Skip to main content

Data Loss Prevention (DLP)

Swif's Data Loss Prevention (DLP) feature monitors outgoing emails in real time and blocks messages that violate your organization's data security policies — before they ever leave your outbox.

Overview

DLP protects sensitive information from being sent through web-based email applications. When enabled, Swif's browser extension inspects outgoing email content at send time. If a policy violation is detected, the email is blocked instantly — it will not be sent and will not appear in your Sent folder.

DLP operates entirely within the browser. There is no need to install additional software or configure email server rules.

Enabling Beta Features

Before you can enable Data Loss Prevention (DLP), you must first subscribe to beta features at the organization level. By default, beta features are opted-out for all new and existing organizations.

For Admins:

  1. Navigate to Organization Settings in the Swif dashboard.

  2. Locate the Beta Features section.

  3. Toggle the Beta Features switch to ON.

  4. Once enabled, a "Beta" badge will appear next to supported features (like DLP) in the navigation menu, and the feature pages will become visible.

Note: While the feature flag is organization-wide, specific DLP rules are still configured at the team level under Organization Settings > Team.

Requirements

  • Swif Browser Extension: Must be installed and active on managed devices. Learn more at deploy browser extensions.

  • Beta Access: Ensure the Beta Features toggle is enabled in Organization Settings to view the DLP Events dashboard.

Supported Applications

Application

Platform

Mechanism

Real-Time Block

Attachment Scanning

Confluence

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

DropBox

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Front

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Gmail (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Google Drive (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Google Drive

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

GitHub

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

HubSpot

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Jira

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Outlook (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

OneDrive

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Microsoft Team (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Notion

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Slack (web)

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

SharePoint

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Zendesk

macOS, Windows, Linux

Browser Extension

✅ Yes

Yes

Note: DLP currently covers the web versions of Gmail and Outlook accessed through a supported browser with the Swif extension installed. Native desktop mail clients are not covered at this time.

How It Works

  1. Compose as normal — Draft your message in Gmail or Outlook web as usual. Swif does not monitor keystrokes or interrupt you while typing.

  2. Click Send — DLP inspection evaluates the email body at the exact moment you click Send.

  3. Policy evaluation — Content is checked against your organization’s active DLP policies and sensitive data classifiers.

  4. Outcome:

    • ✅ No violation detected → The email is sent immediately.

    • ⚠️ Potential security risk detected → A "Potential security risk found" modal appears with two options:

      • Cancel Send: Closes the warning modal and preserves your compose draft so you can remove sensitive information.

      • Send Anyway: Confirms your intent and sends the message.

Detected Sensitive Data Categories

Swif DLP inspects email body text in real time against a wide range of sensitive data patterns and compliance identifiers:

Category

Description & Examples

Credentials & API Tokens

Passwords, bearer tokens, API secret keys, and session credentials.

Cryptographic Private Keys

PEM-formatted private keys (e.g., -----BEGIN PRIVATE KEY-----).

Financial Information

Credit card numbers, CVV/CVC codes, and bank account numbers.

Government IDs

Social Security Numbers (SSN), passport numbers, and national identifiers.

Health & PII (PHI)

Medical diagnoses, patient IDs, employee salary records, and sensitive personal data.

Confidential Business Data

Proprietary project codenames, unreleased pricing, and M&A / acquisition targets.

Note: Swif's classifier is optimized to prevent false positives — routine business discussions (such as discussing password rotation policies or sending links to public documentation) will not trigger security warnings.

Configure DLP rules

DLP rules are managed at the team level by your organization administrator. This granular control allows you to apply specific security policies to different employee groups and applications.

Prerequisite:
Before configuring rules, ensure that Beta Features are enabled in your Organization Settings. As a beta feature, the Data Loss Prevention tab will only be visible in Team Settings when this toggle is ON.

For Admins:

  1. Navigate to Team Settings in the Swif dashboard.

  2. Locate and click the Data Loss Prevention tab.

  3. If no rules have been created yet, click Create Rule to begin.

  4. In the rule creation modal, configure the following:

    • Rule Name: Enter a descriptive name for the policy (e.g., "Engineering Sensitive Data Policy").

    • Employee Group: Select the specific group of users this rule should apply to.

    • Supported Applications: Select one or more applications (e.g., Gmail, Outlook) where the rule will be enforced.

  5. Click Save. A success notification will confirm the rule is active and being synced to managed devices.

Managing Existing Rules:

  • Edit or Delete: Click the "..." (More Actions) menu next to any existing rule to modify its configuration or remove it.

  • Multiple Rules: You can define multiple rules for the same team or employee group. Swif will evaluate all applicable rules simultaneously at the moment an email is sent.

Privacy & Data Security


Swif is designed with a privacy-first approach. While the DLP Events Dashboard provides visibility into policy violations, Swif never stores the raw body text or sensitive data from your emails.

For DLP rules and events, Swif only persists metadata required for reporting and audit trails, such as:

  • Rule ID and rule name

  • Employee group ID and group name

  • Supported application (e.g., Gmail, Outlook)

  • The final decision (Allowed or Blocked) and the reason

  • Timestamp and reporting context

This ensures that administrators can monitor security trends and policy enforcement without compromising employee privacy or storing sensitive message content.

Privacy in Exported Reports

When exporting DLP reports (CSV or JSON), Swif strictly excludes the raw body text, message contents, and attachment payload data. Exported files contain only metadata (timestamps, employee identifiers, application names, triggered rule categories, and evaluation decisions) to maintain compliance and confidentiality.


Monitoring & Reporting

Administrators can monitor DLP activity and policy enforcement in real time through the DLP Events Dashboard. This centralized view provides visibility into blocked actions, event trends, and detailed logs across the organization.

  • Summary Metrics: View high-level statistics on total events and blocked actions.

  • Event Trends: Track policy violations over time to identify spikes or patterns.

  • Detailed Logs: Review specific triggers, including the application, action taken, and the final decision (Blocked, Allowed, or Flagged).

  • Privacy First: To maintain security, Swif does not store or display the raw body text of emails in the dashboard.

For a comprehensive guide on how to use these reporting features, see our article on Monitoring Data Loss Prevention (DLP) Events.

What Gets Inspected

Content Type

Inspected?

Email body text

✅ Yes

Attachments (files added to the email)

Not yet

Subject line

✅ Yes

Recipients

Policy-dependent

DLP also supports server-side detection through connected integrations, providing an additional layer of coverage beyond the real-time browser block.

Supported Platforms

OS

Supported

macOS

✅ (via Chrome/Edge extension)

Windows

✅ (via Chrome/Edge extension)

Linux

✅ (via Chrome/Edge extension)


Exporting DLP Reports

Administrators can generate and export comprehensive DLP event reports for compliance auditing, internal security reviews, or external analysis.

How to Generate a Report

  1. Navigate to DLP Events in the Swif dashboard.

  2. Click the Generate Report button located above the events table.

  3. Configure your report criteria using the available filters and date range picker:

    • Date Range: Select a preset or custom range (defaults to the last 7 days).

    • Employees: Filter by one or multiple employees.

    • Applications: Filter by specific services (e.g., Gmail, Outlook, GitHub, Slack).

    • Decisions: Filter by event outcomes (Allow, Block, Flagged).

  4. Click Download Report and select your preferred file format:

    • CSV (default spreadsheet-compatible format)

    • JSON (structured raw data format)

  5. A confirmation notification will appear once the file has been generated and downloaded.

Exported Report Fields

DLP event exports include structured metadata while strictly maintaining privacy:

Column / Field

Description

Date & Time

Timestamp when the event was evaluated

Employee

Name and identifier of the user who triggered the event

App

Application where the activity occurred (e.g., Gmail Web, Outlook Web)

Submitted Action

Specific user action evaluated (e.g., email send, file share)

Decision

Action taken by the DLP engine (Allow or Block)

Outcome

Final state after user interaction (e.g., Cancelled, Sent Anyway, Blocked)

Reason

Policy classifier and rule criteria that triggered the event

Export Limits & Permissions

  • Administrator Access: Exporting DLP reports requires team administrator privileges.

  • Export Limit: Single report exports are processed in optimized keyset batches and capped at a maximum of 100,000 records per export.


Frequently Asked Questions

Q: Will DLP slow down my email sending?

A: No. Policy evaluation happens in milliseconds at send time. You will not notice any delay for compliant emails.

Q: What happens if my email is blocked?

A: You'll see a notification directly in Gmail or Outlook explaining the block. Your email draft is preserved — you can edit it and try again.

Q: Does DLP read my emails while I'm typing?

A: No. DLP only inspects the email at the moment you click Send. It does not monitor drafts, keystrokes, or content in real time while composing.

Q: Are native desktop clients (Apple Mail, Outlook desktop app) supported?

A: Not currently. DLP covers Gmail and Outlook web apps only, accessed through a browser with the Swif extension installed.

Q: Is DLP enabled by default?

A: No. DLP is off by default and must be explicitly enabled by your team administrator in Team Settings.

Q: Does DLP work if I'm offline?

A: DLP requires an active browser extension connection. If the extension is disabled or not present, DLP enforcement will not apply.

Q: Can I see why my email was blocked?

A: The block notification will indicate that a DLP policy was triggered. Contact your administrator for details on your organization's specific policy rules.

Q: What sensitive data types does Swif DLP detect?

A: Swif detects credentials (passwords, bearer tokens), private keys, payment card & banking data, government IDs (SSNs, passports), health/PII records, and confidential business terms.

Q: What options do users have when a DLP warning is triggered?

A: When a warning modal appears upon clicking Send, users can select Cancel Send to return to their draft and edit the content, or Send Anyway if authorized to proceed.

For questions about your organization's DLP policies, contact your Swif administrator.

Q: What file formats are supported for DLP event exports?

A: You can export DLP event reports in either CSV or JSON format.

Q: Is there a limit on how many DLP event records can be exported at once?

A: Yes. Exports support up to 100,000 records per request. For larger historical datasets, adjust the date range picker or apply multi-select filters to export records in targeted batches.

Q: Do exported reports contain sensitive email bodies or file attachments?

A: No. In accordance with Swif's privacy-first architecture, raw message bodies and sensitive contents are never stored or included in CSV/JSON exports. Only audit metadata and violation trigger reasons are included.

Q: Who can export DLP reports?

A: Only authenticated team administrators with access to the Swif dashboard can generate and download DLP event reports.

Did this answer your question?