Proofpoint DLP in 2026: Email-First Strength, and Where AI Prompts Slip Past the Browser
.jpeg)
Proofpoint built its name on email security, and its DLP carries that DNA. For a lot of security teams, Proofpoint DLP is the natural add-on: the email gateway is already there, the people-centric risk model makes sense, and the insider threat tooling is well regarded. In 2026, though, the data your people leak most casually is not in an email. It is in a prompt. If you are comparing the whole category, our guide to the best data loss prevention tools ranks the field. This post goes deep on Proofpoint.
The short answer
Proofpoint DLP is a family of products, Enterprise DLP, Adaptive Email DLP, and endpoint DLP built on the same agent as Insider Threat Management (ITM), unified in a cloud console and strongest on email and user behavior. Its generative AI prompt controls are documented as working only when the endpoint agent and Proofpoint's ZenWeb browser extension run together, on a defined list of browsers and AI sites, and its newest agentic AI features are not expected until year-end 2026. dope.security takes a different path: Dopamine DLP reads AI prompts and uploads on the device through the web gateway itself, and Cloud Application Control blocks personal AI accounts, with no browser extension to deploy.
That is a testable claim. Open ChatGPT in Safari on a managed Mac, or in a private window you have not locked down, and see which controls follow you.
What is Proofpoint DLP?
Proofpoint's DLP portfolio was assembled over several acquisitions, and the history explains the shape of the product today.
- 2019. Proofpoint bought ObserveIT for $225 million, which became Insider Threat Management.
- 2021. Thoma Bravo took Proofpoint private in a $12.3 billion deal.
- December 2023. Proofpoint closed its acquisition of Tessian, which became Adaptive Email DLP.
- October 2024. Proofpoint agreed to acquire Normalyze for data security posture management (DSPM).
- February 2026. Proofpoint acquired Acuvity for AI runtime security and governance.
Proofpoint's Data Security menu now lists six products: Data Security for AI, Enterprise DLP, Adaptive Email DLP, Insider Threat Management, DSPM, and Digital Communications Governance, with Email DLP and Encryption still sold as its own product. A separate AI Security menu adds Secure AI Usage by People, Secure AI Usage by Agents, and Secure MCP. That is a broad portfolio. It is also a lot of product names to map onto one problem.
How Proofpoint DLP works
Proofpoint describes its approach as human-centric: watch the data and the person moving it, then decide. In practice, that runs across three control points.
- Email. Proofpoint's email DLP and Adaptive Email DLP inspect outbound mail and catch misdirected messages, which is where Proofpoint's heritage is deepest.
- Endpoint. Proofpoint says Endpoint DLP "is built on the same agent and back-end platform as Proofpoint ITM," and admins can move a user up to full ITM-level collection in a few clicks. Proofpoint calls the agent a "stable, lightweight user-mode" agent.
- Browser. The ZenWeb extension gives the agent page-level context in Chromium browsers. Without it, Proofpoint's documentation says the agent reads URLs through accessibility APIs or the address bar, which it describes as "less accurate" and able to add browser latency.
Proofpoint's platform docs list Windows 10 and 11, macOS 14 through 26, and several Linux distributions, with a minimum of 8 GB of RAM and 2 GB available for the agent on Windows. Content from ZenWeb is sent to the customer's Proofpoint tenant for analysis, so classification happens in Proofpoint's cloud. If you are weighing where DLP should enforce at all, our breakdown of endpoint DLP vs network DLP covers the trade-offs.
What Proofpoint DLP does well
Credit where it is due. Proofpoint has real strengths, and customers rate it highly.
- Email is a first-class channel. If misdirected email and outbound attachments are your biggest data loss problem, Proofpoint was built for it.
- Insider risk context. ITM can capture metadata and screenshots around risky activity, which gives investigators a timeline rather than a lone alert. Our post on insider risk management for data in motion covers why that context matters.
- One agent for DLP and ITM. Teams can run lighter DLP collection for most users and heavier ITM collection for a watch list, in mixed mode.
- Customer ratings. Proofpoint says it was named a Gartner Peer Insights Customers' Choice for DLP in 2024 and 2025, and Enterprise DLP holds about 4.5 out of 5 on Gartner Peer Insights.
If your DLP program is mostly about email and a defined set of high-risk users, Proofpoint is a credible choice.
Where Proofpoint DLP gets complicated for AI in 2026
The AI story is where the control points show their edges. Everything below comes from Proofpoint's own documentation and announcements.
Prompt controls need the agent and the extension together
Proofpoint's ZenWeb documentation says detecting and preventing text submitted to generative AI websites "is supported only with the Agent and ZenWeb." ZenWeb is a Chromium-based extension that needs no extra license, and it covers a fixed list of 16 generative AI sites, including ChatGPT, Gemini, Copilot, Claude, DeepSeek, Perplexity, Grok, and Mistral. That is solid coverage of the big names. It is also a list, and lists need maintaining as new AI tools appear every month.
The browser list has gaps
ZenWeb's documented browser support is Chrome, Edge, Island, Brave, and Opera on Windows, and Chrome, Edge, and Firefox on macOS. Safari on the Mac and Firefox on Windows are not on the ZenWeb list. Private browsing is not covered unless the user allows the extension there, and Proofpoint's documented workaround is to force the extension on in Edge InPrivate or block Incognito entirely in other browsers. File uploads are limited to 1,000 files. None of this is unusual for an extension-based control, but it means your AI coverage is only as wide as your browser policy.
Desktop AI apps are a different control point
People increasingly use AI through desktop apps, IDEs, and command-line tools, not just browser tabs. We did not find Proofpoint documentation describing prompt inspection inside desktop AI apps; its documented text-submit control is the agent plus ZenWeb in the browser. If your engineers live in desktop AI clients, test that path specifically. Our guide to detecting shadow AI in desktop apps, IDEs, and CLIs explains why the browser is only part of the picture.
The newest AI features are still on the roadmap
On September 22, 2026, Proofpoint announced an Agentic Data and AI Security system with detection, investigation, and remediation agents and "Semantic Business Policies." Proofpoint says these are "expected to be available by year-end 2026." That is promising, but it is not something you can deploy today, so evaluate what ships now.
Customers report dashboard and policy complexity
PeerSpot reviewers in 2026 describe a dashboard with an "overwhelming amount of information" that requires training, a steep learning curve, policy complexity, and slow support responses. One reviewer from a large retailer called the number of products and the packaging "confusing." These are customer reports, not universal truths, but they fit a portfolio built through acquisitions.
Proofpoint DLP vs dope.security: the head-to-head
Both products aim to stop sensitive data from leaving. They sit in different places on the machine. Here is the comparison, line by line.
- Where AI prompts are caught. Proofpoint documents generative AI text-submit detection only with its endpoint agent plus the ZenWeb browser extension. dope.security intercepts AI prompts and file uploads in its on-device SSL inspection proxy, so there is no extension to deploy or keep enabled.
- Browser coverage. ZenWeb supports a defined list of Chromium browsers plus Firefox on macOS, and private windows need extra configuration. dope.security inspects web traffic on the device, independent of which browser is open.
- Corporate vs personal AI accounts. Proofpoint documents separating corporate and personal generative AI activity with agent 5.0 or later. dope.security Cloud Application Control blocks personal ChatGPT, Claude, Google, and Microsoft 365 logins while allowing approved enterprise tenants, and for Claude the control covers both browser and desktop app usage with OS-level enforcement.
- How content is classified. Proofpoint analyzes content in the customer's Proofpoint tenant using its detectors and policies. Dopamine DLP classifies prompts and uploads with large language models through zero-retention OpenAI APIs, with no data retention and no training on your data, and explains each detection in a plain-language Dopamine Summary.
- Endpoint footprint. Proofpoint lists a minimum of 8 GB of RAM with 2 GB available for its agent on Windows. dope.endpoint runs natively on Mac and Windows using under 100 MB of RAM.
- Web security. Proofpoint does not currently market a secure web gateway in its product menu. dope.security is a Fly-Direct secure web gateway first, with URL filtering, anti-malware, and SSL inspection on the device.
- Email. Proofpoint inspects outbound email natively and deeply. dope.security does not replace an email gateway; teams that need email DLP keep it.
- Data at rest in the cloud. Proofpoint adds DSPM through Normalyze. dope.security CASB Neural scans OneDrive and Google Drive for publicly or externally shared files containing PII, PCI, PHI, or IP, with one-click remediation, in the same console.
Dopamine DLP is protected by US Patent 12,464,023. Read how it works in meet Dopamine DLP.
Replace Proofpoint DLP, or run dope.security alongside it?
For most teams, this is not either-or. Proofpoint owns email. The AI and web layer is where the gap sits.
- Keep email DLP where it is. If Proofpoint already protects your outbound mail, leave it there.
- Put AI and web enforcement on the endpoint. Deploy dope.security on Mac and Windows, turn on Cloud Application Control for your AI tenants, and run Dopamine DLP in Monitor mode to see what sensitive data flows into AI tools before you block anything. The control works in every browser because it does not live in one.
- Test the corporate vs personal split. Our walkthrough on blocking personal ChatGPT while keeping the corporate account and our guide to blocking personal Claude accounts show the exact steps.
- Consolidate where it makes sense. Our take on replacing legacy DLP covers the sequencing, and our comparison of Forcepoint DLP shows how another incumbent handles the same AI problem.
Deployment is the part teams worry about, and it goes fastest. Outreach Health secured 99% of its devices within one week and cut web access tickets by 70% in 90 days.
The bottom line on Proofpoint DLP
Put simply: Proofpoint DLP is excellent where Proofpoint has always been strong, email and people-centric insider risk, but its AI prompt controls are documented as an agent plus a browser extension working on a set list of browsers and sites, with the agentic features still ahead. If you want every AI prompt and upload inspected on the laptop regardless of browser, and personal AI accounts blocked while corporate ones keep working, that is what dope.security was built to do. Explore Dopamine DLP and the Fly-Direct Secure Web Gateway, or book a 20-minute demo and we will run the personal AI account test live.
Frequently Asked Questions
What does Proofpoint DLP include?
Proofpoint's Data Security portfolio includes Enterprise DLP, Adaptive Email DLP (from the Tessian acquisition), Insider Threat Management (from ObserveIT), DSPM (from Normalyze), Data Security for AI, and Digital Communications Governance, with Email DLP and Encryption sold separately. Endpoint DLP runs on the same agent and back end as ITM.
Is Proofpoint Endpoint DLP the same as Proofpoint ITM?
They share one agent. Proofpoint says Endpoint DLP is built on the same agent and back-end platform as ITM, and admins can move a user from DLP-level collection to full ITM-level collection, including screenshots around risky activity, in a few clicks. Organizations can run both in mixed mode across different users.
Can Proofpoint DLP stop data from going into ChatGPT?
Yes, in supported browsers. Proofpoint documents generative AI text-submit detection and prevention only with its endpoint agent plus the ZenWeb extension, across 16 listed AI sites. dope.security inspects AI prompts and uploads in its on-device proxy, independent of browser, and Cloud Application Control blocks personal ChatGPT accounts while allowing the corporate workspace.
Which browsers does Proofpoint ZenWeb support?
Proofpoint lists Chrome, Edge, Island, Brave, and Opera on Windows, and Chrome, Edge, and Firefox on macOS. Safari on Mac and Firefox on Windows are not on the ZenWeb list, and private browsing needs the extension forced on or Incognito blocked.
Does Proofpoint have a secure web gateway?
Proofpoint does not currently market a secure web gateway in its product menu; its web-facing data controls run through the endpoint agent and ZenWeb extension. dope.security is a Fly-Direct secure web gateway with on-device SSL inspection, URL filtering, and anti-malware, with Dopamine DLP and Cloud Application Control built in.
Can I run dope.security alongside Proofpoint?
Yes. Many teams keep Proofpoint for email security and email DLP and add dope.security on the endpoint for web and AI governance: Cloud Application Control for corporate AI tenants, Dopamine DLP for prompts and uploads, and CASB Neural for overshared files in OneDrive and Google Drive, all in one console.



