Secure every web request.
On your own infrastructure.
EnforceGate vX is a self-hosted secure web gateway: URL filtering, network access control, SSL/TLS inspection and a captive portal. Enterprise-grade web security that runs inside your perimeter and deploys in minutes, with no cloud dependency: every request is decided on-box, with no backhaul to a vendor cloud.
An operator CLI you already know.
If you run Cisco IOS or Juniper Junos, EnforceGate vX feels like home: a real interactive
CLI with operational, privileged and configuration modes, show verbs and staged
commits. No web console required.
-
Cisco IOS & Juniper Junos, in one shell
It works like the network gear you already run: the same command modes, inline
?help, and a safe staged workflow: you edit a change,commitit, and roll it back if needed. Know Cisco IOS or Juniper Junos? You're productive on day one. -
Up to 150M rules, built for categories
The engine loads up to ~150 million rules in memory and matches every request locally, which is large enough to run full URL-category filtering from your own lists, with no cloud lookup. Benchmarked in under 5 GiB with sub-microsecond decisions that stay flat as the rule set grows.
-
A scriptable toolbox
Every verb is also a flat, scriptable command. Wrap them in your own shell scripts, cron jobs and CI: a sysadmin-friendly environment you can automate end to end, no SDK required.
One gateway. Complete control of web traffic.
Every core capability below ships in every edition: no essential filtering, inspection or policy control locked behind a higher tier. Identity-aware access, the web console and operator SSO unlock with Pro and Enterprise editions.
URL filtering
Allow or deny HTTP and HTTPS by URI, hostname, SNI, user-agent and client IP (MAC on the local segment). Every request gets a per-URL verdict before it leaves your network.
Network access control
Permit or deny by identity principal (users, groups), client posture, or network origin, matched on the same attributes as your URL policies.
SSL/TLS inspection
Three modes: off, peek (SNI) and bump (full decryption), so you choose how much HTTPS visibility each deployment needs. The inspection CA is generated in seconds by the interactive installer.
Captive portal
Block, warn and AUP verdicts redirect the visitor to an in-product explanation page in English, French, German and Italian, with an optional, recorded "Proceed anyway".
Plain-text policies
Edit .policy files with the editor of your choice such as vi, or nano: domain lists, regex, SNI and user-agent matching. The engine saves a snapshot before every reload, so you can roll back to a previous version with a single command.
Git-backed policies
Policies and domain/URL lists are plain-text files kept under git. Every change is versioned and attributed (who changed what, when and why), so you can diff, audit and roll back to any point, with the built-in commands or the git you already know.
Built for the jobs you actually have.
From acceptable-use enforcement to threat control and guest access: one engine, configured to your policy.
Acceptable use & compliance
Enforce what your organisation may browse: block or warn by category, with an Acceptable Use page users acknowledge.
- Domain-list & regex policies
- Audited acknowledgement
- Default-permit or default-deny
Malware, phishing & C2 egress
Stop outbound connections to known-bad destinations before they leave your network, with optional HTTPS inspection.
- Block phishing & C2 domains
- SSL/TLS inspection (opt-in)
- Daily-updated threats feed (add-on)
Guest, kiosks & BYOD
Give unmanaged devices safe, filtered access with a self-service CA install page and per-origin policy, no agent required.
- Self-service CA install page
- Per users / groups / origin rules
- Multilingual captive portal
From signed download to enforcing in three steps.
Verify & install
Download the cosign-signed bundle, verify it, and run the guided installer: it loads the images, starts the stack, and waits for the engine to be ready.
Point your clients
Publish the bundled Squid proxy on :3128 through a PAC/WPAD file, browser or OS proxy settings, or group policy. The connector forwards every request to the engine over the encrypted Defendr protocol.
Write policies & enforce
Edit plain-text .policy rules in the editor of your choice. eghost policy compiles and reloads the engine live: no restart, no dropped connections.
And the policy behind it is a plain-text, human-readable file:
inline comments, unquoted keys, no rigid syntax. Save it in rules.d/ and
it compiles & reloads live.
From a policy edit to an enforced block, live.
An operator defines a policy in the CLI; a matching request gets a verdict and is redirected to the captive portal: the whole path, in real time, on a single appliance.
The enterprise gateway, re-engineered for ownership.
Everything a secure web gateway should give you, without the cloud lock-in, the per-seat bill, or the expensive hardware. Shipped as signed, verifiable images you run and control: no telemetry and runs air-gapped. It scales, too: ~150 million rules matched on-box in sub-microsecond time (see the performance white paper).
Your data stays home
Traffic, policies and logs never leave your infrastructure. No backhaul through a vendor cloud, no data-residency headaches.
Predictable cost
A fraction of a cloud web gateway, priced by edition, not per seat, per Gbps, or per request. You know your spend at signing, with no renewal-time surprises.
Verifiable supply chain
Hardware-anchored signing, in-image integrity checks, and a read-only root filesystem. Trust you can verify, not take on faith.
Swiss engineering & support
Built in the Swiss Alps and supported by the engineers who write the code, with a reply within one business day.
A secure web gateway you run, not a cloud you rent.
How EnforceGate vX stacks up against cloud secure-web-gateway services and on-prem proxy appliances, on the criteria that actually move the needle.
| EnforceGate vX | Cloud SWG / proxy appliance | |
|---|---|---|
| Deployment | Self-hosted container or VM, live in minutes | Proprietary appliance, or forced cloud |
| Your data | Stays inside your network | Backhauled to the vendor cloud |
| Scale | ~150M rules in <5 GiB, sub-µs, all local | Cloud lookups, capped local lists |
| Management | Cisco / Junos-style CLI; plain-text, git-backed policies | GUI console and change tickets |
| Openness | Signed, inspectable, adaptable: ships vi, git, bash |
Sealed, unverifiable appliance |
| Pricing | Flat by edition, no usage metering | Per-seat plus bandwidth tiers |
| Upgrades | In-place, 1–2 min | Maintenance windows, manual patching |
| Lock-in | No cloud or data lock-in: runs on your infrastructure | Deep platform lock-in |
Comparison reflects typical cloud secure-web-gateway and on-prem proxy deployments; capabilities vary by vendor and tier.
Editions that scale with your environment.
Pro
$179 / instance / yr
USD · per instance, per year
For small shops and tech-savvy operators: the full secure web gateway on one instance, with URL filtering, the operator CLI and git-backed policy, plus the AI-curated Exosys domain lists (60+ categories, fully offline, updated several times a day), threat-intelligence feeds, automatic updates and ticketed support. Bundles 25 connector sessions.
Business
$675 / instance / yr
USD · per instance, per year
For SMEs and MSPs: everything in Pro plus Active Directory integration and the user-aware advanced captive portal, the TLS connector that mirrors decrypted traffic to an IDS or DLP, and 40 bundled connector sessions.
Enterprise
Custom
quote-based
For corporate, government and regulated fleets: unlimited scale with high availability, multi-tenant fleet management, directory integration with AD and RADIUS, the TLS connector for IDS/IPS, SSO and RBAC, compliance exports, SLA support, real-time AI threat detection with a captive-portal AI assistant, and the NGFW modules on our roadmap.
What each edition includes. Pro is available today; Business and Enterprise are in development, and their columns describe planned capabilities.
Pro Available |
Business Coming Soon |
Enterprise Coming Soon |
|
|---|---|---|---|
| Core SWG · CLI · git policy | ✓ | ✓ | ✓ |
| No telemetry · verifiable offline | ✓ | ✓ | ✓ |
| Offline / air-gap activation | ✓ | ✓ | ✓ |
| Captive portal | Standard | Advanced | Enhanced |
| Blocklists | Exosys Curated · 60+ categories | Exosys Curated · 60+ categories | Exosys Curated · 60+ categories |
| Threat-intelligence feed | ✓ | ✓ | ✓ |
| AI anomaly & threat detection | ✕ | ✕ | ✓ |
| AI captive-portal assistant | ✕ | ✕ | ✓ |
| Directory integration | ✕ | Active Directory | AD + RADIUS |
| Multi-tenancy · fleet management | ✕ | ✕ | ✓ |
| Bundled connector sessions | 25 | 40 | 50 |
| TLS connector | ✕ | ✓ | ✓ |
| Automatic updates | Online / Automatic | Online / Automatic | Online / Automatic |
| Support | Direct | Advanced | Premium |
| Documentation | User Documentation | Integration & Design guides | Integration & Design guides |
| SSO · SAML · RBAC | ✕ | ✕ | ✓ |
| Compliance exports (CIPA / GDPR) | Basic | Basic | Full + audit log |
| NGFW modules | Add-on | Add-on | Included |
| Best for | Small shops · SOHO · tech-savvy users | SME · MSPs | Corporate · government · large fleets |
| Business and Enterprise are in development; their columns describe planned capabilities, not a commitment to dates or specifications. Prices are in USD per instance per year, excluding VAT; Enterprise is quote-based. | |||
Questions, answered.
The things security and IT teams check before they trial a gateway.
What is a secure web gateway?
How do I block or filter websites across my network?
3128 through the usual proxy settings, whether that is a
PAC or WPAD file, browser or operating-system proxy configuration, or group policy.
That covers anything that speaks HTTP through a proxy, not only workstations and laptops: printers and other appliances, and servers, which you can restrict to the destinations they legitimately need such as package mirrors and vendor update endpoints. Used that way it acts as an HTTP firewall for outbound web traffic.
You then define a policy of what to allow or block: by domain, URL, category (adult content, gambling, social media, malware and more), or by user, group and IP. Every request is decided on-box and can be blocked, warned or redirected to a captive portal, and plain-text policies reload live so you can change what's blocked without downtime. It's a self-hosted way to filter employee or student internet access, and to control what your servers and devices may reach, without a cloud service.
Can I bring my own threat-intel and domain feeds, or am I locked into yours?
Yes, and being open to outside intelligence is a genuine difference from the big vendors. Cloud secure web gateways from the likes of Cisco, Palo Alto Networks and Zscaler are built around their category database and their cloud: you largely enforce the taxonomy they ship, decisions run through their service, and folding in large external feeds or your own intelligence is limited to what the platform chooses to allow.
EnforceGate is open by design. An optional, sandboxed toolbox sidecar ships a real
scripting environment (bash, Python 3,
curl, git,
jq and pip), so you can pull
any source on a schedule: the free
UT1 category corpus,
abuse.ch's
ThreatFox and
URLhaus threat feeds, a
commercial feed you already subscribe to, or your own internal lists. A short script converts each
source into an on-box list and reloads the engine live, and matching stays entirely local, with no
per-request cloud lookup.
This works on every edition. Prefer not to assemble your own? Pro, Business and Enterprise also bundle the Exosys Curated Domain Lists (60+ AI-classified categories), but you can always add, replace or blend in your own sources.
Where does our traffic and data go?
Can I just build this on Squid myself?
How is EnforceGate vX licensed?
More questions? See the full FAQ.
See EnforceGate vX in your own network.
Tell us about your environment and we'll come back with a tailored quote and a deployment plan.