Prompt DLP Checklist: What to Inspect Before AI Data Leaves the Browser
The most effective prompt DLP programs start with the data attackers prize and regulators scrutinize: credentials, financial identifiers, personal information, infrastructure details, and confidential business terms.
Inspection should happen before submission, not after a platform stores chat history. Security teams should combine deterministic pattern matching with managed dictionaries for company-specific terms such as project names, acquisition code words, privileged system names, and customer account labels.
- Secrets: API keys, passwords, tokens, private keys, and access credentials.
- PII: email addresses, phone numbers, SSNs, SINs, tax IDs, and postal identifiers.
- Enterprise data: internal hostnames, IP ranges, financial codes, and managed keywords.
Context Security