← Back to Cloudflare One
DLP

Data Loss Prevention

Predefined + custom profiles, EDM, and MIP labels — inline and at rest.

✓ Guided dashboard demo
Mental model

How DLP works across users, traffic, and policy

Use this page to show DLP as a reusable data-control layer, not a standalone checkbox. Profiles define what sensitive data looks like; Gateway, CASB, and AI controls decide where to inspect it and what action to take when it appears.

Define sensitive dataDLP profiles describe what Cloudflare should detect: financial data, credentials, secrets, PII, source code, or custom patterns.
Attach profiles to traffic controlsGateway and AI controls use those profiles to inspect uploads, responses, prompts, or tool results.
Take action close to the userCloudflare can block, log, or govern the risky data movement without waiting for origin-side controls.
Configured proof

A synthetic secret leaves OpenCode. DLP stops it before the model sees it.

The primary proof runs from OpenCode on UTM Demo Mac through the configured AI Gateway. The Credentials and Secrets profile classifies the request and the firewall blocks it.

OpenCode on UTM Demo Mac
> Help debug this request. It contains a synthetic
  Cloudflare-token-shaped value for the DLP demo.

Failed Dependency: Request content blocked due to DLP policy violations
Configured

Try the configured proof

  1. Connect WARP on the UTM Demo Mac.
  2. Open OpenCode through the protected AI Gateway path.
  3. Submit the prepared synthetic token-shaped prompt.
  4. Show the block response, then verify the DLP event in dashboard logs.
Use the prepared non-working value. Never paste a real credential.
Reusable data control

Define sensitive data once, then enforce it across traffic, AI, and SaaS.

DLP profiles answer “what is sensitive?” Enforcement surfaces answer “where should Cloudflare inspect it, and what should happen?”

≡

Predefined + custom

Use maintained detections, regex, dictionaries, exact data match, and document fingerprints.

▧

OCR image scanning

Detect matching printed text in images when image scanning is enabled.

AI

AI context analysis

Adjust confidence using surrounding context to reduce noisy detections.

✱

Payload log masking

Choose full mask, partial mask, or clear text according to investigation and privacy needs.

⌁

Encrypted evidence

Encrypt matching payload and prompt data with an account-controlled public key.

↔

Inline + at rest

Apply profiles to Gateway and AI traffic, then reuse them with supported CASB integrations.

Configured in this account

Two active profiles, multiple enforcement paths.

The OpenCode proof is primary. Financial uploads and MCP tool responses show that the same profile model extends beyond one application.

Active DLP profileFinancial Information

13 / 13 entries enabled; used by Block Credit Card Uploads.

Active DLP profileCredentials and Secrets

Cloudflare token/key detections enabled; used in MCP and AI demos.

Gateway HTTP ruleBlock Credit Card Uploads

Blocks POST traffic matching the Financial Information DLP profile.

Gateway HTTP ruleBlock MCP Portal DLP traffic

Blocks credentials/secrets in MCP tool response traffic.

AI Gateway firewallopencode-team-access AI Gateway

Blocks Credentials and Secrets DLP on model requests.

Inactive DLP profilesAI Prompt profiles

Available placeholders for future AI prompt classification demos.

Configured walkthrough

Follow the DLP decision path

  1. Start with the OpenCode token-block proof from the UTM Demo Mac.
  2. Explore Credentials and Secrets as the reusable profile behind the decision.
  3. Review the opencode-team-access AI Gateway firewall and its request-side blocking.
  4. Compare Financial Information and Block Credit Card Uploads as a secondary inline example.
  5. Review logs, masking, confidence tuning, and the path from visibility to enforcement.
Coverage to mention

Beyond the primary proof

  • Exact Data Match and custom datasets for organization-specific records.
  • Microsoft Information Protection labels and document fingerprints.
  • CASB content findings for supported SaaS storage and AI integrations.
  • OCR, AI context analysis, evidence encryption, and payload masking.
Open in dashboard

The profiles, policies, AI firewall, and evidence behind the proof.

DLP overview ↗Metrics, recommendations, detections, and scanning controlsDLP profiles ↗Credentials and Secrets plus Financial InformationGateway HTTP policies ↗Financial upload and MCP response enforcementAI Gateway ↗Open the opencode-team-access firewall configuration
Built by Rodrigo Nobre with Cloudflare Workers