Aryaka's differentiation is the operational model, not the technology. Where Big Six SASE platforms require dedicated networking and security staff to configure, monitor, and maintain, Aryaka sells a fully managed service: Aryaka's NOC/SOC operates the SD-WAN and SSE on behalf of the customer. Where Cato says "we made it simple enough for your team to run," Aryaka says "we'll run it for you." This is the correct answer for organizations that cannot staff a Big Six SASE deployment correctly — a misconfigured Cato or Palo Alto deployment is worse than a well-managed Aryaka one.
Pillar scope: As of this review (2026-07-11), Aryaka is formally scored on four of the five Codex pillars — ZTNA, SSE, SD-WAN, and AIOps. Sovereignty remains out of scope by design (Aryaka has no sovereignty-specific certifications program tracked by this Codex). Aryaka's Unified SASE 2.0 launch (November 2025) added native, GA Universal ZTNA and Next-Gen DLP (NLP-based contextual analysis, OCR, NER-based sensitive data detection) — this is a genuine architecture change, not a co-packaged add-on, and the co-packaged Palo Alto Prisma Access SSE option remains available in parallel for customers who prefer it. AI>Secure (GenAI/shadow-AI threat inspection) shipped as GA as part of this launch; vendor-cited ROI figures are self-reported and unverified. The new ZTNA and SSE scores in scores.json (9 and 10 criteria respectively) are grounded in Aryaka's own product documentation as of July 2026 — several sub-capabilities (agentless access, an enterprise browser, EDM/document fingerprinting, API-mode CASB) are confirmed as not yet shipped or not found in Aryaka's own materials, and are scored conservatively rather than assumed.
Primary fit: Lean IT (P1) and Platform/Network Architect (P4) who want SD-WAN outcomes without SD-WAN operations. Primary limitation: Aryaka's core strength remains managed SD-WAN + AIOps — that operational model is proven and field-validated. ZTNA and SSE are genuine, native capabilities as of November 2025, but they are new: agentless access and an enterprise browser are not yet available, ML-based DLP classification lacks EDM/document fingerprinting, and CASB is inline-only with no API mode found. Organizations with strong internal security ops teams, or complex DLP/CASB requirements, should treat Aryaka's native SSE/ZTNA as directionally credible but not yet field-proven at Big Six depth — pairing with a Big Six SSE (native or Prisma Access) remains a reasonable architecture for those buyers today.
SD-WAN / GLOBAL WAN SERVICES
The Managed Service Distinction
Every Big Six SASE vendor delivers a platform. Aryaka delivers a service. The customer receives network connectivity and security outcomes — not a console to configure. Aryaka's operations team handles provisioning, policy tuning, fault detection, and incident response. The customer's IT team interacts with Aryaka via a portal and a dedicated account team, not via a CLI or policy engine.
This model exists because the Big Six platforms, despite their ZTP and simplification investments, still require skilled engineers to operate correctly. A Cato deployment managed by an undertrained team will develop policy debt, misconfigured security rules, and missed alerts within 18 months. Aryaka's NOC/SOC doesn't have that problem because Aryaka's own staff is accountable for outcomes.
- No internal WAN operations expertise required
- 24×7 NOC/SOC proactively detects and resolves issues before users report them
- SmartConnect private backbone purpose-built for WAN optimization (FEC, dedup, TCP acceleration)
- Strong APAC and emerging market backbone coverage — historically underserved by MPLS alternatives
- Gartner-named in Global WAN Services MQ; also an Honorable Mention in Gartner's July 2025 Magic Quadrant for SASE Platforms (that cycle's Leaders: Palo Alto, Cato, Netskope, Fortinet) — independent validation as a standalone SASE vendor, not just a WAN services player
- Positioned as a Challenger/Outperformer in GigaOm's 2025 SASE Radar — third-party validation from a second analyst firm
- SSE depth trails Big Six for complex DLP/CASB programs
- Less customer-side control — wrong fit for organizations with strong internal security ops teams
- Smaller PoP network (40+) than Cato (85+) or Cloudflare (330+)
- Not a full SASE replacement for organizations with advanced security requirements
- Managed model introduces vendor dependency — exit complexity higher than self-operated platforms
ZTNA Analysis
Aryaka's Universal ZTNA shipped as a native, generally available capability with the November 2025 Unified SASE 2.0 launch — it runs inline within the same OnePASS single-pass PoP stack as NGFW, SWG, IPS, and CASB, rather than as a bolted-on module. Micro-segmentation is enforced at FQDN/IP/port/path granularity with identity, device, and posture context evaluated together. One disclosure worth flagging directly, per Aryaka's own datasheet: the ZTNA client itself is built on Cloudbrink technology, a third-party ZTNA/SD-WAN technology vendor — this is a legitimate architecture fact, not a criticism, but it means Aryaka's ZTNA client is not built entirely in-house.
The Universal ZTNA client performs pre-session device health checks (OS patch level, EDR status, disk encryption) plus continuous re-evaluation via 24-hour certificate rotation and risk-based step-up/block. No named third-party EDR integration partners are disclosed, unlike Palo Alto's or Cato's documented CrowdStrike/SentinelOne integrations — worth a direct question in evaluation if continuous EDR-correlated posture is a requirement. Identity integration uses SAML with major IdPs (Okta, Entra ID), inherits MFA/SSO, and triggers step-up authentication from device posture/risk signals — a real conditional-access mechanism. There is no standalone, continuous user-risk-scoring (UEBA) engine independent of posture.
ZTNA traffic rides Aryaka's existing SmartCONNECT private backbone — vendor-stated sub-30ms backbone latency and sub-20ms latency to the nearest edge, with up to 99.999% availability SLA. Backbone density (40+ PoPs) remains smaller than Cato (85+) or Cloudflare (330+), consistent with Aryaka's existing SD-WAN latency positioning in this Codex. The client covers Windows 10/11, macOS 13+, iOS 15+, and Android 11+ per Aryaka's datasheet. Linux support exists only as a beta command-line client — not yet full-parity GUI coverage — and ChromeOS is not mentioned in Aryaka's materials.
Two capabilities are genuinely not available yet, and this Codex states that plainly rather than spinning it. Agentless access: Aryaka's own FAQ states clientless/agentless access is planned but not shipped — the FAQ describes it as arriving "eventually," stated twice across the November/December 2025 documentation. Universal ZTNA today is agent-based only for every application type. Enterprise browser: Aryaka has no native or partnered enterprise browser product. Browser-session protection is delivered instead through a separate remote browser isolation partnership with Menlo Security (see the SSE section below), which is not the same thing as a dedicated enterprise browser with policy-unified DLP and session controls.
Aryaka's Bandwidth Quality Index (BQI) scores each ZTNA session in real time on latency, jitter, loss, and throughput, with SIEM export — genuine per-session telemetry. No evidence of ISP-level fault attribution or synthetic SaaS-application monitoring comparable to Zscaler ZDX or Netskope DEM was found in Aryaka's materials. Legacy app support is confirmed for agent-based RDP, SSH, and database protocol access via Universal ZTNA; Aryaka's own FAQ flags that specific UDP-based legacy protocol support is not fully documented publicly, so this Codex scores that sub-capability conservatively pending confirmation.
▲ Strengths
Native, GA Universal ZTNA inline within the OnePASS single-pass stack — a genuine architecture change from the co-packaged-only model. Solid device posture, identity, and per-app micro-segmentation. Backbone latency is competitive given PoP count. Real per-session DEM via BQI.
▼ Watch Areas
Agentless access is not shipped — agent required for every app type today. No enterprise browser; browser protection depends on the third-party Menlo Security RBI partnership. ZTNA client is co-developed with Cloudbrink, not built entirely in-house. No named EDR integration partners or standalone UEBA engine. Linux client is beta CLI only. All of this is new (Nov 2025) with no long-term field validation.
SSE Analysis
Next-Gen DLP is enforced within the same OnePASS single-pass architecture as NGFW, SWG, IPS, CASB, and Universal ZTNA, under one policy plane, per Aryaka's own FAQ — architecturally this matches the single-pass definition this Codex applies to Cato and Netskope. Classification uses AI-powered named-entity recognition (NER), contextual/NLP analysis, OCR for images and documents, and API/LLM request-body inspection: a real ML-based approach, not regex-only. The capability launched alongside Universal ZTNA in November 2025, so it carries the same caveat — genuinely capable, but without long-term field validation at Big Six scale.
Corrected 2026-07-22: Aryaka's own Next-Gen DLP datasheet documents Exact Data Match (EDM) classification — hashed-database comparison against known sensitive records — alongside AI-powered NER, contextual/NLP analysis, OCR, and API/LLM request-body inspection. A prior version of this Codex stated EDM was absent; that was a research miss, not a vendor change (the datasheet has been live since at least Feb 2026). The remaining real gap: no named document-fingerprinting/IDM capability was found, unlike the deepest DLP tiers Netskope and Palo Alto document for their platforms.
Dynamic certificate generation and SSL proxy interception are documented on Aryaka's own docs site, but interception is described as rule-based/selective rather than universal by default, and no published throughput or scale metrics were found for TLS decryption capacity per PoP. CASB is a genuine capability — Aryaka's datasheet documents deep inline/proxy enforcement via DPI, with per-app, per-user, and per-activity controls plus Shadow IT discovery, all through the OnePASS architecture. No API-mode CASB for scanning data at rest in sanctioned SaaS repositories (M365, Salesforce, etc.) was found in any Aryaka materials — treat the CASB story as inline-only until that's confirmed otherwise.
RBI has been available since Fall 2024, delivered through a technology partnership with Menlo Security (Secure Cloud Browser) — this is disclosed here because it's a legitimate architecture fact this Codex's "source or flag" standard requires surfacing, not because it's a weakness by itself. Isolated sessions are redirected to Menlo's environment, not an Aryaka-native isolation engine. Aryaka positions RBI as integrated into the same policy and observability fabric as SD-WAN, firewall, and SWG, but the isolation engine itself is third-party — worth knowing before assuming RBI is fully native.
AI>Secure, part of Unified SASE 2.0, provides inline prompt/response inspection for PII, source-code, and credential exposure; prompt-injection/jailbreak blocking; shadow-AI discovery with app risk scores; and compliance mapping to the EU AI Act, ISO 42001, and NIST AI RMF. This is a genuinely developed capability for a new entrant to GenAI security — vendor-cited ROI figures (20–30% incident reduction) are self-reported and unverified, and should be treated as marketing claims pending independent confirmation. Shadow IT / SaaS discovery is documented via the CASB module (dashboard, risk categorization), with shadow-AI discovery handled separately through AI>Secure; no published app-catalog size (a specific "30,000+"-style figure, as Zscaler and Netskope both publish) was found to support a higher tier here.
Cloud-delivered L7 firewalling — app-layer filtering, IPS, URL filtering, TLS inspection — runs through Aryaka's own OnePASS engine. Worth disclosing alongside the Cloudbrink and Menlo Security partnerships noted elsewhere in this document: Aryaka's branch NGFW appliance has historically used licensed Palo Alto VM-series technology for the physical NGFW component. That's a partner-technology dependency, flagged here on the same evidentiary basis this Codex applies to other vendors' component sourcing — not a criticism of FWaaS capability itself.
▲ Strengths
Native, GA Next-Gen DLP inline within OnePASS single-pass architecture. Real ML/NLP-based classification (NER, OCR, contextual analysis). AI>Secure is a genuinely developed GenAI governance capability for a new entrant. RBI available since Fall 2024 (via Menlo Security) and CASB inline enforcement are both functional today.
▼ Watch Areas
No EDM or document fingerprinting in DLP. TLS inspection is rule-based/selective, not universal by default, with no published scale metrics. CASB is inline-only — no API mode found for at-rest SaaS scanning. RBI depends on third-party Menlo Security, not a native isolation engine. Branch NGFW component has historically relied on licensed Palo Alto VM-series technology. All SSE capability is new (Nov 2025) with no long-term field validation at Big Six scale.
SD-WAN Analysis
Aryaka operates its own private global backbone (SmartConnect) with 40+ PoPs, purpose-built for WAN optimization. SLA-backed latency with FEC, packet deduplication, and TCP optimization. For enterprise WAN connectivity in APAC and emerging markets — historically underserved by MPLS alternatives — Aryaka's backbone coverage and performance is frequently cited as superior to Big Six alternatives in terms of consistent middle-mile latency. Application-aware path steering is managed by Aryaka's NOC, not the customer — the operations team monitors SLAs, detects degradation, and reroutes traffic before users are impacted.
SmartConnect is a private global network with SLA-backed fiber interconnects between PoPs. Unlike Cato's backbone (which also serves the SSE enforcement function), Aryaka's backbone is purpose-built for WAN transport optimization — FEC, packet duplication, and TCP acceleration are the primary design goals. This makes Aryaka's WAN performance story particularly strong for latency-sensitive workloads: financial transactions, unified communications, cloud ERP.
Aryaka deploys physical CPE (Aryaka WAN PoP) at customer locations that auto-registers with the SmartConnect backbone. The CPE is managed by Aryaka — firmware updates, policy changes, and troubleshooting are handled by Aryaka's team, not the customer's IT staff. ZTP is available; Aryaka's on-boarding team typically coordinates the initial deployment with the customer's facilities or network team.
▲ Strengths
Private SLA-backed backbone with WAN optimization (FEC, dedup, TCP acceleration). Strong APAC and emerging market coverage. Managed path steering — Aryaka NOC handles tuning and troubleshooting. Best for global enterprises wanting managed WAN without internal expertise.
▼ Watch Areas
40+ PoPs — fewer than Cato (85+) or Cloudflare (330+). Less transparent than self-managed SD-WAN — customers have limited visibility into backbone routing decisions. Managed model means less control over path policy customization. Not suitable for organizations that need to manage their own SD-WAN policy plane.
AIOps Analysis
Aryaka's AIOps story is unique and shouldn't be evaluated the same way as Big Six platform AIOps. Rather than AI tools for customers to use, Aryaka's NOC/SOC uses AI/ML tools to manage the network proactively on behalf of customers. The 24×7 managed service includes proactive fault detection, automated RCA, and Aryaka engineers contacting customers when issues are detected before users report them.
The Big Six AIOps story is: "here are dashboards, alerts, and policy tools — your team runs them." Aryaka's AIOps story is: "our team runs them for you." For organizations without NOC staff, Aryaka's model delivers operationally superior outcomes to a Big Six platform operated by an undertrained or understaffed team. For organizations with dedicated network engineers who want full control and visibility, Aryaka's managed model is constraining.
Aryaka's NOC monitors path performance and application experience metrics continuously. When a degradation trend is detected, the NOC investigates and remediates before the SLA is breached and before users open helpdesk tickets. This is structurally equivalent to Cato's predictive path optimization — the difference is that Cato uses algorithms, and Aryaka uses a combination of algorithms and human engineers. The outcome is similar; the operational model is different. Aryaka's November 2025 Unified SASE 2.0 launch introduced AI>Observe (real-time threat detection and network visibility) and AI>Perform (proactive performance analytics), extending the NOC's ability to detect anomalies and reroute traffic before customers observe impact.
▲ Strengths
24×7 NOC/SOC proactive monitoring and remediation — customers don't need AIOps tools if Aryaka's team is operating them. Proactive fault detection before user-reported tickets. Best AIOps for organizations without dedicated NOC/NetOps staff. MTTR typically better than self-operated platforms for the same buyer profile.
▼ Watch Areas
Limited customer-side AIOps tooling — less suitable for organizations that want to run their own incident correlation and policy automation. Security AIOps (UEBA, cross-product correlation) depends on the SSE tier chosen. Not comparable to Palo Alto Cortex XDR or Zscaler ZDX for organizations with dedicated SecOps teams.
Persona Fit Summary
| Persona | Aryaka Fit | Primary Reason | Watch |
|---|---|---|---|
| Lean IT SMB–Mid-market | PRIMARY | Managed SASE delivers outcomes without requiring the lean team to operate a platform. Cato is the primary self-operated alternative; Aryaka is the right answer when the team genuinely cannot staff platform operations. | SSE depth ceiling — if DLP sophistication requirements grow, the team may need to separate SSE from WAN. |
| Global Security Ops Large Enterprise | NOT RECOMMENDED | Large security ops teams want control, visibility, and policy ownership — exactly what Aryaka's managed model removes. Palo Alto or Zscaler serve this persona. | — |
| Data-First / Regulated Finance · Healthcare · Legal | PARTIAL | Aryaka SD-WAN as the connectivity layer paired with Netskope or Palo Alto SSE/ZTNA is viable for regulated organizations that need managed WAN without sacrificing compliance-grade DLP. | Aryaka's native SSE/ZTNA is now pillar-scored (see ZTNA and SSE sections above), but DLP lacks EDM/document fingerprinting and CASB is inline-only — not yet at Big Six depth for the most demanding compliance programs. Architect as Aryaka WAN + Big Six SSE pairing for those buyers today. |
| Platform / Network Architect 500–5,000 employees | ALTERNATIVE | For organizations with global branch connectivity requirements and APAC/emerging market footprint where Cato's 85 PoP coverage is insufficient, Aryaka's managed backbone is a credible alternative. Cato remains primary if self-operated is acceptable. | Less customer control over SD-WAN policy plane than Cato. Managed model dependency. Verify APAC PoP coverage matches the specific deployment geography. |
Changelog
| Date | Version | Change |
|---|---|---|
| 2026-07-22 | v1.5 | Codex-wide accuracy review pass: corrected dlp_ml_classification note — Aryaka's own Next-Gen DLP datasheet confirms EDM classification (score 3→4 in scores.json); the prior "no EDM" claim was a research miss, not a vendor change. Reworded "co-developed with Cloudbrink" to "built on Cloudbrink technology" to match Aryaka's own licensing language. Flagged (not applied): Aryaka's current ZTNA datasheet lists a "Clientless access option" as a Tier 3 licensing feature even though the FAQ still frames agentless access as future — worth a recheck next cycle before raising agentless_access from 1. |
| 2026-07-11 | v1.4 | Full ZTNA + SSE pillar scoring added (9 + 10 criteria) following Unified SASE 2.0 launch. New sections added for both pillars. Scores are conservative where public documentation is thin (agentless_access=1, enterprise_browser=1 — genuinely not yet shipped; dlp_ml_classification=3 — no EDM/fingerprinting found). Disclosed Cloudbrink (ZTNA client) and Menlo Security (RBI) technology partnerships. |
| 2026-07-10 | v1.3 | Codex review pass: reconciled BLUF with the doc's own Nov 2025 Unified SASE 2.0 changelog entry — SSE/ZTNA are now native+GA, not purely co-packaged. Corrected "not in SASE MQ" claim (Aryaka is a July 2025 Honorable Mention). Formal ZTNA/SSE pillar scoring flagged as pending, not performed this pass. |
| 2026-04-20 | v1.1 | Corrected Gartner Peer Insights label (not MQ); added ZTNA scope note (Nov 2025 Universal ZTNA launch); added AI>Observe, AI>Perform, and Next-Gen DLP references from Unified SASE 2.0. |
| 2026-04-19 | v1.0 | Initial working document created under v2.0 Codex structure. Content extracted and expanded from sase_emerging.html contextual analysis. Aryaka scored on SD-WAN and AIOps pillars; SSE and ZTNA null by design (co-packaged, not proprietary). |