# What is a Secure Web Gateway (SWG)?

> A secure web gateway (SWG) is a security service that mediates user or device access to web destinations and applies an organization’s outbound web-use and data-protection policies.

- Canonical URL: https://yellowcube.eu/glossary/secure-web-gateway/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It may run as an appliance, cloud service, or distributed endpoint-connected service. An SWG combines traffic control with policy and security analysis; it is broader than the proxy mechanism often used to carry traffic.

Traffic may reach an SWG through proxy settings, endpoint agents, network redirection, or tunnels. Controls can include user and device policy, URL categories, reputation, malicious-content detection, file handling, data loss prevention, and logging. TLS inspection is optional and requires managed trust, narrow exclusions, and privacy analysis.

### Key points

- **Coverage:** Define which users, devices, locations, applications, protocols, and address families are governed. Test direct connections, roaming devices, QUIC, and failure modes.
- **Policy quality:** Combine destination and content signals with identity, device state, and business purpose. Provide review paths for misclassification and emergency access.
- **Privacy and resilience:** Minimize records, restrict administrator access, and address data residency. Capacity, regional presence, fail-open or fail-closed behavior, and provider outages affect business availability.
- **Important limitation:** An SWG cannot prove allowed content is safe, repair vulnerable endpoints, or govern traffic that never reaches it. Encrypted, pinned, unsupported, or bypassed protocols create blind spots. Decryption moves plaintext and trust keys into the service, increasing privacy and compromise impact.

### Related terms

[Secure access service edge (SASE)](<https://yellowcube.eu/glossary/secure-access-service-edge/>) · [Security service edge (SSE)](<https://yellowcube.eu/glossary/security-service-edge/>) · [Proxy server](<https://yellowcube.eu/glossary/proxy-server/>) · [Web application firewall (WAF)](<https://yellowcube.eu/glossary/web-application-firewall/>) · [Uniform Resource Locator (URL) filtering](<https://yellowcube.eu/glossary/uniform-resource-locator-filtering/>) · [Unified threat management (UTM)](<https://yellowcube.eu/glossary/unified-threat-management/>)

### Sources

[NIST CSRC glossary: Secure Web Gateway](https://csrc.nist.gov/glossary/term/secure_web_gateway) · [NIST SP 800-215: Guide to a Secure Enterprise Network Landscape](https://csrc.nist.gov/pubs/sp/800/215/final) · [NIST SP 1800-35: Implementing a Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/1800/35/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

