Comparisons

COMPARISON

Locke vs CASB and Secure Service Edge Platforms

CASB and SSE platforms — Netskope, Zscaler, Palo Alto Prisma SASE, and similar — govern outbound traffic at the network layer. Every major vendor now ships AI-specific modules: detecting traffic to known AI services, logging or blocking requests, and in some deployments inspecting prompt content via TLS interception. They give compliance teams the centralised, auditable record they need. But they work server-side, after data has already left the device — and they can't inspect anything on endpoints without TLS interception deployed, which usually rules out personal devices and creates friction even on managed ones.

When CASB and Secure Service Edge platforms fits

  • You need centralised visibility and a full audit log of all AI service traffic across the corporate network or managed endpoints.
  • You need to block access to unsanctioned AI tools at the network layer for an entire fleet of managed devices.
  • Your existing CASB or SSE investment already covers your device estate and you need to extend policy to AI destinations.

When Locke fits

  • You want detection to happen before data leaves the device — eliminating the on-the-wire exposure that even CASB inspection involves.
  • Your workforce includes personal or BYOD devices where TLS interception is not deployed and CASB content inspection cannot reach.
  • You need a zero-knowledge control: the privacy layer itself never sees prompt content, unlike CASB inspection which reads the full prompt.

Side-by-side

DimensionLockeCASB and SSE platforms
Where inspection runsOn the device, inside the browser, before any network call.At the network layer, after data has left the endpoint.
Coverage of personal and BYOD devicesSame controls regardless of device type — runs in the browser.Requires TLS interception or endpoint agent; often not deployed on personal devices.
Does sensitive data cross the network?No — masked before any network call is made.Yes — data leaves the endpoint and passes through the CASB inspection point.
Prompt visibility to the inspection vendorZero — Sonomos never sees prompt content.The CASB operator can read full prompt content for policy evaluation.
Deployment effortPer-user, on-device install (Locke desktop app coming soon) — days to weeks.Network proxy, endpoint agent, or identity integration — weeks to months.

Bottom line

CASB and SSE give you the centralised, network-layer governance regulated enterprises need — audit logs, policy enforcement, AI destination controls. Locke covers what they can't reach: the prompt that never hits the proxy, the personal device with no TLS interception, the ten seconds before a network call is even made. Together, the gaps close.