Skip to content

SquareX (now part of Zscaler)

Browser Detection and Response pioneer protecting against malicious extensions, browser-based malware, and identity attacks, acquired by Zscaler in early 2026.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

SquareX built a Browser Detection and Response (BDR) platform, applying the detect-and-respond model long used for endpoints and networks to the browser itself, a threat surface that traditional endpoint and network security tools often have limited visibility into. Its capabilities included detection of malicious browser extensions, identity-based attacks conducted through the browser, browser-delivered malware, and browser-native data loss prevention with file isolation, extending consistent protection across managed and unmanaged devices alike.

Backed by Sequoia Capital Southeast Asia and based in Singapore, SquareX built its BDR approach around the idea that the browser has become the primary application most knowledge workers use all day, yet is frequently the least monitored layer of the security stack. On February 5, 2026, Zscaler announced its acquisition of SquareX, stating the deal would extend Zscaler’s Zero Trust Exchange platform’s uncompromising security posture to unmanaged devices via advanced browser-based protections suited to the AI era.

The acquisition reflects the same industry consolidation trend seen with CrowdStrike’s acquisition of Seraphic around the same period, as major security platform vendors race to close browser-layer visibility gaps by acquiring specialized browser security startups rather than building the capability from scratch; SquareX’s technology now operates as part of Zscaler’s platform rather than as a standalone product.

Innovation Matrix Assessment

Innovation Velocity 7/10

Went from an early-stage, Sequoia-backed startup to acquisition by a major public security platform vendor within roughly three years, an unusually fast validation cycle.

Operational Value 6/10

Extends threat detection and response into the browser layer, closing a real visibility gap for security teams, particularly for unmanaged and BYOD devices.

Market Momentum 7/10

Acquisition by Zscaler, a large publicly traded security vendor, within about three years of founding is strong, independently verifiable evidence of market and technical validation.

Category Disruption 5/10

Applying a detect-and-respond model specifically to browser activity is a useful reframing of browser security, but it now operates as an integrated feature within a larger incumbent's platform rather than as an independent disruptive force.

Real-World Efficacy 5/10

Selection for acquisition by a major, technically sophisticated security vendor is a meaningful signal, though independent, pre-acquisition third-party efficacy testing was not found in this research.

Enduring Relevance 6/10

Browser-based threats and unmanaged-device risk remain a growing concern, and now integrated into Zscaler's platform, the technology is likely to see continued investment and relevance.

Why CISOs Should Care

Extends detection-and-response coverage into the browser, including for unmanaged devices, closing a visibility gap that traditional endpoint and network tools often miss.

What Makes It Different

Applied the detect-and-respond operating model specifically to browser activity rather than treating the browser as just another endpoint surface to scan.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A fast-moving browser security specialist validated by rapid acquisition; now assessed as an integrated Zscaler capability rather than a standalone company.

Editorial Note: Claims vs. Verified Findings

Acquisition date and Zscaler's stated rationale are independently reported; original company founding year, HQ, and funding details are best-available estimates given limited independent pre-acquisition reporting.

Sources