The architecture difference, in one question
Where is the decision made, and on whose machine?
Their data sheet answers it: “the user’s traffic is forwarded to a Zscaler cloud data center over the internet”, and “the connection between an authorized user and a private app is stitched together in the cloud”. ZPA Private Service Edge moves the stitching into your building, and is “hosted by the customer organization but managed by Zscaler”, registering “with the Zscaler cloud” to “download the relevant policies and configurations”. Their Azure reference architecture adds, in a note on double encryption: “if you want to ensure that traffic data is never accessible within the Zscaler cloud, even when transiting the ZPA Service Edge, you must use your own PKI.”
QS-WAN has one answer available. The control tower is software you install, on premise, in a private cloud, or on a network with no route out. Enrolment, certificate issuance, key exchange and policy signing happen there. Hosting it yourself, on premise or air gapped, is a supported deployment rather than a variant you have to argue for, and in that deployment nothing registers anywhere outside your boundary. Gateways sit beside the LANs you already run, so air gapped networking isn’t a mode you switch on. It’s what’s left when the tower has no uplink to lose.