Yes—Zscaler acquired SquareX. Zscaler announced and closed the purchase of the privately held browser-security company on February 5, 2026. The announcement initially said the financial terms were undisclosed; a later Zscaler filing reported an approximately $113 million cash purchase price, subject to purchase-price adjustments. The deal brings SquareX’s Browser Detection and Response technology into Zscaler’s broader Zero Trust platform, with a particular focus on Chrome, Edge and unmanaged or BYOD devices.
What Zscaler bought
SquareX marketed Browser Detection and Response (BDR), a browser-layer security category designed to protect users in browsers they already use rather than requiring a separate enterprise browser. Its stated use cases included malicious-extension detection, phishing and credential-theft protection, browser-based attack prevention, SaaS and private-application security, generative-AI data-loss controls and insider-threat monitoring.
The technology is intended to work through lightweight browser extensions. That makes it relevant to contractors, partners, temporary workers and employees using personal devices, where installing a full endpoint agent may be impractical or unacceptable.
BDR is not another name for endpoint detection and response (EDR), a secure web gateway (SWG), a VPN or an enterprise browser. It operates closer to activity inside the browser session.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Why the browser has become a security boundary
Browsers now handle SaaS applications, private web applications, cloud storage, identity and OAuth workflows, file transfers, generative-AI services and sensitive copy-and-paste operations. Network controls can observe connections, and endpoint tools can observe parts of device activity, but browser-specific actions and threats may require controls in the session itself.
In its later Zero Trust Browser messaging, Zscaler identified malicious extensions and scripts, browser-identity and OAuth attacks, keystroke logging, screenshots and GenAI data exposure as browser-centered risks. Those are Zscaler’s threat-model and product assertions, not independent efficacy results proving that conventional network or endpoint tools miss every such event.
Why Zscaler made the acquisition
Zscaler’s stated strategy is to extend its Zero Trust Exchange from cloud and network controls into the browser. The company positions browser controls as an option when legacy access models create too much exposure or operational burden:
- VPN: can provide broader network reach than a user needs.
- VDI: can add cost, infrastructure and user-experience complexity.
- Endpoint agents: are difficult to deploy on personal, contractor or partner devices.
- Dedicated enterprise browsers: require user migration, policy changes and change management.
- Cloud proxies: may not see every action after content is rendered in the browser.
Zscaler’s proposed alternative is lightweight browser enforcement combined with its existing access, threat-prevention and data-security services. The company specifically named Google Chrome and Microsoft Edge and said the approach could cover managed and unmanaged devices, including BYOD, without requiring a separate third-party enterprise browser or a full endpoint agent.
Rank #2
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Extension, enterprise browser, cloud browser or agent?
The acquisition should not be read as making other security layers obsolete. Each deployment model places the control boundary in a different location.
| Approach | Main benefit | Main trade-off |
|---|---|---|
| Browser extension | Minimal user disruption and familiar Chrome or Edge workflows | Usually less device and browser control than a managed browser or endpoint agent; deployment and tampering must be addressed |
| Dedicated enterprise browser | Deeper browser policy, workspace and standardization controls | Requires deployment, user migration and ongoing browser management |
| Cloud browser or isolation | Strong separation for higher-risk sessions | Can affect application compatibility and user experience |
| Endpoint agent | Broad operating-system telemetry and device controls | Hard to install or govern on some unmanaged devices |
| VPN or VDI | Familiar legacy access patterns | Can increase cost, lateral-movement exposure, operational overhead and latency |
In April 2026, Zscaler described Zero Trust Browser as supporting a cloud browser, a browser extension and an enterprise-browser form factor. That is a flexible architecture, not proof that every organization can replace its existing browser, agent, VPN or VDI deployment with an extension.
The transaction value and corporate timeline
- February 5, 2026: Zscaler announced the SquareX acquisition and said it closed that day. The press release did not disclose terms. Zscaler’s announcement.
- Later regulatory disclosure: Zscaler reported an approximately $113.0 million cash purchase price, subject to adjustments, for SquareX Holdings, Inc. The filing also indicated that the purchase-price allocation was initially incomplete and could change as accounting work continued. Zscaler filing.
- April 2025: SquareX had previously announced a $20 million Series A led by SYN Ventures, according to SecurityWeek’s acquisition coverage.
- April 29, 2026 onward: Zscaler publicly incorporated SquareX capabilities into its Zero Trust Browser and BDR positioning.
The $113 million figure is therefore a later reported cash purchase price, not the amount stated in the original announcement and not evidence of SquareX’s valuation, revenue multiple, profitability or investor returns.
What the acquisition means for unmanaged devices
The clearest target use cases are BYOD, contractors, suppliers, field staff, temporary workers and merger-and-acquisition environments. A browser extension can apply corporate-session policies without giving the employer complete control of the underlying computer.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
That boundary matters. An extension does not automatically provide operating-system telemetry, hardware attestation, patch management, protection for native applications or visibility into unrelated local activity. Organizations still need endpoint, identity, network and data-security controls for risks outside the browser.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Privacy, deployment and coverage risks
Extension deployment
- Users may disable or remove the extension.
- Browser-management policies, extension stores or application security policies may block installation.
- Browser updates or conflicts with business applications can break workflows.
- Unsupported browser versions may leave users outside policy coverage.
BYOD privacy
Corporate visibility and employee privacy can conflict on a personal device. A work profile or dedicated work browser may help separate contexts, but employers still need clear consent, acceptable-use, telemetry, retention and incident-response rules—especially where controls involve screenshots, keystrokes or browsing metadata.
Coverage outside the browser
Browser controls do not automatically secure native desktop applications, email clients, command-line tools, non-browser protocols, unrelated local files, kernel-level compromise or device configuration drift.
Integration and acquisition risk
Zscaler identified technology integration, effects on SquareX’s existing business and employee retention as acquisition risks. Buyers should distinguish technology integration from product packaging, sales licensing, customer migration, brand changes and roadmap continuity.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRank #4
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
How buyers should evaluate the offering
Organizations considering Zscaler’s browser strategy should obtain written answers to these questions:
- Is the extension included in an existing Zscaler subscription or licensed separately?
- Which Chrome and Edge versions, operating systems and Chromium-based browsers are supported? Are Safari and Firefox supported?
- What remains enforced if the extension is disabled, tampered with or removed?
- Does deployment require a Zscaler client, or can the extension operate independently?
- Can policies vary by user, device posture, application, data type and risk score?
- Can administrators control copy, paste, downloads, uploads, printing and screenshots?
- How are browser extensions assessed, blocked and monitored?
- What browser data is collected, where is it processed and how long is it retained?
- How does the product handle contractors and third parties without granting unnecessary employee access?
- What is the rollback plan if a policy disrupts a business-critical application?
- What independent testing and customer references are available?
- How does the total cost compare with a dedicated enterprise browser, endpoint agents, VDI or competing browser-security products?
Who is most likely to benefit?
The approach may fit enterprises that already use Zscaler Internet Access, Private Access or related Zero Trust services; have many SaaS and web applications; need controls for contractors or BYOD; want browser-based GenAI data policies; or are trying to reduce reliance on VDI for web workflows.
It may be a poor fit for organizations needing complete operating-system telemetry, protection for substantial non-browser workloads, tightly standardized managed-browser baselines, or a standalone tool independent of a broader Zscaler architecture. Buyers that prohibit browser extensions or require transparent self-service pricing should also investigate alternatives.
What remains unverified publicly
Public announcements and filings do not establish SquareX’s standalone revenue, the number of customers transferred to Zscaler, post-acquisition retention, feature-by-feature parity with the pre-acquisition product, independent BDR efficacy testing, generally published pricing or whether every original SquareX product remains available in its prior form.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The strategic signal is clearer than those operating details: Zscaler considers the browser an increasingly important enforcement point in Zero Trust, SASE, SSE and AI-security architectures. The acquisition adds a browser layer; it does not turn browser security into a universal replacement for endpoint, identity, network or data-loss controls.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




