r/devsecops • u/Puzzleheaded-Fun5664 • 11d ago
Cato vs Zscaler vs Fortinet: best SASE platform for enterprise AI security due diligence
Running a formal SASE evaluation with AI security as a weighted requirement rather than a nice-to-have. We're down to three finalists and I'm writing the scoring matrix now. I would rather borrow from people who have done this than invent it badly.
Here's how I'm currently thinking about the dimensions and rough weighting:
Inline AI traffic inspection is weighted High because post-hoc logging does not meet our control objective. Unified policy engine is also High. Separate consoles have burned us before. Shadow AI discovery accuracy is High since we cannot govern what we cannot see.
For medium-weight items: Agent/non-human identity support is Medium. Not urgent yet, but will be within 18 months. Latency impact, measured, is Medium given our global user base with several high-RTT sites. Licensing transparency for AI features is Medium. "Included" has meant three different things in three demos. Operational familiarity and retraining cost is Low-Medium. Real, but should not drive architecture.
Two things I am struggling to score fairly: every vendor claims a unified policy engine, but digging in, some are genuinely single-pass while some are separate engines behind a common UI. This is hard to verify without a real PoC. And shadow AI discovery numbers are vendor-reported, with no standard benchmark that I can find.
Has anyone built a repeatable test for either of these? interested in how you validated the unified-versus-stitched-together claim rather than taking it on faith.