Full inline SSE - firewall, DLP, CASB and ZTNA - running in your own infrastructure. No vendor cloud in the path. Allod Solutions never sees your traffic.
Cloud SSE vendors (Zscaler, Netskope, Palo Alto Prisma) protect your network by routing your traffic through their infrastructure. The inspection capability and the surveillance exposure are the same thing.
Your traffic shares inspection infrastructure with other tenants. A breach, a legal demand, or a misconfiguration at the vendor affects everyone on the platform.
Every URL, every search, every upload - retained and turned into someone else's data asset. Under GDPR and the CLOUD Act, that log is a subpoena waiting to land.
Contractual privacy promises depend on the vendor's incentives staying aligned with yours - permanently. Architectural constraints don't have that problem.
Every enforcement layer your security team needs - running on hardware you control.
Firewall rules evaluated per-domain before the connection is established. Wildcard domains, domain categories, geo-based rules and process-aware filtering - matched against every outbound request in real time.
Process-awareFive inspection depths - from headers-only to full body - let you tune overhead against sensitivity. Keyword lists, regex patterns and file-type detection trigger configurable actions. Post-detection escalation temporarily upgrades a device to full inspection after a hit. Body samples stored in your own S3 bucket. The same rules reach USB writes and SSH/SCP/rsync/git exfiltration too - channels the HTTP proxy itself can't see - with a git push blocked outright before it completes.
Per-device encryptionEvery outbound connection is classified against the Allod app catalog. Shadow IT surfaces automatically in the dashboard - ranked by fleet coverage, no manual imports. Connect ALLOD DAM and the same classification splits automatically into sanctioned Corporate IT and everything else, using DAM's own approved-systems register - not a second allowlist to maintain by hand. Tenant restrictions allow corporate accounts while blocking personal ones on the same service. Upload controls per category.
App-awareAccess routes pushed to enrolled agents via heartbeat - only traffic matching configured CIDRs tunnels through the connector, everything else goes direct. Connector daemons on private networks dial out to the controller, so agents reach internal resources without inbound firewall rules. Private and public traffic share the same policy engine and event log.
No inbound rulesEvents are written only when a rule triggers - regular traffic is not stored. Each event is encrypted with an HKDF-derived key tied to the originating device, so a breach of one record does not expose others. GDPR Article 15 export and Article 17 erasure are built into the admin UI - no support ticket, no vendor involvement.
Audit-readyThe proxy inspects POST bodies for password fields and alerts when corporate credentials are submitted to a non-approved host. Two signals combine: typosquat detection against your approved app list catches lookalike login pages, and email domain matching identifies company accounts regardless of the destination. Works without IdP log access.
Phishing-awareEvery DNS query intercepted by the agent is scored for high-entropy labels, abnormal lengths, suspicious record types, and query rate to the same apex domain. When the threshold is crossed, the subdomain labels are decoded - base32 and base64url, concatenated and per-label - and the recovered plaintext or hex is attached to the event. Other vendors tell you a query looked suspicious. Allod tells you what it contained. Public DNS-over-HTTPS resolvers are blocked at the proxy layer to prevent bypass.
Payload decodedController and proxy in one binary, SQLite, no external dependencies - operational in minutes. Scale out with stateless proxy nodes in any region; each polls the controller every 30 s and applies updates atomically, with no connection drops. Built-in geo-aware routing connects agents to the nearest healthy proxy automatically.
Your infrastructureALLOD SWG runs entirely in your network. There is no shared cloud between your endpoints and the internet - every packet is inspected on hardware you control and goes nowhere near Allod Solutions infrastructure.
The controller stores your policy. Proxy nodes are stateless and disposable - start one in a new region, point it at the controller, and it's live in seconds. Agents configure the OS proxy and install the CA certificate automatically on enrolment.
Admin UI, policy store, and controller API. In single-node mode the proxy runs here too. In multi-node mode this is the only stateful component.
Stateless CONNECT proxy. Pulls firewall and DLP config from the controller every 30 s and applies changes atomically - no dropped connections during policy updates.
Lightweight daemon on macOS, Windows and Linux. Configures the OS proxy, installs the CA certificate, and heartbeats to the controller.
Optional daemon on private networks. Dials outbound to the controller - no inbound firewall rules needed on the private network side.
VPNs route everything through a tunnel and hand users a broad CIDR range - subnet conflicts, split-tunnel complexity, and full network access once inside.
ALLOD ZTNA pushes configured access routes to agents via heartbeat. Only traffic matching those CIDRs goes through the connector tunnel - everything else goes direct, keeping latency low for regular browsing.
Four steps from raw traffic to a secured, policy-enforced request - all of it on hardware you control.
The agent configures the OS proxy to route outbound traffic to the nearest proxy node.
The proxy decrypts TLS, then evaluates firewall, DLP and CASB rules in memory - process name, user identity, content and TLS fingerprint all considered.
Allow, block or proxy is applied instantly according to your policy - deterministic, explainable, and under your control.
Rule-triggered events are written to the encrypted event log. Traffic that matches no rule is not stored.
ALLOD SWG is built to work alongside your existing security tools - not replace them. Identity, threat intelligence, EDR and observability all connect through standard protocols.
SCIM v2 keeps users and groups in sync from your IdP - Okta, Microsoft Entra ID, Authentik or any SCIM-compliant provider. Policies can be scoped per user or group without manual imports. Admin login via OIDC. CA distribution to MDM-managed devices via SCEP, so agents trust the proxy certificate automatically on enrolment. Proxy egress IPs are pushed automatically to Okta Network Zones and Entra ID Named Locations when proxies register - lock your IdP to only accept logins that pass through the gateway without any manual allowlist management.
Okta · Entra ID · AuthentikConnect one or more MISP instances to block domains, IPs and TLS fingerprints (JA3/JARM/JA4) sourced from your own threat feeds. The abuse.ch SSL Blacklist maps JA3 fingerprints to malware families in real time. JA4DB provides community-curated application fingerprints. Complemented by on-device DGA detection, typosquatting checks, and DNS exfiltration detection - which scores every intercepted query for high-entropy labels and abnormal query rates, decodes base32/base64 payloads inline, and blocks public DNS-over-HTTPS resolvers to prevent bypass.
MISP · abuse.ch SSLBL · JA4DB · DNS exfiltrationDLP alerts, firewall blocks, threat feed hits, DGA detections and compliance failures are pushed to CrowdStrike Falcon as custom IOCs - so your SOC sees network and endpoint context in the same platform. The same events are available as structured JSON webhooks for any SOAR or ticketing system.
CrowdStrike Falcon · WebhooksHTTP access events are published to Zeek Broker as Allod::http_request events, letting your existing Zeek or Corelight pipeline consume SWG traffic without format changes. Security alerts are forwarded to Slack or any webhook endpoint. Admin actions are written to a structured audit trail via rsyslog. Swap SQLite for Postgres when your event volume grows.
Book a 30-minute demo with our engineering team. We'll walk through your policy - firewall, DLP, CASB or ZTNA - end to end.