Track Netskope with a free Huntertech account. Get outage alerts, watchlists, and cross-vendor monitoring in one place.

Try for free
6 updates in the last 7 days/40 total historical

Netskope updates

Release notes and changelog entries from the vendor feed. Refine with filters, then choose All, Recent to focus the list.

Updated 4 days ago

Product updates

All updates

Showing 25 of 40 updates
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of the new features and enhancements.

Increased SWAP Size

Increased the SWAP space to align with general recommendations and minimize memory performance pressure on the system.

Policy Support for HTTP Redirect

Netskope now supports a native HTTP Redirect policy action. This allows administrators to automatically route users to a new URL (e.g., a corporate app instance) using standard HTTP 307 headers, replacing the need for manually doing so via user notification links. To learn more, view Policy Support for HTTP Redirect.

Virtual Appliance139.0.0What's New
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of fixed issues in this release.

IssueDescription
1031565
After upgrading to appliance version 135.0.0, a timing issue during appliance startup could cause the URL database updater service to fail, resulting in the data plane (DPOP) stopping traffic processing. This occurred when an internal directory was created with incorrect permissions due to the order in which system components started up.

This issue is now fixed. The required directories are now created with the correct permissions during initialization, ensuring the URL database updater starts reliably regardless of component startup order.
1030520
Fixed an issue where certain sites became unreachable due to an LFS configuration mismatch when LFS was enabled on the global tenant but disabled on the appliance.

994372
A high-severity "Diagnostic Agent Health" alarm appeared on the tenant dashboard roughly every 6 hours and cleared on its own after about 5 minutes. The diagnostic agent was healthy throughout β€” no data was lost and no functionality was affected. The alarm was a false positive.

This issue is now fixed and the agent now re-establishes its connection immediately when the gateway closes it, completing recovery in seconds rather than minutes. The agent's health status remains healthy throughout the reconnect, so the spurious alarm no longer fires.
916659
Fixed an issue where after an appliance upgrade, the Diagnostic Agent's manually disabled state was not preserved, causing unexpected error logs and alarms. Administrators who had intentionally disabled the service needed to re-disable it after every upgrade.
848972
When TSS is enabled and Large File Scanning (LFS) is enabled in the Netskope UI, but LFS is disabled in the DPoP CLI, the proxy still inspected files larger than 16 MB. This issue is now fixed.

Virtual Appliance139.0.0Fixed Issues
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of the new features and enhancements.

Increased SWAP Size

Increased the SWAP space to align with general recommendations and minimize memory performance pressure on the system.

Policy Support for HTTP Redirect

Netskope now supports a native HTTP Redirect policy action. This allows administrators to automatically route users to a new URL (e.g., a corporate app instance) using standard HTTP 307 headers, replacing the need for manually doing so via user notification links. To learn more, view Policy Support for HTTP Redirect.

Virtual Appliance139.0.0What's New
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of fixed issues in this release.

IssueDescription
1031565
After upgrading to appliance version 135.0.0, a timing issue during appliance startup could cause the URL database updater service to fail, resulting in the data plane (DPOP) stopping traffic processing. This occurred when an internal directory was created with incorrect permissions due to the order in which system components started up.

This issue is now fixed. The required directories are now created with the correct permissions during initialization, ensuring the URL database updater starts reliably regardless of component startup order.
1030520
Fixed an issue where certain sites became unreachable due to an LFS configuration mismatch when LFS was enabled on the global tenant but disabled on the appliance.

994372
A high-severity "Diagnostic Agent Health" alarm appeared on the tenant dashboard roughly every 6 hours and cleared on its own after about 5 minutes. The diagnostic agent was healthy throughout β€” no data was lost and no functionality was affected. The alarm was a false positive.

This issue is now fixed and the agent now re-establishes its connection immediately when the gateway closes it, completing recovery in seconds rather than minutes. The agent's health status remains healthy throughout the reconnect, so the spurious alarm no longer fires.
916659
Fixed an issue where after an appliance upgrade, the Diagnostic Agent's manually disabled state was not preserved, causing unexpected error logs and alarms. Administrators who had intentionally disabled the service needed to re-disable it after every upgrade.
848972
When TSS is enabled and Large File Scanning (LFS) is enabled in the Netskope UI, but LFS is disabled in the DPoP CLI, the proxy still inspected files larger than 16 MB. This issue is now fixed.

Virtual Appliance139.0.0Fixed Issues
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of the new features and enhancements.

Increased SWAP Size

Increased the SWAP space to align with general recommendations and minimize memory performance pressure on the system.

Policy Support for HTTP Redirect

Netskope now supports a native HTTP Redirect policy action. This allows administrators to automatically route users to a new URL (e.g., a corporate app instance) using standard HTTP 307 headers, replacing the need for manually doing so via user notification links. To learn more, view Policy Support for HTTP Redirect.

Virtual Appliance139.0.0What's New
Ongoing
Jul 31, 2026, 02:21 AM EDT
Virtual Appliance Release Notes Version 139.0.0

Here is the list of fixed issues in this release.

IssueDescription
1031565
After upgrading to appliance version 135.0.0, a timing issue during appliance startup could cause the URL database updater service to fail, resulting in the data plane (DPOP) stopping traffic processing. This occurred when an internal directory was created with incorrect permissions due to the order in which system components started up.

This issue is now fixed. The required directories are now created with the correct permissions during initialization, ensuring the URL database updater starts reliably regardless of component startup order.
1030520
Fixed an issue where certain sites became unreachable due to an LFS configuration mismatch when LFS was enabled on the global tenant but disabled on the appliance.

994372
A high-severity "Diagnostic Agent Health" alarm appeared on the tenant dashboard roughly every 6 hours and cleared on its own after about 5 minutes. The diagnostic agent was healthy throughout β€” no data was lost and no functionality was affected. The alarm was a false positive.

This issue is now fixed and the agent now re-establishes its connection immediately when the gateway closes it, completing recovery in seconds rather than minutes. The agent's health status remains healthy throughout the reconnect, so the spurious alarm no longer fires.
916659
Fixed an issue where after an appliance upgrade, the Diagnostic Agent's manually disabled state was not preserved, causing unexpected error logs and alarms. Administrators who had intentionally disabled the service needed to re-disable it after every upgrade.
848972
When TSS is enabled and Large File Scanning (LFS) is enabled in the Netskope UI, but LFS is disabled in the DPoP CLI, the proxy still inspected files larger than 16 MB. This issue is now fixed.

Virtual Appliance139.0.0Fixed Issues
Ongoing
Jul 27, 2026, 04:47 PM EDT
AI Security Ops Release Notes Version

AISecOps DLP Agent enhancements

DLP Investigations & Quota Management

  • New Tenant Default: Auto-investigation is now enabled by default for new tenants.
  • UX Improvement: The investigation trail now allows for independent per-step expand/collapse, making it easier for analysts to focus on specific details.
  • Attribution: Cases now surface β€œInvestigated by” attribution, showing the user email for manual runs or β€œAutomatic investigation” for system-initiated runs.

Case Details, Performance, and Context

  • Enhanced Incident Context: Incidents originating from web browsing now display the Site name and URL in the incident side panel, giving investigators destination context.
  • Speed & Accuracy: Significant performance improvements have been implemented for large tenants, including faster server-side duplicate-case search and a speedup on the Cases-list page count.

Integrations & Configuration

  • Data View Schedule: Insight Generation cron is rescheduled from four times daily to daily at 2:30am PST.
  • Rule Clarity: User-created Case Rules now show the author’s email on the rule card, replacing the generic β€œCreated by Netskope” label.
  • Safety Net: The rule editor now prompts the user to confirm discarding changes when canceling a form.

Documentation Link: The Help link in the agent UI now points to the public AISecOps DLP Agent documentation.

AI Security OpsWhat's New
Ongoing
Jul 27, 2026, 04:46 PM EDT
AI Security Ops Release Notes Version

AISecOps DLP Agent enhancements

DLP Investigations & Quota Management

  • New Tenant Default: Auto-investigation is now enabled by default for new tenants.
  • UX Improvement: The investigation trail now allows for independent per-step expand/collapse, making it easier for analysts to focus on specific details.
  • Attribution: Cases now surface β€œInvestigated by” attribution, showing the user email for manual runs or β€œAutomatic investigation” for system-initiated runs.

Case Details, Performance, and Context

  • Enhanced Incident Context: Incidents originating from web browsing now display the Site name and URL in the incident side panel, giving investigators destination context.
  • Speed & Accuracy: Significant performance improvements have been implemented for large tenants, including faster server-side duplicate-case search and a speedup on the Cases-list page count.

Integrations & Configuration

  • Data View Schedule: Insight Generation cron is rescheduled from four times daily to daily at 2:30am PST.
  • Rule Clarity: User-created Case Rules now show the author’s email on the rule card, replacing the generic β€œCreated by Netskope” label.
  • Safety Net: The rule editor now prompts the user to confirm discarding changes when canceling a form.

Documentation Link: The Help link in the agent UI now points to the public AISecOps DLP Agent documentation.

AI Security OpsWhat's New
Ongoing
Jul 21, 2026, 01:34 PM EDT
Enterprise Browser Release Notes July 15, 2026

Desktop Upgrade to Enterprise Browser v1.5.6

Upgrade v1.5.6 | 146.0.7680.214 is now available for Netskope Enterprise Browser.

Desktop Platforms: Windows (x86, ARM), MacOS

Main updates:

  • Screen Share Guard (Beta)
  • File Downloads Control – Restrict and Encrypt (Beta)
  • Control Text Input (Beta)
  • Save As (Beta)
  • Inform users about the restrictions that apply
  • macOS MDM (PKG)
  • InfoBar for Private Clipboard
  • Data Masking (Beta)
  • Security patches available until Jun 3, 2026

macOS MDM support (PKG)

This update introduces a native macOS installer package to ensure a seamless administrative experience.

  • Standardized PKG Installer: A native macOS .pkg file is now generated automatically in our CI/CD pipeline, ensuring every release is ready for enterprise distribution.
  • MDM Compatibility: Fully optimized for major providers (Jamf, Kandji, Intune) to support Silent Installation, enabling zero-touch deployment without end-user prompts.
  • Validated Deployment Scenarios: Verified workflows for fresh installs, in-place upgrades from manual versions, and remote configuration via MDM profiles (.plist).
  • Parity with Windows: Provides IT teams with a consistent deployment logic and documentation set across both Windows (MSI) and macOS (PKG) for hybrid fleet management

Enterprise Browser Restrictions and Controls Enhancement

This update introduces two primary UI components designed to keep users informed about their security posture without interrupting their browsing experience.

1. Page-Level β€œPolicy” Button (Address Bar)

A new β€œPolicy” button has been added to the navigation bar, positioned immediately before the β€œSite Information” (lock) icon.

  • Real-time Context: When clicked, it displays a popup listing the specific Netskope policy name (rulename) governing the current site.
  • Action Visibility: It explicitly lists which browser controls are currently Blocked or Enabled, including:
    • Copy / Paste operations
    • Print operations
    • Screen capture
    • Watermarking
    • New: Save As, File Downloads, Data Masking, and Text Input Suppression.
  • Status: If no restrictions apply, it clearly states: β€œAll actions allowed.”

2. Profile-Level Configuration (Profile Menu)

The profile popup (accessed by clicking the user icon in the toolbar) has been expanded to include a β€œGeneral Configuration” section. This surfaces the status of key browser-wide policies:

  • Password Manager: Enabled/Disabled
  • Developer Tools: Enabled/Disabled
  • Notifications & Popups: Enabled/Disabled
  • Media Access: Audio/Video input permissions
  • New: Intelligent Tab Sharing status

Sandboxed Clipboard Notification Infobar

When β€œSandboxed Clipboard” settings were active, users were often unaware why copy/paste actions between the Enterprise Browser and external applications were failing, leading to confusion and perceived β€œbugs.”

This feature proactively notifies users when clipboard operations are blocked by administrator policies using a non-intrusive infobar.

Key Capabilities:

  • Contextual Notifications: Displays specific messages based on the block direction:
    • Copying out of Enterprise Browser: β€œPasting data outside of this browser has been blocked by administrator policies.”
    • Pasting into Enterprise Browser: β€œCopying data from outside of this browser has been blocked by administrator policies.”
  • Supports all Sandboxed Clipboard modes, including full Sandbox, Read-only, and Write-only restrictions.

Screen Share Guard (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces Screen Share Guard, a privacy-first security layer designed to prevent the accidental exposure of sensitive corporate or personal data during virtual meetings (e.g., Zoom, Teams, Google Meet).

Key Capabilities:

  • Real-Time Content Analysis: The browser automatically analyzes the active tab’s content upon page load. Using a hybrid engineβ€”combining heuristic regex pattern matching with a lightweight ML coreβ€”it determines if a page contains sensitive info like financial data, credentials, or PII.
  • Privacy Overlay: If high-risk content is detected, the browser applies an opaque gray mask over the page content. This prevents the data from being visible to meeting participants while keeping the tab title and URL visible for the presenter’s navigation.
  • User-Centric Controls: Users maintain explicit control through a warning dialog. They can choose to β€œView Page” (accepting the risk for that domain) or β€œKeep Protected.” Manual β€œShow/Hide” toggles are also available via the tab’s context menu.
  • Hybrid Extraction: Supports both standard HTML web pages and large PDF documents (up to 100MB) using an Accessibility Tree (AXTree) snapshotting strategy for high-performance text extraction.
  • Smart Allowlisting: Includes a built-in allowlist of 100+ low-risk domains (e.g., search engines, news, reference sites) to minimize friction and prevent false positives during general browsing.

File Download Control – Restrict and Encrypt (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces a high-performance File Download Control engine for the Enterprise Browser. This update moves beyond simple binary (allow/block) actions to a sophisticated streaming architecture that enables real-time encryption.

Key Capabilities:

  • File Download Protection: Supports β€œBlock, Allow, or Encrypt” logic for files by processing data directly in the browser renderer.,eliminating proxy-induced latency.
  • Automatic Local Encryption: Admins can enforce a policy that automatically encrypts files as they are saved to the device, ensuring sensitive data remains protected even if it needs to live on unmanaged storage. EB will add the .eb file extension to the original file.
  • Per-Profile Encryption: Encrypted files can only be opened within the same Enterprise Browser User profile that performed the download.
  • Seamless decryption on re-upload: Encrypted downloads are automatically decrypted when uploaded back through the browser via file chooser or drag-and-drop. Supported encrypted files can also be viewed within the corresponding Enterprise Browser profile (like PDFs, Images, etc.)
  • Unified Policy Framework: Download block is also natively integrated with β€œSave As” options. Restricting a download also covers β€œSave Page As”, β€œSave Link as”, β€œSave Image As” items as well, to close common bypass loops.
  • Integrated Info Bar: A native browser notification bar provides real-time status and justification prompts during the download and encryption / decryption lifecycle.

Browser Protection Policies – Control Text Input (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces Text Input Suppression for the Enterprise Browser, a new Browser Protection control that renders sensitive web pages effectively read-only. Users can continue to view and navigate applications, but attempts to add, modify, or replace text in editable regions are rejected (with a user notification via the info bar) thereby closing a common data-exfiltration path without breaking the ability to read or scroll.

Key Capabilities:

  • Universal Input Coverage: Enforced inside the renderer’s editing pipeline so suppression applies uniformly across physical keyboards, on-screen keyboards, multi-lingual IMEs (Chinese, Japanese, Korean), voice dictation, drag-and-drop into editable regions, and clipboard paste.
  • Spellcheck and Autocorrect Aware: Spelling indicators continue to render as non-mutating decorations, but autocorrect and β€œReplace with suggestion” actions are blocked β€” the underlying text is preserved exactly as rendered.
  • Autofill Protection: Browser autofill is suppressed, preventing addresses, credit cards, and saved form values from populating fields under a protected policy.
  • Canvas Text Coverage: For applications that use for editing (e.g. Figma, browser-hosted code editors), text-producing input is filtered. Non-text canvas interactions ( like drawing, map pan/zoom, HTML5 games) are intentionally left untouched to preserve web compatibility.
  • Site Isolation Aware: Enforcement is per-frame, so the policy is automatically respected inside cross-origin iframes. Users cannot bypass the lock by interacting with embedded third-party content.
  • Tab and Focus Preserved: Keyboard navigation (Tab / Shift+Tab) and programmatic focus continue to work normally to avoid regressing accessibility flows.

Browser Protection Policies – Control β€œSave As” (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

The β€œSave As” Control policy allows administrators to govern whether users can save web content to their local devices. This feature integrates directly into the existing β€œEnterprise Browser Protection” policy pipeline, alongside existing controls like Copy, Print, and Screenshot.

Key Capabilities:

  • Comprehensive UI Coverage: Blocks β€œSave As” actions across all major entry points:
  • Main Menu: File -> Save page as...
  • Context Menu (Right-click): β€œSave image as…”, β€œSave link as…”, β€œSave audio/video as…”, and β€œSave video frame as…”
  • PDF & Plugins: Blocks β€œSave as…” and β€œDownload” buttons within the embedded PDF viewer.
  • Keyboard Shortcuts: Governs Ctrl+S (Windows/Linux) and Cmd+S (macOS).
  • Granular Policy Enforcement: Policies are applied on a per-domain basis
  • User Feedback: When an action is blocked, users receive an immediate infobar notification, ensuring they understand why the action was restricted without interrupting their workflow.
  • Tenant-Level Fallback: Admins can define a default β€œfallback” behavior (Allow or Block) for domains where a specific policy hasn’t been defined.

Browser Protection Policies – Data Masking (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Enterprise Browser introduces Real-Time Data Masking, a shippable beta security tool that automatically redacts sensitive info (like credit card numbers) within the browser renderer.

Developed across two major milestones, the system combines a dynamic rendering engineβ€”which prevents visual latency in modern web appsβ€”with a robust backend rollout control to ensure a stable deployment.

It also includes β€œRed Pixel” testing to guarantee that sensitive data is never momentarily visible before being masked.

During Beta this feature is not configurable via the WebUI.

Enterprise Browser15.2026What's New
Ongoing
Jul 21, 2026, 01:33 PM EDT
Enterprise Browser Release Notes July 15, 2026

Desktop Upgrade to Enterprise Browser v1.5.6

Upgrade v1.5.6 | 146.0.7680.214 is now available for Netskope Enterprise Browser.

Desktop Platforms: Windows (x86, ARM), MacOS

Main updates:

  • Screen Share Guard (Beta)
  • File Downloads Control – Restrict and Encrypt (Beta)
  • Control Text Input (Beta)
  • Save As (Beta)
  • Inform users about the restrictions that apply
  • macOS MDM (PKG)
  • InfoBar for Private Clipboard
  • Data Masking (Beta)
  • Security patches available until Jun 3, 2026

macOS MDM support (PKG)

This update introduces a native macOS installer package to ensure a seamless administrative experience.

  • Standardized PKG Installer: A native macOS .pkg file is now generated automatically in our CI/CD pipeline, ensuring every release is ready for enterprise distribution.
  • MDM Compatibility: Fully optimized for major providers (Jamf, Kandji, Intune) to support Silent Installation, enabling zero-touch deployment without end-user prompts.
  • Validated Deployment Scenarios: Verified workflows for fresh installs, in-place upgrades from manual versions, and remote configuration via MDM profiles (.plist).
  • Parity with Windows: Provides IT teams with a consistent deployment logic and documentation set across both Windows (MSI) and macOS (PKG) for hybrid fleet management

Enterprise Browser Restrictions and Controls Enhancement

This update introduces two primary UI components designed to keep users informed about their security posture without interrupting their browsing experience.

1. Page-Level β€œPolicy” Button (Address Bar)

A new β€œPolicy” button has been added to the navigation bar, positioned immediately before the β€œSite Information” (lock) icon.

  • Real-time Context: When clicked, it displays a popup listing the specific Netskope policy name (rulename) governing the current site.
  • Action Visibility: It explicitly lists which browser controls are currently Blocked or Enabled, including:
    • Copy / Paste operations
    • Print operations
    • Screen capture
    • Watermarking
    • New: Save As, File Downloads, Data Masking, and Text Input Suppression.
  • Status: If no restrictions apply, it clearly states: β€œAll actions allowed.”

2. Profile-Level Configuration (Profile Menu)

The profile popup (accessed by clicking the user icon in the toolbar) has been expanded to include a β€œGeneral Configuration” section. This surfaces the status of key browser-wide policies:

  • Password Manager: Enabled/Disabled
  • Developer Tools: Enabled/Disabled
  • Notifications & Popups: Enabled/Disabled
  • Media Access: Audio/Video input permissions
  • New: Intelligent Tab Sharing status

Sandboxed Clipboard Notification Infobar

When β€œSandboxed Clipboard” settings were active, users were often unaware why copy/paste actions between the Enterprise Browser and external applications were failing, leading to confusion and perceived β€œbugs.”

This feature proactively notifies users when clipboard operations are blocked by administrator policies using a non-intrusive infobar.

Key Capabilities:

  • Contextual Notifications: Displays specific messages based on the block direction:
    • Copying out of Enterprise Browser: β€œPasting data outside of this browser has been blocked by administrator policies.”
    • Pasting into Enterprise Browser: β€œCopying data from outside of this browser has been blocked by administrator policies.”
  • Supports all Sandboxed Clipboard modes, including full Sandbox, Read-only, and Write-only restrictions.

Screen Share Guard (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces Screen Share Guard, a privacy-first security layer designed to prevent the accidental exposure of sensitive corporate or personal data during virtual meetings (e.g., Zoom, Teams, Google Meet).

Key Capabilities:

  • Real-Time Content Analysis: The browser automatically analyzes the active tab’s content upon page load. Using a hybrid engineβ€”combining heuristic regex pattern matching with a lightweight ML coreβ€”it determines if a page contains sensitive info like financial data, credentials, or PII.
  • Privacy Overlay: If high-risk content is detected, the browser applies an opaque gray mask over the page content. This prevents the data from being visible to meeting participants while keeping the tab title and URL visible for the presenter’s navigation.
  • User-Centric Controls: Users maintain explicit control through a warning dialog. They can choose to β€œView Page” (accepting the risk for that domain) or β€œKeep Protected.” Manual β€œShow/Hide” toggles are also available via the tab’s context menu.
  • Hybrid Extraction: Supports both standard HTML web pages and large PDF documents (up to 100MB) using an Accessibility Tree (AXTree) snapshotting strategy for high-performance text extraction.
  • Smart Allowlisting: Includes a built-in allowlist of 100+ low-risk domains (e.g., search engines, news, reference sites) to minimize friction and prevent false positives during general browsing.

File Download Control – Restrict and Encrypt (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces a high-performance File Download Control engine for the Enterprise Browser. This update moves beyond simple binary (allow/block) actions to a sophisticated streaming architecture that enables real-time encryption.

Key Capabilities:

  • File Download Protection: Supports β€œBlock, Allow, or Encrypt” logic for files by processing data directly in the browser renderer.,eliminating proxy-induced latency.
  • Automatic Local Encryption: Admins can enforce a policy that automatically encrypts files as they are saved to the device, ensuring sensitive data remains protected even if it needs to live on unmanaged storage. EB will add the .eb file extension to the original file.
  • Per-Profile Encryption: Encrypted files can only be opened within the same Enterprise Browser User profile that performed the download.
  • Seamless decryption on re-upload: Encrypted downloads are automatically decrypted when uploaded back through the browser via file chooser or drag-and-drop. Supported encrypted files can also be viewed within the corresponding Enterprise Browser profile (like PDFs, Images, etc.)
  • Unified Policy Framework: Download block is also natively integrated with β€œSave As” options. Restricting a download also covers β€œSave Page As”, β€œSave Link as”, β€œSave Image As” items as well, to close common bypass loops.
  • Integrated Info Bar: A native browser notification bar provides real-time status and justification prompts during the download and encryption / decryption lifecycle.

Browser Protection Policies – Control Text Input (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Netskope introduces Text Input Suppression for the Enterprise Browser, a new Browser Protection control that renders sensitive web pages effectively read-only. Users can continue to view and navigate applications, but attempts to add, modify, or replace text in editable regions are rejected (with a user notification via the info bar) thereby closing a common data-exfiltration path without breaking the ability to read or scroll.

Key Capabilities:

  • Universal Input Coverage: Enforced inside the renderer’s editing pipeline so suppression applies uniformly across physical keyboards, on-screen keyboards, multi-lingual IMEs (Chinese, Japanese, Korean), voice dictation, drag-and-drop into editable regions, and clipboard paste.
  • Spellcheck and Autocorrect Aware: Spelling indicators continue to render as non-mutating decorations, but autocorrect and β€œReplace with suggestion” actions are blocked β€” the underlying text is preserved exactly as rendered.
  • Autofill Protection: Browser autofill is suppressed, preventing addresses, credit cards, and saved form values from populating fields under a protected policy.
  • Canvas Text Coverage: For applications that use for editing (e.g. Figma, browser-hosted code editors), text-producing input is filtered. Non-text canvas interactions ( like drawing, map pan/zoom, HTML5 games) are intentionally left untouched to preserve web compatibility.
  • Site Isolation Aware: Enforcement is per-frame, so the policy is automatically respected inside cross-origin iframes. Users cannot bypass the lock by interacting with embedded third-party content.
  • Tab and Focus Preserved: Keyboard navigation (Tab / Shift+Tab) and programmatic focus continue to work normally to avoid regressing accessibility flows.

Browser Protection Policies – Control β€œSave As” (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

The β€œSave As” Control policy allows administrators to govern whether users can save web content to their local devices. This feature integrates directly into the existing β€œEnterprise Browser Protection” policy pipeline, alongside existing controls like Copy, Print, and Screenshot.

Key Capabilities:

  • Comprehensive UI Coverage: Blocks β€œSave As” actions across all major entry points:
  • Main Menu: File -> Save page as...
  • Context Menu (Right-click): β€œSave image as…”, β€œSave link as…”, β€œSave audio/video as…”, and β€œSave video frame as…”
  • PDF & Plugins: Blocks β€œSave as…” and β€œDownload” buttons within the embedded PDF viewer.
  • Keyboard Shortcuts: Governs Ctrl+S (Windows/Linux) and Cmd+S (macOS).
  • Granular Policy Enforcement: Policies are applied on a per-domain basis
  • User Feedback: When an action is blocked, users receive an immediate infobar notification, ensuring they understand why the action was restricted without interrupting their workflow.
  • Tenant-Level Fallback: Admins can define a default β€œfallback” behavior (Allow or Block) for domains where a specific policy hasn’t been defined.

Browser Protection Policies – Data Masking (BETA)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature.

Enterprise Browser introduces Real-Time Data Masking, a shippable beta security tool that automatically redacts sensitive info (like credit card numbers) within the browser renderer.

Developed across two major milestones, the system combines a dynamic rendering engineβ€”which prevents visual latency in modern web appsβ€”with a robust backend rollout control to ensure a stable deployment.

It also includes β€œRed Pixel” testing to guarantee that sensitive data is never momentarily visible before being masked.

During Beta this feature is not configurable via the WebUI.

Enterprise Browser15.2026What's New
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Here is the list of the new features and enhancements.

Private Access Cloud

Pattern Matching Support in Application Definition

Private application definitions now support pattern matching for host (FQDN) entries. This is useful for environments where application hostnames are dynamically generated and only partially predictable. For example, container platforms such as AWS ECS that create names like nginx.consumers.sandbox.internal-1e2cdc5, where only the middle segment (consumers.sandbox.internal) is stable. Instead of defining each host individually, administrators can define a single pattern that matches the stable portion of the name, reducing configuration overhead and keeping policy in sync as applications are created and destroyed.

Supported Operating Systems: All supported platforms

Minimum Netskope Client Version: 140.0.0 (Private Build: 139.0.0)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

Publisher

Software Version: 139.0

Supported Publisher Versions: 139.0, 138.0, and 137.0.

General Availability Date: July 16, 2026

Updated Kernel Versions

PlatformKernel Version
OVA
VHDX
AMI
VHD
QCOW2
5.15.0-181-generic
6.8.0-1059-azure
6.5.0-1024-aws
6.8.0-1059-azure
5.15.0-181-generic

SHA Hash for Publisher Images

Image TypeSHA256
OVA
d7d603fecce0322903726f76c740451216be994282c6d7abedd64786b55ba046
VHDX
55a90afc831fac9151a6cc0e1a3540cfa3dadb0c0806c2a16ebd9cdf9aa48591
QCOW2
b2396819e17baa4ed220125d93c2182ad59dde2d92cd9616a7ccb183fe65ad24

OVA/VHDX Hosting on the Alicloud

OVA hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.ova
VHDX hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.vhdx
QCOW2 hosting on the Alicloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.qcow2

Validation of All DNS Records on Publisher

This release introduces a tenant-level option (disabled by default) to perform Publisher-first DNS validation and resolution for private applications matched by an exact FQDN policy. Previously, exact-match apps configured with use_publisher_dns: false received an immediate locally generated stub IP without resolving through the Publisher, which did not preserve the DNS answer structure (for example, CNAME chains). This could disrupt workloads that rely on DNS aliasing and canonicalization, such as Microsoft SQL AlwaysOn listeners and Kerberos/SPN flows.

When the option is enabled, QTYPE A queries for exact-match policy hits are validated and resolved via the Publisher before the client responds. The returned DNS response preserves the full DNS structure (CNAME chain and other record sets) while still enforcing ZTNA steering by rewriting A-record data to the stub IP. Wildcard matching and validation behavior are unchanged. The toggle is available in the management UI with RBAC and audit support.

The initial release covers QTYPE A queries only (AAAA/HTTPS/SVCB are not in scope). This option is disabled by default; there are no behavioral changes unless you enable it.

Local Broker

Dedicated Local Broker Hostname Per Steering Configuration

Administrators can now assign a dedicated Local Broker hostname (FQDN) to individual Traffic Steering configurations. Instead of all users resolving a single tenant-wide hostname, different user groups can be mapped to distinct LBR hostnames.

For tenants using latency-based local broker selection (GSLB), the dedicated hostname also serves as a per-steering-config DNS fallback when GSLB is unavailable.

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.
Netskope Private Access139What's New
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Private Access Cloud

Issue NumberDescription
1026259
Resolved an issue where the Netskope Client failed to establish the Prelogon tunnel when the device certificate’s issuer chain contained non-ASCII characters encoded as ISO-8859-1 (for example, German umlauts such as Γ€ and ΓΌ) inside an ASN.1 field tagged as UTF8STRING. In affected environments, the Client reported a certificate issuer mismatch on the Organization (O=) field and the Gateway rejected the connection with Device certificate fails for Prelogon. The certificate issuer comparison now correctly handles these mis-encoded values, allowing Prelogon authentication to succeed without requiring users to rebuild their PKI.
Netskope Private Access139Fixed Issues
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Publisher

Issue NumberDescription
1042230
When deploying a Publisher on RHEL 9.x using the generic bootstrap script, the deployment may fail with Error: SELinux relabeling of /home/ is not allowed. This occurs because the container bootstrap step attempts an SELinux relabel of the user’s home directory, which is blocked in some hardened SELinux configurations.
905088
The Enable Publisher DNS Records Validation option may be visible in Global Attributes on the Publishers page before the corresponding capability is fully available. Do not enable this option until the feature is confirmed available for your tenant, as toggling it while the feature is incomplete has no supported effect.
Netskope Private Access139Known Issues
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Here is the list of the new features and enhancements.

Private Access Cloud

Pattern Matching Support in Application Definition

Private application definitions now support pattern matching for host (FQDN) entries. This is useful for environments where application hostnames are dynamically generated and only partially predictable. For example, container platforms such as AWS ECS that create names like nginx.consumers.sandbox.internal-1e2cdc5, where only the middle segment (consumers.sandbox.internal) is stable. Instead of defining each host individually, administrators can define a single pattern that matches the stable portion of the name, reducing configuration overhead and keeping policy in sync as applications are created and destroyed.

Supported Operating Systems: All supported platforms

Minimum Netskope Client Version: 140.0.0 (Private Build: 139.0.0)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

Publisher

Software Version: 139.0

Supported Publisher Versions: 139.0, 138.0, and 137.0.

General Availability Date: July 16, 2026

Updated Kernel Versions

PlatformKernel Version
OVA
VHDX
AMI
VHD
QCOW2
5.15.0-181-generic
6.8.0-1059-azure
6.5.0-1024-aws
6.8.0-1059-azure
5.15.0-181-generic

SHA Hash for Publisher Images

Image TypeSHA256
OVA
d7d603fecce0322903726f76c740451216be994282c6d7abedd64786b55ba046
VHDX
55a90afc831fac9151a6cc0e1a3540cfa3dadb0c0806c2a16ebd9cdf9aa48591
QCOW2
b2396819e17baa4ed220125d93c2182ad59dde2d92cd9616a7ccb183fe65ad24

OVA/VHDX Hosting on the Alicloud

OVA hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.ova
VHDX hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.vhdx
QCOW2 hosting on the Alicloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.qcow2

Validation of All DNS Records on Publisher

This release introduces a tenant-level option (disabled by default) to perform Publisher-first DNS validation and resolution for private applications matched by an exact FQDN policy. Previously, exact-match apps configured with use_publisher_dns: false received an immediate locally generated stub IP without resolving through the Publisher, which did not preserve the DNS answer structure (for example, CNAME chains). This could disrupt workloads that rely on DNS aliasing and canonicalization, such as Microsoft SQL AlwaysOn listeners and Kerberos/SPN flows.

When the option is enabled, QTYPE A queries for exact-match policy hits are validated and resolved via the Publisher before the client responds. The returned DNS response preserves the full DNS structure (CNAME chain and other record sets) while still enforcing ZTNA steering by rewriting A-record data to the stub IP. Wildcard matching and validation behavior are unchanged. The toggle is available in the management UI with RBAC and audit support.

The initial release covers QTYPE A queries only (AAAA/HTTPS/SVCB are not in scope). This option is disabled by default; there are no behavioral changes unless you enable it.

Local Broker

Dedicated Local Broker Hostname Per Steering Configuration

Administrators can now assign a dedicated Local Broker hostname (FQDN) to individual Traffic Steering configurations. Instead of all users resolving a single tenant-wide hostname, different user groups can be mapped to distinct LBR hostnames.

For tenants using latency-based local broker selection (GSLB), the dedicated hostname also serves as a per-steering-config DNS fallback when GSLB is unavailable.

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.
Netskope Private Access139What's New
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Private Access Cloud

Issue NumberDescription
1026259
Resolved an issue where the Netskope Client failed to establish the Prelogon tunnel when the device certificate’s issuer chain contained non-ASCII characters encoded as ISO-8859-1 (for example, German umlauts such as Γ€ and ΓΌ) inside an ASN.1 field tagged as UTF8STRING. In affected environments, the Client reported a certificate issuer mismatch on the Organization (O=) field and the Gateway rejected the connection with Device certificate fails for Prelogon. The certificate issuer comparison now correctly handles these mis-encoded values, allowing Prelogon authentication to succeed without requiring users to rebuild their PKI.
Netskope Private Access139Fixed Issues
Ongoing
Jul 16, 2026, 02:41 PM EDT
Netskope Private Access Release Notes Version 139.0

Publisher

Issue NumberDescription
1042230
When deploying a Publisher on RHEL 9.x using the generic bootstrap script, the deployment may fail with Error: SELinux relabeling of /home/ is not allowed. This occurs because the container bootstrap step attempts an SELinux relabel of the user’s home directory, which is blocked in some hardened SELinux configurations.
905088
The Enable Publisher DNS Records Validation option may be visible in Global Attributes on the Publishers page before the corresponding capability is fully available. Do not enable this option until the feature is confirmed available for your tenant, as toggling it while the feature is incomplete has no supported effect.
Netskope Private Access139Known Issues
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Here is the list of the new features and enhancements.

Private Access Cloud

Pattern Matching Support in Application Definition

Private application definitions now support pattern matching for host (FQDN) entries. This is useful for environments where application hostnames are dynamically generated and only partially predictable. For example, container platforms such as AWS ECS that create names like nginx.consumers.sandbox.internal-1e2cdc5, where only the middle segment (consumers.sandbox.internal) is stable. Instead of defining each host individually, administrators can define a single pattern that matches the stable portion of the name, reducing configuration overhead and keeping policy in sync as applications are created and destroyed.

Supported Operating Systems: All supported platforms

Minimum Netskope Client Version: 140.0.0 (Private Build: 139.0.0)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

Publisher

Software Version: 139.0

Supported Publisher Versions: 139.0, 138.0, and 137.0.

General Availability Date: July 16, 2026

Updated Kernel Versions

PlatformKernel Version
OVA
VHDX
AMI
VHD
QCOW2
5.15.0-181-generic
6.8.0-1059-azure
6.5.0-1024-aws
6.8.0-1059-azure
5.15.0-181-generic

SHA Hash for Publisher Images

Image TypeSHA256
OVA
d7d603fecce0322903726f76c740451216be994282c6d7abedd64786b55ba046
VHDX
55a90afc831fac9151a6cc0e1a3540cfa3dadb0c0806c2a16ebd9cdf9aa48591
QCOW2
b2396819e17baa4ed220125d93c2182ad59dde2d92cd9616a7ccb183fe65ad24

OVA/VHDX Hosting on the Alicloud

OVA hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.ova
VHDX hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.vhdx
QCOW2 hosting on the Alicloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.qcow2

Validation of All DNS Records on Publisher

This release introduces a tenant-level option (disabled by default) to perform Publisher-first DNS validation and resolution for private applications matched by an exact FQDN policy. Previously, exact-match apps configured with use_publisher_dns: false received an immediate locally generated stub IP without resolving through the Publisher, which did not preserve the DNS answer structure (for example, CNAME chains). This could disrupt workloads that rely on DNS aliasing and canonicalization, such as Microsoft SQL AlwaysOn listeners and Kerberos/SPN flows.

When the option is enabled, QTYPE A queries for exact-match policy hits are validated and resolved via the Publisher before the client responds. The returned DNS response preserves the full DNS structure (CNAME chain and other record sets) while still enforcing ZTNA steering by rewriting A-record data to the stub IP. Wildcard matching and validation behavior are unchanged. The toggle is available in the management UI with RBAC and audit support.

The initial release covers QTYPE A queries only (AAAA/HTTPS/SVCB are not in scope). This option is disabled by default; there are no behavioral changes unless you enable it.

Local Broker

Dedicated Local Broker Hostname Per Steering Configuration

Administrators can now assign a dedicated Local Broker hostname (FQDN) to individual Traffic Steering configurations. Instead of all users resolving a single tenant-wide hostname, different user groups can be mapped to distinct LBR hostnames.

For tenants using latency-based local broker selection (GSLB), the dedicated hostname also serves as a per-steering-config DNS fallback when GSLB is unavailable.

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.
Netskope Private Access139What's New
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Private Access Cloud

Issue NumberDescription
1026259
Resolved an issue where the Netskope Client failed to establish the Prelogon tunnel when the device certificate’s issuer chain contained non-ASCII characters encoded as ISO-8859-1 (for example, German umlauts such as Γ€ and ΓΌ) inside an ASN.1 field tagged as UTF8STRING. In affected environments, the Client reported a certificate issuer mismatch on the Organization (O=) field and the Gateway rejected the connection with Device certificate fails for Prelogon. The certificate issuer comparison now correctly handles these mis-encoded values, allowing Prelogon authentication to succeed without requiring users to rebuild their PKI.
Netskope Private Access139Fixed Issues
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Publisher

Issue NumberDescription
1042230
When deploying a Publisher on RHEL 9.x using the generic bootstrap script, the deployment may fail with Error: SELinux relabeling of /home/ is not allowed. This occurs because the container bootstrap step attempts an SELinux relabel of the user’s home directory, which is blocked in some hardened SELinux configurations.
905088
The Enable Publisher DNS Records Validation option may be visible in Global Attributes on the Publishers page before the corresponding capability is fully available. Do not enable this option until the feature is confirmed available for your tenant, as toggling it while the feature is incomplete has no supported effect.
Netskope Private Access139Known Issues
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Here is the list of the new features and enhancements.

Private Access Cloud

Pattern Matching Support in Application Definition

Private application definitions now support pattern matching for host (FQDN) entries. This is useful for environments where application hostnames are dynamically generated and only partially predictable. For example, container platforms such as AWS ECS that create names like nginx.consumers.sandbox.internal-1e2cdc5, where only the middle segment (consumers.sandbox.internal) is stable. Instead of defining each host individually, administrators can define a single pattern that matches the stable portion of the name, reducing configuration overhead and keeping policy in sync as applications are created and destroyed.

Supported Operating Systems: All supported platforms

Minimum Netskope Client Version: 140.0.0 (Private Build: 139.0.0)

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

Publisher

Software Version: 139.0

Supported Publisher Versions: 139.0, 138.0, and 137.0.

General Availability Date: July 16, 2026

Updated Kernel Versions

PlatformKernel Version
OVA
VHDX
AMI
VHD
QCOW2
5.15.0-181-generic
6.8.0-1059-azure
6.5.0-1024-aws
6.8.0-1059-azure
5.15.0-181-generic

SHA Hash for Publisher Images

Image TypeSHA256
OVA
d7d603fecce0322903726f76c740451216be994282c6d7abedd64786b55ba046
VHDX
55a90afc831fac9151a6cc0e1a3540cfa3dadb0c0806c2a16ebd9cdf9aa48591
QCOW2
b2396819e17baa4ed220125d93c2182ad59dde2d92cd9616a7ccb183fe65ad24

OVA/VHDX Hosting on the Alicloud

OVA hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.ova
VHDX hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.vhdx
QCOW2 hosting on the Alicloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.qcow2

Validation of All DNS Records on Publisher

This release introduces a tenant-level option (disabled by default) to perform Publisher-first DNS validation and resolution for private applications matched by an exact FQDN policy. Previously, exact-match apps configured with use_publisher_dns: false received an immediate locally generated stub IP without resolving through the Publisher, which did not preserve the DNS answer structure (for example, CNAME chains). This could disrupt workloads that rely on DNS aliasing and canonicalization, such as Microsoft SQL AlwaysOn listeners and Kerberos/SPN flows.

When the option is enabled, QTYPE A queries for exact-match policy hits are validated and resolved via the Publisher before the client responds. The returned DNS response preserves the full DNS structure (CNAME chain and other record sets) while still enforcing ZTNA steering by rewriting A-record data to the stub IP. Wildcard matching and validation behavior are unchanged. The toggle is available in the management UI with RBAC and audit support.

The initial release covers QTYPE A queries only (AAAA/HTTPS/SVCB are not in scope). This option is disabled by default; there are no behavioral changes unless you enable it.

Local Broker

Dedicated Local Broker Hostname Per Steering Configuration

Administrators can now assign a dedicated Local Broker hostname (FQDN) to individual Traffic Steering configurations. Instead of all users resolving a single tenant-wide hostname, different user groups can be mapped to distinct LBR hostnames.

For tenants using latency-based local broker selection (GSLB), the dedicated hostname also serves as a per-steering-config DNS fallback when GSLB is unavailable.

This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.
Netskope Private Access139What's New
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Private Access Cloud

Issue NumberDescription
1026259
Resolved an issue where the Netskope Client failed to establish the Prelogon tunnel when the device certificate’s issuer chain contained non-ASCII characters encoded as ISO-8859-1 (for example, German umlauts such as Γ€ and ΓΌ) inside an ASN.1 field tagged as UTF8STRING. In affected environments, the Client reported a certificate issuer mismatch on the Organization (O=) field and the Gateway rejected the connection with Device certificate fails for Prelogon. The certificate issuer comparison now correctly handles these mis-encoded values, allowing Prelogon authentication to succeed without requiring users to rebuild their PKI.
Netskope Private Access139Fixed Issues
Ongoing
Jul 16, 2026, 02:40 PM EDT
Netskope Private Access Release Notes Version 139.0

Publisher

Issue NumberDescription
1042230
When deploying a Publisher on RHEL 9.x using the generic bootstrap script, the deployment may fail with Error: SELinux relabeling of /home/ is not allowed. This occurs because the container bootstrap step attempts an SELinux relabel of the user’s home directory, which is blocked in some hardened SELinux configurations.
905088
The Enable Publisher DNS Records Validation option may be visible in Global Attributes on the Publishers page before the corresponding capability is fully available. Do not enable this option until the feature is confirmed available for your tenant, as toggling it while the feature is incomplete has no supported effect.
Netskope Private Access139Known Issues
Ongoing
Jul 15, 2026, 03:52 PM EDT
AI Gateway Release Notes Version

Content Redaction for AI Gateway

Sensitive data stays out of AI β€” automatically

AI adoption in enterprises is accelerating, along with a growing issue: employees paste sensitive data (PII, financial records, credentials) directly into AI prompts. AI Gateway 1.6 addresses this with Content Redaction: Data Leak Protection (DLP) masking intercepts sensitive content before it reaches the AI model and again on the way out.
Your DLP policies now extend all the way into AI prompts and responses.
No new tools. No new policy engine. If you already have Netskope DLP, it now works on AI traffic β€” automatically.

Content redaction in AI Gateway

What you can do with it:

Mask promptsDLP policies detect and mask PII, credentials, and financial data in plain-text and JSON AI requests before they reach the model.
Mask responsesAI-generated responses are inspected and masked before delivery to the end user.
Plain text & JSONRedaction works across plain-text prompts and structured JSON payloads.
Redaction event fieldsNew event fields show redaction status per transaction for audit visibility.

For more information, see Redact Sensitive Data.

UX & Configuration Boosts

Streaming Response Inspection

Your security checks no longer come at the cost of user experience

Previously, AI Gateway buffered the entire AI response before running content inspection, so users saw nothing until processing finished. For long responses like code generation or summaries, this caused noticeable delay. AI Gateway 1.6 introduces streaming inspection: content is inspected and forwarded as it arrives, preserving the real-time feel of AI interactions.

AI Gateway-CLI Diagnostics

Run appliance checks from the menu β€” no shell access needed

AI Gateway 1.6 adds a Diagnostics section to the AI Gateway – CLI interactive menu. Administrators can select and run diagnostic commands directly from the TUI β€” without unlocking the appliance or accessing the underlying shell. Every run is recorded in the appliance audit log.

CommandWhat It Tests
ping
Network reachability β€” tests connectivity to a target host
traceroute
Network path to a target host
nslookup
DNS resolution and hostname lookup
nc
Port connectivity β€” tests TCP/UDP connection to a host:port
date
System clock and time-zone correctness
Access: Available to all admins before and after enrollment. Each diagnostic run is logged to the appliance audit log.

Expanded AI Schemas & Providers

Three New Predefined AI Providers

More AI providers, same governance β€” no custom config needed

AI Gateway 1.6 adds three new predefined providers, giving your teams governed access to a broader set of AI platforms β€” without needing to configure custom providers manually. Select, apply policy, and go.

Custom Topics for AI Guardrails

Your guardrails, your rules β€” define content categories specific to your organisation.

AI Gateway 1.6 adds Custom Topics to AI guardrail profiles, letting you define organization-specific content categories for detection and policy enforcement.

Predefined categories don’t cover every organization’s risks. Custom Topics let you tailor content categories to your industry, policies, or risk areas without waiting for Netskope.

The updated LLM image remains backward compatible with AI Gateway 1.5 for predefined category detection; only custom topics require upgrading.

For more information, see AI Guardrails Policy.

AWS Bedrock Mantle Endpoint Support

Access more models via AWS Bedrock β€” AI Gateway now supports the Mantle endpoint

AWS Bedrock exposes two distinct endpoint types with different host URL formats. AI Gateway v1.6 adds full support for the bedrock-mantle endpoint, which previously could not be used with Claude models.

Endpoint TypeHost URL PatternUnderlying ModelAI SchemaExample Provider
bedrock-runtimebedrock-runtime.{region}.amazonaws.com
Any
AWS Bedrock
cust-bedrock
bedrock-mantlebedrock-mantle.{region}.api.aws
Anthropic (Claude)
Claude
cust-mantle-cla
bedrock-mantlebedrock-mantle.{region}.api.aws
OpenAI-compatible
OpenAI (Compatible)
cust-mantle-ope
Authentication: The authentication method for bedrock-mantle is identical to bedrock-runtime β€” no additional credential configuration is required.

For more information, see Configure AWS Bedrock as a Custom AI Provider.

Behind-the-Scenes Improvements

Custom Provider Hostnames Are Auto-Normalized

Envoy required lowercase. Now AI Gateway handles that for you.

Envoy, the underlying proxy in AI Gateway, requires strictly lowercase hostnames to route traffic correctly. Previously, configuring a custom provider with a mixed-case hostname could cause Envoy to fail routing silently β€” no error, just broken traffic. AI Gateway 1.6 automatically normalizes custom provider hostnames to lowercase before passing them to Envoy.

No action required. Normalization is applied automatically. Existing custom provider configurations with mixed-case hostnames will continue to work without any changes.

DLP Incidents Now Have Unique Titles

Goodbye, three identical incident titles

Incident objects now use the /.json format, making each incident uniquely traceable. Previously, when multiple prompts were blocked by DLP in the same session, all incidents shared the same object name and title, making it impossible to match incidents to prompts.

ACTION REQUIRED

Enable Content Redaction
Content Redaction requires the DLP_ENABLE_REDACTION feature flag and must be activated.

  1. Confirm the feature flag is active: GET /api/v2/policy/aig/dlp/featureflags.
  2. Go to Policies β†’ AI Gateway β†’ DLP in your Netskope tenant.
  3. Ensure your DLP profiles include the data identifiers to redact in AI traffic (PII, financial data, credentials).
  4. Apply the policy to the relevant AI Gateway steering configuration.
Content Redaction does not apply retroactively to active sessions.

Review AI Gateway-CLI Diagnostics Access
The new Diagnostics section in AI Gateway – CLI is available to all admins without unlocking the appliance. Review CLI access before upgrading if you enforce strict least privilege policies.

  1. Audit current AI Gateway – CLI admin access roles in your tenant.
  2. Confirm Diagnostics access aligns with your support and operations team scope.
AI Gateway1.6What's New
Ongoing
Jul 15, 2026, 03:52 PM EDT
AI Gateway Release Notes Version

OAuth Gateway URL Hardening

OAuth redirect URLs are now anchored server-side β€” attacker input ignored

The OAuth gateway URL is now anchored server-side; the HTTP/2 :authority header is ignored when building redirect URLs in the traffic intercept service. A security review found that an attacker could craft a malicious :authority value to hijack the OAuth flow to an attacker-controlled destination.

All AI Gateway 1.6 deployments include this fix automatically upon upgrade.

Mistral File Inspection Now Works Correctly

AI Gateway was speaking OpenAI. Mistral uses a different dialect.

The file ID detection logic now supports both OpenAI (file- prefix) and Mistral (UUID format) file reference formats. File content inspection for Mistral’s Files API failed silently because AI Gateway checked only for the OpenAI prefix file-. Since Mistral uses UUID-format IDs without a prefix, its file references were skipped by the inspection pipeline.

AI Gateway1.6Fixed Issues
Ongoing
Jul 15, 2026, 03:46 PM EDT
AI Gateway Release Notes Version

Content Redaction for AI Gateway

Sensitive data stays out of AI β€” automatically

AI adoption in enterprises is accelerating, along with a growing issue: employees paste sensitive data (PII, financial records, credentials) directly into AI prompts. AI Gateway 1.6 addresses this with Content Redaction: Data Leak Protection (DLP) masking intercepts sensitive content before it reaches the AI model and again on the way out.
Your DLP policies now extend all the way into AI prompts and responses.
No new tools. No new policy engine. If you already have Netskope DLP, it now works on AI traffic β€” automatically.

Content redaction in AI Gateway

What you can do with it:

Mask promptsDLP policies detect and mask PII, credentials, and financial data in plain-text and JSON AI requests before they reach the model.
Mask responsesAI-generated responses are inspected and masked before delivery to the end user.
Plain text & JSONRedaction works across plain-text prompts and structured JSON payloads.
Redaction event fieldsNew event fields show redaction status per transaction for audit visibility.

For more information, see Redact Sensitive Data.

UX & Configuration Boosts

Streaming Response Inspection

Your security checks no longer come at the cost of user experience

Previously, AI Gateway buffered the entire AI response before running content inspection, so users saw nothing until processing finished. For long responses like code generation or summaries, this caused noticeable delay. AI Gateway 1.6 introduces streaming inspection: content is inspected and forwarded as it arrives, preserving the real-time feel of AI interactions.

AI Gateway-CLI Diagnostics

Run appliance checks from the menu β€” no shell access needed

AI Gateway 1.6 adds a Diagnostics section to the AI Gateway – CLI interactive menu. Administrators can select and run diagnostic commands directly from the TUI β€” without unlocking the appliance or accessing the underlying shell. Every run is recorded in the appliance audit log.

CommandWhat It Tests
ping
Network reachability β€” tests connectivity to a target host
traceroute
Network path to a target host
nslookup
DNS resolution and hostname lookup
nc
Port connectivity β€” tests TCP/UDP connection to a host:port
date
System clock and time-zone correctness
Access: Available to all admins before and after enrollment. Each diagnostic run is logged to the appliance audit log.

Expanded AI Schemas & Providers

Three New Predefined AI Providers

More AI providers, same governance β€” no custom config needed

AI Gateway 1.6 adds three new predefined providers, giving your teams governed access to a broader set of AI platforms β€” without needing to configure custom providers manually. Select, apply policy, and go.

Custom Topics for AI Guardrails

Your guardrails, your rules β€” define content categories specific to your organisation.

AI Gateway 1.6 adds Custom Topics to AI guardrail profiles, letting you define organization-specific content categories for detection and policy enforcement.

Predefined categories don’t cover every organization’s risks. Custom Topics let you tailor content categories to your industry, policies, or risk areas without waiting for Netskope.

The updated LLM image remains backward compatible with AI Gateway 1.5 for predefined category detection; only custom topics require upgrading.

For more information, see AI Guardrails Policy.

AWS Bedrock Mantle Endpoint Support

Access more models via AWS Bedrock β€” AI Gateway now supports the Mantle endpoint

AWS Bedrock exposes two distinct endpoint types with different host URL formats. AI Gateway v1.6 adds full support for the bedrock-mantle endpoint, which previously could not be used with Claude models.

Endpoint TypeHost URL PatternUnderlying ModelAI SchemaExample Provider
bedrock-runtimebedrock-runtime.{region}.amazonaws.com
Any
AWS Bedrock
cust-bedrock
bedrock-mantlebedrock-mantle.{region}.api.aws
Anthropic (Claude)
Claude
cust-mantle-cla
bedrock-mantlebedrock-mantle.{region}.api.aws
OpenAI-compatible
OpenAI (Compatible)
cust-mantle-ope
Authentication: The authentication method for bedrock-mantle is identical to bedrock-runtime β€” no additional credential configuration is required.

For more information, see Configure AWS Bedrock as a Custom AI Provider.

Behind-the-Scenes Improvements

Custom Provider Hostnames Are Auto-Normalized

Envoy required lowercase. Now AI Gateway handles that for you.

Envoy, the underlying proxy in AI Gateway, requires strictly lowercase hostnames to route traffic correctly. Previously, configuring a custom provider with a mixed-case hostname could cause Envoy to fail routing silently β€” no error, just broken traffic. AI Gateway 1.6 automatically normalizes custom provider hostnames to lowercase before passing them to Envoy.

No action required. Normalization is applied automatically. Existing custom provider configurations with mixed-case hostnames will continue to work without any changes.

DLP Incidents Now Have Unique Titles

Goodbye, three identical incident titles

Incident objects now use the /.json format, making each incident uniquely traceable. Previously, when multiple prompts were blocked by DLP in the same session, all incidents shared the same object name and title, making it impossible to match incidents to prompts.

ACTION REQUIRED

Enable Content Redaction
Content Redaction requires the DLP_ENABLE_REDACTION feature flag and must be activated.

  1. Confirm the feature flag is active: GET /api/v2/policy/aig/dlp/featureflags.
  2. Go to Policies β†’ AI Gateway β†’ DLP in your Netskope tenant.
  3. Ensure your DLP profiles include the data identifiers to redact in AI traffic (PII, financial data, credentials).
  4. Apply the policy to the relevant AI Gateway steering configuration.
Content Redaction does not apply retroactively to active sessions.

Review AI Gateway-CLI Diagnostics Access
The new Diagnostics section in AI Gateway – CLI is available to all admins without unlocking the appliance. Review CLI access before upgrading if you enforce strict least privilege policies.

  1. Audit current AI Gateway – CLI admin access roles in your tenant.
  2. Confirm Diagnostics access aligns with your support and operations team scope.
AI Gateway1.6What's New

Data access

Unlock more updates for Netskope

You're seeing 40 updates from the last 7 days without signing in.

Public session

Public

Next step: Free - 7 days history and full feed tools. No card required to start.

What you can unlock

Higher tiers unlock more history and more rows.

  • Recommended next step

    Free

    Same 7 days window Β· adds plan perks

    • Incidents, maintenance, updates, and advisories
    • Unlimited vendor monitoring
    • Analytics and trends
    Alerts

    Plan perks

  • Standard

    30 days history

    • Everything in Free
    • Analytics
    • Compliance snapshots
    Alerts

    Wider window

  • Pro

    90 days history

    • Everything in Standard
    • Analytics
    • REST API

    Wider window