Secure every web request.
On your own infrastructure.
EnforceGate vX is a self-hosted secure web gateway — URL filtering, network access control, SSL/TLS inspection and a captive portal. Enterprise-grade web security that runs inside your perimeter and deploys in minutes, with no cloud dependency — every request is decided on-box, with no backhaul to a vendor cloud.
An operator CLI you already know.
If you run Cisco IOS or Juniper Junos, EnforceGate vX feels like home — a real interactive
CLI with operational, privileged and configuration modes, show verbs and staged
commits. No web console required.
-
Cisco IOS & Juniper Junos, in one shell
It works like the network gear you already run — the same command modes, inline
?help, and a safe staged workflow: you edit a change,commitit, and roll it back if needed. Know Cisco IOS or Juniper Junos? You're productive on day one. -
Up to 150M rules — built for categories
The engine loads up to ~150 million rules in memory and matches every request locally — large enough to run full URL-category filtering from your own lists, with no cloud lookup. Benchmarked in under 5 GiB with sub-microsecond decisions that stay flat as the rule set grows.
-
A scriptable toolbox
Every verb is also a flat, scriptable command. Wrap them in your own shell scripts, cron jobs and CI — a sysadmin-friendly environment you can automate end to end, no SDK required.
One gateway. Complete control of web traffic.
Every core capability below ships in every edition — no essential filtering, inspection or policy control locked behind a higher tier. Identity-aware access, the web console and operator SSO unlock with Pro and Enterprise.
URL filtering
Allow or deny HTTP and HTTPS by URI, hostname, SNI, user-agent and client IP (MAC on the local segment). Every request gets a per-URL verdict before it leaves your network.
Network access control
Permit or deny by identity principal (users, groups), client posture, or network origin — matched on the same attributes as your URL policies.
SSL/TLS inspection
Three modes — off, peek (SNI) and bump (full decryption) — so you choose how much HTTPS visibility each deployment needs. The inspection CA is generated in seconds by the interactive installer.
Captive portal
Block, warn and AUP verdicts redirect the visitor to an in-product explanation page in English, French, German and Italian — with an optional, recorded "Proceed anyway".
Plain-text policies
Edit .policy files with the editor of your choice such as vi, or nano — domain lists, regex, SNI and user-agent matching. The engine saves a snapshot before every reload, so you can roll back to a previous version with a single command.
Git-backed policies
Policies and domain/URL lists are plain-text files kept under git. Every change is versioned and attributed — who changed what, when and why — so you can diff, audit and roll back to any point, with the built-in commands or the git you already know.
Built for the jobs you actually have.
From acceptable-use enforcement to threat control and guest access — one engine, configured to your policy.
Acceptable use & compliance
Enforce what your organisation may browse — block or warn by category, with an Acceptable Use page users acknowledge.
- Domain-list & regex policies
- Audited acknowledgement
- Default-permit or default-deny
Malware, phishing & C2 egress
Stop outbound connections to known-bad destinations before they leave your network, with optional HTTPS inspection.
- Block phishing & C2 domains
- SSL/TLS inspection (opt-in)
- Daily-updated threats feed (add-on)
Guest, kiosks & BYOD
Give unmanaged devices safe, filtered access with a self-service CA install page and per-origin policy — no agent required.
- Self-service CA install page
- Per users / groups / origin rules
- Multilingual captive portal
From signed download to enforcing in three steps.
Verify & install
Download the cosign-signed bundle, verify it, and run the guided installer — it loads the images, starts the stack, and waits for the engine to be ready.
Point your clients
Send web traffic through the bundled Squid proxy on :3128. The connector forwards every request to the engine over the encrypted Defendr protocol.
Write policies & enforce
Edit plain-text .policy rules in the editor of your choice. eghost policy compiles and reloads the engine live — no restart, no dropped connections.
And the policy behind it is a plain-text, human-readable file —
inline comments, unquoted keys, no rigid syntax. Save it in rules.d/ and
it compiles & reloads live.
From a policy edit to an enforced block — live.
An operator defines a policy in the CLI; a matching request gets a verdict and is redirected to the captive portal — the whole path, in real time, on a single appliance.
The enterprise gateway, re-engineered for ownership.
Everything a secure web gateway should give you — without the cloud lock-in, the per-seat bill, or the expensive hardware. Shipped as signed, verifiable images you run and control — no telemetry, runs air-gapped, and it never stops filtering when a subscription lapses. It scales, too: ~150 million rules matched on-box in sub-microsecond time — see the performance white paper.
Your data stays home
Traffic, policies and logs never leave your infrastructure. No backhaul through a vendor cloud, no data-residency headaches.
Predictable cost
A fraction of a cloud web gateway — priced by edition, not per seat, per Gbps, or per request. You know your spend at signing, with no renewal-time surprises.
Verifiable supply chain
Hardware-anchored signing, in-image integrity checks, and a read-only root filesystem. Trust you can verify, not take on faith.
Swiss engineering & support
Built in the Swiss Alps and supported by the engineers who write the code — with a reply within one business day.
A secure web gateway you run — not a cloud you rent.
How EnforceGate vX stacks up against cloud secure-web-gateway services and on-prem proxy appliances — on the criteria that actually move the needle.
| EnforceGate vX | Cloud SWG / proxy appliance | |
|---|---|---|
| Deployment | Self-hosted container or VM, live in minutes | Proprietary appliance, or forced cloud |
| Your data | Stays inside your network | Backhauled to the vendor cloud |
| Scale | ~150M rules in <5 GiB, sub-µs, all local | Cloud lookups, capped local lists |
| Management | Cisco / Junos-style CLI; plain-text, git-backed policies | GUI console and change tickets |
| Openness | Signed, inspectable, adaptable — ships vi, git, bash |
Sealed, unverifiable appliance |
| Pricing | Flat by edition — no usage metering | Per-seat plus bandwidth tiers |
| Upgrades | In-place, 1–2 min | Maintenance windows, manual patching |
| Lock-in | No cloud or data lock-in — runs on your infrastructure | Deep platform lock-in |
Comparison reflects typical cloud secure-web-gateway and on-prem proxy deployments; capabilities vary by vendor and tier.
Free to run. Yours to keep.
Start with Lite — free, forever, on a single instance. Pro and Enterprise are on the way for fleets and regulated environments — join the waitlist and we'll tell you when they ship. Every edition is self-hosted, sends no telemetry, runs fully air-gapped, and never stops filtering when a subscription lapses.
Lite
Free
perpetual · commercial use permitted
A single instance with the full core secure web gateway: URL filtering, the operator CLI, git-backed policy, bring-your-own community blocklists, and the open captive portal.
Join Early AccessPro
~$890 / instance / yr
indicative · pricing confirmed at launch
For MSPs and growing teams: multi-tenant fleet management, managed category and threat-intelligence feeds, automatic updates, ticketed support, and a TLS connector that mirrors decrypted traffic for IDS/IPS.
Enterprise
Custom
quote-based
For regulated and large fleets: unlimited scale with high availability, SSO and RBAC, compliance exports, SLA support, and the NGFW modules on our roadmap.
What ships in Lite today, and what's planned for Pro and Enterprise. Everything outside the Lite column is on our roadmap — in development, not shipping yet.
Lite Available |
Pro Coming Soon |
Enterprise Coming Soon |
|
|---|---|---|---|
| Deployment | 1 instance | Up to 10 sites | Unlimited + HA |
| Core SWG · CLI · git policy | ✓ | ✓ | ✓ |
| Never bricks on expiry | ✓ | ✓ | ✓ |
| No telemetry · verifiable offline | ✓ | ✓ | ✓ |
| Offline / air-gap activation | ✓ | ✓ | ✓ |
| Open captive portal | ✓ | ✓ | ✓ |
| Blocklists | Community / bring your own | Managed categories | Managed categories |
| Threat-intelligence feed | ✕ | ✓ | ✓ |
| Directory integration | ✕ | Active Directory | AD + RADIUS |
| Multi-tenancy · fleet management | ✕ | ✓ | ✓ |
| Bundled connector sessions | 10 | 25 | 50 |
| TLS connector | ✕ | ✓ | ✓ |
| Automatic updates | Manual | Online / Automatic | Online / Automatic |
| Support | Community | Email · business hours | Priority SLA |
| Documentation | User docs | Full + Integration & Design guides | Full + Integration & Design guides |
| SSO · SAML · RBAC | ✕ | ✕ | ✓ |
| Compliance exports (CIPA / GDPR) | ✕ | Basic | Full + audit log |
| NGFW modules | ✕ | Add-on | Included |
| Best for | Homelab · SOHO | MSPs · SME | Regulated · large fleets |
| Pro and Enterprise are in development; their columns describe planned capabilities, not a commitment to dates or specifications. Lite is free for a single instance and stays fully operational after release, with no time limit. The Pro price shown is indicative and may change at launch. | |||
Questions, answered.
The things security and IT teams check before they trial a gateway.
What is a secure web gateway?
How do I block or filter websites across my network?
How is EnforceGate vX licensed?
Where does our traffic and data go?
How is EnforceGate vX managed?
Scripted, system-administrator style — drive the engine non-interactively with the
egctl utility and clear, self-describing verbs
(show-version, show-policy-list,
request-policy-reload), ideal for shell scripts, cron and CI.
Interactive, network-engineer style — a modal CLI that blends Cisco IOS and Juniper Junos: add, set, edit, remove, comment and annotate policies, validate them, and roll a change back, all without leaving the session. Staged
edit → commit → rollback will feel familiar to
anyone who runs Junos.
REST Client API (coming soon) — integrate EnforceGate with your own tooling and automation.
In every case the underlying policy configuration is backed by
git, so
every change is versioned, easy to back up, and simple to diff or audit.How large does EnforceGate vX scale?
Can it filter by category?
.policy lists. Matching stays on-box with no cloud category service and
no per-request lookup, and the ~150-million-rule capacity is large enough to load full category sets. You decide
which categories to enforce and how current they are — Exosys doesn't impose a fixed taxonomy.Can it restrict outbound traffic from servers (egress filtering)?
Can I just build this on Squid myself?
Is SSL/TLS inspection legal to enable?
peek reads
only the SNI; bump performs full decryption and requires an explicit, audited
acknowledgement before it will start. Whether decryption is lawful depends on your jurisdiction and the notice
or consent you provide — you remain responsible for that determination. In bump
mode you also distribute the inspection CA to client trust stores, and certificate-pinned applications — many
banking and mobile apps, and some SaaS — can't be decrypted and need explicit bypass rules.How long does deployment take?
How are upgrades performed?
Can it run air-gapped or offline?
What support is included?
Test EnforceGate vX in your own network.
Join the Early Access waiting list. If you're selected, we'll email your invite and the verified download — no credit card, no sales call.
You're on the list.
If you're selected, we'll email with your invite and download.