No more typing reviews! Try our Samantha, our new voice AI agent.

Netwrix Endpoint Protector vs Zscaler Zero Trust Exchange Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare One
Sponsored
Ranking in Data Loss Prevention (DLP)
21st
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
23
Ranking in other categories
Email Security (20th), Secure Web Gateways (SWG) (12th), Cloud Access Security Brokers (CASB) (13th), Distributed Denial-of-Service (DDoS) Protection (8th), Software Defined WAN (SD-WAN) Solutions (12th), Access Management (11th), Bot Management (3rd), ZTNA as a Service (9th), ZTNA (4th), Secure Access Service Edge (SASE) (10th), Remote Browser Isolation (RBI) (3rd)
Netwrix Endpoint Protector
Ranking in Data Loss Prevention (DLP)
16th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
29
Ranking in other categories
No ranking in other categories
Zscaler Zero Trust Exchange...
Ranking in Data Loss Prevention (DLP)
5th
Average Rating
8.4
Reviews Sentiment
6.9
Number of Reviews
68
Ranking in other categories
Cloud Access Security Brokers (CASB) (8th), Application Control (4th), ZTNA as a Service (1st), Secure Access Service Edge (SASE) (2nd), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of June 2026, in the Data Loss Prevention (DLP) category, the mindshare of Cloudflare One is 2.0%, up from 1.5% compared to the previous year. The mindshare of Netwrix Endpoint Protector is 1.8%, down from 1.9% compared to the previous year. The mindshare of Zscaler Zero Trust Exchange Platform is 4.1%, down from 6.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Data Loss Prevention (DLP) Mindshare Distribution
ProductMindshare (%)
Zscaler Zero Trust Exchange Platform4.1%
Netwrix Endpoint Protector1.8%
Cloudflare One2.0%
Other92.1%
Data Loss Prevention (DLP)
 

Featured Reviews

CV
Network Architect at IP Dimension
Cloud security has improved remote access and has reduced costs for smaller client sites
I have used Cloudflare One's Identity-Aware Proxy, and it is quite straightforward from what I have seen so far. The app registration on the Azure side integrates fully into Cloudflare, and I am very satisfied with that part because it is easy to set up. The integration of Cloudflare One's Secure Web Gateway and Zero Trust Network Access works without any issues. That part is pretty automatic, and if you complete the rest of the setup, it comes together by itself with no issues from my side. What makes it nice is that we can actually start replacing on-site firewalls at this stage for the smaller clients because it does not matter if they go to a coffee shop or work from home; they are still secured by the same connection. The hops get shorter and you get better latency. We have done testing to see if it is better. One thing that we did notice with our proof of concept with our current client is that they have people connecting from the UK. When they used their previous VPN solution, uploading CAD drawings and other files to the server took a long time. They mentioned that it is much quicker on Cloudflare One's solution. I definitely believe that is part of the improved performance, and I am satisfied with that as well. What is nice about Cloudflare One is that it makes the setup easier and also easier to train technicians to maintain it. Compared to legacy systems, we do not need to get fancy firewalls in place that are costly. That is definitely also a cost-saver with Cloudflare One.
SB
Senior System Administrator at Exotel Techcom Pvt. Ltd
Ensures seamless real-time alerts and smooth deployment with room for Linux functionality improvement
The licensing issue was eventually resolved by the team, but the Linux client issue persisted. Not all the policies applied to the Linux clients were as effective as those for Mac and Windows. That was somewhat of a downside for us. I cannot speak to whether they have improved this in the past two years. An area for improvement is that when a package is provided, there should be no additional elements required from the user's side. For instance, there is an activation key, and you have to specify the host where you need to redirect and fetch the license. That was disappointing when it comes to mass deployment.
Vibin Thomas - PeerSpot reviewer
Technical Team Lead - Content Security at Valuepoint Systems
Zero trust access has transformed remote connectivity and now simplifies secure app usage
Zscaler Zero Trust Exchange Platform, especially Zscaler Private Access, is very strong, though there are a few areas where improvements can be made. One challenge observed is around initial troubleshooting and visibility. While Zscaler Private Access provides logs, it can sometimes take time to pinpoint the exact cause of access issues, especially in complex environments with multiple policies and identity integration. Another area is the dependency on identity and connector health. Since Zscaler Private Access is heavily reliant on app connectors and identity providers, any issues with these components can impact user access, making proper monitoring critical. During the initial setup, policy configuration and application onboarding require careful planning, especially for larger environments with many applications. These challenges are manageable with proper design and monitoring. Overall, the platform delivers strong security and user experience. I would recommend a few improvements, especially around user interface, reporting, and troubleshooting experience. From a user interface perspective, while the platform is powerful, the policy configuration and navigation can feel complex, especially for new users. A more simplified and intuitive layout for policy mapping and application access would help reduce the learning curve. In terms of reporting, Zscaler Private Access provides logs, but having more built-in customizable dashboards and analytics would be very helpful. Better visibility into user access patterns, application performance, and real-time troubleshooting insights would improve operational efficiency. From a support and troubleshooting standpoint, it would be beneficial to have more granular centralized visibility, allowing for quick end-to-end tracing of a user request from authentication to application access without switching between multiple views. These improvements would make the platform even more efficient, especially for large-scale enterprise environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloudflare is simple to use."
"The best feature is rate limiting. If I'm expecting 500 visits per hour, Cloudflare will limit the requests if I suddenly get 50,000."
"Cloudflare Access is part of the Zero Trust philosophy."
"The solution has different options that can be used to differentiate DDoS attacks."
"Using Cloudflare One makes my work quite easy because for DDoS protection, all I need to do is understand the OSI model and click; it makes it easier than trying to write a command line or use a Linux command."
"It is a stable solution."
"The capabilities of the software are strong enough for me to do what it's supposed to do. For me, we don't need to do a lot of configuration on our site. We just enable it and monitor it."
"The blocking feature is very good."
"There are effectively two areas of DLP to look at from a technical perspective. One is how it performs the pickup of information traversing the system and the other is how the policy engine, which analyzes the data, works. On the first aspect, CoSoSys is probably best of breed for macOS because they're reasonably well-integrated into the operating system. They're looking at the file system operations level, not at the execution level."
"Endpoint Protector's best features are its protection and user-friendliness."
"There are a lot of features, but the main feature is that I can use a device serial number to unlock any particular machine or for all machines. If I have a phone, like a Samsung phone, I can whitelist that specific phone for full access wherever it is plugged into any of our devices. This is the same with a USB, because most USBs come in bulk and have the same serial number. I can then whitelist that particular USB to be read-write with full access."
"My advice for anybody who is considering this product is that it's user-friendly, and everyone can easily understand the details about how it works."
"Its robust security audit and compliance functionalities prove especially beneficial for businesses in sectors like BFSI (Banking, Financial Services, and Insurance) and Information Technology."
"I rate technical support as ten out of ten."
"My advice for anybody who is considering this product is that if they want something to protect data on both Macs and PCs then this is a very good choice."
"Netwrix Endpoint Protector works on Linux and macOS to block USB ports, control internet access, and manage other peripheral ports."
"I find all Zscaler Private Access features valuable because each replaces flawed technologies, such as EPAs being replacements for VPN and PR as a replacement for PAM, so I can't mention only one valuable feature. Overall, Zscaler Private Access is a good solution."
"Zscaler's technical support is quite good."
"I like its ease of use. It has a single pane of glass for the ZIA and ZPA pieces. It is very manageable. It is also very easy to deploy for secure access, and it gives half-decent coverage for visibility in terms of what the users use and what data is being proxied through the access gateway."
"Zscaler SASE is probably the number one cloud-based proxy security solution."
"The policies are very easy to implement."
"I like the web filtering capabilities."
"The scalability by definition is kind of intrinsically built-in."
"From a cost perspective, I would say fair market value, and then from an efficiency perspective, I notice a very good user experience, which is easy to use with Zscaler Zero Trust Exchange Platform."
 

Cons

"Cloudflare DDoS has poor technical support."
"Our subscription plan for the solution has a limitation of bot signatures."
"The tool should provide on-premise versions. Currently, all versions are cloud-based."
"From a logging perspective, it is still a bit difficult to see exactly what users are being blocked with the current views."
"The onboarding process can be improved a little bit."
"They don't have a person to provide support for customers using the solution under their free plan."
"Feedback could be enhanced."
"When there are any dynamic changes in complex applications, the tool takes a lot of time, making its analytics-related area a major matter of concern where improvements are needed."
"The policy engine could use a bit of work. It's somewhat lacking in terms of the granularity of the policies that you can create."
"There are times when the server needs to be updated, and it would help if I got a notification for when the newest version comes out, because at the moment, I'm going in every now and then and checking. Sometimes it comes out and I didn't know it had come out."
"It would be better if they had an inbound restriction feature. For example, I work out of my home from my personal computer. All my policies can be deployed while working. When I am done, I should be able to use my machine as my personal machine, and all these policies should be waived. In the next release, I want time bound restriction of the policies because most of these users were working out of home and using their personal computers."
"When you want to uninstall and reinstall, there are a lot of issues. You have to do a lot of workarounds to reinstall Endpoint Protector. This is a major issue that we have constantly because we still have old systems with XP. While there are only very few, we need to run them because there are machines attached that only run on XP. When we need to uninstall and reinstall on XP or Windows 10, we have serious issues left in the Registry Editor everywhere. There is a lot of manual interference to get the reinstallation to work. For the uninstallation of Endpoint Protector, they need to work on this so it doesn't leave any leftovers behind."
"It needs to improve in terms of policy customization."
"CoSoSys Endpoint Protector's network-level DLP and integration with mail servers need improvement."
"In Linux a user can remove a getent anytime. There is no control there on the file structure in Linux. So if this solution could give us information on what users removed in the dashboard, it would help us."
"It would be helpful to implement filtering mechanisms so that we can sort and view the data based on software and vendor, providing more clarity and ease in analysis."
"The pricing for Private Access seems to be on the expensive side, and I believe they should consider making it more competitive with other solutions."
"The area that requires improvement is their support. The current support is lacking."
"In the next release, I would like to see RE2 Regex supported."
"Zscaler Private Access's reporting is poor. We should have more insight into the reports regarding what is blocked and allowed."
"Occasionally, issues arise in the LogStack by a third party, particularly for government websites accessed by numerous users."
"Zscaler Private Access also needs improvement in terms of its interface and security."
"It has massive room for improvement. The Zscaler product itself is okay, but it doesn't give enough granularity for us as an organization to stipulate rules or processes, especially for data-driven services. For instance, we can stick on SSL inspection, but it's just a click box. It doesn't allow us to go any further into the detail of the SSL inspection. We also can't pull it out without having an additional logging server. It just doesn't give us enough granularity. They should give us more control over the interfaces because it is all backend. They weren't very open to discussing their backend architecture with us in terms of their own data centers. They can maybe a little bit more open about what components are there and how the backend infrastructure works alongside Zscaler. Its licensing can be better. Some of the additional licensing costs are quite high, and they should have certain features ready and available as a baseline rather than having to purchase additional licenses for it. Their support should also be improved. I initially had a consultant from Zscaler for its deployment, but the support that I had throughout the deployment of the project wasn't the best."
"The scalability is a weak point right now. Its scaling capabilities are lacking, and we'd like to see that improve in the future."
 

Pricing and Cost Advice

"The pricing of the solution is cheap. The licensing cost is also very low. I rate the cost and pricing a three out of ten."
"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"The price tag is no longer $200,000, but rather $300,000 to $400,000. It's twice."
"The solution is not that expensive."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"The solution's pricing lacks transparency."
"The prices are slightly expensive."
"Cloudflare Zero Trust Platform's pricing is good."
"The price of Endpoint Protector by CoSoSys is more or less the same as other competing solutions."
"We found the pricing pretty attractive. However, volume-based pricing wasn't available."
"For what it's doing, the cost is somewhat high for us, but it's the cost of doing business with the clients that we have."
"The product has average pricing."
"Pricing is quite reasonable. For smaller organizations, it lets them get into the product domain, whereas a lot of vendors won't even talk to them. CoSoSys is just about at that sweet spot of being serious enough that you have to budget for it, but at the same time, affordable enough that the value is well worth it."
"The software comes with a higher price tag when compared to other DLP solutions."
"This is a budget-friendly solution that covers all the aspects of host-level DLP."
"I don't have any issue with the licensing and pricing. I would love for it to be cheaper, but at the same time I'm getting a lot from it."
"My company is a Zscaler Private Access partner, so the customers pay for the license fees."
"The pricing is expensive and on the higher end. Honestly, in my opinion, it is not worth the price."
"As per industry leads, Zscaler CASB is an expensive solution."
"The pricing is quite high, especially when it comes to the gateway."
"The cost is expensive. It depends on the number of users."
"The licensing model for Zscaler Cloud DLP allows you to only buy what you need. You don't need to buy it as a whole, so it's good."
"The price is competitive."
"In terms of market positioning, I would describe Zscaler Private Access as offering optimal pricing. Based on our experience, Cato Networks tends to be slightly more expensive."
report
Use our free recommendation engine to learn which Data Loss Prevention (DLP) solutions are best for your needs.
900,838 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
19%
Comms Service Provider
10%
Financial Services Firm
9%
Manufacturing Company
8%
Financial Services Firm
13%
Construction Company
11%
University
8%
Manufacturing Company
8%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
8%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise1
Large Enterprise12
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise8
Large Enterprise7
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise12
Large Enterprise46
 

Questions from the Community

What needs improvement with Cloudflare Zero Trust Platform?
In my opinion, Cloudflare One can be improved mainly through compatibility, as the integration should be much simpler...
What is your primary use case for Cloudflare Zero Trust Platform?
Cloudflare One's primary use case for my organization is to protect servers and to provide remote access with the VPN...
What is your experience regarding pricing and costs for Endpoint Protector?
When we started, the price was reasonable, but it has been increasing over time. I rate the price as four, indicating...
What needs improvement with Endpoint Protector?
The licensing issue was eventually resolved by the team, but the Linux client issue persisted. Not all the policies a...
What is your primary use case for Endpoint Protector?
Our main use case involved compliance requirements stating that we wanted to have DLP functionality on our endpoint d...
What is the better solution - Prisma Access or Zscaler Private Access?
We looked into Prisma Access before choosing Zscaler Private Access (ZPA). Palo Alto’s Prisma Access is a secure ac...
What is your experience regarding pricing and costs for Zscaler Cloud DLP?
It's an affordable solution. I would rate the pricing a six out of ten. Once after deployment, you start bundling up ...
What is your primary use case for Zscaler Cloud DLP?
In Qatar industries, the legacy systems like the Bluecoat Proxy is still being used, these solutions work at a limite...
 

Also Known As

Cloudflare Area 1 Email Security, Cloudflare Bot Management, Cloudflare Gateway, Cloudflare Zero Trust Platform, Cloudflare DDoS, Cloudflare SASE & SSE Platform
CoSoSys Endpoint Protector
Zscaler SASE, Zscaler DLP, Zscaler CASB, Zscaler CSPM, Zscaler Browser Isolation, Zscaler Posture Control
 

Overview

 

Sample Customers

23andMe
Samsung, Toyota, Philips, Zeppelin, Western Union, eBay
Siemens, AutoNation, GE, NOV
Find out what your peers are saying about Netwrix Endpoint Protector vs. Zscaler Zero Trust Exchange Platform and other solutions. Updated: June 2026.
900,838 professionals have used our research since 2012.