Policy & DLP
Classification & enforcement for data heading OUT to AI tools. Powered by GCP Sensitive Data Protection. From-AI is monitor + warn + attest only — never configurable to block.
Every detector inherits its category's confidence + enforcement; override any row and it sticks (reset with ↺).
Blocking a tool is a deliberate opt-in. It kills the whole site — a false-positive is the fastest way to get Zeflin uninstalled. Most orgs leave every tool Allowed and rely on per-data-type Redact (above); Block is for tools you want off entirely.
All tools allowed — safest default.
Store de-identified previews instead of raw matched values for the analyst view (separate from the outbound Redact action above). Raw reveal stays privileged + audited.
Captured content expires and is hard-deleted after this window. Set in org settings.
Curated, safe prompt templates
Coming laterFine-grained per-policy roles
Coming laterConditional, composable rules
Coming laterClassification runs on GCP Sensitive Data Protection. US companies only. Every change is recorded in the append-only audit log.