Secure every web request.
On your own infrastructure.
EnforceGate vX is a self-hosted secure web gateway: URL filtering, network access control, SSL/TLS inspection and a captive portal. Enterprise-grade web security that runs inside your perimeter and deploys in minutes, with no cloud dependency: every request is decided on-box, with no backhaul to a vendor cloud.
No cloud lookup, no telemetry, your own the data.
An operator CLI you already know.
If you run Cisco IOS or Juniper Junos, EnforceGate vX feels like home: a real interactive
CLI with operational, privileged and configuration modes, show verbs and staged
commits. No web console required.
-
Cisco IOS & Juniper Junos, in one shell
It works like the network gear you already run: the same command modes, inline
?help, and a safe staged workflow: you edit a change,commitit, and roll it back if needed. Know Cisco IOS or Juniper Junos? You're productive on day one. -
Up to 150M rules, built for categories
The engine loads up to ~150 million rules in memory and matches every request locally, which is large enough to run full URL-category filtering from your own lists, with no cloud lookup. Benchmarked in under 5 GiB with sub-microsecond decisions that stay flat as the rule set grows.
-
A scriptable toolbox
Every verb is also a flat, scriptable command. Wrap them in your own shell scripts, cron jobs and CI: a sysadmin-friendly environment you can automate end to end, no SDK required.
One gateway: complete control
Take control of your web traffic to reduce your exposure to security threats, with no data ever shared with a vendor.
URL filtering
Allow or deny web traffic by URI, hostname, SNI, user-agent and client IP. Every request gets a per-URL verdict before it leaves your network.
Network access control
Permit or deny by identity principal (users, groups), client posture, or network origin, matched on the same attributes as your URL policies.
SSL/TLS inspection
Three modes: off, peek (SNI) and bump (full decryption), so you choose how much HTTPS visibility each deployment needs. The inspection CA is generated in seconds by our interactive installer.
Captive portal
Block, warn and AUP verdicts redirect the visitor to an in-product explanation page in English, French, German and Italian, with an optional, recorded "Proceed anyway".
Plain-text policies
Edit .policy files with the editor of your choice such as vi, or nano: domain lists, regex, SNI and user-agent matching. The engine saves a snapshot before every reload, so you can roll back to a previous version with a single command.
Git-backed policies
Policies and domain/URL lists are plain-text files kept under git. Every change is versioned and attributed (who changed what, when and why), so you can diff, audit and roll back to any point, with the built-in commands or the git you already know.
Built for the jobs you actually have.
From acceptable-use enforcement to threat control and guest access: one engine, configured to your policy.
Acceptable use & compliance
Enforce what your organisation may browse: block or warn by category, with an Acceptable Use page users acknowledge.
- Domain-list & regex policies
- Audited acknowledgement
- Default-permit or default-deny
Malware, phishing & C2 egress
Stop outbound connections to known-bad destinations before they leave your network, with optional HTTPS inspection.
- SSL/TLS inspection
- Block phishing websites
- Category-based filtering
Guest, kiosks & BYOD
Give unmanaged devices safe, filtered access with a self-service CA install page and per-origin policy, no agent required.
- Self-service CA install page
- Multilingual captive portal
- Available portal source code
From signed download to enforcing in three steps.
Verify & install
Download the cosign-signed bundle, verify it, and run the guided installer: it loads the images, starts the stack, and waits for the engine to be ready.
Point your clients
Point your hosts at the bundled proxy through a PAC/WPAD file, browser proxy settings, or AD group policy. The connector forwards every request to the engine over the encrypted Defendr protocol.
Write policies & enforce
Edit plain-text .policy rules in the editor of your choice such as vi. Reload the engine policy engine with a single command: no restart, no dropped connections.
And the policy behind it is a plain-text, human-readable file:
inline comments, unquoted keys, no rigid syntax. Save it in rules.d/ and
it compiles & reloads live.
From a policy edit to an enforced block.
An operator defines a policy in the CLI - a matching request gets redirected to the captive portal to warn the user
The enterprise gateway, re-engineered for ownership.
Everything a secure web gateway should give you, without the cloud lock-in, the per-seat bill, or the expensive hardware. Shipped as signed, verifiable images you run and control: no outside telemetry and can run fully air-gapped. It scales, too: ~150 million rules matched on-box in sub-microsecond time (see the performance white paper).
Your data stays home
Traffic, policies and logs never leave your infrastructure. No backhaul through a vendor cloud, no data-residency headaches.
Predictable cost
A fraction of a cloud web gateway, priced by edition, not per seat, per Gbps, or per request. The price you sign up for is the price you renew at.
Verifiable supply chain
Hardware-anchored signing, in-image integrity checks, and a read-only root filesystem. Trust you can verify, not take on faith.
Swiss engineering & support
Built with passion in the Swiss Alps and supported by the same engineers who wrote the code.
A secure web gateway you run, not a cloud you rent.
How EnforceGate vX stacks up against cloud secure-web-gateway services and on-prem proxy appliances, on the criteria that actually move the needle.
| EnforceGate vX | Cloud SWG / proxy appliance | |
|---|---|---|
| Deployment | Self-hosted container or virtual machine (VM) | Proprietary appliance or forced cloud |
| Your data | Stays inside your network | Backhauled to the vendor cloud |
| Scale | Up to 150 million rules in <5 GiB of RAM | Cloud lookups, capped local lists |
| Management | Cisco / Junos-style CLI | Web GUI |
| Openness | Signed, inspectable, adaptable | Sealed, unverifiable appliance |
| Pricing | Flat by edition, no usage metering | Per-seat plus bandwidth tiers |
| Upgrades | Live, seamless upgrades | Required reloads, minutes long downtimes |
Editions that scale with your environment.
Pro
$189 / year
per instance
For small shops and tech-savvy operators: the full secure web gateway on one instance, with URL filtering, the operator CLI and git-backed policy, plus the AI-curated Exosys domain lists (59 categories, fully offline, updated regularly), automatic updates and Direct support. Bundles 25 connector sessions.
Start 30-day free trialor subscribe now · card required, cancel anytime
Business
$675 / year
per instance
For SMEs and MSPs: everything in Pro plus Active Directory integration and the user-aware advanced captive portal, the TLS connector that mirrors decrypted traffic to an IDS or DLP, and the daily threat-intelligence feed. Adds the full documentation set with integration and design guides, Advanced support, and 40 bundled connector sessions.
Enterprise
Ask us
For corporate, government and regulated fleets: unlimited scale with high availability, multi-tenant fleet management, directory integration with AD and RADIUS, TLS connector for IDS/IPS, SSO and RBAC, compliance exports, SLA support, real-time AI threat detection with a captive-portal AI assistant, and the NGFW modules on our roadmap.
Pro Available |
Business Coming Soon |
Enterprise Coming Soon |
|
|---|---|---|---|
| Core SWG · CLI · git policy | ✓ | ✓ | ✓ |
| No telemetry · verifiable offline | ✓ | ✓ | ✓ |
| Offline / air-gap activation | ✓ | ✓ | ✓ |
| Captive portal | Standard | Advanced | Enhanced |
| Blocklists | Exosys Curated · 59 categories | Exosys Curated · 59 categories | Exosys Curated · 59 categories |
| Threat-intelligence feed | Coming soon | ✓ | ✓ |
| AI anomaly & threat detection | ✕ | ✕ | ✓ |
| AI captive-portal assistant | ✕ | ✕ | ✓ |
| Directory integration | ✕ | Active Directory | AD + RADIUS |
| Multi-tenancy · fleet management | ✕ | ✕ | ✓ |
| Bundled connector sessions | 25 | 40 | 50 |
| TLS connector | ✕ | ✓ | ✓ |
| Automatic updates | Online / Automatic | Online / Automatic | Online / Automatic |
| Support | Direct | Advanced | Premium |
| Documentation | User Documentation | Integration & Design guides | Integration & Design guides |
| SSO · SAML · RBAC | ✕ | ✕ | ✓ |
| Compliance exports (CIPA / GDPR) | Basic | Basic | Full + audit log |
| NGFW modules | Add-on | Add-on | Included |
| The Business and Enterprise editions are in development; their columns describe planned capabilities, not a commitment to dates or specifications. Prices are in USD per instance per year, excluding VAT; Enterprise is quote-based. | |||
Questions, answered.
The things security and IT teams check before they trial a gateway.
Is there a free trial?
What is a secure web gateway?
How do I block or filter websites across my network?
That covers anything that speaks HTTP through a proxy, not only workstations and laptops: printers, appliances and servers, which you can restrict to the destinations they legitimately need such as package mirrors and vendor update endpoints. Used that way it acts as an HTTP firewall for outbound web traffic.
You then define a policy of what to allow or block: by domain, URL, category (adult content, gambling, social media, malware and more), or by user, group and IP. Every request is decided on-box and can be blocked, warned or redirected to a captive portal, and plain-text policies reload live so you can change what's blocked without downtime. It's a self-hosted way to filter employee or student internet access, and to control whats your servers and devices may reach, without a cloud service.
Can I bring my own threat-intel and domain feeds, or am I locked into yours?
Yes, and being open to outside intelligence is a genuine difference from the big vendors. Cloud secure web gateways from the likes of Cisco, Palo Alto Networks and Zscaler are built around their category database and their cloud: you largely enforce the taxonomy they ship, decisions run through their service, and folding in large external feeds or your own intelligence is limited to what the platform chooses to allow.
EnforceGate is open by design. An optional, sandboxed toolbox sidecar ships a real
scripting environment (bash, Python 3,
curl, git,
jq and pip), so you can pull
any source on a schedule: the free
UT1 category corpus,
abuse.ch's
ThreatFox and
URLhaus threat feeds, a
commercial feed you already subscribe to, or your own internal lists. A short script converts each
source into an on-box list and reloads the engine live, and matching stays entirely local, with no
per-request cloud lookup.
This works on every edition. Prefer not to assemble your own? The Pro, Business and Enterprise editions also bundle the Exosys Curated Domain Lists (59 AI-classified categories), but you can always add, replace or blend in your own sources.
Where does our traffic and data go?
Can I just build this on Squid myself?
How is EnforceGate vX licensed?
More questions? See the full FAQ.
See EnforceGate vX in your own network.
Tell us about your environment and we'll come back with a tailored quote and a deployment plan.