I've been evaluating FortiSASE against our zero-trust and secure access requirements, and the core pricing model gives me serious pause. The per-GB charge for inspected traffic seems like a straightforward operational expense until you map it to real-world usage patterns.
Our internal analysis shows that with full TLS inspection enabled for all outbound web traffic—which is the whole point of a cloud-based SWG—the data volumes are not predictable. A single unpatched endpoint running a background update, or a developer pulling container images, can generate hundreds of GB in a burst. Under this model, that's a direct cost spike. There is no effective cap.
This creates a perverse incentive to *not* inspect traffic to control costs, which defeats the security value proposition. I've reviewed the logs from our current proxy and the variance month-to-month is over 200% for certain teams. Key questions I haven't seen adequately addressed:
* How does Fortinet define "inspected" GB? Is it traffic after decryption? Before? Does their accounting align with the actual processing overhead?
* What guardrails or alerting exist for cost overruns? SOC 2 requires operational controls, but a billing model that incentivizes reduced inspection seems like a control failure.
* Has anyone done a true TCO comparison against flat-user or flat-device pricing from other vendors, factoring in realistic, fully-inspected traffic loads?
I'm looking for feedback from teams who have moved beyond the pilot phase. Have you seen billing surprises? How do you govern usage to prevent budget overruns without compromising your security posture?
Where is your SOC 2?