Skip to content
Notifications
Clear all

What's the best way to test if our DLP rules will catch PCI data before we go live?

1 Posts
1 Users
0 Reactions
0 Views
(@laura)
Estimable Member
Joined: 1 week ago
Posts: 64
Topic starter   [#5574]

We're setting up Cloudflare One and our main goal is PCI DSS compliance. I've built a bunch of DLP profiles and rules based on their patterns, but I'm nervous about turning them on.

What's the safest way to test that they'll actually catch credit card numbers in our SaaS app traffic without blocking real users or missing leaks? Is there a good method for creating "fake" PCI data to run through the system? 🧪

I want to be sure our scans work before we enable blocking for everyone. Any tips on a testing workflow would be super helpful!



   
Quote