Zscaler vs Cato: best SASE platform for enterprise GenAI security in production
We are a ZIA/ZPA shop, roughly 4,000 seats, renewal in about seven months. Not shopping for the sake of it, but the AI requirements landed after our last contract and I want to know whether we are better off expanding here or looking at Cato.
Where we are with Zscaler on the AI side: SSL inspection is solid, the AI app category exists, DLP works about as well as our policies deserve. What I am less clear on is inline prompt-level control versus app-level allow/block, and how much of the newer AI functionality is included versus a separate SKU.
The Cato pitch we got leaned heavily on single-pass processing and one policy engine covering network, security, and AI, plus their inline inspection story. Sounded clean in the demo. Skeptical of demos.
Asking here specifically because I want the incumbent perspective: if you have added AI controls on top of an existing ZIA deployment, was it configuration or a new purchase; how has inspection performance held up on streaming LLM responses; has anyone actually evaluated Cato head to head and stayed, and what kept you; and for anyone who left, what was the deciding factor?