GenAI DLP
Overview
GenAI DLP is the data-protection side of AI Usage Control. It focuses on what your team pastes, uploads, submits, prints, or downloads in the browser, and detects sensitive content before it leaves for an AI tool. It runs in the browser through the Dralvia extension, so there is no proxy to deploy and no browser to replace.
Why this matters
Generative AI tools are easy to reach and easy to overshare with. A single paste can move source code, an API key, a customer record, or a contract into a tool your company does not control. GenAI DLP gives you detection and enforcement at the moment the data is about to move.
What it detects
Dralvia classifies browser content into clear data classes:
- Secrets (for example tokens and keys)
- Credentials (for example passwords and login material)
- Source code
- Regulated data
Detection runs on the actions that move data: paste and clipboard, file upload, form and text submission, print, and download.
What you can use it for
- Warn, redact, or block when secrets or credentials are sent to an AI tool.
- Warn or block source-code paste or upload to unapproved AI tools.
- Strip a secret from an otherwise safe prompt so the rest still works.
- Keep regulated data out of personal AI accounts.
- Give reviewers redacted evidence of what was detected and where.
Policy modes
For each data class you choose how Dralvia acts when a match is found:
- Allow: let the action through and record it (monitor only).
- Warn: show the user a warning and let them decide.
- Redact: remove the sensitive part before it reaches the AI tool and let
the safe remainder through. The user sees the redacted text inline (sensitive
spans replaced with
[REDACTED]) plus a short notice, so nothing is changed silently. - Block: stop the action.
Allow is monitor only. Warn, Redact, and Block are increasingly strict. Redact is useful when a prompt is mostly safe but contains a secret or credential: the secret is stripped and the rest of the prompt still works.
Supported AI tools
Dralvia recognizes a maintained list of common AI tools (for example ChatGPT) and applies your policy by destination, so the same rules follow your team across tools. New tools are added over time. To confirm coverage for a specific tool, check AI Usage Control, which shows the AI destination for each event.
How to use it
- Install the Dralvia browser extension for your company.
- Open Browser Protection, then Policy Controls, to set the data-class rules (which classes to watch and whether to allow, warn, redact, or block).
- Use AI Usage Control to decide which AI destinations the rules apply to and to review AI-specific activity.
- Start in allow mode, move to warn or redact, then to block as you gain confidence.
The same settings are available in the UI and the API.
Evidence and privacy
GenAI DLP keeps redacted evidence only. It records the data class that was matched and a short redacted sample, and it does not store the raw text, raw code, raw file contents, passwords, or full token values.
What Dralvia does and does not claim
Dralvia provides browser-native data protection for AI workflows. It can allow, warn, redact, or block based on your policy. Dralvia does not provide endpoint-wide DLP outside the browser, and by default policy may be set to allow or warn unless you choose to redact or block.
How to test it
- Paste a sample API key into an AI tool and confirm it is detected as a secret.
- With the data class set to Redact, paste a prompt that mixes safe text and
a sample secret. Confirm the secret is replaced with
[REDACTED]in the field while the safe text remains, and that a "Redacted" notice appears. - With the data class set to Block, repeat and confirm the paste is stopped.
- Paste or upload a sample source-code file to an unapproved AI tool and confirm it is detected as source code.
- Confirm the matching event shows a redacted sample, not the raw value, and that its outcome reads Allow, Warn, Redacted, or Block.
How to roll back
Change the relevant data-class rule in Browser Protection, Policy Controls, back to allow or warn, or disable it. Changes take effect for new actions.
Troubleshooting
- Nothing happens when I paste a secret: confirm the extension is connected (open its settings and use Check connection), that the data class is enabled, and that the mode is Warn, Redact, or Block rather than Allow.
- Redact did not strip the secret: redact works on text paste and drop. A file upload cannot be redacted inline, so it falls back to a warning. Use Block for files you want stopped.
- The tool is not recognized as an AI destination: coverage is by destination. Check the event in AI Usage Control. If a tool you use is missing, contact support so it can be added.
- The event shows Warn but I set Redact: the outcome pill reads "Redacted" for redact actions. If it reads Warn, the content matched a warn rule, not a redact rule.
Related
- AI Usage Control
- Browser Extension
- EvidencePack
- Product overview: GenAI DLP