European Alternatives to Zscaler

Looking for a European alternative to Zscaler? Zscaler, Inc. is a San Jose, California company; its End User Subscription Agreement is governed by California law with the courts of Santa Clara County, and its data processing agreement names Zscaler, Inc. as processor and relies on standard contractual clauses and the EU-US Data Privacy Framework for transfers out of the EEA.

Eleven European tools cover parts of the job: zero trust access and private networks, firewall-based remote access, DNS-layer web filtering and one managed SASE service, from companies in Germany, Poland, France, Switzerland, Finland, Denmark and the United Kingdom.

11 Alternatives
100% GDPR Compliant
How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy

11 European Alternatives to Zscaler

NetBird

Berlin open-source zero trust network on WireGuard, with a free cloud plan for 5 users and published prices

#1 for replacing Zscaler
Germany

Defguard

Self-hosted WireGuard access platform from Szczecin with connection-level MFA and an AGPL core

#2 for replacing Zscaler
Poland

Systancia

French zero trust remote and privileged access platform (cyberelements Gate), as software or SaaS

#3 for replacing Zscaler
France

Open Systems

Zurich managed SASE service with SD-WAN, firewall, secure web gateway, CASB and ZTNA

#4 for replacing Zscaler
Switzerland

Stormshield

French firewalls with ZTNA host checks, MFA and per-group application policy included at no extra cost

#5 for replacing Zscaler
France

genua genusphere

Browser-based, VPN-free access to internal applications from a German security vendor

#6 for replacing Zscaler
Germany

SSH.com PrivX

Helsinki-listed vendor with passwordless, just-in-time access to servers and applications

#7 for replacing Zscaler
Finland

LANCOM Trusted Access

Cloud-managed trusted access client and VPN from LANCOM, now part of Rohde & Schwarz

#8 for replacing Zscaler
Germany

Sophos ZTNA

Zero trust access that shares device health with Sophos firewall and endpoint, contracted under English law

#9 for replacing Zscaler
United Kingdom

Heimdal DNS Security

Copenhagen DNS-layer web filtering for networks and endpoints, with a free trial

#10 for replacing Zscaler
Denmark

Securepoint Cloud Shield

Lueneburg DNS-based web protection for networks and devices, served from servers in Germany

#11 for replacing Zscaler
Germany

Key takeaways

  • Zscaler, Inc. is a San Jose company whose subscription agreement is governed by California law with the Santa Clara County courts, and whose data transfers from the EEA rest on standard contractual clauses and the EU-US Data Privacy Framework.
  • NetBird (Berlin) is the most open: a Free plan for 5 users and 100 machines, Team at €6 and Business at €12 per user a month, mostly open-source code, and German law.
  • Defguard (Szczecin) is self-hosted with an AGPL core and connection-level MFA, with a free Business tier up to 10 users and one location.
  • Systancia (France) and genua (Germany) sell zero trust access to applications without a classic VPN, as software or as a service, with no published prices.
  • Open Systems (Zurich) is the only one here that sells a managed SASE service with a secure web gateway, but its own site could not be opened for this page.
  • Heimdal and Securepoint filter web traffic at the DNS layer, which is a lighter job than a full web gateway.

Why people leave Zscaler

Zscaler sells security as a cloud service. Companies send their staff's internet traffic and their access to internal applications through it, so that they can replace a VPN and an on-premises web proxy.

Its Private Access product brokers connections between a user and a single approved application instead of giving the user a place on the network, and its own product page lists inline traffic inspection, data loss prevention and browser isolation. It shows no prices: you ask for a demo.

The company is Zscaler, Inc. of San Jose, California. Its End User Subscription Agreement is governed by the laws of California, with the federal and state courts in Santa Clara County as the exclusive venue, and it contains no arbitration clause.

The agreement text does not say which Zscaler entity you contract with. The data processing agreement names Zscaler, Inc. as processor and uses EU standard contractual clauses (with a UK addendum) and the EU-US Data Privacy Framework for transfers out of the EEA.

None of the eleven European tools below copies all of Zscaler. Open Systems comes nearest as a managed service. Most of the others cover the access side (replacing a VPN with per-application access), and two cover only the DNS layer of web filtering. Which one fits depends on which half of the Zscaler job you actually use.

  • Your contract and your court are in California The subscription agreement picks California law and the Santa Clara County courts. For a European buyer, a dispute then means litigating on the other side of the Atlantic. The European tools here contract under German, Polish, French, Swiss, Finnish, Danish or English law, and for NetBird, Defguard and Heimdal the venue is the vendor's home court.
  • Transfers rely on a framework, not on location Zscaler's data processing agreement handles transfers out of the EEA with standard contractual clauses and certification under the EU-US Data Privacy Framework, and it keeps a list of sub-processors with 30 days' notice and a right to object. That is a lawful route, but it depends on a framework that can change. Self-hosted tools like NetBird, Defguard and genua remove the question because the control plane runs where you put it.
  • You may be paying for more than you use Zscaler's platform spans web security, private access, data protection and more, and its pricing is by quote only. A company that mostly wants to retire a VPN may need only the access half, and NetBird, Defguard and Stormshield publish or include that part openly. A company that needs a managed web gateway has fewer European options.
  • The European answers are different kinds of product Three are open-source or self-hostable access platforms, three are French or German security vendors that also sell firewalls or on-premises gateways, one is a managed SASE operator, one is a UK security vendor, and two filter at the DNS layer. Treat the list as a menu of parts, not as eleven like-for-like replacements.

What you have to replace, not just match

Start by splitting what Zscaler does for you into two jobs: private access (staff reaching internal apps and servers) and web security (staff browsing the internet, with filtering and inspection). Check which of the two you actually use and which policies sit on top. Access is the easier job to move; the web gateway with inspection and data loss prevention is where Europe has fewer like-for-like options.

Move access first, in parallel. Install one of the access tools next to Zscaler for a small group, move one application at a time, and keep the old path until the logs show nobody uses it. Do not forget identity: every tool here relies on your identity provider for sign-in and MFA, so the work is mostly mapping groups and policies.

The alternatives compared

European Zscaler alternatives, in the order this page ranks them, compared on headquarters, pricing and jurisdiction
PositionToolHeadquartersPricingJurisdiction
#5 Stormshield Issy-les-Moulineaux, France Enterprise pricing on request EU (France)
#10 Heimdal DNS Security Copenhagen, Denmark Per endpoint, quoted EU (Denmark)

How each alternative compares to Zscaler

#1

NetBird

an open, self-hostable zero trust network with published prices

Best for: Teams that want to replace a VPN with identity-based access and can try it free first

NetBird is run by NetBird GmbH, Rosenthaler Str. 36, Berlin, registered at Amtsgericht Berlin (Charlottenburg) under HRB 237529 B. Its terms are under German law, and for business customers the venue is the registered seat of NetBird GmbH.

It builds a private network of peer-to-peer WireGuard connections with a central access policy. Its repository lists SSO and MFA, group-based access rules, device posture checks, traffic event logging, private DNS and re-authentication. Most code is BSD-3-Clause, and the management, signal and relay parts are AGPLv3, so you can self-host with Docker Compose.

Its pricing page lists Free at €0 for up to 5 users and 100 machines, Team at €6 and Business at €12 per user a month, and Enterprise on request, with extra machines at €0.50 a month on Team and Business. Device approvals, MDM and EDR controls, posture checks and traffic logging are on Business.

What NetBird does better than Zscaler

  • German company under German law, where Zscaler is governed by California law
  • A free plan, published prices and self-hosting, where Zscaler sells by quote
  • Open-source code you can read
  • Simple per-user pricing

Where NetBird is a step down from Zscaler

  • Covers private access only: no web gateway, no inline inspection or data loss prevention
  • A much smaller company and platform than Zscaler
  • Posture checks and logging are on the €12 Business plan
  • Self-hosting makes you responsible for operating it

Standout against Zscaler. It is the only tool here where you can read the code, see the prices and start free before talking to anyone.

#2

Defguard

a self-hosted WireGuard platform with MFA on every connection

Best for: Technical teams that want to run their own access platform and keep all data in their own infrastructure

Defguard Sp. z o.o. is registered at ul. Cyfrowa 6/317, 71-441 Szczecin (KRS 0001168794, EU VAT PL851-332-92-06). Its terms are under Polish law, with the courts competent for its Szczecin seat.

It combines a WireGuard VPN with an identity provider, connection-level MFA (TOTP, WebAuthn, email), firewall rules by user and group, and LDAP or Active Directory sync, and it describes itself as fully self-hosted with no external dependencies. The repository is AGPL for most code, with an enterprise directory under a separate license.

The pricing page lists Open Source as always free, Business as free up to 10 users and one location with paid options, and Enterprise on request. It shows no prices for the paid options.

What Defguard does better than Zscaler

  • Polish company under Polish law with a local court
  • MFA on the WireGuard connection itself
  • A free tier for small teams and an open-source core
  • Nothing leaves your infrastructure when self-hosted

Where Defguard is a step down from Zscaler

  • No web gateway, inspection or data loss prevention
  • Paid Business and Enterprise prices are not shown
  • A young, small vendor compared with Zscaler
  • You run and patch the servers yourself

Standout against Zscaler. It enforces multi-factor authentication on every WireGuard connection and runs entirely on your own servers.

#3

Systancia

a French zero trust access and privileged access platform

Best for: French and European organizations that want ZTNA for IT and industrial systems, as software or as a service

Systancia is SA SYSTANCIA, Actipolis III, Sausheim, France (RCS Mulhouse 419 687 231, capital €2.5 million). Its homepage describes an independent cybersecurity vendor.

Its platform is branded cyberelements: Gate for zero trust remote access to IT and operational technology systems, Cleanroom for zero trust privileged access, Identity for entitlements, and Access for authentication. It calls itself a Product Leader in KuppingerCole's 2024 Leadership Compass for ZTNA and a representative vendor in Gartner's 2023 Market Guide, which are its own statements. Gate is available as software or as a cloud service, and its site says its data centers are in France.

No prices are shown on its site; you contact it.

What Systancia does better than Zscaler

  • French company under French law, with a French register entry
  • Covers industrial and operational systems, not only office applications
  • Privileged access is in the same suite
  • Sold as software or as a service

Where Systancia is a step down from Zscaler

  • No published prices
  • Does not offer a web gateway with inspection
  • Its certifications and rankings are its own claims and were not checked
  • A smaller ecosystem than Zscaler

Standout against Zscaler. It treats operational technology and privileged access as part of the same zero trust platform.

#4

Open Systems

the nearest to Zscaler in scope, as a managed Swiss SASE service

Best for: Larger companies that want SD-WAN, firewall, web gateway and ZTNA run for them

Open Systems AG is at Räffelstrasse 29, 8045 Zürich (commercial register number CH-270.3.001.794-5), and the listing of its imprint says it is part of the Swiss Post Group. Switzerland is outside the EU and EEA, but it is within the contracting-entity rule used on this site. Its website terms are under Swiss law with Zürich as venue.

Its platform description lists SD-WAN, firewall, secure web gateway, CASB and ZTNA, run as a managed service with a 24 by 7 operations center and a named customer success manager. This is the only tool in the list that matches Zscaler's breadth in a managed form.

Its own website returned an access error when opened for this page, so these details come from search listings of its pages. The customer contract and prices could not be checked.

What Open Systems does better than Zscaler

  • Covers a secure web gateway and ZTNA together, which most others here do not
  • Managed by the vendor, with a service team
  • Swiss company and Swiss-law website terms
  • Operated for large, multi-country customers

Where Open Systems is a step down from Zscaler

  • No published prices and no self-service trial
  • Its site could not be opened, so claims are unverified
  • Customer contract and hosting locations not checked
  • Switzerland is outside the EU and the EEA

Standout against Zscaler. It sells the SASE package as a managed service, which no other tool here does.

#5

Stormshield

French firewalls with ZTNA included at no extra cost

Issy-les-Moulineaux, FranceEnterprise pricing on request#8 in endpoint protection

  • Which law reaches it. EU (France). Zscaler is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Mostly the EEA, with international transfers under EU standard contractual clauses.
  • Source code. Closed source, as Zscaler is.
  • Independently checked. ANSSI CSPN, CCN-LINCE (Spain), Cybersecurity Made in Europe label.

Best for: Organizations that already run or plan to run next-generation firewalls and want ZTNA on top

Stormshield is a French société par actions simplifiée at 2-10 rue Marceau, Issy-les-Moulineaux (RCS Nanterre 428 173 975, capital €2.79 million). Its website is hosted by OVHcloud.

Its ZTNA page describes host checks on the workstation (operating system, domain, firewall, VPN client, antivirus), a zero-trust policy per user or group, multi-factor authentication, micro-segmentation and, in firmware 5, single sign-on. A ZTNA agent opens a VPN connection from the workstation to the allowed resources. Stormshield says all of this is included in its products at no extra cost.

It is a firewall-based approach, so you run the appliances, not a cloud service.

What Stormshield does better than Zscaler

  • ZTNA features are included in the firewall, with no separate license
  • French company with a French register entry
  • Host-compliance checks before access is granted
  • Suited to industrial and public-sector sites

Where Stormshield is a step down from Zscaler

  • You run the firewalls; there is no global cloud broker
  • No cloud web gateway with inspection like Zscaler Internet Access
  • Prices are not shown on the pages opened
  • Less suited to a company with no hardware or with many small sites

Standout against Zscaler. It treats ZTNA as a feature of the firewall you already buy.

stormshield.com Visit Stormshield
#6

genua genusphere

browser-based access to internal applications without a VPN client

Best for: Public-sector and regulated organizations that want zero trust access they can run themselves

genua GmbH is at Domagkstrasse 7, 85551 Kirchheim near Munich (HRB 98238, Amtsgericht München), and its homepage says it is a subsidiary of the Bundesdruckerei Group.

genusphere gives users browser-based access to the applications they are allowed to use, with no VPN client, role-based authorization, encryption of all traffic, audit-proof logging and sign-in through Microsoft Entra ID or Keycloak. It can run on-premises, on Kubernetes or in the cloud, and genua says the operator keeps full data sovereignty.

genua also sells VPN clients and firewall appliances (genuconnect, genuscreen). No prices are shown; you contact sales.

What genua genusphere does better than Zscaler

  • Runs where you decide, with the operator keeping the data
  • No client software needed for browser-based access
  • German vendor, part of the Bundesdruckerei Group
  • Part of a wider range of firewalls and VPN products

Where genua genusphere is a step down from Zscaler

  • Applications reached by browser only, not all network protocols
  • No web gateway or data loss prevention
  • No published prices and no free tier
  • You operate the platform yourself

Standout against Zscaler. It gives users access to applications in a browser, with no client and no VPN.

#7

SSH.com PrivX

passwordless, just-in-time access for servers and applications

Best for: IT and DevOps teams that mainly need controlled access to servers and infrastructure

SSH Communications Security Oyj has its global headquarters at Karvaamokuja 2D, Helsinki. I could not open its terms, so its contracting law is not confirmed here.

PrivX is described on its product page as a privileged access management product built on zero standing privileges, ephemeral and passwordless access, with certificate-based authentication for both people and machines. It is aimed at cloud-native environments, and the page offers a free trial but no price.

It is closer to privileged access than to a user-wide web and application gateway, so it replaces part of Zscaler's private access use, not its web security.

What SSH.com PrivX does better than Zscaler

  • Finnish company (an Oyj, a public limited company)
  • Passwordless, short-lived access reduces standing credentials
  • Built for servers, containers and cloud infrastructure
  • A free trial

Where SSH.com PrivX is a step down from Zscaler

  • Not a general web or application gateway for all staff
  • No published prices
  • Terms and governing law could not be checked
  • Sold as a privileged-access product, not a SASE platform

Standout against Zscaler. It removes standing credentials: access is granted just in time, on certificates, and expires.

#8

LANCOM Trusted Access

cloud-managed trusted access from a German network vendor, now part of Rohde & Schwarz

Best for: Organizations that already use LANCOM networking and its Management Cloud

Since 1 July 2026, LANCOM Systems appears under the name Rohde & Schwarz Networks and Cybersecurity GmbH, Adenauerstrasse 20/B2, Würselen (HRB 16976, County Court Aachen). Its Management Cloud is listed as ISO/IEC 27001 certified.

LANCOM Trusted Access is described in a 2022 press release and datasheet as a cloud-managed access client for office, home and mobile staff, with Active Directory integration through the Management Cloud and access limited to assigned applications, and optionally also usable as a managed VPN client.

The current product page returned a not-found error and the homepage does not mention ZTNA, so this entry rests on older documents. Check that the product is still sold under this name before you plan around it.

What LANCOM Trusted Access does better than Zscaler

  • German company, with cloud management said to be GDPR-compliant
  • Fits into LANCOM networks and SD-WAN
  • Active Directory integration
  • ISO/IEC 27001 listing for its management cloud

Where LANCOM Trusted Access is a step down from Zscaler

  • Current product details could not be verified
  • No web gateway or data loss prevention
  • No published prices
  • Best value only if you already run its networking

Standout against Zscaler. It manages the trusted access client from the same cloud as your LANCOM networks.

#9

Sophos ZTNA

zero trust access that shares device health with Sophos firewall and endpoint

Best for: Organizations that already run Sophos endpoint and firewall products

Sophos' end-user terms name Sophos Limited as the contracting company for customers outside the United States, Canada and Latin America, under the law of England and Wales with English courts. Who owns the group was not checked for this page.

Its ZTNA page describes multi-factor authentication, device health checks in access policies, micro-segmentation, and automatic isolation of a compromised device through Synchronized Security and Active Threat Response. It is built into Sophos Protected Browser with RDP and SSH clients, and sold as part of the Sophos Workspace Protection bundle.

No prices are shown on its page.

What Sophos ZTNA does better than Zscaler

  • English-law contract with an English court, for customers outside the Americas
  • Device health decides access automatically
  • Integrated with a firewall and endpoint you may already own
  • Isolates a compromised device without manual steps

Where Sophos ZTNA is a step down from Zscaler

  • The UK is outside the EU and EEA
  • Strongest if you already use Sophos products
  • No published prices
  • Group ownership was not verified

Standout against Zscaler. Access decisions follow the device health reported by the rest of the Sophos stack.

#10

Heimdal DNS Security

DNS-layer web filtering for networks and endpoints, from Copenhagen

Copenhagen, DenmarkPer endpoint, quoted#11 in endpoint protection

  • Which law reaches it. EU (Denmark). Zscaler is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Customer-selectable data centre: EU (Netherlands or Germany), UK, US or UAE.
  • Source code. Closed source, as Zscaler is.

Best for: Small and mid-sized organizations that mainly want to block malicious and unwanted domains

Heimdal Security A/S is at Vester Farimagsgade 1, Copenhagen (CVR 35 80 24 95). Its license agreement is under Danish law, with the Copenhagen city court as the venue in the first instance, apart from some cases such as non-payment or IP infringement.

Its DNS Security product has a network and an endpoint variant. The vendor describes a local DNS filter (DarkLayer Guard) with allow and block lists, DNS over HTTPS filtering, category blocking and logging. Its homepage offers a free trial and sends visitors to a bundles page for pricing, which I did not open.

It filters at the DNS layer, so it does not decrypt and inspect web traffic.

What Heimdal DNS Security does better than Zscaler

  • Danish company under Danish law, with a Copenhagen venue
  • Light to deploy compared with a full gateway
  • Free trial
  • Part of a wider endpoint and patching platform already on this site

Where Heimdal DNS Security is a step down from Zscaler

  • No private application access or ZTNA
  • DNS filtering only, no inline inspection or data loss prevention
  • Prices not checked
  • Not designed for the largest enterprises

Standout against Zscaler. It adds DNS filtering to an endpoint security platform and can run on the device or the network.

heimdalsecurity.com Visit Heimdal DNS Security
#11

Securepoint Cloud Shield

German DNS-based web protection served from servers in Germany

Best for: German small and mid-sized businesses and their IT service partners

Securepoint GmbH is at Bleckeder Landstraße 28, Lüneburg, registered at the Lüneburg commercial register. It also has a Swiss subsidiary in Baar.

Cloud Shield routes DNS requests from devices through Securepoint's own servers with regularly updated filter lists, using encrypted DNS (DNS over TLS or HTTPS). Its documentation lists category and content filtering, including time-based rules, and says the servers are in Germany. It sits beside Securepoint's firewalls, mail security and managed detection.

No prices are shown on its pages, and documentation is largely in German.

What Securepoint Cloud Shield does better than Zscaler

  • German company with servers in Germany
  • Part of a package with firewalls and mail security
  • Simple to switch on by pointing DNS at it
  • Sold alongside firewalls and mail security from the same vendor

Where Securepoint Cloud Shield is a step down from Zscaler

  • DNS filtering only, no inline inspection
  • No private application access
  • Documentation mostly in German
  • No published prices

Standout against Zscaler. It is the German DNS filter you can pair with Securepoint firewalls and mail security from one partner.

What actually breaks when you switch

The hard part of leaving Zscaler is policy, not software. Years of web categories, application segments, exceptions and SSL inspection rules do not export to another tool. Export what you can, then rebuild the rules in the new tool one group of users at a time, and keep Zscaler on for the rest until the new rules have run clean.

If you use Zscaler for inline inspection and data loss prevention, the tools here are mostly thinner. Only Open Systems describes a web gateway with CASB, and its site could not be opened, so ask for a trial and read the contract. Heimdal and Securepoint filter DNS only.

Several prices are not shown, including Systancia, genua, Open Systems, Sophos, Stormshield, SSH.com, LANCOM and Securepoint. Only NetBird publishes a full price list, and Defguard publishes its free tiers. Ask for a written quote that covers the number of users, sites and log retention you actually need.

Is there a European tool that does everything Zscaler does?

Not in a single product that I could verify. The closest in scope is Open Systems of Zurich, which describes a managed SASE platform with SD-WAN, firewall, secure web gateway, CASB and ZTNA. Its site could not be opened for this page, so check the current service description and the customer contract directly.

For the rest, you combine parts: an access tool (NetBird, Defguard, Systancia, genua, SSH.com, Stormshield, LANCOM or Sophos) for private applications, and DNS filtering (Heimdal, Securepoint) or a firewall with web filtering for browsing.

Which of these can I try without talking to sales?

NetBird has a Free plan with up to 5 users and 100 machines and publishes its prices. Defguard's Open Source edition is free and its Business edition is free for up to 10 users and one location. SSH.com offers a free trial of PrivX, and Heimdal's homepage offers a free trial.

Systancia, genua, Open Systems, Sophos, Securepoint and LANCOM show no prices on the pages I could open, so expect a quote.

Can I host it myself?

NetBird can be self-hosted with a Docker Compose quickstart, and Defguard describes itself as fully self-hosted. genusphere runs on-premises or on Kubernetes, and Systancia sells Gate as software or as a service. Stormshield's ZTNA is a feature of its firewalls, which you run yourself.

Self-hosting moves operational work onto you. If you want somebody else to run it, the managed options are NetBird's cloud plans, Systancia's SaaS, Open Systems and Heimdal.

How is this different from a VPN?

A classic VPN puts a user on a network. Zero trust access, as Zscaler Private Access and the tools here describe it, checks the user and often the device and then allows a connection to specific applications or groups of resources. Some tools here, such as NetBird and Defguard, build on WireGuard but add identity, group policy and MFA on top. genusphere goes further and gives browser access to approved applications without a client.

Which one to pick

If you want to retire a VPN and try the replacement yourself, start with NetBird: it is the one with a free plan, published prices and open code. Defguard is the choice for a technical team that wants to run the platform on its own servers.

If you want a French or German vendor with a public-sector profile, look at Systancia, genua or Stormshield. If you want a managed service that covers the web gateway too, Open Systems is the only one in the list that describes it, and it needs a careful look at the contract because its site could not be opened.

Heimdal and Securepoint are light DNS filters, not gateways. Choose them if blocking bad domains is the job, not if you need inspection.

Be realistic about the gap. Zscaler is a large cloud platform that inspects traffic inline and prices by quote, and none of the eleven matches all of it. Switch if California law and a Santa Clara County venue are the problem, and keep Zscaler for the web security you cannot yet replace.

Frequently Asked Questions

It depends on the job. NetBird scores highest on this page because you can try it free, read the prices, and self-host it, but it is an access network and not a web gateway. If you need a managed SASE service with a secure web gateway, Open Systems is the one to look at first. If you want zero trust access from a French or German vendor with a public-sector profile, look at Systancia or genua.

No. Zscaler, Inc. is in San Jose, California. Its subscription agreement is governed by California law, and the exclusive venue is the federal and state courts in Santa Clara County. The agreement does not name a specific Zscaler entity, and its data processing agreement names Zscaler, Inc. as processor.

Its data processing agreement relies on EU standard contractual clauses and a UK addendum, and says the company is certified under the EU-US Data Privacy Framework, the UK extension and the Swiss-US framework. It keeps a list of sub-processors, gives 30 days' notice of new ones, and lets customers object on data protection grounds.

Its product pages show no prices. You request a demo or contact sales. For comparison, NetBird lists €6 per user a month on Team and €12 on Business, with a Free plan, and extra machines at €0.50 a month on those two plans.

NetBird GmbH in Berlin (Amtsgericht Charlottenburg, HRB 237529 B) lists Free at €0 for up to 5 users and 100 machines, Team at €6 and Business at €12 per user a month, and Enterprise on request. Its terms are under German law, and for business customers the venue is the seat of NetBird GmbH. Most of the code is BSD-3-Clause, with AGPLv3 for the management, signal and relay parts.

Mostly. Its repository uses the AGPL for most code, and a separate enterprise directory under its own license. Defguard lists an Open Source edition as always free, and a Business edition that is free for up to 10 users and one location, with paid options for more. The contracting company is Defguard Sp. z o.o. in Szczecin (KRS 0001168794) under Polish law.

genua is a subsidiary of the Bundesdruckerei Group, by its own homepage. Open Systems describes itself in its imprint listing as part of the Swiss Post Group. LANCOM Systems is now Rohde & Schwarz Networks and Cybersecurity GmbH since 1 July 2026. For Sophos, its terms name Sophos Limited and English law, and I did not verify who owns the group.

Its end-user terms name Sophos Limited as the contracting company for customers outside the United States, Canada and Latin America, under the law of England and Wales with English courts. The United Kingdom is outside the EU but is covered by the contracting-entity rule used on this site. Its ZTNA is sold inside the Sophos Workspace Protection bundle with no public price.

Only in part. Heimdal DNS Security and Securepoint Cloud Shield both filter at the DNS layer, which blocks known bad and unwanted domains before a connection is made. They do not decrypt and inspect traffic the way a full web gateway does. They suit small and mid-sized organizations that mainly want category blocking and malware protection.

Several describe themselves that way. Stormshield and genua are aimed at public-sector and critical-infrastructure buyers, and LANCOM's Management Cloud is listed as ISO/IEC 27001 certified. Systancia describes recognition by KuppingerCole and Gartner. These are the vendors' own statements, and I did not verify any certificate, so ask for the document.

About the author

One person researches and writes every comparison page on European Purpose and checks the compliance and pricing claims against the vendor's own documentation.

Sebastiaan Smits

Sebastiaan Smits

Founder · Amsterdam, Netherlands

Founder of European Purpose. Researches and writes the reviews and checks where each company is actually established.

Read our editorial process for how we source, verify and update these pages, and how paid placement works.

Explore More European Alternatives

Discover privacy-focused European alternatives to other popular US tech services.

More Web Security Browse All Categories