Zedmos
Zedmos SASE beside Cato

Zedmos vs Cato Networks: SASE on your hubs or in their points of presence

Bandwidth and per-user licensing, where inspection happens, jurisdiction, the SLA and Internet Recovery behaviour, exploit record, MSP pools and cloud DLP, from Cato's own knowledge base and terms, each with its source.

TopicCato Networks from their own documentsZedmos
Licensing modelSubscription only, with a minimum term of twelve months: sites licensed by bandwidth, remote users per named ZTNA User, and the Socket edge appliance paid per device over the contract term with hardware refresh included. Threat Prevention, CASB, DLP and the AI security products are Premium Security items on top of the base products.Sources: Cato knowledge base: product catalog · Cato knowledge base: hardware · Cato master subscription agreementPer firewall, not per site bandwidth or per user. The hub is your own firewall on your own hardware or on ZedmosOS; remote users connect with a standard WireGuard client and there is no per-seat licence.
Where inspection happensIn Cato's cloud: the Socket's default behaviour is to route all traffic to a Cato point of presence for inspection, and the Socket itself is a connectivity appliance whose only local function is a LAN firewall. Cato states 95+ points of presence on Cato-owned infrastructure.Sources: Cato knowledge base: Socket LAN firewall · Cato knowledge base: connecting sites · Cato knowledge base: SASE sovereigntyOn hubs you run: your own firewalls, on your hardware or on ZedmosOS. Site and remote traffic lands on the hub and meets the whole engine there. Nothing passes through Zedmos.
JurisdictionCato Networks Ltd., a privately held company in Tel Aviv, Israel, valued above $4.8 billion at its 2025 Series G; contracting entities include Cato Networks (EU) B.V. under Dutch law and Cato Networks (Germany) GmbH. The data-processing agreement makes Cato a GDPR processor using standard contractual clauses for transfers outside the EEA; the data-hosting sub-processor is Amazon Web Services, Inc. (United States).Sources: Cato master subscription agreement · Cato data processing and privacy agreement · Cato knowledge base: sub-processors · Series G press release, June 2025A German company. Inspection and logs stay on hubs and a console you run; nothing is stored by Zedmos. Our licence and threat-intelligence services run in Frankfurt.
When the point of presence is unreachableA service-level agreement of 99.999 % availability, measured monthly. When the tunnel to the point of presence is lost, the Socket moves immediately to Internet Recovery mode and sends traffic straight to the local ISP; Cato's security protections, such as firewall and IPS, are not applied until the point of presence is reachable again.Sources: Cato master subscription agreement · Cato knowledge base: Internet Recovery · Cato knowledge base: recovery mechanismsThere is no cloud to lose. Inspection runs on the hub you operate; if a hub stops answering, the console moves the spokes to a backup hub after a silence threshold and a health check. If the console itself is unreachable, every firewall keeps enforcing. No availability SLA is published.
Exploit record0 entries in the CISA Known Exploited Vulnerabilities catalogue (version 2026.09.11).Sources: CISA KEV — Cato Networks0 entries as well. Ours is published with our CRA class, an SBOM per release, the disclosure path and the support period, on a page that stays up whatever the number becomes.
MSP billingThe Channel First Partner Program with MSP tracks, starting with no upfront capital expenditure; Cato SMB FlexPool, launched September 2026, lets MSPs buy a pool of licences and bandwidth and self-provision customers from it. No minimum pool size or billing frequency is published.Sources: Channel First Partner Program, May 2025 · Cato SMB FlexPool, September 2026MSP tier: multi-tenant, unlimited firewalls, billed monthly in arrears on the month-end count. Your brand on the console and on the box.
AI and data loss preventionCato DLP and CASB with generative-AI controls, Cato XDR and, from March 2026, Cato AI Security and Neural Edge with NVIDIA GPUs across the backbone; all are functions of the cloud platform, with AI-security sub-processors including AWS, Google Cloud, Microsoft Azure and OpenAI.Sources: Cato press release: GenAI security controls, April 2025 · Cato press release: AI Security and Neural Edge, March 2026 · Cato knowledge base: sub-processorsDLP and the AI gateway run on the hub you operate. 61 content detectors; prompts, uploads and files checked before they leave; the model that decides runs on your hardware, with no third-party sub-processor. Inline only: there is no API-mode connector into a SaaS tenant.
Price changes, 2025–2027No list-price increase found. From January 2027 a Bursting Model bills Bandwidth Pool usage above the licensed capacity, measured at the 95th percentile, as a one-time charge or a capacity expansion.Sources: Cato knowledge base: usage measurementPer firewall, quoted on request. Bandwidth is whatever your hardware carries; there is no pool to exceed.
What Cato has that Zedmos does notA Leader in the Gartner Magic Quadrant for SASE Platforms three years running, more than 4,000 enterprise customers, 2025 annual recurring revenue above $350 million, over $1 billion raised, a private backbone of 95+ Cato-owned points of presence, a published availability SLA, and the Cato CTRL threat-research lab.Sources: Gartner SASE Platforms Magic Quadrant 2026, press release · Cato ARR press release, February 2026 · Cato knowledge base: SASE sovereigntyNone of those. A small German vendor whose SASE runs on your own hubs, with a published exploit record, a console you own, and a licence that does not care which box it runs on.

Cato Networks built the first single-vendor SASE cloud and is a Gartner Leader for it; nothing on this page disputes that. The comparison is about where inspection happens, what is licensed, under whose law, and what happens when a point of presence is unreachable. Every claim on the left carries its source; if one is wrong, write to us and it will be corrected.

Checked: 2026-09-13

Is Zedmos an alternative to Cato Networks?

Zedmos is compared with Cato Networks above on licensing, management, jurisdiction, exploit record and what each is delivered as. Zedmos is software on hardware you own, managed from a console you host yourself or use hosted from Frankfurt, licensed per firewall, from a German vendor under EU law, with zero entries in the CISA Known Exploited Vulnerabilities catalogue. The last row of the table is what Cato Networks has that Zedmos does not.

All comparisonsOur exploit record