Skip to main content
Cisco Umbrella integrates with Inviolet in the two directions described in the network enforcement overview: observe (read the vendor’s egress logs into Inviolet) and enforce (block direct LLM access).

Observe (CASB) — available today

Inviolet’s casb-umbrella connector pulls Cisco Umbrella egress events and ingests the ones bound for LLM providers, so bypass volume and attribution show up in the Shadow IT analytics view. Set it up: Inviolet → Settings → Data Sources → Admin Connectors → New → Cisco Umbrella, then paste your credentials. Credentials: Umbrella — an API key + secret (Admin → API Keys) + your Umbrella org id.

Enforce (SWG) — on request

Network enforcement packs for Cisco Umbrella (block direct LLM API + consumer UIs, forcing traffic through Inviolet) are delivered per engagement. Unlike Cloudflare — which matches at the DNS layer natively — Cisco Umbrella enforcement is scoped to your tenant’s capabilities. Contact us to scope a deployment.
Cloudflare is the reference vendor, validated end to end (enforcement + observability). See the Cloudflare guide for the full pattern; the same shape applies here once your enforcement pack is built.