Data Security Becomes the Organizing Principle of Cloudflare One
Cloudflare One has expanded well beyond its original scope of network traffic security. Today it spans endpoints, SaaS applications, and increasingly, AI tools. The reason for that expansion is straightforward: the controls themselves were never the end goal. They exist to prevent credential theft, session hijacking, and ultimately, the unauthorized exfiltration of sensitive data.
That reframing drives a single set of questions across the platform:
- Where is sensitive data located?
- Who has access to it?
- What routes exist for it to move outside approved boundaries?
The answer Cloudflare is building is a unified data security model that follows information across four states: protection in transit, visibility and control at rest, enforcement in use on endpoints, and coverage at the prompt as AI becomes an interface to corporate data. These aren't independent features but layers of one system where visibility informs policy and enforcement covers gaps at the point where content leaves an application.
Granular Copy and Paste Controls for Browser-Based RDP
Cloudflare One's browser-based RDP provides remote access without requiring a managed device or installed client. That fits contractors, partners, and occasional-use workflows. But browser-delivered RDP raises a question about data movement: what happens when users copy content between their local machine and the remote session?
New clipboard controls in the Cloudflare One Access Application Policies let administrators determine whether copy and paste is permitted in either direction for browser-based RDP sessions. The balance is between productivity and security. Restricting clipboard operations entirely can push users toward screenshots, manual retyping, or unmanaged tools. Instead, administrators can allow copying into the session while blocking copying out. That permits a support agent to paste notes into a customer portal but prevents sensitive customer data from being copied onto an unmanaged endpoint.
The feature is now configurable within Access Application Policies for browser-based RDP applications.
Operation-Level Detail in HTTP Logs
Tuning SaaS policies effectively requires knowing what users actually do inside applications. Cloudflare's operation mapping interprets the elements of an HTTP request as a specific action, like SendPrompt in ChatGPT. Multiple operations that serve the same purpose are grouped into an application control such as Share or Upload. This abstraction simplifies policy authoring in the HTTP policy builder.
That same mapping now extends to logging. For traffic matching Cloudflare's operation maps, log events will automatically include both the application control group and the granular operation without additional configuration. An investigation into ChatGPT usage now shows whether a user merely sent a prompt, whereas previously only the traffic event itself was visible. This additional context accelerates forensic analysis and helps administrators spot risky behavior patterns with less guesswork.
On-Device DLP for Clipboard Data
Sensitive information frequently leaves managed applications through the system clipboard—a developer pasting proprietary code into an unauthorized LLM, for instance, or a customer record ending up in a personal tool. Cloudflare One already protects data in transit via Gateway and DLP, and at rest via CASB API integrations. Endpoint DLP extends that protection to data in use.
The new enforcement capability in the Cloudflare One Client targets high-signal workflows like clipboard movement. When sensitive content is copied from a protected SaaS application, it no longer becomes policy-free simply because it touched the OS clipboard. Admin-defined DLP detection profiles continue to apply at the endpoint, preventing that data from being pasted into unapproved destinations.
For existing Cloudflare One customers, Endpoint DLP adds this layer without requiring a second agent or complex integration, completing the enforcement model between managed applications and user actions.
Microsoft 365 Copilot Scanning via API CASB
Cloudflare One's API CASB integration, which provides API-based scanning of SaaS applications for security misconfigurations, now covers Microsoft 365 Copilot. The integration detects chats, prompts, responses, and uploaded files that match enabled DLP profiles.
Copilot findings include rich context such as file references, profile matches, and interaction metadata, allowing security teams to triage without parsing raw audit logs. A CASB finding, for example, might surface a file used in a Copilot session that matches a DLP profile, showing exactly what content triggered the alert.
The findings are enabled by default for the Microsoft 365 integration. Existing users need only update their Microsoft 365 connection in the Cloudflare One dashboard to begin receiving them. New integrations gain the capability upon connection. Cloudflare says coverage across additional AI assistants and core SaaS platforms will expand through 2026.
A Unified Path Forward
The trajectory across these updates is consistent: Cloudflare One is becoming more data-security-aware at every layer. The near-term additions—clipboard controls, operation-level logs, on-device DLP, and Copilot scanning—each address a specific gap where data can move beyond sanctioned boundaries.
Longer term, the vision is to embed data-oriented configurability, visibility, and guardrails into the workflows teams already use in Access, Gateway, endpoint enforcement, and SaaS integrations. The stated goal is that regardless of where users work or how data moves, Cloudflare One can explain what's happening and provide the controls to manage it.



