Secure Web Gateway (SWG)
Filter the web. Protect every user.
Cato SWG adds a layer of protection from internet threats and enforces corporate standards for website access.
Block the bad sites. Before they load.
Block malicious, compromised, phishing, and parked domains with an always-current blacklist.
One web policy. Everywhere, instantly.
Ready-to-use policies aligned to security best practices are enforced uniformly across the entire enterprise the moment you enable them.
The open web is an open door.


Web-borne threats
Phishing, malware delivery, and compromised sites expose users to attacks the moment a page loads.
Policy circumvention
Users preview images and video through search engines, bypassing organizational content and compliance policies.
Inconsistent enforcement
Web policy applied unevenly across users, locations, and devices leaves gaps — and compliance risk.
No web visibility
Without normalized event data, security teams can't see who accessed what — or prioritize their response.
Filter the web.
Enforce it everywhere.
Web access is everywhere, and so is web-borne risk. Cato SWG inspects and controls all internet traffic from the cloud — including encrypted sessions — enforcing one access and threat policy for every user and location without backhauling to an appliance.
Zero Trust Security (SSE) Solution BriefEnable best-practice policies
Turn on ready-to-use policies aligned to internet security best practices — enforced uniformly across the enterprise.
Categorize and filter
Classify sites across 80+ categories and block malicious, phishing, and parked domains with an always-current blacklist.
Refine and monitor
Refine by user, location, and device; customize notifications; and retain every event for visibility and reporting.
Cato Networks Advanced Security Services
Secure Web Gateway (SWG) Capabilities
Instant protection with 80+ categories
Ready-to-use policies align with internet security best practices and enforce uniformly across the enterprise the moment they're enabled.
- 80+ website classification categories
- Refine by user identity, location, and device posture
- Choose Allow, Block, or Prompt per policy

Defend against phishing and malware sites
Blocking malicious, compromised, phishing, and parked domains reduces user exposure to web-borne threats.
- Always-current blacklist of malicious domains
- Block compromised, phishing, and parked sites
- Log access attempts for analysis and training

Prevent policy circumvention via search
Enforce Safe Search and content restrictions so users can't bypass compliance policies through search engines.
- Enforce Safe Search on popular search engines
- Apply YouTube content restrictions
- Enable in a few clicks for all users and locations

Customizable block and prompt pages
Clear notifications let users request an exception or report an error, and pages can carry your brand and IT contact details.
- Fully customizable block and prompt pages
- Add enterprise branding and IT contact info
- Let users request exceptions or re-categorization

Total visibility with logging and reporting
All event data is retained and normalized into Cato's Data Lake and can be queried with a built-in events engine.
- Pre-defined and custom queries with filters
- Generate PDF reports for auditing or execs
- SIEM-like functionality on a single platform

Watch how Cato does it
Customers love Cato
Microsoft Defender does some web filtering, but it's limited and not as configurable or easy to use as what we can do in Cato with all the different types of filtering groups and SWG features. There's a lot more flexibility we'll have in Cato.
Get a live demo
Secure every interaction across the enterprise, cloud, and AI with the only purpose-built SASE platform.
15–30 minute session with a SASE product expert
Discuss your use cases and how we can help
Live product demonstration where applicable
See Cato in Action
Request received
Thanks, there. A Cato specialist will reach out at to schedule your session.
