluation_type":"summary","finding":"Global fit | Architecturally global by design (160+ data centres, six continents), with genuinely better-evidenced Middle East coverage than Cato's profile showed, but named-country detail is thin outside North America, Europe and the Middle East. | Table 7 | Medium-High | Always verify buyer-specific country coverage directly rather than relying on the general 'most countries' claim.","buyer_implication":"Always verify buyer-specific country coverage directly rather than relying on the general 'most countries' claim.","qualification":"Architecturally global by design (160+ data centres, six continents), with genuinely better-evidenced Middle East coverage than Cato's profile showed, but named-country detail is thin outside North America, Europe and the Middle East. | Table 7 | Medium-High | Always verify buyer-specific country coverage directly rather than relying on the general 'most countries' claim.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:e557ade902585e984c6be977","evaluation_type":"summary","finding":"Who is this genuinely best suited for? (mandatory) | Large enterprises and US federal/public-sector agencies wanting to retire legacy VPN and perimeter-firewall infrastructure and consolidate SWG, CASB, DLP and ZTNA under one security-first console - particularly where FedRAMP High or DoD IL5 authorisation is a hard requirement, and particularly for organisations whose primary need is securing internet/SaaS/private-app access rather than building out branch WAN infrastructure. | Tables 1, 13, 14, 15 (FedRAMP depth, remote-access maturity, case study evidence) | High | Buyers matching this profile can proceed with real confidence in the core security claims; buyers whose primary need is branch/SD-WAN maturity should weigh Table 4's evidence gaps carefully.","buyer_implication":"Buyers matching this profile can proceed with real confidence in the core security claims; buyers whose primary need is branch/SD-WAN maturity should weigh Table 4's evidence gaps carefully.","qualification":"Large enterprises and US federal/public-sector agencies wanting to retire legacy VPN and perimeter-firewall infrastructure and consolidate SWG, CASB, DLP and ZTNA under one security-first console - particularly where FedRAMP High or DoD IL5 authorisation is a hard requirement, and particularly for organisations whose primary need is securing internet/SaaS/private-app access rather than building out branch WAN infrastructure. | Tables 1, 13, 14, 15 (FedRAMP depth, remote-access maturity, case study evidence) | High | Buyers matching this profile can proceed with real confidence in the core security claims; buyers whose primary need is branch/SD-WAN maturity should weigh Table 4's evidence gaps carefully.","confidence":"high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:ef48e32e51a9b4385d7a5a2e","evaluation_type":"summary","finding":"Overall Netify Assessment | Zscaler is the most credible, deeply-evidenced choice in this comparison set for buyers whose primary need is mature, government-grade SSE - the FedRAMP High/DoD IL5 authorisation and decade-plus-proven security stack are genuinely differentiated and well-documented. Its clearest weak points relative to a backbone-first competitor like Cato are the absence of an owned private backbone and a materially thinner evidence base for large-scale branch/SD-WAN deployment. Commercial opacity and tier-gating risk are real but at least directionally corroborated by multiple independent analyses, which is a stronger evidentiary position than a single anecdote would give. This profile is solid enough to support initial shortlist guidance for security-first and US public-sector buyers specifically, but the flagged UK/EU compliance gaps and branch-evidence gap should be closed out with Zscaler directly before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Zscaler engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato profile.","buyer_implication":"Recommend direct Zscaler engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato profile.","qualification":"Zscaler is the most credible, deeply-evidenced choice in this comparison set for buyers whose primary need is mature, government-grade SSE - the FedRAMP High/DoD IL5 authorisation and decade-plus-proven security stack are genuinely differentiated and well-documented. Its clearest weak points relative to a backbone-first competitor like Cato are the absence of an owned private backbone and a materially thinner evidence base for large-scale branch/SD-WAN deployment. Commercial opacity and tier-gating risk are real but at least directionally corroborated by multiple independent analyses, which is a stronger evidentiary position than a single anecdote would give. This profile is solid enough to support initial shortlist guidance for security-first and US public-sector buyers specifically, but the flagged UK/EU compliance gaps and branch-evidence gap should be closed out with Zscaler directly before use in a high-stakes procurement decision. | Whole profile | Medium-High overall | Recommend direct Zscaler engagement to close the flagged evidence gaps, mirroring the same next step recommended for the Cato profile.","confidence":"medium_high","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]},{"id":"evaluations:fd9ca03c2137b91201722f5c","evaluation_type":"summary","finding":"SSE deployment to remote users | Client Connector or clientless rollout to remote/mobile users; NOV's COVID-19-driven scale-up to 27,500 remote users is the standout evidence point | IdP integration (Okta) generally a prerequisite for user-aware policy | End-user self-install typical | Not itemised | NOV: leadership described being able to commit to supporting all 27,500 users working remotely on short notice | Not itemised | Not detailed | Genuinely strong, large-scale, real-world evidence - arguably stronger than the equivalent Cato row, since NOV's story includes both scale (27,500 users) and a clear time-pressure context (pandemic onset).","buyer_implication":null,"qualification":"Client Connector or clientless rollout to remote/mobile users; NOV's COVID-19-driven scale-up to 27,500 remote users is the standout evidence point | IdP integration (Okta) generally a prerequisite for user-aware policy | End-user self-install typical | Not itemised | NOV: leadership described being able to commit to supporting all 27,500 users working remotely on short notice | Not itemised | Not detailed | Genuinely strong, large-scale, real-world evidence - arguably stronger than the equivalent Cato row, since NOV's story includes both scale (27,500 users) and a clear time-pressure context (pandemic onset).","confidence":"unresolved","verified_date":"2026-07-22T00:00:00.000Z","freshness_state":"current","evidence_source_ids":[]}],"evidence_sources":[{"id":"evidence:zscaler:11","url":"https://techzine.eu/blogs/security/141973/zscaler-optimizes-zero-trust-for-agentic-ai-security/","title":"Techzine - Zscaler optimizes Zero Trust for agentic AI security (reporting on a Zscaler announcement)","publisher":"","publication_date":"2026-06-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:1","url":"https://zscaler.com/learn/company-faq","title":"Zscaler - Company FAQ","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:30","url":"https://zscaler.com/compliance/overview","title":"Zscaler - Compliance Centre overview","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:24","url":"https://zscaler.com/privacy-compliance/compliance","title":"Zscaler - Compliance and Security Standards","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:18","url":"https://zscaler.com/customers/autonation","title":"Zscaler - Customer Story: AutoNation","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:17","url":"https://zscaler.com/customers/baker-baker","title":"Zscaler - Customer Story: Baker & Baker","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:20","url":"https://zscaler.com/customers/csc","title":"Zscaler - Customer Story: CSC","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:19","url":"https://zscaler.com/customers/mindbody","title":"Zscaler - Customer Story: Mindbody","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:21","url":"https://zscaler.com/customers/nov","title":"Zscaler - Customer Story: NOV","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:22","url":"https://zscaler.com/customers/ust","title":"Zscaler - Customer Story: UST","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:23","url":"https://zscaler.com/customers/zscaler","title":"Zscaler - Customer Story: Zscaler on Zscaler","publisher":"","publication_date":"2025-12-23T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:14","url":"https://zscaler.com/datasecurity","title":"Zscaler - Data Security product page","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:28","url":"https://zscaler.com/industries/government-cisa","title":"Zscaler - Government Cybersecurity / Federal Cybersecurity (CJIS, CMMC Level 2)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:27","url":"https://zscaler.com/zpedia/zero-trust-architecture-compliance","title":"Zscaler - How Zero Trust Architecture Supports Regulatory Compliance","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:46","url":"https://zscaler.com/partners/technology/operations","title":"Zscaler - Operations Technology Partners page (CrowdStrike, Okta, SentinelOne, Anomali, Recorded Future, Cyware, EclecticIQ integrations)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:41","url":"https://zscaler.com/resources/data-sheets/zscaler-premium-support-advanced-plus.pdf","title":"Zscaler - Premium Support Advanced Plus data sheet","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:42","url":"https://zscaler.com/resources/data-sheets/zscaler-premium-support-advanced.pdf","title":"Zscaler - Premium Support Advanced data sheet","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:10","url":"https://zscaler.com/learn/products-and-solution-faq","title":"Zscaler - Products & Solutions FAQ","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:38","url":"https://zscaler.com/legal/sla-support","title":"Zscaler - SLA & Support legal page (MDR, Business Insights SLAs)","publisher":"","publication_date":"2026-03-31T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:5","url":"https://help.zscaler.com/downloads/zero-trust-branch/reference-architecture/secure-internet-access-zscaler-zero-trust-branch/secure-internet-access-with-zscaler-zero-trust-branch.pdf","title":"Zscaler - Secure Internet Access with Zscaler Zero Trust Branch (reference architecture guide)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:16","url":"https://zscaler.com/products-and-solutions/securing-generative-ai","title":"Zscaler - Securely Use Generative AI with Zscaler Zero Trust Exchange","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:15","url":"https://zscaler.com/blogs/product-insights/securing-gen-ai-and-microsoft-copilot-how-zscaler-data-protection-keeps","title":"Zscaler - Securing GenAI and Microsoft Copilot with Zscaler Data Security","publisher":"","publication_date":"2026-04-16T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:39","url":"https://zscaler.com/resources/data-sheets/zscaler-support-essentials.pdf","title":"Zscaler - Support Essentials data sheet (P1-P4 SLA response times)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:43","url":"https://zscaler.com/resources/data-sheets/zscaler-support-guide-for-government-users.pdf","title":"Zscaler - Support Guide for US Government Cloud Customers data sheet","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:45","url":"https://zscaler.com/resources/data-sheets/zscaler-support-plus.pdf","title":"Zscaler - Support Plus data sheet","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:29","url":"https://zscaler.com/industries/public-sector/state-and-local","title":"Zscaler - Zero Trust Cybersecurity Solutions for State and Local Government","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:47","url":"https://zscaler.com/partners/okta-and-crowdstrike","title":"Zscaler - Zero Trust Security with Zscaler, Okta, and CrowdStrike (partner page)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:25","url":"https://zscaler.com/industries/public-sector/federal","title":"Zscaler - Zero Trust Solutions for Federal Government","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:26","url":"https://zscaler.com/privacy-compliance/ccpa","title":"Zscaler - Zscaler and the CCPA","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:37","url":"https://tr.tradingview.com/news/reuters.com,2025-07-01:newsml_Zaw4fzX3y:0-pressr-zscaler-expands-public-data-centre-footprint-in-ksa-to-secure-digital-transformation","title":"Zscaler - press release (via Reuters/TradingView): Zscaler Expands Public Data Centre Footprint in KSA","publisher":"","publication_date":"2025-07-01T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:35","url":"https://zscaler.com/press/zscaler-extends-edge-compute-now-operating-over-150-data-centres","title":"Zscaler - press release: Extends Edge Compute, Now Operating in Over 150 Data Centres","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:36","url":"https://zscaler.com/press/zscaler-powers-its-global-data-centres-and-offices-100-renewable-energy","title":"Zscaler - press release: Powers its Global Data Centres and Offices with 100% Renewable Energy (150+ data centres)","publisher":"","publication_date":"2021-11-18T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:34","url":"https://ir.zscaler.com/news-releases/news-release-details/zscaler-significantly-expands-global-sovereignty-zero-trust","title":"Zscaler - press release: Significantly Expands Global Sovereignty on Zero Trust Exchange Platform (160+ data centres, dedicated logging planes)","publisher":"","publication_date":"2026-03-12T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:12","url":"https://ir.zscaler.com/news-releases/news-release-details/zscaler-unveils-new-product-innovations-secure-agentic-ai","title":"Zscaler - press release: Unveils New Product Innovations to Secure Agentic AI","publisher":"","publication_date":"2026-06-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:32","url":"https://zscaler.com/press/zscaler-achieves-zero-trust-security-service-fedramp-high-authorization","title":"Zscaler - press release: Zscaler Achieves FedRAMP High Authorization","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:31","url":"https://zscaler.com/press/zscaler-achieves-iso-27001-certification-its-cloud-security-service","title":"Zscaler - press release: Zscaler Achieves ISO 27001 Certification for Cloud Security","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:44","url":"https://help.zscaler.com/support-offerings","title":"Zscaler Help Portal - Support Offerings","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:2","url":"https://sec.gov/Archives/edgar/data/1713683/000171368326000047/zs-01312026_991.htm","title":"Zscaler, Inc. - SEC Form 8-K (FY2026 earnings release)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:50","url":"https://help.zscaler.com/downloads/zscaler-technology-partners/identity/zscaler-okta-and-crowdstrike-deployment-guide/Zscaler-Okta-CrowdStrike-Deployment-Guide-FINAL.pdf","title":"Zscaler/Okta/CrowdStrike - joint Business Development / Deployment Guide","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_1","source_status":"current"},{"id":"evidence:zscaler:48","url":"https://okta.com/blog/customers-and-partners/beyond-the-perimeter-how-okta-crowdstrike-and-zscaler-deliver-end-to-end-zero-trust/","title":"Okta - Beyond the perimeter: How Okta, CrowdStrike, and Zscaler deliver end-to-end Zero Trust (Okta's own blog, independent named company)","publisher":"","publication_date":"2025-09-03T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_2","source_status":"current"},{"id":"src_financial_services_fin_486","url":"https://www.zscaler.com/customers/abanca","title":"ABANCA Case Study | Customer Stories | Zscaler","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:58","url":"https://bestnegotiationconsultingfirms.com/blog/zscaler-enterprise-licensing-pricing.html","title":"Best Negotiation Consulting Firms - Zscaler Enterprise Licensing & Pricing Guide 2026 (third-party)","publisher":"","publication_date":"2026-02-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:33","url":"https://cabrilloclub.com/insights/tools/fedramp-finder/zscaler-govt-cloud","title":"Cabrillo Club - Zscaler Government Cloud FedRAMP Finder entry (third-party)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_476","url":"https://www.zscaler.com/customers/capitec-bank-limited","title":"Capitec Bank Limited | Zscaler","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:56","url":"https://checkthat.ai/brands/zscaler/pricing","title":"CheckThat.ai - Zscaler Pricing 2026: Plans, Costs & TCO (third-party)","publisher":"","publication_date":"2026-03-30T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:60","url":"https://cybersecurityo.com/iam-vendors/zscaler-zero-trust-review/","title":"CyberSecurityO - Zscaler Review 2026: Zero Trust Platform (third-party)","publisher":"","publication_date":"2026-04-01T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_475","url":"https://www.zscaler.com/customers/fannie-mae","title":"Fannie Mae Case Study | Customer Stories | Zscaler","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_474","url":"https://www.zscaler.com/customers/hastings-direct","title":"Hastings Direct Case Study | Customer Stories | Zscaler","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_478","url":"https://www.zscaler.com/blogs/product-insights/how-zscaler-dspm-helps-europe-s-financial-sector-achieve-dora-compliance","title":"How Zscaler DSPM Helps Europe's Financial Sector Achieve DORA Compliance","publisher":"zscaler.com","publication_date":"2025-07-30T00:00:00.000Z","verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:57","url":"https://itqlick.com/zscaler/pricing","title":"ITQlick - Zscaler Pricing 2026: Hidden Costs & Total ROI (third-party)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:9","url":"https://useluminix.com/reports/company-overviews/zscaler-company-overview-zero-trust-security-platform-financials-and-market-position-2026","title":"Luminix - Zscaler Company Overview report (third-party)","publisher":"","publication_date":"2026-03-03T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:55","url":"https://nosavenopay.com/blog-zscaler-enterprise-pricing","title":"NoSaveNoPay - Zscaler Pricing: Zero Trust Network Access Enterprise Cost (third-party)","publisher":"","publication_date":"2025-09-01T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_485","url":"https://www.zscaler.com/customers/onemain-financial","title":"OneMain Financial Case Study | Customer Stories | Zscaler","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:4","url":"https://pitchbook.com/profiles/company/55108-72","title":"PitchBook - Zscaler company profile","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:53","url":"https://redresscompliance.com/zscaler-enterprise-licensing-guide.html","title":"Redress Compliance - Zscaler Enterprise Licensing Guide 2026","publisher":"","publication_date":"2026-02-09T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_484","url":"https://www.zscaler.com/privacy-compliance/customer-compliance/pci-dss","title":"SASE Solutions for PCI DSS 4.0 Compliance & Enhanced Security","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:8","url":"https://sase.cloud/vendors/zscaler","title":"SASE.cloud - Zscaler vendor profile (third-party comparison site)","publisher":"","publication_date":"2026-02-15T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:6","url":"https://thenetworkdna.com/2026/03/zscaler-zero-trust-network-access-ztna.html","title":"The Network DNA - Zscaler ZTNA Architecture & Configuration Guide (third-party technical blog)","publisher":"","publication_date":"2026-03-17T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_481","url":"https://www.zscaler.com/blogs/product-insights/understanding-zscaler-s-approach-digital-sovereignty-modern-era","title":"Understanding Digital Sovereignty in the Modern Era","publisher":"zscaler.com","publication_date":"2025-07-01T00:00:00.000Z","verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:52","url":"https://vendr.com/marketplace/zscaler","title":"Vendr - Zscaler Software Pricing & Plans 2026","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:54","url":"https://venn.com/learn/zscaler-pricing/","title":"Venn - Zscaler Pricing in 2026 (third-party)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:49","url":"https://wwt.com/lab/zscaler-internet-access-crowdstrike-and-okta-integration-lab","title":"WWT (Zscaler partner) - ZIA/CrowdStrike/Okta Integration Lab","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:13","url":"https://wwt.com/product/zscaler-ai-security/overview","title":"WWT (Zscaler partner) - Zscaler AI Security overview","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:59","url":"https://webasha.com/blog/zscaler-zero-trust-exchange-in-2025-how-it-secures-remote-work-cloud-applications-and-user-access-with-zero-trust-architecture","title":"Web Asha Technologies - Zscaler Zero Trust Exchange in 2026 (third-party blog)","publisher":"","publication_date":"2025-04-05T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:7","url":"https://zerometric.net/review/zscaler-zero-trust-exchange/","title":"ZeroMetric - Zscaler Zero Trust Exchange 2026 Review (third-party)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:51","url":"https://zerotrustcost.com/zscaler-pricing","title":"ZeroTrustCost.com - Zscaler Pricing 2026 (third-party analysis summarising AWS Marketplace listing prices)","publisher":"","publication_date":"2026-06-14T00:00:00.000Z","verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_487","url":"https://www.zscaler.com/resources/data-sheets/zscaler-nanolog-streaming-service.pdf","title":"Zscaler Nanolog Streaming Service data sheet","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_479","url":"https://www.zscaler.com/legal/sla-support","title":"Zscaler SLA Support | Service Level Agreement Documentation","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_482","url":"https://ir.zscaler.com/news-releases/news-release-details/zscaler-security-cloud-receives-fips-140-2-validation-encryption","title":"Zscaler Security Cloud Receives FIPS 140-2 Validation for Encryption","publisher":"ir.zscaler.com","publication_date":"2018-04-11T00:00:00.000Z","verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_480","url":"https://www.zscaler.com/privacy-compliance/subprocessors","title":"Zscaler Sub-Processors: Security & Privacy Standards","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-09-12T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"evidence:zscaler:40","url":"https://slideplayer.com/slide/11219828/","title":"Zscaler Support Best Practices Guide (third-party-hosted slide deck of Zscaler material)","publisher":"","publication_date":null,"verified_date":"2026-07-22T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_manufacturing_mfg_067","url":"https://www.zscaler.com/industries/manufacturing","title":"Zscaler for Manufacturing","publisher":"zscaler.com","publication_date":null,"verified_date":"2026-07-29T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"},{"id":"src_financial_services_fin_477","url":"https://compliance.zscaler.com/","title":"Zscaler's Compliance Center","publisher":"compliance.zscaler.com","publication_date":null,"verified_date":"2026-09-14T00:00:00.000Z","reliability_tier":"tier_3","source_status":"current"}]}