Account Access Management & Permissions
Detecting sensitive data and misconfigurations in AWS and GCP with Cloudflare One

Detecting sensitive data and misconfigurations in AWS and GCP with Cloudflare One

3/21/2025 · Alex Dunbrack, Michael Leslie

What this post added

Introduced Cloud DLP (Data Loss Prevention) functionality integrated with Cloudflare CASB to scan objects in Amazon S3 buckets and Google Cloud Storage for sensitive data. This includes pre-built detection profiles for common data types and custom profiles using regular expressions. Also enhanced posture management features to identify misconfigurations in IAM, bucket, and object settings. The implementation utilizes a serverless architecture with a Compute Account, Controller function, Crawler process, and Scanner function to ensure data privacy and scalability.

Read the original post ↗