Zscaler is truly amazing. It can't do HTTP/2. Our product is HTTP/2-only. So we can't use our own product at work.
The theory so far it that it's related to their activities, working in DevOps they will sometimes generate "suspicious" traffic patterns which will then trigger someone policy in Zscaler, but they're not actually sure.