Unified DLP reporting and remediation
Skyhigh reports on DLP violations across all custom applications and other cloud services in a unified interface and provides multi-tier remediation options including notify administrator, encrypt, and block.
Deep integration with on-premises DLP solutions
With Skyhigh you have the option of leveraging our best-in-class DLP engine or the policies in your existing on-premises solution such as Symantec DLP, Intel McAfee DLP, Forcepoint DLP, and more.
Secure BYOD access to custom applications
Skyhigh enforces access control policies based on user groups, device, activity, and geography with coarse blocking and granular activity-level permissions. Skyhigh integrates with EMM/MDM solutions to enforce distinct access policies based on device management status, such as allowing unmanaged devices to preview in the browser but not download files.
Capture an audit trail of user activity
Skyhigh captures an audit trail of all user activity in custom applications and supports post-incident forensic investigations as part of Skyhigh’s complete incident response workflow.
Insider and privileged user threats
Skyhigh automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and team to identify activity indicative of insider threat. Privileged User Analytics identifies risk from dormant administrator accounts, excessive permissions, and unnecessary escalation of privileges and user provisioning.
Skyhigh detects compromised account activity in custom applications based on brute force login attempts, logins from new and untrusted locations, and consecutive login attempts from two locations in a time period that implies impossible travel – even if the two logins occur across multiple cloud services – to support immediate remediation and limit exposure.
“Skyhigh continues to expand its security controls beyond SaaS to help companies cover their custom-built applications running in IaaS including the IaaS platforms themselves.”
“Skyhigh allows us to extend DLP outside the perimeter and into the cloud and the user experience is seamless.”
“Skyhigh helps us understand how employees use the cloud to identify insider threats, compromised credentials, and excessive privileged user access.”
“In an environment with millions of unique events each day, Skyhigh does a nice job of cutting through the noise and directing us to the areas of greatest security concern. ”
Encrypt files with enterprise-owned keys
Protect unstructured data stored in custom applications with standards-based AES encryption. Skyhigh integrates with any KMIP-compliant key management server, enabling enterprises to maintain control of encryption keys and comply with industry regulations and internal security policies.
Custom application security without coding
Skyhigh extends visibility and security controls to custom applications without making changes to the application code. AI-Driven Activity Mapper automatically maps the signature of any application against a uniform set of canonical activities, enabling standardized controls across applications.
Skyhigh is the #1 CASB
Breadth of Functionality
Only CASB to provide DLP, threat protection, access control, and structured data encryption in unified one product.
Breadth of Coverage
Only CASB to cover all cloud services (SaaS, PaaS & IaaS), all devices (managed and unmanaged) and from anywhere (on and off network)
Only CASB that scales to support 2 billion cloud transactions per day at the world’s largest global enterprises.
Only CASB that is FedRAMP compliant, ISO 27001/27018 certified, and stores no sensitive customer data in our cloud.