Data sprawl meets a new threat surface

Security teams are wrestling with a data landscape that keeps expanding in every direction. Data now lives across hybrid and multi-cloud environments, and the applications employees rely on daily — cloud email, shared storage, and SaaS collaboration suites such as Microsoft 365 — have become prime targets for exfiltration attempts. At the same time, two newer risks are compounding the challenge. The rapid adoption of generative AI tools creates new opportunities for users to paste sensitive information into opaque systems. And the source code that powers digital business is increasingly exposed across developer platforms like GitHub, sometimes in plain sight on public repositories.

These two risks often intersect. High-profile organizations have blocked ChatGPT and similar tools outright, and incidents such as an engineer uploading sensitive code to the tool illustrate the danger. As developers lean on AI to accelerate work, the long-term consequences of sharing proprietary data remain unclear.

Regulatory pressure is rising in parallel. The number of U.S. states with comprehensive privacy laws has grown from just three in 2021 to eleven today, while updates to existing standards like PCI DSS introduce stricter obligations. Organizations that fail to adapt face both compliance penalties and the growing likelihood of a damaging breach.

Legacy DLP is not built for this

Traditional data loss prevention (DLP) products are struggling to meet these modern challenges. High setup complexity, operational overhead, and poor user experience mean that, in practice, many DLP controls are bypassed or never fully deployed — often ending up as expensive shelfware. Backhauling traffic through on-premise appliances for inspection adds cost and latency, slowing down employees and diminishing productivity across the business.

Cloudflare One for Data Protection

A unified data protection suite

Cloudflare One for Data Protection brings together previously separate service categories into a unified platform: DLP, cloud access security broker (CASB), Zero Trust network access (ZTNA), secure web gateway (SWG), remote browser isolation (RBI), and cloud email security. All these capabilities are delivered across Cloudflare’s global network and are available today as part of the Cloudflare One SASE offering.

The goal is to make security teams more effective by unifying inline and API-based connectivity with policy management. For employees, the aim is preserving fast, reliable experiences so that security doesn’t get in the way of work. And for the organization as a whole, the suite aims to provide agility in responding to evolving data security and privacy requirements.

What customers are solving for

Three use cases dominate how customers are putting Cloudflare One for Data Protection into action.

Securing AI tools and developer code

Insurance technology company Applied Systems deployed Cloudflare One specifically to secure data in AI environments. The company runs the public instance of ChatGPT in an isolated browser, allowing the security team to enforce copy-paste blocks that stop users from copying sensitive information — including developer code — into the AI tool. According to Chief Information Security Officer Tanner Randolph, “We wanted to let employees take advantage of AI while keeping it safe.”

The approach balances enabling AI adoption against the risk of accidental data leakage, and it represents a model other customers are exploring as they seek to hydrate developer productivity without exposing valuable code.

Gaining visibility into data exposure

For many customers, the first step is understanding which unsanctioned apps are in use and applying controls such as allow, block, or isolate. A second, growing step is scanning SaaS applications for misconfigurations and sensitive data using CASB and DLP integrations, then remediating issues through SWG policies.

A UK ecommerce company with 7,500 employees used this approach. Part of a larger migration from Zscaler to Cloudflare, the company set up API integrations between its SaaS environments and Cloudflare’s CASB to begin scanning. During integration, the company synced its existing DLP policies with Microsoft Purview Information Protection sensitivity labels, allowing it to apply its established classification framework. The company got to identifying data exposure risks within a day of setting up the connections.

Meeting regulatory compliance requirements

Compliance mandates such as GDPR, CCPA, HIPAA, and GLBA have been with us for years, but newer laws require more proactive monitoring and protection. PCI DSS v4.0, effective in 2025, includes expanded requirements — for example, multi-factor authentication (MFA) must be enforced for every access request to the cardholder data environment, for every user and location (requirement 8.4.2), and MFA systems must be configured to prevent replay attacks and bypass attempts (requirement 8.5).

Cloudflare One helps customers address these requirements by enforcing MFA across applications and users, using the same services Cloudflare deploys to enforce hard key authentication internally. Combined with DLP controls, detailed audit logs, and an overall Zero Trust posture, these capabilities support a broader compliance strategy.

BLOG-1961 Embedded Image - fMWBic

Platform convergence as the differentiator

Cloudflare One approaches data protection not as a stack of separate tools but as a converged platform. DLP, CASB, SWG, ZTNA, RBI, and email security share a single control plane and interface, which removes the operational overhead of stitching together distinct products. The underlying network is what makes this practical: enforcement happens close to the user and the data, rather than at a chokepoint that adds latency.

Deployment flexibility is a core part of the design. Organizations can enforce policies through API-based scans of SaaS applications, which require only read-only permissions to identify misconfigurations and sensitive data—no need to request full admin access from IT or business teams. For endpoint coverage, clientless ZTNA and browser isolation extend protection to contractors and third parties without installing software, while organizations that prefer proxy-based enforcement can use the single device client with self-enrollment or WAN on-ramps. The breadth of options is meant to keep data protection deployed and effective, not shelved.

BLOG-1961 Embedded Image - LVgfr3

Speed and adaptability at network scale

Cloudflare’s network spans more than 300 cities across over 100 countries, and the company says its single-pass inspection enforces controls faster than offerings from Zscaler, Netskope, and Palo Alto Networks. Because security processing happens in one pass, layering data controls onto traffic does not force a disruptive slowdown for end users.

The architecture is also designed to evolve. Built on a programmable network, Cloudflare says it can ship new capabilities quickly and adopt emerging standards such as IPv6-only connections and HTTP/3 encryption. That same flexibility applies to detection logic: AI and machine learning models can be deployed across network locations to support context-aware, higher-precision detection as data protection use cases shift—for instance, guarding code within AI development environments.

Getting started

For organizations weighing near-term priorities—securing AI tooling and developer code, regaining visibility into SaaS sprawl, or staying ahead of regulatory requirements—Cloudflare positions the unified suite as a way to address multiple risk categories from one platform. A free workshop with Cloudflare experts is available for teams that want to evaluate the approach hands-on.

Additional material includes the product’s press release, the data protection solution page, and a technical blog covering the roadmap in more depth.