Z Services Cloud
Access Security Broker

Box Security Solution

Unlock the benefits of cloud-based file sharing and collaboration while meeting security, compliance
and governance requirements

Enforce data loss prevention policies in Box

Z Services CASB enforces DLP policies across data at rest and in motion to ensure compliance with regulations and internal policies. Z Services CASB supports DLP rules based on keywords, data identifiers, user groups, and regular expressions. Enforcement actions include coach users, notify administrator, block, encrypt, quarantine, tombstone, and delete. Leverage pre-built industry templates, create custom policies in Z Services CASB, or leverage policies in an existing on-premises DLP solution.

Unified DLP reporting and remediation

Z Services CASB reports on DLP violations in Box and other cloud services in a unified interface with highlighted excerpts revealing the exact content that triggered the DLP policy. During review, if a file does not violate a policy, the reviewer can rollback the remediation action to restore the file and/or its sharing permissions. Quarantined files are stored in a secure account within Box, not in Z Services CASB’s platform, for added security.

Deep integration with on-premises DLP solutions

With Z Services CASB you have the option of leveraging our best-in-class DLP engine or the policies in your existing on-premises solution such as Symantec DLP, Intel McAfee DLP, Forcepoint DLP, and more. Z Services CASB optionally performs a first-pass content inspection, brokers inspection by the on-premises solution, acts as an enforcement point to apply policies to data in the cloud, and registers enforcement in the on-premises solution that maintains the policy.

Detect internal and external threats

Z Services CASB captures a complete record of all user activity in Box and leverages machine learning to analyze activity across multiple heuristics and accurately detect threats. As a comprehensive cloud security platform, Z Services CASB can detect cross-cloud threats that involve usage in Box and across other cloud services. As threats are resolved, Z Services CASB automatically incorporates this data into its behavioral models to improve detection

Detect internal and external threats

Insider and privileged user threats

Z Services CASB automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and team to identify activity indicative of insider threat, whether the threat is accidental or malicious. Privileged User Analytics identifies risk from dormant administrator accounts, excessive permissions, and unnecessary escalation of privileges and user provisioning.

Compromised accounts

Z Services CASB detects compromised account activity in Box based on brute force login attempts, logins from new and untrusted locations for a user, and consecutive login attempts from two locations in a time period that implies impossible travel, even if the two logins occur across two cloud services. Darknet Intelligence reveals user accounts for sale online that are at risk of compromise.

Analyze sharing and enforce collaboration policies

Z Services CASB audits collaboration activity and visually summarizes all sharing events within the organization, with partners, with personal emails, and via untraceable shared links. Secure Collaboration enforces collaboration policies based on sharing activity and document content and can take action by modifying permissions and revoking links.

Analyze sharing and enforce collaboration policies

Make Box your corporate standard

Z Services CASB identifies all file sharing and collaboration solutions that employees use in place of the corporate standard, Box, and provides a risk rating for each service. Using Z Services CASB, you can enforce risk-based governance controls and coach users to Box to improve collaboration while also reducing cost and risk.

Make Box your corporate standard



Cloud Data loss Prevention
Cloud Data loss Prevention Enforces DLP policies based on data identifiers, keywords, and structured/unstructured fingerprints across data at rest and uploaded or shared in real time.
Unstructured Data Fingerprinting
Fingerprints sensitive files and detects exact match and partial or derivative matches with a policy-defined threshold for percentage similarity to the original.
Closed-Loop Policy Enforcement
Optionally leverages policies in on-premises DLP systems, enforces policies, and registers enforcement actions in the DLP system where the policy is managed.
Structured Data Fingerprinting
Fingerprints billions of unique values stored in enterprise databases and systems of record and supports exact match detection of each value.
Match Highlighting
Displays an excerpt with content that triggered a DLP violation. Enterprises, not Skyhigh, store excerpts, meeting stringent privacy requirements.
Pre-Built DLP Templates
Provides out-of-the-box DLP templates and a broad range of international data identifiers to help identify sensitive content such as PII, PHI, or IP.
Policy Violation Management
Offers a unified interface to review DLP violations, take manual action, and rollback an automatic remediation action to restore a file.
Secure Collaboration
Enforces real-time external sharing policies based on domain whitelist/blacklist and content and educates users on acceptable collaboration policies.
Structured Data Fingerprinting
Multi-Tier Remediation Provides coach user, notify administrator, block, apply rights management, quarantine, tombstone, and delete options and enables tiered response based on severity.


Delivers a threat dashboard and incident-response workflow for insider threats, privileged user threats, and compromised accounts.
Privileged User Analytics
Identifies excessive user permissions, inactive accounts, inappropriate access, and unwarranted escalation of privileges and user provisioning.
Cloud Activity Monitoring
Provides a comprehensive audit trail of all user and administrator activities to support post-incident investigations and forensics.
Malware Protection
Identifies and blocks known signatures, sandboxes suspicious files, and detects behavior indicative of malware exfiltrating data via cloud services and ransomware.
User Behavior Analytics
Automatically builds a self-learning model based on multiple heuristics and identifies patterns of activity indicative of a malicious or negligent insider threat.
Guided Learning
Provides an adjustable sensitivity scale for each anomaly type with real-time preview showing the impact of a change on anomalies detected by the system.
Account Compromise Analytics
Analyzes login attempts to identify impossible cross-region access, brute- force attacks, and untrusted locations indicative of compromised accounts.


Shadow IT Discovery
Discovers all shadow IT cloud services employees are using in place of the corporate standard, Box.
Coaching and Enforcement
Displays just-in-time coaching messages guiding users from unapproved services to Box and enforces granular policies such as read-only access.
On-Demand Data Scan
Identifies sensitive data stored at rest in Box with the ability to target scans based on date range, user, sharing status, and file size.
Collaboration Analytics
Visually summarizes sharing with third-party business partners, personal emails, and internal users and reports on policy exceptions.


Contextual Access Control
Enforces policies based on user, managed/unmanaged device, personal/corporate account, and geography with coarse and activity-level enforcement.
Contextual Authentication
Forces additional authentication steps in real-time via integration with identity management solutions based on pre-defined access control policies.
Encryption and Tokenization
Delivers peer-reviewed, function-preserving encryption schemes using enterprise-controlled keys, and tokenization for data at rest and in transit.
Information Rights Management
Applies rights management protection to files uploaded to or downloaded from Box, ensuring sensitive data is protected anywhere.


Skyhigh Gateway
Enforces policies with an inline proxy and steers traffic via device agent, proxy chaining, DNS, and identity providers to cover all access scenarios.
Integration with SIEMs
Collects log files from SIEMs and provides the ability to report on incidents and events from Skyhigh in SIEM solutions via syslog and API integration.
Skyhigh Cloud Connector
Connects to cloud services via cloud provider APIs to provide visibility and enforce security and compliance policies for all users and cloud-to-cloud activity.
Integration with IDM
Leverages identity management (IDM) solutions for pervasive and seamless traffic steering through Skyhigh’s proxy and contextual authentication.
Skyhigh Enterprise Connector
Facilitates integration with firewalls, proxies, SIEMs, directory services via LDAP, on-premises DLP, HSMs, and EMM/MDM solutions and tokenizes sensitive data.
Integration with IRM
Integrates with leading information rights management systems to enforce existing policies across sensitive data.
Integration with On-Premises DLP
Provides integration and closed-loop remediation with existing on-premises DLP solutions such as Symantec, Intel McAfee, and Forcepoint.
Integration with EMM/MDM
Integrates with enterprise mobility management solutions to enforce access control policies based on whitelisted devices and EMM/MDM certificates.
One of our cloud enablement specialists would be delighted to show you Skyhigh in action. Request A Demo

Z Services CASB by Skyhigh is the #1 CASB

Breadth of Functionality
Breadth of Functionality
Only CASB to provide DLP, threat protection, access control, and structured data encryption.
Breadth of Coverage
Breadth of Coverage
Only CASB to cover all users across all devices and support all cloud services, including custom apps on IaaS.
Platform Scalability
Platform Scalability
Only CASB that scales to support 2 billion cloud transactions per day at the world's largest global enterprises
Platform Security
Platform Security
Only CASB that is FedRAMP compliant, ISO 27001/27018 certified, and stores no customer data in our cloud.
Get a personalized assessment of all cloud services in use by your employees and their associated risk. Request A Cloud Audit