Closing the SaaS data blind spot

Cloudflare’s API-based Cloud Access Security Broker (CASB), released in September, scans SaaS applications such as Google Workspace, Microsoft 365, Salesforce, and Box for misconfigurations, insecure settings, files shared inappropriately, and user access risks. The aim was to remove the burden of manual security checks across a growing list of applications by flagging discovered threats for IT and security teams.

Customer feedback, however, highlighted a limitation: raw misconfiguration alerts lack context. A publicly exposed kickball schedule is not equivalent to an exposed customer list, and administrators wanted the ability to differentiate between the two. The recurring question was simple: what about the sensitive data stored inside the files being collaborated on?

From network-level detection to storage-level insight

How Cloudflare CASB and DLP work together to protect your data

Cloudflare’s DLP product, also launched in September, addressed data in transit through the company’s Secure Web Gateway (Gateway). It detects sensitive strings — such as credit card or social security numbers — as employees attempt to upload them to services like Google Drive or send them via Slack, and blocks the HTTP request before it reaches the destination application.

That coverage leaves a gap. Data already sitting in SaaS applications never traverses the corporate network, so it is invisible to network-based inspection. The same questions surfaced again: how can organizations identify sensitive information that is stored, not transmitted?

Combining CASB and DLP

In early 2023, Cloudflare Zero Trust will pair CASB’s scanning capabilities with DLP’s detection engine. The combined offering will let customers connect their SaaS applications and scan files — documents, spreadsheets, PDFs — for sensitive data including personally identifiable information (PII), payment card data (PCI), or custom regex patterns defined by the organization.

The workflow is straightforward: a CASB scan identifies an exposed file, and DLP classification tells the administrator whether the contents warrant immediate action. Credit card numbers in a Google Doc or social security numbers in an Excel spreadsheet become actionable alerts rather than undifferentiated misconfiguration notices.

This expansion completes a broader data loss prevention story across Cloudflare’s Zero Trust platform:

  • DLP covers data in transit via Gateway.
  • CASB handles shared file monitoring and now stored data classification.
  • Remote Browser Isolation (RBI) addresses data in use.
  • Area 1 provides email DLP.

Together, these cover the primary vectors for data exfiltration and misuse, giving organizations the signals they need to quickly assess severity and prioritize remediation.