Predefined + custom profiles, EDM, and MIP labels — inline and at rest.
Use this page to show DLP as a reusable data-control layer, not a standalone checkbox. Profiles define what sensitive data looks like; Gateway, CASB, and AI controls decide where to inspect it and what action to take when it appears.
The primary proof runs from OpenCode on UTM Demo Mac through the configured AI Gateway. The Credentials and Secrets profile classifies the request and the firewall blocks it.
> Help debug this request. It contains a synthetic
Cloudflare-token-shaped value for the DLP demo.
Failed Dependency: Request content blocked due to DLP policy violations
DLP profiles answer “what is sensitive?” Enforcement surfaces answer “where should Cloudflare inspect it, and what should happen?”
Use maintained detections, regex, dictionaries, exact data match, and document fingerprints.
Detect matching printed text in images when image scanning is enabled.
Adjust confidence using surrounding context to reduce noisy detections.
Choose full mask, partial mask, or clear text according to investigation and privacy needs.
Encrypt matching payload and prompt data with an account-controlled public key.
Apply profiles to Gateway and AI traffic, then reuse them with supported CASB integrations.
The OpenCode proof is primary. Financial uploads and MCP tool responses show that the same profile model extends beyond one application.
13 / 13 entries enabled; used by Block Credit Card Uploads.
Cloudflare token/key detections enabled; used in MCP and AI demos.
Blocks POST traffic matching the Financial Information DLP profile.
Blocks credentials/secrets in MCP tool response traffic.
Blocks Credentials and Secrets DLP on model requests.
Available placeholders for future AI prompt classification demos.