Compare

Honest about the footprint. Clear about the edge.

Cato, Zscaler and Cloudflare One run large, excellent PoP fleets we do not claim to match. Our edge is architectural: a sovereign, self-hosted control plane that never holds a private key, is multi-tenant by construction, compiles one write-once policy to many enforcement targets, and integrates the mesh, full SASE, SD-WAN, threat detection and network emulation on one governed fabric.

vs Catovs Zscalervs Tailscalevs Cloudflare One

Compare

Honest about the footprint. Clear about the edge.

Cato, Zscaler and Cloudflare One run large, excellent PoP fleets — 85+, 150+ and 330+ cities we do not claim to match. Our edge is different: a sovereign, self-hosted control plane that never holds a private key, is multi-tenant by construction, and integrates the mesh, full SASE, SD-WAN and network emulation on one governed fabric.

CapabilitySASE MeshCatoZscalerTailscaleCloudflare One
SASE breadth (ZTNA/SWG/CASB/FWaaS/DLP)Full — ZTNA + SWG + CASB + FWaaS + DLP (SS-26)Full SASEFull SASE (ZIA / ZPA)Mesh VPN — no SWG/CASB/DLPFull SASE (Gateway + Access)
Mesh / ZTNA private accessWireGuard mesh + ZTNA on one fabricZTNA (agent / agentless)ZPA ZTNAWireGuard mesh + tailnet ACLsWARP + Access ZTNA
Self-hosted / sovereign control planeYes — self-host the whole control planeNo — vendor cloudNo — vendor cloudNo — coordinator is SaaS (self-host = Headscale)No — vendor cloud
Zero-knowledge (no private key in control plane)Yes — proven in the artifact (# PrivateKey, raw-scan guard)NoNoPartial — coordinator holds key metadataNo
Multi-tenant meshesYes — per-tenant, X-Tenant-Id on every netmapVendor multi-tenant SaaSVendor multi-tenant SaaSOne tailnet per accountOne org account
Native WireGuard coordinationYes — netmap/wg-config/coord/rekey (ADR-0072)Proprietary IPsec / edgeProprietary tunnelsYes — WireGuard (SaaS coordinator)WireGuard (WARP)
Write-once policy → multi-target compileYes — UPO compiles to ztna/sdwan/firewall + apply-diffPer-product policyPer-product policyTailnet ACL onlyPer-product policy
Delta-driven coordination pollYes — cursor deltas + netmap_version (map-poll replacement)n/an/aYes — map-poll (SaaS)n/a
Network emulation / digital twinYes — EVE-NG labs + validate + console over the meshNoNoNoNo
Threat detection on the fabricYes — Zeek mesh chaos-rig audit + detections (SS-28)IPS / threat (SaaS)IPS / sandbox (SaaS)NoGateway threat (SaaS)
PoP footprint (honest)Sovereign / self-hosted PoPs + DERP fleet — not a global PoP race85+ PoPs150+ data centersGlobal DERP relays (SaaS)330+ cities

Competitor capabilities are summarised in good faith and change often — check each vendor for current details. We are deliberately honest that the incumbents win raw PoP footprint (Cato 85+, Zscaler 150+, Cloudflare 330+ cities). SASE Mesh's differentiator is being sovereign, zero-knowledge, multi-tenant, integrated and self-hosted — not global PoP parity.

Where we win

The differentiators, stated plainly.

zero-knowledge

The control plane never holds a private key

Enroll by public key only; the exported wg-config carries a # PrivateKey comment where an assignable line would be, and a raw-scan guard proves the omission. No incumbent coordinator makes that guarantee.

multi-tenant

Per-tenant meshes, not one tailnet

X-Tenant-Id is on every netmap and a cross-tenant read returns zero rows (CI pen test). Tailscale is one tailnet per account; Headscale is single-org.

delta engine

A cursor-based coordination poll

Native WireGuard coordination serves deltas past a cursor with a monotonic netmap_version — the map-poll replacement that retired Headscale (ADR-0072).

write-once policy

UPO compiles one policy to three targets

Author one UnifiedPolicy, compile to ztna / sdwan / firewall, and apply with a reviewable diff. Incumbents make you author policy per product.

sovereignty

Self-host the whole control plane

Run the coordinator, DERP fleet and residency path classes in your own region. There is no vendor cloud in the datapath — the point the incumbents structurally cannot match.

integrated

One fabric, not five products

The mesh, SASE controls, SD-WAN, threat detection and observability share one identity, tenancy and audit boundary — not bolted-on acquisitions.

Honest gaps

Where an incumbent may fit you better.

We would rather you choose well than choose us. Here is where the incumbents genuinely lead.

We do not win the raw PoP race

Cato (85+), Zscaler (150+) and Cloudflare (330+ cities) run large global PoP fleets. SASE Mesh is sovereign and self-hosted — you place PoPs and a DERP fleet where your data must live, not everywhere on earth. If your requirement is a turnkey global anycast edge, an incumbent may fit better.

Managed SaaS convenience vs sovereignty

Tailscale's hosted coordinator and the incumbents' clouds mean zero infrastructure to run. Self-hosting the control plane is the whole point here, but it is real operational surface — you run it (or we run it for you on Enterprise).

Ecosystem maturity

The incumbents have years of connectors, client apps and partner integrations. Our edge is architectural — zero-knowledge, multi-tenant, integrated, write-once policy — not breadth of third-party marketplace.