Policy & DLP

Classification & enforcement for data heading OUT to AI tools. Powered by GCP Sensitive Data Protection. From-AI is monitor + warn + attest only — never configurable to block.

Detection
What Zeflin classifies in outgoing prompts, by category. Expand a category to tune individual GCP Cloud DLP detectors and thresholds.
ConfidenceEnforcement

Every detector inherits its category's confidence + enforcement; override any row and it sticks (reset with ↺).

From AI (inbound)moat
To-AI confidence + enforcement is set per detector in Detection above. From-AI works differently — by design.
AI content landing in Gmail / Docs / Slack / Jira is Monitored, Warned, and Attested — never hard-blocked. A keep-anyway path always remains; it is structurally impossible to block AI content landing in real work.
Allowlists
Contexts exempt from classification (e.g. public, non-sensitive sources).
status pagespublic press releasesopen-source license text
Per-tool access
Whether each AI tool is allowed or blocked outright. Default is Allow; Block replaces the whole site with a Zeflin page.

Blocking a tool is a deliberate opt-in. It kills the whole site — a false-positive is the fastest way to get Zeflin uninstalled. Most orgs leave every tool Allowed and rely on per-data-type Redact (above); Block is for tools you want off entirely.

ChatGPTChatGPT
ALLOWBLOCK
ClaudeClaude
ALLOWBLOCK
GeminiGemini
ALLOWBLOCK
Copilot· soonCopilot
M1.5 · coming
PerplexityPerplexity
M1.5 · coming

All tools allowed — safest default.

Redaction failure behavior
What happens when GCP DLP is slow or unreachable while redacting an outbound prompt.
seconds (5–10s)
Redaction & retention
De-identification of captured content and how long it is retained.
Stored-content de-identification

Store de-identified previews instead of raw matched values for the analyst view (separate from the outbound Redact action above). Raw reveal stays privileged + audited.

Retention window

Captured content expires and is hard-deleted after this window. Set in org settings.

90 days
Coming later
Deferred capabilities — not configurable in this build.
Approved prompt library

Curated, safe prompt templates

Coming later
Role-based access

Fine-grained per-policy roles

Coming later
Policy-engine rule builder

Conditional, composable rules

Coming later

Classification runs on GCP Sensitive Data Protection. US companies only. Every change is recorded in the append-only audit log.