Resources -> Tools

What is SquareX? Benefits, use cases, and alternatives

July 22, 2026
10 min read

While enterprise browser vendors argue you should replace Chrome, SquareX took the opposite bet: keep the browser, add detection. Founded in Singapore in 2023 by Vivek Ramachandran - the security researcher behind training firm Pentester Academy - SquareX coined the category it sells: Browser Detection and Response (BDR), an EDR-style model for the browser delivered as a lightweight extension. The pitch is threat-first: detect and block malicious extensions, advanced phishing, browser-native ransomware, and generative AI data leakage inside the browsers employees already use, no migration required. The company built its name as much on offensive research as product - its "Year of Browser Bugs" program disclosed browser architecture flaws like Syncjacking and polymorphic extensions at DEF CON, Black Hat, and RSA. The market agreed the browser was the blind spot: after a $20 million Series A in 2025, SquareX was acquired by Zscaler in February 2026, folding BDR into a zero-trust platform - a validation of the approach, and a fork in the road for buyers who wanted it standalone.

What is SquareX?

SquareX is a browser security platform delivered as an extension for the browsers an organization already runs - Chrome, Edge, and other major browsers - rather than as a replacement browser. Its architecture spans three pillars. Browser Detection and Response detects and mitigates client-side attacks: malicious or impersonating extensions, identity attacks, advanced spearphishing, malicious files, and QR-based lures, with isolation and content disarm for suspect content. Browser DLP governs data movement - clipboard, file uploads and downloads, and generative AI interactions, blocking sensitive data from being pasted into public AI tools. A set of enterprise browser capabilities rounds it out: secure access to internal apps, SSH/RDP access, and BYOD and contractor coverage positioned as a VDI alternative. The through-line is the EDR analogy: treat the browser as an endpoint, instrument it for telemetry, and give security teams detection and threat-hunting capability where attacks now actually land. Since February 2026, that stack has been part of Zscaler's zero-trust platform.

SquareX Growth Trajectory

SquareX was founded in Singapore in 2023 by Vivek Ramachandran, a twenty-year security veteran best known for founding the security training company Pentester Academy. Early backing came from Peak XV Partners (formerly Sequoia Capital Southeast Asia), followed by a $20 million Series A led by SYN Ventures in April 2025 with Peak XV participating. The company grew visibility fast through an unusual strategy: aggressive vulnerability research. Its Year of Browser Bugs program committed to publishing major browser architecture flaws month after month - eleven research releases disclosed at DEF CON, Black Hat, RSA, and BSides - making SquareX a fixture in security press coverage well beyond its size. The trajectory ended in acquisition rather than IPO: Zscaler acquired SquareX in a deal that closed February 5, 2026, on undisclosed terms, positioning BDR as the browser arm of Zscaler's zero-trust architecture.

SquareX Market Positioning

SquareX positioned itself as the detection-and-response answer to browser security - explicitly contrasting BDR with both enterprise browsers and legacy secure web gateways. Against Island and other replacement browsers, its argument was change management: an extension deploys to the existing browser fleet in days, with none of the migration resistance of swapping every employee's daily driver. Against network-path tools like SWGs and CASBs, its argument was visibility: client-side attacks - malicious extensions, in-page phishing, last-mile data assembly - are invisible to proxies that only see traffic, and can only be caught inside the browser. That framing put it in the same extension-based lane as LayerX and Seraphic, where differentiation came down to SquareX's threat-research DNA and attack-detection depth versus rivals' governance and DLP emphasis. The Zscaler acquisition resets the map: BDR is now a platform capability competing against Palo Alto's Prisma Access Browser and Google's Chrome Enterprise Premium inside the broader zero-trust platform wars, rather than a standalone product competing on its own roadmap.

SquareX Impact Metrics

$20M Series A (2025) | Acquired by Zscaler (Feb 2026) | 11 Research Disclosures in 12 Months | DEF CON, Black Hat & RSA Presence

SquareX's public track record is research-heavy and case-study-light. Its Year of Browser Bugs program delivered on an audacious publishing cadence - major disclosures including Browser Syncjacking (a malicious extension escalating to full browser and device takeover through built-in sync features) and polymorphic extensions (infostealers that visually morph into password managers and crypto wallets), both widely covered in security press. That research engine drove commercial validation: SYN Ventures led its Series A specifically on the BDR thesis, and Zscaler's acquisition barely ten months later is the strongest market signal available - a major zero-trust platform concluded browser-level detection was worth buying rather than building. What the public record lacks is named customer outcomes: unlike the enterprise browser vendors, SquareX published no customer case studies with deployment metrics, so buyers weighing the technology post-acquisition are evaluating architecture and research credibility more than referenceable results.

SquareX Key Features & Capabilities

Browser Detection & Response

EDR-style detection, mitigation, and threat hunting for client-side attacks - phishing, identity attacks, malicious sites, and browser-native malware - with telemetry security teams can investigate.

Malicious Extension Defense

A three-layer extension analysis framework (metadata, static code, and dynamic analysis) flags rogue and impersonating extensions - the attack surface SquareX's own research made famous.

Browser DLP

Policy control over clipboard, file uploads and downloads, and data movement between sites - including insider-driven exfiltration paths.

GenAI Data Protection

Blocks sensitive data from being pasted or uploaded into public AI tools and flags risky prompt behavior by role and data sensitivity.

File Isolation & Content Disarm

Suspicious files and sites open in isolation, with content disarm and reconstruction stripping active threats before they reach the endpoint.

Enterprise Access Controls

Secure access to internal apps and SSH/RDP for BYOD and contractor devices - extension-delivered coverage positioned as a lighter VDI alternative.

SquareX Use Cases

Client-Side Attack Detection

Security teams get detection and response for the attacks that bypass network tools - in-browser phishing, malicious extensions, and browser-native malware assembly.

Extension Risk Management

Organizations audit and control the browser extension sprawl that traditional endpoint tools cannot see inside.

Governing Generative AI

Companies enable AI tools while blocking sensitive data in prompts, pastes, and uploads.

BYOD & Contractor Coverage

Unmanaged devices get browser-level security and access controls without device enrollment or a browser swap.

Zero-Trust Browser Extension

Post-acquisition, Zscaler customers extend zero-trust enforcement into the browser session itself.

SquareX Integrations

Pre-acquisition, SquareX's integration story followed the standard security-stack pattern: identity providers for policy targeting, SIEM export for its detection telemetry - the browser-as-endpoint model only pays off if browser detections reach the tools security teams actually triage in - and deployment through existing browser and device management for fleet rollout. Because it ships as an extension rather than a browser, it composes with whatever browser estate exists, including alongside managed Chrome or Edge configurations. The acquisition redraws this picture in one direction: deep integration with Zscaler's Zero Trust Exchange - browser telemetry feeding the same policy and analytics plane as Zscaler's network and endpoint signals - is now the strategic path, a major gain for Zscaler shops and a consideration for everyone else, since standalone integration breadth is unlikely to be the roadmap priority it once was. Organizations evaluating SquareX today should scope integration questions against Zscaler's platform documentation rather than the startup's original catalog.

SquareX Implementation & Ease of Use

Deployment was SquareX's sharpest argument: a browser extension pushes to the existing fleet through standard browser management in hours, with no browser migration, no endpoint agent install, and no user retraining - employees keep the browser they have. That remains true post-acquisition. The operational surface sits with the security team instead: BDR produces detections, and detections need owners - organizations without a function that triages alerts will use the blocking policies but leave the response value on the table. As a young product, its admin tooling has had far less public scrutiny than the mature enterprise browsers; the review footprint on platforms like G2 is thin, so expectations about console maturity, policy ergonomics, and edge-case browser compatibility (Safari and Firefox coverage has historically trailed Chromium) deserve validation in a pilot. Buyers today should also factor the integration path: implementation now means onboarding into Zscaler's management plane, and existing Zscaler customers will have a materially smoother path than standalone adopters.

SquareX Research Highlights

SquareX published no named customer case studies; its public evidence base is research. These are the highlights that defined its reputation:

Year of Browser Bugs

A year-long disclosure program - eleven major releases including Browser Syncjacking, where a minimal-permission extension escalates to full browser and device takeover through built-in sync features.

Extension Analysis Framework

SquareX's three-layer methodology for judging extension risk - metadata, static code, and dynamic analysis - published openly as a framework for the industry.

AI Browser Vulnerabilities

Research into the new attack surface of agentic AI browsers - OAuth abuse and prompt injection that turn an AI assistant's permissions into an exfiltration channel.

SquareX Pricing

SquareX never published pricing as a standalone company - licensing was quote-based per organization, in line with the browser security category, and marketed as substantially cheaper to operate than replacing browsers or maintaining VDI for the same coverage. The Zscaler acquisition makes historical pricing largely moot: going forward, expect the capability to be packaged and priced within Zscaler's zero-trust platform tiers rather than sold on the startup's original rate card. For existing Zscaler customers that likely means browser security as an attach or bundled module - worth pressing for in renewal negotiations while the integration is young. For everyone else, the honest guidance is that pricing, packaging, and even product naming are in transition, and any evaluation should get current terms directly from Zscaler rather than relying on pre-acquisition references.

SquareX Security & Compliance

SquareX's compliance story runs through visibility: browser-level telemetry produces an activity record for the layer where SaaS work and data movement actually happen, supporting incident investigation and audit evidence that network logs cannot reconstruct. Its DLP controls - clipboard, file, and GenAI channels - map to the data-handling requirements behind frameworks like GDPR and HIPAA, and the isolation and content-disarm features address malware-ingress controls auditors increasingly ask about. The governance obligations cut the usual way: browser telemetry is employee monitoring, and organizations owe notification, proportionality analysis, and counsel review of what is captured for which populations - especially on BYOD devices where personal browsing shares the surface. Post-acquisition, data residency and processing questions move to Zscaler's cloud infrastructure and its compliance certifications, which is a stronger enterprise posture than a three-year-old startup could offer - one of the acquisition's genuine buyer benefits.

Where SquareX Falls Short

SquareX's public record is research-rich and evidence-poor: no named customer case studies, a thin review footprint on G2 and Gartner Peer Insights relative to category incumbents, and admin tooling that has had little independent scrutiny - a materially higher diligence burden than mature alternatives. Its loudest marketing asset cuts both ways: spectacular vulnerability disclosures built awareness, but critics note the same extension architecture SquareX's research undermines is the architecture its product depends on - an extension cannot see or control everything a rebuilt browser can, and determined malware that compromises the browser itself can potentially blind it. The enterprise-access features (VDI replacement, SSH/RDP) are younger and shallower than dedicated enterprise browsers' equivalents. And the acquisition is the dominant uncertainty: Zscaler ownership brings resources and enterprise credibility, but standalone availability, roadmap independence, and pricing are all in transition - organizations not already in the Zscaler ecosystem are effectively evaluating a platform commitment, not a point product. Finally, like all detection-first tools, SquareX watches for attacks; it does not govern how legitimate users handle sensitive data inside their everyday workflows.

SquareX Alternatives

Island

The category-leading enterprise browser - far deeper control by replacing the browser entirely, at six-figure pricing and real migration weight.

LayerX

The closest architectural rival: agentless extension-based browser security with a governance and AI-usage-control emphasis.

Seraphic

Browser security via a JavaScript-level agent that hardens any browser against exploits - protection-first rather than detection-first.

Prisma Access Browser

Palo Alto's enterprise browser, the analogous platform play - browser security absorbed into a SASE stack.

Chrome Enterprise Premium

Google's managed-Chrome tier - DLP and access controls native to the browser most enterprises already run.

SURF Security

Zero-trust enterprise browser emphasizing simpler setup and stack consolidation for unmanaged devices.

SquareX vs. PixieBrix

Category SquareX: Browser Detection & Response PixieBrix: Browser-Native Guardrails & Workflow Control
Deployment Extension on existing browsers - fast fleet rollout, now onboarded through Zscaler's platform. PixieBrix deploys instantly as an extension in the Chrome or Edge employees already use. No platform commitment required.
Protection Model Detects and blocks attacks arriving at the browser: malicious sites, files, extensions, phishing, and exfiltration attempts. Governs actions inside web workflows - the copies, pastes, form entries, and data views where legitimate users create exposure.
Insider Threat Response Detection-led: flags and blocks exfiltration patterns and policy-violating data movement for security team response. Prevents risky actions at the point of work: blocking sensitive clipboard copies, redacting PII on screen, and requiring justification before high-risk changes.
Employee Experience Invisible until something is blocked - security runs in the background of the familiar browser. Transparent guardrails coach users in real time - and the same platform automates their repetitive work, making governance feel like help.
Analytics Attack telemetry and detection events, now feeding Zscaler's analytics plane. PixieBrix Insights tracks workflow execution, guardrail interventions, and automation usage across governed apps.
Integrations SIEM export and identity-driven policy, with deep Zscaler Zero Trust Exchange integration as the go-forward path. Integrates with any web app directly in the browser - no APIs needed - and pushes events to tools like Slack, Jira, and Zendesk.
Ease of Maintenance Security-team owned: detections need triage, and policy tuning lives in the security console. Ops teams maintain guardrails and automations through a no-code editor, updating and deploying to every user instantly.
Governance and Security Browser telemetry powers detection - and is monitoring data that needs scoping, notice, and counsel review. Minimizes collected data by design: enforcement happens locally in the browser, and no monitoring archives accumulate.
Total Cost of Ownership Quote-based, transitioning into Zscaler platform packaging - strongest value inside an existing Zscaler commitment. Low-cost, fast-to-deploy browser layer whose payback spans prevented incidents and automated work alike.

Cover the Inside of the Page, Not Just the Attacks Against It

SquareX made a convincing case that the browser is the new endpoint - and its detection model hunts what attacks it from outside: the malicious extension, the phishing page, the weaponized download. But most data exposure is not an attack. It is a legitimate user doing legitimate work carelessly: the agent reading a full card number off screen, the copy-paste into the wrong system, the record changed without a reason logged. Detection tools watch for adversaries; that risk needs guardrails inside the workflow itself. PixieBrix governs exactly that layer, in the same deployment model SquareX validated - an extension in the browser you already run. PII is redacted before it renders, risky clipboard copies are blocked with an explanation, high-risk changes require justification with a built-in audit trail - and the same platform automates the repetitive steps that produce careless mistakes in the first place. Run PixieBrix alongside browser threat detection as the in-page governance layer, without waiting on anyone's platform roadmap. It installs in minutes and is managed with a no-code editor.

Related content

2026 PixieBrix, Inc.