Direct apples-to-apples comparisons against every major competitor. Where we win, where they win, and where we honestly draw.
vs VMware vSphere · Nutanix AHV/NC2 · SUSE Harvester · Proxmox VE · Citrix Hypervisor · OpenStack
Multi-hypervisor VM orchestration without the VMware tax. A single, sovereignty-grade control plane for VMs across KubeVirt, libvirt, VMware, Hyper-V, AWS, Azure, GCP, Proxmox, Nutanix, and OpenStack.
| Feature | CyForge | VMware vSphere (Broadcom) |
Nutanix AHV / NC2 |
SUSE Harvester | Proxmox VE | Citrix Hypervisor | OpenStack |
|---|---|---|---|---|---|---|---|
| Hypervisor coverage & deployment | |||||||
| Hypervisors under one consoleMore = lower per-vendor lock-in | 10 providers | 1 (ESXi) | 1 (AHV) + ext. | 1 (KubeVirt) | 1 (KVM) | 1 (XenServer) | 1 (KVM) |
| Coexists with vCenter during migration | ✓ | — | ✗ | ✗ | ✗ | ✗ | ✗ |
| Bare-metal install | Helm on K8s | ESXi installer | Nutanix HCI nodes | ISO appliance | Debian ISO | XenServer ISO | DIY |
| Phone-home telemetry (mandatory) | None | Yes (Broadcom) | Yes (Pulse) | Optional | None | Yes | None |
| Architecture support | x86_64 + ARM64 | x86_64 | x86_64 + ARM | x86_64 + ARM64 | x86_64 | x86_64 | x86_64 + ARM64 |
| VM lifecycle & operations | |||||||
| Cross-hypervisor migration with rollbackESX → KubeVirt validated | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| HA auto-restart | ✓ | ✓ | ✓ | Limited | Limited | ✓ | ✓ Masakari |
| Auto-scaling policies | ✓ built-in | Add-on (vROps) | Add-on (Calm) | ✗ | ✗ | Add-on | Heat (DIY) |
| vGPU (NVIDIA / partitioned) | Partial | ✓ licensed | ✓ licensed | Partial | Partial | ✓ | Partial |
| Networking | |||||||
| Software-defined networking | OVN built-in | NSX (separate $) | Flow / AHV | OVN | Linux bridge | Basic | Neutron / OVN |
| Per-VM micro-segmentation | ✓ Network Policies | ✓ NSX-T | ✓ Flow | Limited | Limited | Limited | ✓ Neutron |
| Multi-tenant isolation at network layer | ✓ | ✓ NSX | Partial | ✗ | ✗ | Partial | ✓ |
| Live impossible-travel + geo policy on VMs | ✓ via CyMatrix | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Multi-tenancy & access | |||||||
| Native multi-tenant modelTenant > Org > User | ✓ 3-tier | Cloud Director ($) | Prism Central | ✗ | ✗ | Partial | ✓ Keystone |
| Built-in identity / SSO | SAML, OIDC, internal IdP | AD / LDAP | AD / LDAP | AD basic | PAM / AD | AD | Keystone |
| Bundled VDI + privileged access | ✓ CyDusk included | Horizon (separate $) | Frame (separate $) | ✗ | ✗ | Citrix DaaS | ✗ |
| Bundled remote browser isolation | ✓ CyLens included | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Operations & extensibility | |||||||
| Open Service Provider Interface (SPI)Add a hypervisor without forking | ✓ VmProvider Java SPI | ✗ | ✗ | Partial | Partial | ✗ | ✓ drivers |
| AI-assisted troubleshooting copilot | ✓ CyPilot built-in | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| FTE estimate to operate | 1 platform engineer | 2-3 specialists | 1-2 specialists | 1 generalist | 0.5 generalist | 2 specialists | 5-10 specialists |
| Commercials | |||||||
| List price posture (relative) | 1.0× | 3-5× post-Broadcom | 2-3× | 0.6× open source | 0.4× open source | 2-4× | 0.5× + 4× ops |
| Bundled platform (VDI, RBI, DLP) | ✓ | ✗ separate SKUs | Partial | ✗ | ✗ | Citrix bundle | ✗ |
| Time-to-deploy first VM | < 1 hour (Helm) | Days (vCenter) | Hours (HCI nodes) | 1-2 hours | < 1 hour | Hours | Days-weeks |
vs Citrix DaaS · VMware Horizon · Accops HySecure · Apache Guacamole · CyberArk PAM · AWS AppStream
VDI + privileged access where credentials never reach the endpoint. A single subscription replaces {VDI broker} + {credential vault} + {session recorder} + {MFA add-on}.
| Feature | CyDusk | Citrix DaaS | VMware Horizon | Accops HySecure | Apache Guacamole | CyberArk PAM | AWS AppStream |
|---|---|---|---|---|---|---|---|
| Architecture & deployment | |||||||
| Browser-only access (no client install) | ✓ HTML5 | Citrix Workspace required | Horizon Client required | ✓ HTML5 | ✓ | PSM client required | ✓ |
| Protocols supported | RDP, SSH, VNC, K8s, Telnet | HDX, RDP, SSH | Blast, PCoIP, RDP | RDP, SSH, VNC, web | RDP, SSH, VNC, K8s | RDP, SSH, web, mainframe | DCV / streaming |
| On-prem / air-gap install | ✓ | DaaS = cloud-only | ✓ | ✓ | ✓ | ✓ | ✗ AWS only |
| Multi-tenancy | ✓ Tenant > Org > User | ✓ CSP | Partial | ✓ | ✗ DIY | ✓ | Limited |
| Credential & vault model | |||||||
| Built-in encrypted credential vault | ✓ AES-256-GCM envelope | ✗ separate PAM | ✗ separate PAM | Partial | ✗ | ✓ best-in-class | ✗ |
| Zero-knowledge credential injectionUser and endpoint never see the password | ✓ | ✗ SSO, not zero-knowledge | ✗ | Partial | ✗ | ✓ | ✗ |
| HashiCorp Vault Transit / KMS | ✓ envelope ready | Add-on | Add-on | Partial | ✗ | ✓ | AWS KMS |
| Just-in-time credential checkout | ✓ | ✗ | ✗ | Partial | ✗ | ✓ | ✗ |
| Credential rotation on session end | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✗ |
| Authentication & posture | |||||||
| MFA — Email OTP | ✓ SendGrid | Add-on | Add-on | ✓ | Add-on | ✓ | ✓ |
| MFA — WebAuthn / FIDO2 | Partial (Q3 roadmap) | ✓ Citrix Cloud | ✓ Workspace ONE | ✓ | Add-on | ✓ | ✓ |
| Smart-card / PKCS#11 redirection | ✓ via CyLens | ✓ | ✓ | Partial | ✗ | ✓ | Partial |
| Device posture at session start | ✓ built-in | Add-on (Citrix EPA) | Add-on (Workspace ONE) | ✓ | ✗ | Limited | ✗ |
| Geolocation + impossible travel | ✓ event-driven | Limited | Limited | ✓ | ✗ | ✓ | ✗ |
| Session governance | |||||||
| Session recording (video + keystroke) | ✓ built-in | Add-on (Advanced) | Add-on | Add-on | ✗ DIY | ✓ | Limited |
| Segregation of Duties BLOCKMost products only LOG the violation | ✓ block at approval-time | Limited | Limited | Partial | ✗ | ✓ | ✗ |
| Watermark on session | ✓ configurable | ✓ | ✓ | ✓ | ✗ | Limited | Partial |
| User experience | |||||||
| Contractor self-service onboarding | Hours | Days-weeks | Days-weeks | Hours-days | DIY | Days | Days |
| Time-bound access (TTL) | ✓ | Add-on | Add-on | ✓ | ✗ | ✓ | Limited |
| BYOD-friendly (browser, posture-gated) | ✓ | Workspace app needed | Horizon client needed | ✓ | Limited | PSM client needed | ✓ |
| Commercials | |||||||
| License model | Per concurrent user / year | Per named-user | Per named-user | Per concurrent user | Free + support | Per privileged user | Per AWS user-hour |
| List price posture (relative) | 1.0× | 2-4× post-CSG | 2-3× | 0.8-1.2× regional | 0× + DIY ops | 3-5× PAM-only | Variable hourly |
| Vault included in price | ✓ | ✗ buy CyberArk | ✗ | Partial | ✗ | n/a is the vault | ✗ |
| Mandatory infra beyond product | Just K8s | StoreFront, NetScaler | Connection Server, UAG | HySecure gateway | Servers + reverse proxy | Vault HSM, PSM servers | AWS account |
Footnote: 'Per concurrent user' counts the peak simultaneous sessions, not the named-user roster — typically 30-50% of named users. WebAuthn/FIDO2 enrolment in product Q3 post-raise; redirection through CyLens already supported.
vs Island Browser · Talon (Palo Alto) · AWS WorkSpaces SB · Menlo Security · Chrome Enterprise · Citrix Secure Browser
True remote browser isolation — a Chromium runs in an isolated pod and the user receives only WebRTC / H.264 pixels. The platform integrates DLP, CDR, watermarking, and device-posture policy out of the box.
| Feature | CyLens | Island Browser | Talon (Palo Alto) | AWS WorkSpaces SB | Menlo Security | Chrome Enterprise | Citrix Secure Browser |
|---|---|---|---|---|---|---|---|
| Isolation model | |||||||
| Architectural model | True RBI (server-side Chromium) | Managed browser (endpoint) | Managed browser (endpoint) | Hosted Chromium streaming | DOM-mirroring RBI | Endpoint browser + policy | Hosted Chromium (Citrix Cloud) |
| Code execution stays off endpoint | ✓ | ✗ | ✗ | ✓ | ✓ | ✗ | ✓ |
| Works on unmanaged BYOD without agent | ✓ | ✗ deploys browser | ✗ | ✓ | ✓ | ✗ | ✓ |
| Streaming protocols | WebRTC, H.264, CDP screencast | n/a (local render) | n/a (local render) | Proprietary | DOM-mirror | n/a | HDX over HTML5 |
| DLP & content controls | |||||||
| Built-in DLP engine | ✓ | ✓ Island DLP | ✓ | ✗ use AWS Macie | ✓ | Add-on | Limited |
| DLP pattern coverage | 380+ patterns PII, PHI, PCI, secrets | ~150-200 | Comparable | n/a | Comparable | n/a | Limited |
| CDR (Content Disarm & Reconstruct) | ✓ downloads sanitised | Partial | Partial | ✗ | ✓ | ✗ | ✗ |
| Personalised watermark | ✓ | ✓ | ✓ | Limited | ✓ | ✗ | ✓ |
| Screenshot suppression | ✓ OS-level on pod | Best-effort (endpoint) | Best-effort (endpoint) | Limited | ✓ | ✗ endpoint OS | ✓ |
| Cross-origin iframe DLP (OCR)Stops widget popups | Roadmap Q3 | ✗ | ✗ | ✗ | Partial | ✗ | ✗ |
| Identity & device controls | |||||||
| SAML 2.0 with signature validation | ✓ OpenSAML | ✓ | ✓ | ✓ IAM Identity Center | ✓ | ✓ | ✓ |
| Smart-card / PKCS#11 redirection | ✓ | ✓ | Partial | Limited | Partial | ✗ | ✓ |
| USB / IP device forwarding | ✓ | Limited | Limited | Limited | Limited | ✗ | Limited |
| Device posture before session | ✓ via CyMatrix | ✓ | ✓ | Limited | ✓ | Add-on | Limited |
| Performance & footprint | |||||||
| Typical in-region latency | 40-80 ms (WebRTC) | ~Local | ~Local | 60-120 ms | 80-150 ms | ~Local | 60-120 ms |
| Works fully air-gapped on-prem | ✓ | ✗ cloud-managed | ✗ | ✗ AWS only | Partial | ✗ | ✗ Citrix Cloud |
| Commercials | |||||||
| License model | Per concurrent session / year | Per named-user / year | Per named-user / year | Per AWS user-hour | Per concurrent session | Per managed-user / year | Per concurrent session |
| List price posture (relative) | 1.0× | 1.5-2.5× full-fleet | Comparable | Variable (AWS hourly) | Comparable | Cheap, no isolation | 1.5-2× + Citrix Cloud |
| Bundled with platform | ✓ | ✗ | Prisma SASE bundle | AWS bundle | ✗ | Workspace bundle | Citrix bundle |
| Right-fit user tier | Contractors, BYOD, M&A, high-risk | 50K corp FTEs | 50K corp FTEs | AWS-shop users | High-risk users | Corporate FTEs | Citrix shop users |
Footnote: 'True RBI' = no application code executes on the endpoint; only encoded pixels are streamed back. Latency figures observed in typical in-region deployments with hardware H.264 enabled. Cross-origin iframe DLP via OCR design-complete; roadmap Q3 post-raise — requires GPU on streaming nodes.
vs Zscaler ZIA/SSE · Netskope Intelligent SSE · Forcepoint DLP · Microsoft Purview · SailPoint IdentitySec · Symantec DLP
One policy console for VMs, sessions, browsers, and data. Complementary to network-edge SSE/SWG products, not a replacement.
| Feature | CyMatrix | Zscaler ZIA / SSE | Netskope SSE | Forcepoint DLP | Microsoft Purview | SailPoint IdentitySec | Symantec DLP |
|---|---|---|---|---|---|---|---|
| Where policy is enforced | |||||||
| Inside the workload (VM / session / browser) | ✓ | ✗ network edge | ✗ network edge | Endpoint | M365 boundary | Identity layer | Endpoint |
| Network egress (forward proxy / SWG) | ✗ (coexist) | ✓ best-in-class | ✓ | Limited | ✗ | ✗ | Limited |
| Inside SaaS / API CASB | Limited (browser-side DLP) | ✓ | ✓ CASB leader | Limited | Within MS only | ✗ | Add-on |
| DLP coverage | |||||||
| DLP at browser path (RBI-native) | ✓ via CyLens | Network only | Network only | Endpoint browser | Edge browser only | ✗ | Endpoint |
| DLP at VDI session path | ✓ via CyDusk | ✗ | ✗ | Limited | ✗ | ✗ | Limited |
| Pattern library out-of-box | 380+ | ~250+ | ~250+ | 350+ | 300+ (M365) | n/a | 350+ |
| Access governance | |||||||
| Entitlement catalogue | ✓ | ✗ | ✗ | ✗ | Partial | ✓ best-in-class | ✗ |
| Just-in-time access requests | ✓ | ✗ | ✗ | ✗ | Partial | ✓ | ✗ |
| SoD BLOCK at request-timeMost products only LOG | ✓ block, with reason | ✗ | ✗ | ✗ | Partial | ✓ | ✗ |
| Time-bound entitlement (TTL) | ✓ | ✗ | ✗ | ✗ | Limited | ✓ | ✗ |
| Access certification campaigns | Roadmap Q4 | ✗ | ✗ | ✗ | Limited | ✓ full IGA | ✗ |
| Device & location | |||||||
| Impossible travel detection | ✓ event-driven | ✓ network telemetry | ✓ | Limited | ✓ Entra ID | Limited | Limited |
| Auto session-revoke on impossible travel | ✓ CAE wired | ✓ | ✓ | Limited | ✓ | Partial | Limited |
| Operations & integration | |||||||
| Hierarchical merge (VM > Net > Tenant > System) | ✓ | Per-tenant | Per-tenant | Per-rule | Per-tenant | Per-org | Per-rule |
| One audit log across all enforcement | ✓ | Within ZIA only | Within Netskope only | Within Forcepoint only | Within Purview only | Within IGA only | Within Symantec only |
| Coexists with edge SSE / SWG | ✓ designed to | n/a (it IS SWG) | n/a | Limited | ✓ | ✓ | Limited |
| Commercials | |||||||
| Standalone SKU? | Bundled with platform | ✓ per-user/year | ✓ | ✓ | Bundled with E5 | ✓ | ✓ |
| List price posture (relative) | Included at base | Premium per-user pricing | Premium per-user pricing | Premium per-user pricing | Bundled with E5 | Premium IGA | Premium per-user pricing |
| Right-fit positioning | Workload-side policy plane | Edge SSE / SWG king | CASB-leaning SSE | Endpoint DLP | Microsoft estate | Full IGA | Endpoint DLP |
Footnote: 'Coexist' means complementary — CyMatrix at the workload, SSE/SWG at the network edge. Microsoft Purview is excellent inside the M365 estate; coverage stops at non-MS workloads.
We tell you which categories we don't compete in. Buyers trust this far more than a checkbox matrix claiming everything.
Bring two idle servers. We bring the SE. Five success criteria, hard-coded TCO comparison vs your current renewal quote. Zero procurement, zero commitment.