Cloudflare (vendor claim) introduced a Data Loss Prevention Test Scan that allows administrators to validate DLP profiles using sample content before applying them to production traffic.
The test scan works by sending the supplied text, file, or HAR archive directly to the DLP engine. Because the traffic never passes through the Cloudflare Gateway, Gateway policies are not evaluated and no Gateway activity logs are generated.
Key capabilities reported by Cloudflare include:
- Immediate results showing which DLP profiles matched the sample.
- Detection entries with confidence scores, match context, and proximity keywords.
- File metadata, antivirus status, and OCR output for scanned documents.
The feature is available to all Cloudflare Zero Trust customers, though the specific DLP profiles you can test depend on the tier of your Zero Trust plan (vendor claim).
To use the Test Scan:
- Navigate to the DLP Test Scan page in the Cloudflare dashboard.
- Paste raw text, upload a file, or upload a HAR file containing the traffic you want to evaluate.
- Select one or more DLP profiles to test.
- Run the scan and review the detailed results.
This workflow lets security teams fine‑tune policies, reduce false positives, and gain confidence that the DLP rules will behave as expected once deployed to live traffic.