Introduction
Zscaler operates one of the largest cloud-native security platforms in the industry, built on the premise that internet and application traffic should be inspected and enforced in the cloud rather than routed through a physical appliance at the network perimeter. Jay Chaudhry founded the company in 2007 as his fifth security startup, after founding and selling four earlier companies — SecureIT, CoreHarbor, CipherTrust, and AirDefense — over the preceding decade.
Chaudhry has said publicly that he built Zscaler wanting to become “the Salesforce of cloud security,” and the company has since become one of the standard references for the zero trust architecture model. For readers of Brel’s AI in cybersecurity coverage, Zscaler’s recent acquisitions targeting AI red-teaming and agent data access make it a useful example of a zero trust vendor extending its core “never trust, always verify” principle from human users to autonomous AI agents.
What the company does
Zscaler’s core offering, the Zero Trust Exchange, routes and inspects an organization’s internet-bound, private-application, and increasingly AI-bound traffic through Zscaler’s cloud rather than a customer-owned data center, applying identity- and context-based policy to every connection rather than granting broad network-level trust. The platform has expanded well beyond its original secure web gateway roots into private access, data protection, and — through recent acquisitions — dedicated AI and agent security capabilities.
Who it serves
Zscaler sells primarily to large enterprises and government organizations migrating away from hardware-based VPNs and firewalls toward cloud-delivered zero trust access for a distributed workforce. As agentic AI adoption has grown, the company has increasingly pitched the same platform to security teams needing to govern which internal systems and data sources AI agents, not just human employees, are permitted to reach.
Company background
Jay Chaudhry, born in a village in what is now Himachal Pradesh, India, and educated at IIT (BHU) Varanasi and the University of Cincinnati, founded Zscaler in San Jose, California, in 2007 after building and selling four prior security companies: SecureIT (acquired by VeriSign), CoreHarbor (acquired by USi/AT&T), CipherTrust (merged into Secure Computing), and AirDefense (acquired by Motorola). Zscaler completed its initial public offering on Nasdaq under ticker ZS on March 16, 2018. Chaudhry continues to serve as CEO, chairman, and founder, and has remained the company’s primary public voice on strategy, including its pivot toward securing agentic AI.
Product and AI capabilities
Zscaler has pursued a run of AI-focused acquisitions to extend the Zero Trust Exchange across the AI lifecycle. In November 2025, it acquired SPLX, adding shift-left AI asset discovery, automated red-teaming, and governance so organizations can secure AI investments from development through deployment. In February 2026, it acquired browser security company SquareX, extending zero trust enforcement to the browser layer where much AI tool usage occurs. In May 2026, it acquired identity- and data-mapping specialist Symmetry Systems, adding visibility into which identities — human or machine — can reach which sensitive data, a capability the company has positioned as core to governing what AI agents are actually able to access once granted a connection. Chaudhry has framed this expansion around a specific thesis: that agentic AI systems, which now often outnumber human employees inside large enterprises, represent a new and higher-risk category of “user” that zero trust architecture must extend to cover.
Key developments
Zscaler completed its Nasdaq IPO in March 2018 after a decade of building out its cloud security platform, and has since grown into one of the primary reference vendors for zero trust architecture. Beginning in late 2025, the company shifted a significant share of its acquisition strategy toward AI and agent security: SPLX in November 2025 for AI red-teaming and governance, SquareX in February 2026 for browser-level security, and Symmetry Systems in May 2026 for identity and data-access mapping. Collectively, these deals reflect Chaudhry’s public argument that the fastest-growing security risk inside enterprises has shifted from human users to autonomous AI agents operating with broad, often poorly governed access.
Why it matters
Zscaler is a useful reference point for how a zero trust-native vendor — one whose founding architecture was already built around continuous verification rather than implicit network trust — extends that same model to a new category of non-human identity. Because Zscaler’s platform already inspects a large volume of enterprise internet and application traffic, its acquisitions aimed at AI asset discovery and agent data-access mapping give it a plausible, if still unproven, path to applying zero trust principles to agentic AI at the same scale it has applied them to human users over the past decade.
Sector context
Within Brel’s AI in cybersecurity coverage, Zscaler competes most directly with Palo Alto Networks and Netskope for secure access service edge (SASE) and zero trust budgets, and its move into agent identity and data-access mapping also brings it into closer contact with identity-focused vendors such as Okta and data-security vendors such as Varonis, though each approaches AI agent governance from a different architectural starting point — network traffic for Zscaler, identity for Okta, and data access for Varonis.
Sources and references
This profile draws on Zscaler’s official investor relations announcements and leadership materials, alongside independent press coverage.
- Zscaler Investor Relations — “Zscaler Secures The Enterprise AI Lifecycle With Acquisition of… SPLX” (2025)
- Zscaler — Jay Chaudhry leadership biography
- The Hindu BusinessLine — “If you are reachable, you’re breachable: Zscaler’s Jay Chaudhry”
- Wikipedia — “Jay Chaudhry”