Policy & DLP
To AI enforcementClassification & enforcement for data heading OUT to AI tools. Powered by GCP Sensitive Data Protection. From-AI is monitor + warn + attest only — never configurable to block.
150+ detectors exist in GCP Cloud DLP. This is a representative set — full catalog selection ships later.
| Category | Monitor | Warn | Block |
|---|---|---|---|
| Financial | |||
| PII | |||
| Credentials & secrets | |||
| Health (PHI) | |||
| From AI destinationsmoat AI content pasted into Gmail / Docs / Slack / Jira |
Hard-BLOCK is a deliberate opt-in. A false-positive block gets Zeflin uninstalled. We ship default-WARN; turn on hard-BLOCK only for tools and categories you trust the classifier on.
All tools warn-first — safest default.
Store de-identified previews instead of raw matched values. Raw reveal stays privileged + audited.
Captured content expires and is hard-deleted after this window. Set in org settings.
Curated, safe prompt templates
Coming laterFine-grained per-policy roles
Coming laterConditional, composable rules
Coming laterClassification runs on GCP Sensitive Data Protection. US companies only. Every change is recorded in the append-only audit log.