Zedmos
Zedmos SASE beside Zscaler

Zedmos vs Zscaler: SASE on your hubs or in their cloud

Per-user licensing, where inspection happens, jurisdiction, the published SLA and fail-open behaviour, exploit record, MSSP terms and cloud DLP, from Zscaler's own documents and filings, each with its source.

TopicZscaler from their own documentsZedmos
Licensing modelPer-user subscriptions in platform bundles (Essentials Platform, Zscaler Platform) with advanced modules as add-ons, on one- to three-year terms; the Z-Flex programme sells multi-year spend commitments. List prices are not published.Sources: zscaler.com: pricing and plans · Form 10-Q, quarter ended 31 October 2025 · Form 10-K, fiscal 2026Per firewall, not per user. Remote users connect with a standard WireGuard client and there is no per-seat client licence. Prices are quoted, not published.
Where inspection happensIn Zscaler's cloud: the Zero Trust Exchange runs in over 200 public data centres, and traffic is forwarded to it by the Client Connector agent on each device, or by GRE tunnels or a Branch Connector at each site, and inspected there. Customer-hosted Private Service Edges exist as optional extensions of the same cloud service.Sources: Form 10-K, fiscal 2026 · zscaler.com: Client Connector · Zscaler blog: Zero Trust SASE · zscaler.com: Private AccessOn hubs you run: your own firewalls, on your hardware or on ZedmosOS. Remote traffic lands on the hub and meets the whole engine there. Nothing passes through Zedmos, and no agent is required beyond a standard WireGuard client.
JurisdictionZscaler, Inc., a Delaware corporation in San Jose, California, listed on Nasdaq (ZS). Subscriptions are governed by California law with exclusive jurisdiction in Santa Clara County; European log data is stored in Europe by default across 25 European data centres, 19 of them in the EU. 18 U.S.C. § 2713 obliges US providers to disclose customer data regardless of where it is stored.Sources: Form 10-K, fiscal 2026 · Zscaler end user subscription agreement · Zscaler blog: data control across Europe, May 2025 · 18 U.S.C. § 2713A German company. Inspection and logs stay on hubs and a console you run; nothing is stored by Zedmos. Our licence and threat-intelligence services run in Frankfurt.
When the cloud is unreachableA published SLA: ZIA accepts and processes 99.999 % of a customer's transactions each month, with average latency of 100 ms or less for the 95th percentile; service credits are the sole and exclusive remedy. When the service edge is unreachable, the Client Connector's fail-open or fail-close setting either bypasses to direct internet access or blocks web traffic until it reconnects.Sources: Zscaler service level agreements · Zscaler help: fail-open settingsThere is no cloud to lose. Inspection runs on the hub you operate; if a hub stops answering, the console moves the spokes to a backup hub after a silence threshold and a health check. If the console itself is unreachable, every firewall keeps enforcing. No availability SLA is published.
Exploit record0 entries in the CISA Known Exploited Vulnerabilities catalogue (version 2026.09.11).Sources: CISA KEV — Zscaler0 entries as well. Ours is published with our CRA class, an SBOM per release, the disclosure path and the support period, on a page that stays up whatever the number becomes.
MSP billingA Service Provider partner track with partner-only incentives and an MSSP authorisation; Zscaler's public partner pages publish no billing terms or minimums. Metered, non-seat-based products were about 30 % of new and upsell annual contract value in fiscal 2026.Sources: zscaler.com: service providers · Q4 fiscal 2026 earnings call transcriptMSP tier: multi-tenant, unlimited firewalls, billed monthly in arrears on the month-end count. Your brand on the console and on the box.
AI and data loss preventionZscaler Data Security: inline web and email DLP on the cloud proxy, endpoint DLP, multimode CASB and data security posture management, with GenAI Security as an add-on module; all run within the multi-tenant Zero Trust Exchange.Sources: zscaler.com: data protection · zscaler.com: pricing and plansDLP and the AI gateway run on the hub you operate. 61 content detectors; prompts, uploads and files checked before they leave; the model that decides runs on your hardware. Inline only: there is no API-mode connector into a SaaS tenant.
Price changes, 2025–2026No vendor announcement found. A procurement adviser reported substantial increases across core offerings as of 1 August 2025, with some SKUs 35 % or more higher, and Zscaler reported that Z-Flex customers saw an ARR uplift averaging nearly 30 % in fiscal 2026.Sources: NPI Financial, August 2025 · Q4 fiscal 2026 earnings call transcriptPer firewall, quoted on request. There is no per-user count that grows with headcount.
What Zscaler has that Zedmos does notA Leader in Gartner's Magic Quadrant for Security Service Edge for five consecutive years and in the 2026 Magic Quadrant for SASE Platforms, about 11,000 customers including over 40 % of the Forbes Global 2000, fiscal 2026 revenue of $3.35 billion, over 200 data centres, more than 750 billion transactions a day, a published availability SLA, and the ThreatLabz research team.Sources: zscaler.com: Gartner Magic Quadrant SSE · Form 10-K, fiscal 2026 · ThreatLabzNone of those. A small German vendor whose SASE runs on your own hubs, with a published exploit record, a console you own, and a licence that does not care which box it runs on.

Zscaler operates the largest inline security cloud in the world, and nothing on this page disputes that. The comparison is about where inspection happens, what is licensed, under whose law, and what happens when the cloud is unreachable. Every claim on the left carries its source; if one is wrong, write to us and it will be corrected.

Checked: 2026-09-13

Is Zedmos an alternative to Zscaler?

Zedmos is compared with Zscaler above on licensing, management, jurisdiction, exploit record and what each is delivered as. Zedmos is software on hardware you own, managed from a console you host yourself or use hosted from Frankfurt, licensed per firewall, from a German vendor under EU law, with zero entries in the CISA Known Exploited Vulnerabilities catalogue. The last row of the table is what Zscaler has that Zedmos does not.

All comparisonsOur exploit record