A unified data protection layer for the SASE platform

Cloudflare has rolled its data protection offerings into a single suite within Cloudflare One, its SASE platform. The new Cloudflare One for Data Protection bundles data loss prevention (DLP), cloud access security broker (CASB), Zero Trust network access (ZTNA), secure web gateway (SWG), remote browser isolation (RBI), and cloud email security into one package. The goal is to give organizations a consistent way to safeguard data across web, SaaS, and private applications without juggling multiple point products.

What shipped in the last year

Since DLP and CASB reached general availability in September 2022, Cloudflare has added a steady stream of features. The DLP work falls into three buckets: more customization options for policy design, deeper detection controls, and richer logs for analyzing policy effectiveness. CASB improvements have focused on expanding the number of supported SaaS integrations—now 18, including Microsoft 365, Google Workspace, Salesforce, and GitHub—plus making it easier to remediate findings directly from the dashboard.

A notable shift has been the convergence of CASB and DLP. Organizations can now scan SaaS applications for sensitive data using the same DLP profiles that govern inline traffic. That means, for example, detecting credit card numbers or social security numbers in a publicly shared Google Doc and then taking action through CASB gateway policies.

The table below summarizes key features delivered since the fourth quarter of 2022.

Theme Capability Description
DLP: Customizability Microsoft Information Protection labels integration After a quick API integration, Cloudflare syncs continuously with the Microsoft Information Protection (MIP) labels you already use to streamline how you build DLP policies.
Custom DLP profiles Administrators can create custom detections using the same regex policy builder used across our entire Zero Trust platform for a consistent configuration experience across services.
Match count controls Administrators can set minimum thresholds for the number of times a detection is made before an action (like block or log) is triggered. This way, customers can create policies that allow individual transactions but block up/downloads with high volumes of sensitive data.
DLP: Deepening detection Context analysis Context analysis helps reduce false positive detections by analyzing proximity keywords (for example: seeing “expiration date” near a credit card number increases the likelihood of triggering a detection).
File type control DLP scans can be scoped to specific file types, such as Microsoft Office documents, PDF files, and ZIP files.
Expanded predefined DLP profiles Since launch, DLP has built out a wider variety of detections for common data types, like financial data, personal identifiers, and credentials.
DLP: Detailed detections Expanded logging details Cloudflare now captures more wide-ranging and granular details of DLP-related activity in logs, including payload analysis, file names, and higher fidelity details of individual files. A large percentage of our customers prefer to push these logs to SIEM tools like DataDog and Sumo Logic.
CASB: Expanding integrations and findings API-based integrations
Managing findings
Today, Cloudflare integrates with 18 of the most widely used SaaS apps, including productivity suites, cloud storage, chat tools, and more.
API-based scans not only reveal misconfigurations, but also offer built-in HTTP policy creation workflows and step-by-step remediation guides.
DLP & CASB convergence Scanning for sensitive data in SaaS apps Today, organizations can set up CASB to scan every publicly accessible file in Google Workspace for text that matches a DLP profile (financial data, personal identifiers, etc.).

Near-term roadmap highlights

Cloudflare has also previewed several capabilities slated to arrive in the coming weeks and months. These are designed to extend the same visibility and controls to more data types and environments.

Custom lists and exact data matching go GA

Already shipped: Exact Data Match has moved out of beta. Customers can upload a dataset—names, phone numbers, or other fields—and tell Cloudflare’s DLP exactly what to look for.

Next 30 days: The ability to upload a list of specific words will arrive. Administrators can create DLP policies that search for those keywords in files, then block or log activity that matches.

Why it matters: Bulk-uploading custom terms saves time for administrators who have accumulated long lists of sensitive phrases in incumbent DLP systems. It also eases migration from other vendors. As with all DLP profiles, these custom lists are searched both in inline traffic and within connected SaaS applications.

Predefined profiles for code and health data

Next 30 days: Predefined DLP profiles will detect source code and protected health information (PHI). The code profiles will initially cover Python, JavaScript, Java, and C++, while the PHI profiles will look for medication and diagnosis names. These additions expand coverage to some of the most valuable—and, for PHI, most regulated—data types inside an organization.

Data-at-rest scanning expands to Microsoft 365 and GitHub

Next 30 days: API-based scans of Microsoft 365 (starting with OneDrive) will flag sensitive data in publicly accessible files, using the same DLP definitions for things like credit card numbers or source code. Administrators can then remediate through CASB gateway policies.

By the end of the year: The same integration will be available for GitHub.

Why it matters: The Microsoft 365 addition complements the existing Google Workspace integration, covering two of the most widely used cloud productivity suites. The GitHub integration targets a growing leak vector: according to GitGuardian, 10 million hard-coded secrets were exposed in public GitHub commits in 2022, up 67% from the prior year. Securing developer environments is a recurring customer request, and this integration is a direct response.

Risk scoring with Zero Trust context

Next 30 days: Cloudflare will introduce a user risk score based on behavior detected across Cloudflare One services. Signals like impossible travel anomalies or a spike in DLP violations will feed into the score. Shortly after detection capabilities ship, administrators will be able to attach policy actions based on those risk levels, controlling access to sensitive data and applications in real time.

Why it matters: Manually sifting through log volumes to spot risk patterns is slow and expensive. An out-of-the-box risk score gives organizations a faster way to identify and act on suspicious behavior without building custom analytics.

Getting started with the suite

These features represent only the near-term slice of the data protection roadmap. Organizations interested in testing the new suite can request a workshop through Cloudflare’s enterprise plans, or explore the technical demo and documentation linked from the announcement.