Cloudflare CASB Adds Posture Scans for ChatGPT, Claude, and Gemini
Cloudflare has extended its API-based Cloud Access Security Broker (CASB) to cover three major generative AI platforms: OpenAI's ChatGPT, Anthropic's Claude, and Google's Gemini. The integrations are available today to all Cloudflare One users, letting organizations connect their GenAI accounts and begin scanning for misconfigurations, data exposure, DLP matches, and compliance risks without installing endpoint software.
The new out-of-band scans complement Cloudflare's inline controls. Gateway already provides prompt-level policies and Shadow AI identification as traffic moves to AI providers; CASB now adds visibility into data at rest and the security posture inside these tools themselves.
What the Scans Cover
Each integration targets the specific risks and API surface of its platform. Account owners connect their tenants and CASB starts scanning across several domains: agentless connections, posture management, DLP detection for sensitive data in chat attachments, and GenAI-specific insights tied to each provider's feature set.
For ChatGPT, detections focus on:
- Capability Activation — Flags enabling of ChatGPT-specific features like actions, code execution, and web access.
- External Exposure — Finds chats and GPTs shared beyond the tenant, including public GPTs or those listed on the GPT Store, linked back to their owners.
- Secrets, Keys, and Invites — Spots unused or unrotated API keys and over-privileged or stale invites.
- Sensitive Content — Uses DLP profiles to detect sensitive data such as credentials, financial or health information, and source code in uploaded chat attachments.
The Claude integration provides two main detection categories:
- Secrets, Keys, and Invites — Surfaces high-risk invites, entitlement drift, unused API keys, and rotation gaps.
- Sensitive Content — Monitors uploaded files for sensitive data via DLP profiles.
Cloudflare says it will add detections as Anthropic expands Claude's API capabilities.
Gemini is handled differently because of how Google structures the product: Gemini is delivered as a Google Workspace add-on, not a standalone API. The detections appear within Cloudflare's existing CASB integration for Google Workspace and focus on:
- Identity and MFA — Identifies Gemini users and admins without multi-factor authentication, who are at higher risk of compromise.
- License Hygiene — Flags suspended accounts still holding Gemini or AI Ultra licenses. AI Ultra users have access to more powerful features, including Project Mariner, an autonomous agent prototype capable of running multiple tasks simultaneously in web browsers — making those accounts a higher-value target.
Because Gemini does not yet expose API endpoints for posture issues like public sharing or custom assistant publishing, the integration scope stays narrower than the ChatGPT or Claude offerings.
Positioning and Roadmap
Cloudflare positions the CASB integrations as part of a unified control plane for GenAI adoption, working alongside Gateway's inline protections to give organizations both visibility and enforcement. The company notes that it is itself adopting GenAI and expects providers to continue strengthening security, compliance, and data privacy controls on their platforms.
Existing Cloudflare One customers can enable the integrations directly from their dashboard or contact their account manager. New users can sign up for a 50-seat free tier, and larger deployments can request a consultation. Cloudflare is also inviting customers to join its AI security user research program to preview upcoming functionality.



