What is Secure Web Gateway (SWG)?
An SWG applies policy to user access to internet web services. It can filter URLs, inspect content, detect malware, apply data controls, and inspect TLS traffic where policy and privacy requirements allow. TLS inspection decrypts and then re-encrypts traffic at the gateway. It is not simply encrypting all web traffic. Access to private enterprise applications is normally a ZTNA function, not the core SWG function.
Why it matters
Internet web traffic can carry malware, unsafe content, and sensitive data. An SWG gives an organization a policy and inspection point for that outbound traffic.
How it works
- A device or network sends internet web requests through the gateway.
- The gateway evaluates the destination, identity, content, and configured data or threat rules.
- The gateway allows, blocks, modifies, or records the request and can inspect TLS traffic when configured to do so.
Example
Managed laptops use a cloud SWG that blocks known malware sites and prevents uploads of specified sensitive data to unapproved web services.
Pomerium boundary
Pomerium protects access to private applications and services with identity-aware policy. It is not an SWG and does not replace controls for general internet browsing or outbound content inspection.
Limits and non-claims
- An SWG does not control non-web protocols unless the service has a separate supported control for them.
- TLS inspection creates certificate, privacy, compatibility, and sensitive-data handling requirements.
- An SWG does not replace identity-aware authorization for private applications.
Evaluation checklist
- Which user, destination, protocol, content, and upload or download action does the gateway evaluate?
- How do TLS inspection, certificate trust, privacy limits, and application authorization interact?
- Can alternate egress, encrypted applications, unmanaged devices, or direct connections bypass it?
