DLP Strategy
All notes

Prompt DLP Checklist: What to Inspect Before AI Data Leaves the Browser

The most effective prompt DLP programs start with the data attackers prize and regulators scrutinize: credentials, financial identifiers, personal information, infrastructure details, and confidential business terms.

Inspection should happen before submission, not after a platform stores chat history. Security teams should combine deterministic pattern matching with managed dictionaries for company-specific terms such as project names, acquisition code words, privileged system names, and customer account labels.

  • Secrets: API keys, passwords, tokens, private keys, and access credentials.
  • PII: email addresses, phone numbers, SSNs, SINs, tax IDs, and postal identifiers.
  • Enterprise data: internal hostnames, IP ranges, financial codes, and managed keywords.
Discuss your AI workflow
Context Security Inc. · Quebec, CanadaContextShield · Chrome and Edge