Cloudflare DLP
Compare with…Cloudflare combines HTTP traffic inspection with API-based scans of stored content through CASB. Its documented CASB scan scope is publicly accessible files, with file-type and size limits. [1] [2]
Sources reviewed 2 sources
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Partial
CASB scans include OneDrive, SharePoint and Microsoft 365 Copilot. The documented scope is publicly accessible files. [1]
- AWS
- Partial
S3 is supported for CASB DLP scans. This is not evidence of database scanning. [1]
- Google Cloud
- Partial
Cloud Storage is supported. BigQuery and Cloud SQL are unconfirmed. [1]
- Snowflake and Databricks
- Unconfirmed
- On-prem shares
- Unconfirmed
- SaaS apps
- Partial
Box, Dropbox, Google Drive, OpenAI and Anthropic are listed. Confirm the objects and account editions scanned. [1]
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
HTTP inspection requires traffic routed through Gateway and TLS decryption for HTTPS content. [2]
- Stored data
- CASB scans use application APIs and require both CASB and DLP.
- Enforcement
- Gateway HTTP policies can allow, block or log matching requests.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- Test whether your private, internally shared and public files are included in the proposed scan.
- Check files over 100 MB, image-only documents and multipart uploads.
- When adding a DLP profile to an existing integration, how will you scan older unchanged files?