Self-hosted Secure Web Gateway

Your data is none of our business.

ALLOD | SWG gives you full inline inspection - firewall, DLP, CASB and ZTNA - running entirely in your own infrastructure. No vendor sees your traffic. No shared cloud in the path.

SBOM on every release No CLOUD Act exposure Self-host anywhere No vendor cloud
Self-hosted Secure Web Gateway

Your data is none of our business.

Full inline inspection of every request - firewall, DLP, CASB and ZTNA - running in your own infrastructure. No vendor cloud, no shared tenancy, no CLOUD Act exposure.

0
VENDOR ACCESS
3
PLATFORMS
100%
SELF-HOSTED
ALLOD | SWG
Connected
1,284
Inspected today
9.4M
Data retained
0 bytes
10:42:01 req DIRECT github.com · not logged
10:42:01 req BLOCK *.tracker.io · not logged
10:42:02 req PROXY internal.corp · not logged
Self-hosted Secure Web Gateway

Your data is none of our business.

ALLOD | SWG gives you full inline inspection - firewall, DLP, CASB and ZTNA - in infrastructure you control. Your traffic stays yours.

The problem

Most secure web gateways protect your network by surveilling your people. Every URL, every query, every byte - logged, retained, and turned into someone's data asset.

Logging is a liability

Every retained log is a breach waiting to happen and a subpoena waiting to land.

Latency is a tax

Cloud round-trips and decryption queues slow every user, every day.

Trust shouldn't require faith

"We don't look at your data" means nothing if the architecture still can.

Capabilities

One gateway. Every control. Nothing kept.

A complete secure web gateway - firewall, data-loss prevention, cloud app control and ZTNA - running in your own infrastructure. Allod Solutions has no access to your traffic.

Inline firewall

PAC-based routing with allow, block and proxy rules applied per-domain in real time - wildcards, categories and custom lists.

Process-aware

DLP with full context

Pattern, content, clipboard and file-path inspection - with configurable retention under your control, encrypted per device.

Per-device encryption

CASB controls

Discover and govern shadow IT. Sanction cloud apps, enforce tenant restrictions and stop risky uploads.

App-aware

GDPR tooling

Article 15 data export and Article 17 erasure built into the admin UI. No support ticket, no vendor involvement.

Audit-ready

Self-hosted, anywhere

Run it in your own datacenter, on a cloud provider of your choice, or both. Single node to start - scale out to multiple PoPs as your fleet grows.

Your infrastructure

Full API

Every rule, key and report is scriptable. Automate provisioning and wire ALLOD into your existing stack.

REST + webhooks
ALLOD | DAM

From shadow IT discovery to governed inventory - automatically.

Most organisations have two problems: they don't know what SaaS their people are using, and the ones they do know about haven't been properly reviewed. ALLOD DAM closes both gaps.

When SWG observes a new application on the fleet, DAM automatically queues it for triage. From there, automated probing and a local LLM do the groundwork - so your team reviews conclusions, not raw documents.

Automated vendor risk assessment

DAM probes each vendor's TLS configuration, hosting geography, SPF and MX records, then fetches and parses the privacy policy and DPA. A local LLM extracts retention periods, subprocessor lists and breach notification commitments - no data leaves your infrastructure.

GLEIF entity verification and ownership monitoring

Every vendor is matched against the Global LEI Index - verified legal entity, full ownership chain to ultimate parent. When an acquisition moves a vendor to a new jurisdiction, DAM detects the change and notifies you before your next review cycle.

EU sanctions monitoring

DAM continuously checks every vendor and its ultimate parent against the EU consolidated sanctions list. A match triggers an immediate alert - you find out before your legal team has to ask.

GDPR review workflows and Art. 30 register

Configurable review cycles - annual, contract renewal, DPIA - with structured fields and owner assignments. The Art. 30 Records of Processing Activities register is built in, not bolted on.

Deployment

Your PoPs. Your providers. Your rules.

With cloud SWGs you get their PoPs, their locations, their availability incidents. With ALLOD you decide where your traffic is inspected - Stockholm, Frankfurt, Tokyo, your own rack - and which provider hosts it.

All proxy nodes pull config from a single controller and enforce the same policy. Moving a node or adding a region is a matter of starting a new binary and pointing it at the controller.

Single node to start

Controller and proxy in one binary, SQLite, no external dependencies. Operational in minutes on any Linux host.

Scale out - stateless proxy nodes

Add proxy nodes in any region. Each one polls the controller for config every 30 seconds and applies rules atomically - no connection drops during updates.

GeoDNS routing built in

A built-in PowerDNS backend routes agents to the nearest healthy proxy by GeoIP - no cloud load balancer or global traffic manager required.

Connectors for private networks

On-prem connector daemons connect out to the controller - no inbound firewall rules needed for agents to reach internal resources.

How it works

Inspect everything. In your infrastructure.

Four steps from raw traffic to a secured request - all of it in an environment you control.

1

Route

Traffic reaches the gateway inline via transparent proxy to the infrastructure of your choice

2

Inspect

Firewall, DLP and CASB engines evaluate the request in memory - process, user, content and TLS fingerprint all considered.

3

Decide

Allow, block or proxy is applied instantly according to your policy - deterministic and explainable.

4

Log

Rule-triggered events are stored in your encrypted event log. Regular traffic is not retained. You set the retention window.

The guarantee

Zero vendor access. Full operator control.

ALLOD runs in your infrastructure. Allod Solutions has no access to your traffic, your event log or your policy - by architecture, not by promise.

  • Your traffic never transits Allod infrastructure - no shared cloud in the path
  • Event log encrypted per device using HKDF-derived keys - a breach of one record does not expose others
  • No CLOUD Act or FISA 702 exposure - Allod has no access to subpoena
  • CycloneDX SBOM shipped with every release - verify your dependencies independently
0
Vendor access to your data
Not anonymized and shipped to us. Not held in a shared cloud. Not subject to a vendor's jurisdiction. Zero - because we never have it.
By the numbers

Security teams don't compromise. Neither should privacy.

0
VENDOR DATA ACCESS
3
ENDPOINT PLATFORMS
100%
SELF-HOSTED
0
SHARED INFRASTRUCTURE RISK
Get started

See it run in your environment.

Book a 30-minute demo with our engineering team. Bring your hardest policy - firewall, DLP, CASB or ZTNA - and we'll walk through how it works end to end.