data-security

2 posts

cloudflare

From the endpoint to the prompt: a unified data security vision in Cloudflare One (opens in new tab)

Cloudflare One presents data security as a unified problem spanning networks, SaaS applications, endpoints, and AI prompts. Its strategy is to follow data wherever it moves, combining visibility, policy controls, and enforcement rather than relying on siloed products. The latest updates extend this model from browser-based RDP clipboard controls to SaaS operation logging, endpoint DLP, and Microsoft 365 Copilot scanning. ### Browser-Based RDP Clipboard Controls - Administrators can control whether users copy or paste data between local devices and browser-based RDP sessions. - Policies can be directional and context-specific: - Allow copying into a remote session for productivity. - Block copying sensitive information out to unmanaged endpoints. - The feature is configured through Access Application Policies for browser-based RDP applications. - Granular controls aim to reduce risky workarounds such as screenshots, manual retyping, or use of unsanctioned tools. ### Operation-Level Visibility in SaaS Logs - Cloudflare’s operation-mapping process interprets HTTP request details as recognizable actions, such as `SendPrompt` in ChatGPT. - Related operations are grouped into higher-level Application Controls such as “Share” or “Upload.” - These mapped operations now appear automatically in log events for matching SaaS traffic. - Log details include both the application control and the specific operation, helping teams investigate activity and refine policies more quickly. ### Endpoint DLP for Data in Use - The Cloudflare One Client now provides Endpoint DLP enforcement, beginning with clipboard-based data movement. - This protects sensitive content after it leaves a browser or managed SaaS application and enters the operating system clipboard. - The feature addresses risks such as copying customer records or proprietary code into personal tools or unauthorized AI assistants. - Organizations can extend existing Gateway, DLP, CASB, and API-based controls without deploying a separate endpoint agent. ### Microsoft 365 Copilot Scanning - API CASB can now analyze Microsoft 365 Copilot activity for data-security risks. - Scanning covers Copilot chats and uploads that match configured DLP detection profiles. - Findings include contextual information such as referenced files, matching DLP profiles, and interaction metadata. - This extends Cloudflare’s existing API integrations for OpenAI ChatGPT, Anthropic Claude, and Google Gemini. Cloudflare’s recommendation is effectively to treat data movement as one continuous security problem: control access in transit, monitor activity in SaaS, enforce protections on endpoints, and inspect how data is used in AI prompts. Together, these capabilities are intended to keep policy attached to the data rather than limited to a particular application or product boundary.

figma

Figma Deepens Roots in Australia with Local Data Hosting | Figma Blog (opens in new tab)

Figma is expanding its investment in Australia by introducing enterprise governance features and local hosting for Figma file data. Starting in Q4 2025, Australian customers will be able to store data locally, supporting organizations with strict security and compliance requirements. The move strengthens Figma’s position among regulated industries and marks its first data-residency offering in Asia Pacific. ## Local Data Hosting in Australia - Figma will host file data locally in Australia, including content from: - Figma - FigJam - Make - Sites - Buzz - Slides - Local hosting is intended for industries such as: - Government and the public sector - Healthcare - Financial services - The option provides greater control over data location while preserving Figma’s platform capabilities and scalability. - Australia is Figma’s first local data-hosting market in Asia Pacific, extending similar enterprise offerings already available in Europe and the United States. - Figma opened its Sydney office in November 2024 and serves customers including NAB, Safety Culture, and Atlassian. ## Governance+ for Enterprise Customers Governance+ gives enterprises more control over how employees access and use Figma. - **Centralized controls** - Enforce use of approved Figma instances and networks. - Use IP Allowlisting and Network Access Restrictions to prevent data from moving into unauthorized spaces. - **Account security** - Require two-factor authentication. - Extend idle session timeouts. - Support for multiple SSO configurations is planned. - **Data governance** - Monitor Figma activity through tools such as the Discovery Pipeline. - Support electronic communications retention and legal discovery requirements. ## Existing Enterprise Security Features Governance+ builds on existing enterprise capabilities, including: - Action logs - SAML single sign-on - Role assignments connected to identity-management systems - Restrictions on external collaborators joining an organization Governance+ is available now to customers on Figma’s Enterprise plan. Figma’s Australian data residency option will be particularly useful for organizations that must meet local storage, privacy, and regulatory obligations. Enterprise customers can adopt Governance+ immediately and register interest in local hosting ahead of its planned Q4 2025 launch.