Trellix DLP in 2026: What the Old McAfee DLP Covers Now, and Where AI Slips Through
.jpeg)
Trellix DLP is the old McAfee DLP, and plenty of security teams still run it because it works for what it was built to do: keep regulated data from walking out through USB drives, email, and file shares. The question in 2026 is different. Your people now paste data into AI tools all day, and the controls that stop that live in different places across the old McAfee stack. If you are comparing the whole category, our guide to the best data loss prevention tools ranks the field. This post goes deep on Trellix.
The short answer
Trellix DLP is the endpoint, network, and discovery DLP line that Trellix kept when McAfee Enterprise was split in 2022, managed from Trellix ePolicy Orchestrator (ePO) on-premises or as SaaS. It is mature and broad for regulated data. Its AI protection, though, is gated by platform: the AI Data Risk Dashboard runs on on-premises ePO, the browser content-inspection integrations run on Windows only, and cloud DLP now belongs to a sister company, Skyhigh Security. dope.security takes a single path instead: Dopamine DLP reads AI prompts and uploads on the device, on Mac and Windows, from one console.
That is a testable claim. Pick a Mac, a Windows laptop, and a personal AI account, and see which of them your current DLP actually covers.
What is Trellix DLP?
Trellix DLP started life as McAfee Total Protection for Data Loss Prevention. The ownership history explains a lot about how it is packaged today.
- 2021. Private equity firm STG bought the McAfee Enterprise business for $4 billion.
- January 2022. STG combined FireEye with part of McAfee Enterprise and launched it as Trellix.
- March 2022. The rest of McAfee Enterprise emerged as Skyhigh Security, with a portfolio that included the secure web gateway, CASB, ZTNA, and cloud DLP, according to SecurityWeek's coverage of the launch.
- January 2025. Trellix named Vishal Rao CEO, leading both Trellix and Skyhigh, with STG still the owner.
Trellix's own DLP product page now says it partners with Skyhigh Security to extend its DLP into cloud data repositories. In plain language: the endpoint and network pieces of the old McAfee DLP are at Trellix, and the cloud and web pieces are at Skyhigh. If you run both, you run two companies' products. We cover the Skyhigh side in our look at Skyhigh Security alternatives.
The current Trellix lineup, per its product and suite pages, looks like this.
- DLP Endpoint Complete. Endpoint DLP with Device Control included, for Windows and macOS.
- DLP Network Monitor and DLP Network Prevent. Network-based inspection of data in motion.
- DLP Discover. Scanning and classification of data at rest in repositories.
- Trellix Data Security suites. Bundles that combine DLP with Trellix Data Encryption and an optional Database Security add-on.
How Trellix DLP works
Everything runs through ePO. Trellix's Endpoint Complete datasheet says ePO is available on-premises or as SaaS, and the DLP policy, rule sets, classifications, and incident management all live there. If your team already manages Trellix endpoint security in ePO, DLP slots into a console they know.
Detection is classic, rule-driven DLP, and Trellix documents a deep toolbox.
- Advanced patterns. Regular expressions for structured data such as card numbers and national IDs.
- Exact data matching. EDM on Network Prevent, Network Monitor, and Discover, for matching against real records.
- Fingerprinting. Document and web content fingerprinting to catch copies of known sensitive files.
- OCR. An add-on for Network and Discover, and for the Windows endpoint since version 11.12.
- Auto-classification. In Discover, alongside rights management integration.
Trellix says the products inspect more than 400 file formats. Licensing is not published as a list price; reseller listings show per-node licensing sold in volume bands. The trade-off with any rule engine is the same: precision depends on the rules your team writes and maintains. Our breakdown of endpoint DLP vs network DLP explains where each enforcement point earns its keep.
What Trellix DLP does well
Credit where it is due. Trellix DLP has real strengths, and buyers rate it well.
- Breadth across channels. Endpoint, network, and discovery under one policy model covers USB, email, printing, file shares, and repositories.
- Device control built in. Removable media control ships with Endpoint Complete rather than as a separate product.
- Serious detection options. EDM, fingerprinting, and OCR are the tools regulated industries ask for.
- Solid reviews. Trellix DLP holds a 4.5 out of 5 rating from about 380 ratings on Gartner Peer Insights.
If your DLP program is mostly about regulated data at rest and on removable media, Trellix is a credible incumbent.
Where Trellix DLP gets complicated for AI in 2026
The AI story is where the platform seams show. None of these gaps come from our opinion. They come from Trellix's own datasheets and release notes.
AI controls start from URL lists
Trellix's 2023 guidance on preventing leaks to ChatGPT told admins to build URL lists of AI sites and combine them with clipboard protection, web upload rules, and web application control. At the time, Trellix noted that macOS was reporting-only for this use case and that blocking worked in Firefox while Chrome and Edge were monitor-only. That guidance is from 2023 and some limits may have changed, but the design pattern carried forward. Trellix's AI Data Risk Dashboard, announced on April 8, 2026 as a free upgrade, builds on existing URL-based DLP policies and a catalog of more than 400 AI apps, and tracks copy, paste, clipboard, and file uploads to AI tools.
The newest AI features are platform-gated
Two of the most useful recent additions come with conditions buyers should check before assuming coverage.
- AI Data Risk Dashboard. Trellix's datasheet lists it for on-premises ePO, with Endpoint Windows 11.14 or later, Endpoint macOS 11.13 or later, and Network 11.11 or later. If you moved to ePO SaaS, confirm availability.
- Browser content inspection. The API-based integrations with Chrome Enterprise, Edge for Business, Firefox, and Island are Windows-only, on version 11.14 or later.
- Other Windows-first features. Trellix's June 2025 release notes list endpoint OCR, enhanced visual labeling, and some device rules as Windows-only, while macOS 11.11 had only just gained clipboard protection and AirDrop monitoring.
For a Mac-heavy engineering team, that matters. The people most likely to paste source code into an AI tool are often the ones on the platform with the thinnest coverage.
Corporate vs personal AI accounts
The hardest AI test is not "is this ChatGPT." It is "is this our ChatGPT workspace or someone's personal account on the same domain." We did not find a Trellix document describing a DLP control that separates a corporate AI tenant from a personal one. A URL list treats both the same, because they share a hostname. That kind of tenant control typically sits with the web gateway, which in the old McAfee world now belongs to Skyhigh. We walk through the test in how to block personal ChatGPT while keeping the corporate account.
Customers report tuning and console effort
Reviewers on Gartner Peer Insights and PeerSpot describe recurring themes: the product needs careful configuration and policy tuning, on-premises deployments carry SQL and architecture overhead, the console can feel overwhelming and slow to load, and some report endpoint slowdowns and weaker macOS clipboard and print protection. Support experiences are mixed, with some reviewers praising it and others citing slow ticket resolution. These are customer reports, not universal truths, but they line up with what rule-heavy DLP usually costs to run.
Trellix DLP vs dope.security: the head-to-head
Both products aim to stop sensitive data from leaving. They are built on different assumptions about where the risk now lives. Here is the comparison, line by line.
- How AI traffic is identified. Trellix DLP builds AI protection on URL lists, clipboard and upload rules, and a 400+ app catalog. dope.security inspects web traffic on the device with an on-device SSL inspection proxy and intercepts AI prompts and file uploads directly.
- How content is classified. Trellix DLP relies on patterns, EDM, fingerprints, and OCR that your team configures. Dopamine DLP classifies prompts and uploads with large language models through zero-retention OpenAI APIs, and explains each detection in a plain-language Dopamine Summary.
- Platform coverage for AI. Trellix documents its newest browser inspection as Windows-only and its AI dashboard as on-premises ePO. dope.endpoint runs natively on Mac and Windows with the same policy, using under 100 MB of RAM.
- Corporate vs personal AI accounts. We found no documented Trellix DLP tenant control. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to approved corporate tenants and blocks personal logins on the same domain.
- AI tool coverage. Trellix tracks AI apps from its catalog. Dopamine DLP covers ChatGPT, Claude, Perplexity, Abacus, and Copilot, with Block, Monitor, and Off modes.
- Data at rest in the cloud. Trellix partners with Skyhigh for cloud repositories. dope.security CASB Neural scans OneDrive and Google Drive for publicly or externally shared files containing PII, PCI, PHI, or IP, with one-click remediation, in the same console.
- Management. Trellix DLP runs in ePO, on-premises or SaaS, with feature differences between them. dope.console is a single cloud console built from scratch for SWG, CAC, Dopamine DLP, and CASB Neural.
Dopamine DLP is protected by US Patent 12,464,023. Read how it works in meet Dopamine DLP.
Replace Trellix DLP, or run dope.security alongside it?
You do not have to rip anything out on day one. A lot of teams keep what works and close the AI gap first.
- Keep Discover and Network where they earn their keep. If you have years of tuned EDM and fingerprint policies for regulated data at rest, that investment still has value.
- Put AI enforcement on the endpoint. Deploy dope.security on Mac and Windows, turn on Cloud Application Control for your AI tenants, and put Dopamine DLP in Monitor mode to see what sensitive data is flowing into AI tools before you block anything.
- Move cloud data at rest to one console. Use CASB Neural to find overshared files in OneDrive and Google Drive instead of stitching in a second vendor.
- Write the policy once. Our guide to building a DLP policy maps policy clauses to controls you can actually enforce.
Deployment is the part teams worry about, and it is the part that goes fastest. Outreach Health secured 99% of its devices within one week and cut web access tickets by 70% in 90 days. If you are weighing a broader DLP change, our take on replacing legacy DLP covers the sequencing.
The bottom line on Trellix DLP
Put simply: Trellix DLP is a capable rule engine for the channels McAfee built it for, but its AI coverage depends on which operating system you run, which ePO you run, and which half of the old McAfee stack you bought. If you want AI prompts and uploads inspected the same way on every Mac and Windows laptop, with personal AI accounts blocked and corporate ones allowed, that is what dope.security was built to do. Explore Dopamine DLP and the Fly-Direct Secure Web Gateway, or book a 20-minute demo and we will run the personal AI account test live.
Frequently Asked Questions
Is Trellix DLP the same as McAfee DLP?
Yes, Trellix DLP is the continuation of McAfee's DLP line. After STG bought McAfee Enterprise in 2021, the endpoint, network, and discovery DLP products went to Trellix, launched in January 2022, while the web gateway, CASB, and cloud DLP went to Skyhigh Security in March 2022.
Is Trellix DLP managed in ePO?
Yes. Trellix DLP is managed through Trellix ePolicy Orchestrator, which Trellix offers on-premises or as SaaS. Some newer features have conditions: Trellix lists its AI Data Risk Dashboard for on-premises ePO, so confirm feature availability for your deployment model before you plan around it.
Can Trellix DLP stop data from going into ChatGPT?
Trellix DLP can apply clipboard, upload, and web application rules to AI sites defined in URL lists, and its April 2026 AI Data Risk Dashboard tracks activity across a catalog of more than 400 AI apps. We did not find a documented control that separates a corporate ChatGPT workspace from a personal account on the same domain. dope.security Cloud Application Control does that, and Dopamine DLP inspects the prompt itself on the device.
Does Trellix DLP work on macOS?
Yes, Trellix DLP Endpoint supports Windows and macOS. Trellix documents several features as Windows-only, including endpoint OCR and the browser content-inspection integrations for Chrome Enterprise, Edge for Business, Firefox, and Island. dope.security runs natively on Mac and Windows with the same policy on both.
What is the difference between Trellix DLP and Skyhigh DLP?
Trellix DLP covers endpoints, network traffic, and data discovery, managed in ePO. Skyhigh Security, the other half of the former McAfee Enterprise, sells cloud DLP alongside its secure web gateway and CASB. Trellix says it partners with Skyhigh to extend its DLP into cloud repositories, so full coverage can mean two vendors.
Can I run dope.security alongside Trellix DLP?
Yes. Many teams keep existing DLP rules for regulated data at rest and add dope.security on the endpoint for AI governance: Cloud Application Control for corporate AI tenants, Dopamine DLP for prompts and uploads, and CASB Neural for overshared files in OneDrive and Google Drive, all in one console.



