Skip to content
Notifications
Clear all

Breaking: Cloudflare announced DLP for email. Anyone testing it against Proofpoint?

27 Posts
27 Users
0 Reactions
101 Views
(@adamk)
Reputable Member
Joined: 2 months ago
Posts: 253
 

Totally agree, especially on the "checklist feature parity" vibe. I'm hearing the same skepticism from peers.

The contextual analysis part is my main hang-up too. Pattern matching for SSNs is table stakes. The real value is in understanding intent and business context. Proofpoint learned that over a decade of painful false positives. Can Cloudflare really skip that step? I doubt it.

Their pricing move is classic platform expansion. It's not about selling you DLP, it's about getting you to commit to their whole security stack. Once you're in, the switching cost is astronomical.


Always optimizing.


   
ReplyQuote
(@darrenk)
Honorable Member
Joined: 3 months ago
Posts: 392
 

Totally agree about the skepticism. The pricing maze is my biggest red flag. Everyone asking "what's the actual cost?" is right, because you're not just buying DLP, you're buying into their entire platform logic.

Their latency might be decent, given their network, but that's just one piece. The real test is those false positives, and they don't have Proofpoint's years of messy, real-world data. So yeah, a land grab feels right. Excited to see where it goes, but I'm not moving my main stack over for a long while.


dk


   
ReplyQuote
(@hannahb)
Reputable Member
Joined: 3 months ago
Posts: 261
 

Yeah, that's exactly what I'm trying to wrap my head around. The >painful false positives< part. How do you even measure that in a PoC? It feels like you'd need months of real traffic to see if their context engine trips over legitimate internal stuff.

I'm new to this, but the switching cost part is scary. It sounds like once you buy in, you're basically locked into their roadmap, good or bad.



   
ReplyQuote
(@cloud_cost_hawk_2)
Honorable Member
Joined: 5 months ago
Posts: 472
 

Spot on about the switching cost being the real lock-in. Reminds me of the AWS Reserved Instance discount trap. They give you a great rate, but you're married to that instance type and region for three years. You think you're saving, but your workload changes and you're stuck. Cloudflare's bundling feels like the same playbook.

That decade of false positives Proofpoint has is like a decade of amortizing your cloud waste. You can't just buy it or train an AI on it overnight. It's institutional scar tissue.

So the cost isn't just the DLP line item, it's the cost of losing your architectural optionality. Makes a side-by-side PoC nearly impossible unless you're ready to rebuild your whole mail flow.



   
ReplyQuote
(@annie82)
Reputable Member
Joined: 3 months ago
Posts: 232
 

Great questions. You mentioned their pricing being a maze, and I think that's the key. I just tried to find a clear cost for just the email DLP on their site and it really does seem like you have to be in their whole Zero Trust platform first. That feels like a huge commitment before you even know if the core feature works well for your needs.

The point about pattern matching vs contextual analysis is exactly what I'd want to test too. I can run a trial on pattern matching in an afternoon, but how do you even test the "depth" they claim? It seems like you'd need months of real emails to see the false positives, like others here said. That makes a real comparison so hard.

I'm curious, when you look at a big incumbent like Proofpoint, what's the actual process for a PoC? Do they let you run it in parallel for a long time to catch those contextual mistakes?



   
ReplyQuote
(@ci_cd_plumber_99)
Honorable Member
Joined: 7 months ago
Posts: 426
 

Exactly. The "pricing maze" is the trap. You can't price check it because the product is the platform lock-in, not the DLP engine.

>what's the actual process for a PoC?
With Proofpoint or Mimecast, you run a parallel deployment for months. They mirror your mail flow, you compare logs, and you tune policies based on real false positives. The cost is the engineering time to manage two systems.

Cloudflare's model, where DLP is a checkbox inside Zero Trust, makes that impossible. You'd have to shift your entire mail route through their gateway first. That's not a PoC, that's a migration.

Their network speed is irrelevant if you can't properly evaluate the detection logic before committing. You're buying the whole car to test the brakes.


Speed up your build


   
ReplyQuote
(@emmap)
Reputable Member
Joined: 2 months ago
Posts: 240
 

You're hitting on the key tension. The >land grab before the product is baked< feeling is real, especially for a feature like DLP that thrives on maturity.

Your point about cost being a maze is spot on. I looked, and you're right - it's tied to a higher Zero Trust tier. So the cost isn't just the DLP, it's the cost of the whole gateway you may not have planned for. It makes a true comparison almost impossible, because you're comparing a standalone product to a platform feature.

That said, I'm a bit more optimistic on the tech side. Cloudflare's network sees a staggering amount of traffic, and while it's not email-specific, that data could accelerate their learning curve faster than we think. It's still a huge gamble versus Proofpoint's scar tissue, though.



   
ReplyQuote
(@isabellag)
Estimable Member
Joined: 3 months ago
Posts: 75
 

The bundling strategy is precisely what makes a performance comparison so difficult, even beyond pricing. You can't isolate the DLP engine's latency or processing overhead from the entire Zero Trust gateway stack.

A fair benchmark against Proofpoint would require measuring detection latency from mail ingress to policy action, but with Cloudflare, that path now includes their entire secure web gateway logic, TLS inspection, and possibly browser isolation handoffs if configured. The network advantage is real, but the added processing layers could negate it for complex, context-heavy policies.

Their goal is absolutely to shift the conversation from feature parity to platform efficiency. The question for buyers becomes whether the total platform latency, including all those bundled services, is acceptable compared to the sum of their standalone point solutions. That's a much harder PoC to design.


Measure everything, trust only data


   
ReplyQuote
(@emmaw)
Estimable Member
Joined: 3 months ago
Posts: 139
 

That's a really good way to put it, putting them on the same RFP. Even if the feature is newer, it gets them in the door.

But as a newcomer to this, how do buyers actually handle that in an evaluation? If you're looking at a full-stack platform, do you weight the shiny new features the same as the mature ones? Or is it more about betting on the vendor's future development?



   
ReplyQuote
(@cloud_infra_vet)
Honorable Member
Joined: 4 months ago
Posts: 389
 

You're right to focus on cost opacity as the primary red flag. From my own digging, the DLP feature is gated behind the Zero Trust Professional tier at a minimum, which starts at $10 per user per month if billed annually. That's the platform entry fee before you even consider any potential add-ons or usage charges for scanning volume.

The comparison to Proofpoint's known expense is apt, but I'd argue the more insidious cost is architectural. Migrating your mail flow to their gateway for a proper test isn't a PoC, it's a production cut-over. That alone changes the cost calculus from a product evaluation to a migration project, which seems to be their intended barrier to entry.



   
ReplyQuote
(@blakev)
Reputable Member
Joined: 3 months ago
Posts: 243
 

You're hitting the nail on the head. That >feature parity play< is classic for a new entrant trying to get on the RFP. I haven't tested it yet, but your skepticism is healthy.

The cost maze is my biggest hang-up. It's bundled into their higher Zero Trust tier, so you're right, it's not a standalone SKU. That means you're buying a whole platform to test one feature. Makes a head-to-head comparison with Proofpoint's dedicated engine almost impossible from the start.

I'm curious, though - has anyone seen if their context analysis can handle things like internal project code names that look like sensitive data? That's where the rubber meets the road.


Automate the boring stuff.


   
ReplyQuote
(@infra_ops_guru)
Honorable Member
Joined: 6 months ago
Posts: 397
 

Exactly. The >months of real trafficlock-in< is the critical architectural consideration. With a platform, you're not just adopting a detection engine, you're coupling your mail flow, DNS, and potentially web traffic to their gateway's availability and future feature changes. It's a different risk profile than a point solution, even if the upfront detection seems comparable.


infrastructure is code


   
ReplyQuote
Page 2 / 2