Zscaler DLP in 2026: What It Inspects, What It Misses, and What It Costs

Zscaler DLP in 2026: What It Inspects, What It Misses, and What It Costs

Zscaler DLP is one of the most common reasons security teams stay on Zscaler. It rides the same Zero Trust Exchange as Zscaler Internet Access, it promises one policy across web, SaaS, endpoint, and email, and it is already in the building. The question worth asking in 2026 is simpler and more uncomfortable: how much of your data actually passes through it? If you are weighing the platform as a whole, our honest comparison of Zscaler alternatives is the wider view. This post is about the DLP piece specifically.

The short answer

Zscaler DLP is a family of data loss prevention capabilities inside Zscaler's Data Security portfolio: inline DLP that inspects web and SaaS traffic routed through the Zscaler cloud, endpoint DLP delivered through Client Connector, out-of-band SaaS API scanning, and email and AI application controls. The detection is solid. The catch is coverage. Zscaler DLP can only inspect what reaches the Zero Trust Exchange decrypted, cert-pinned apps and developer tools routinely end up on bypass lists, and the pieces that govern AI prompts are licensed separately. dope.security takes a different route: Dopamine DLP reads file uploads and AI prompts on the device, before anything leaves, inside the same agent that does SSL inspection.

That is a testable claim. Pull your current SSL bypass list, count the apps on it, and then check which Zscaler SKUs cover prompt-level DLP on your contract. The two numbers tell you how much of your data Zscaler DLP actually sees.

What is Zscaler DLP?

Zscaler describes its Data Security offering as unified classification and data security posture management combined with an inline DLP proxy. In practice, "Zscaler DLP" is several capabilities that share a policy engine and a console.

  • Inline DLP. Inspects web, SaaS, and email traffic that flows through Zscaler Internet Access and enforces policy in the traffic path. This is the flagship capability and the one most customers mean by Zscaler DLP.
  • Endpoint DLP. Extends policy to device channels through Client Connector. Zscaler's own product page lists removable storage, network shares, printing, and native cloud sync apps like Dropbox, Box, and OneDrive.
  • SaaS API scanning. Out-of-band CASB scanning of data already sitting in sanctioned SaaS tenants.
  • DSPM and classification. Posture management and classification for data at rest, which Zscaler has folded into the same Data Security story.
  • AI application security. Shadow AI visibility, prompt-level insights, and inline DLP controls for AI apps, delivered alongside AI Guard and the AI Scanning platform.

If you want the broader platform explainer first, start with what Zscaler actually is. The short version is that everything above assumes traffic gets to Zscaler first.

How Zscaler DLP works

Inline DLP is a proxy function. Client Connector forwards traffic from the device to a Zscaler Service Edge, the service decrypts it, the DLP engine inspects the content, and the request continues or gets blocked. That design has real advantages. One inspection point sees many channels, policy lives in one place, and there is no separate DLP appliance to run.

It also defines the limits. A proxy-based DLP engine sees what the proxy sees, which means three kinds of traffic slip out of scope. First, anything on the SSL bypass list. Second, anything the client does not forward, such as split-tunneled destinations. Third, anything that never crosses the network at all, which is why Zscaler sells endpoint DLP as a separate capability for USB, printing, and file shares.

The bypass list is the real DLP policy

This is the part most DLP evaluations skip. Zscaler's own documentation acknowledges that certificate-pinned applications such as Microsoft 365, WebEx, and Dropbox cannot be inspected through its proxy, and that developer tools like Docker, Python, and Git break under SSL inspection. The standard fix is a bypass. Every bypass is a destination your inline DLP no longer reads. Two of the three pinned apps on that list are file-sharing and collaboration tools, which is exactly where sensitive data moves. We cover the mechanics in certificate pinning and SSL inspection.

What Zscaler DLP does well

Credit where it is due. Zscaler DLP is a strong choice in several situations.

  • You already route everything through ZIA. If inspection is already happening, adding DLP policy to the same path is operationally efficient.
  • One policy across channels. Zscaler's pitch of a single DLP policy for endpoint, inline, and cloud is real, and it beats stitching three vendors together.
  • Classification depth. Exact data match, predefined dictionaries, and classifiers give mature teams precise tools for structured data.
  • Posture and at-rest coverage. DSPM and API scanning let one vendor answer both "where is my data" and "where is it going."

Where Zscaler DLP falls short in 2026

The friction shows up in three places: licensing, performance, and AI coverage.

Three purchases that look like one feature

Zscaler sells in stacked editions and add-ons. Prompt-level DLP requires the Data Protection add-on, and AI Guard and the AI Scanning platform are licensed separately. That is not a hidden fee, it is how the catalog works, but it means "we have Zscaler DLP" and "Zscaler DLP inspects our AI prompts" can be two very different statements on the same contract. Pricing has also moved. NPI Financial found some Zscaler SKUs priced 35% or more above prior levels in August 2025. We break down the AI line items in the real cost of Zscaler AI governance add-ons, and the wider picture in Zscaler pricing in 2026.

Inspection has a price in latency

Every inspected request detours to a Zscaler node and back, and DLP is one more module in the stack. Customers report latency growing two to three times as modules pile up, and Gartner has cited a 10% to 20% throughput drop. That matters for DLP specifically, because the usual response to a slow, broken app is a bypass, and every bypass shrinks what DLP can see.

AI coverage stops where the proxy stops

Zscaler's AI dashboard gives real visibility into shadow AI usage and prompts that pass through the proxy. The gaps are the same ones as above. AI desktop apps and developer tools that pin certificates or break under inspection get bypassed. Split-tunneled traffic never arrives. And inspecting a prompt tells you what was typed, not whether it went to your corporate ChatGPT workspace or a personal account on the same domain. That tenant question is where most AI data risk actually sits, and we walk through it in how to block personal ChatGPT while keeping the corporate account.

Zscaler DLP vs Dopamine DLP: the head-to-head

Both products want sensitive data to stay put. They put the control point in different places. Here is the comparison, line by line.

  • Where inspection happens. Zscaler inline DLP inspects traffic after Client Connector forwards it to a Zscaler Service Edge. Dopamine DLP inspects file uploads and AI prompts on the device, before the data leaves, inside the dope.security agent.
  • Cert-pinned and developer apps. Zscaler documents that it cannot inspect pinned Microsoft 365, WebEx, and Dropbox traffic and that Docker, Python, and Git break under inspection, which leads to bypass lists. dope.security performs SSL inspection on the endpoint and surfaces SSL errors from certificate pinning so admins can create targeted bypasses in a few clicks.
  • How content is classified. Zscaler relies on dictionaries, exact data match, and classifiers that administrators tune. Dopamine DLP classifies extracted text with large language models through zero-retention OpenAI APIs, with no rule configuration required and fewer false positives than regex rules.
  • AI prompt coverage. Zscaler prompt-level DLP requires the Data Protection add-on, with AI Guard and AI Scanning licensed separately. Dopamine DLP covers ChatGPT, Claude, Perplexity, Abacus, and Copilot as part of the product.
  • Personal vs corporate accounts. Content inspection alone does not separate tenants. dope.security Cloud Application Control restricts ChatGPT, Claude, Google, and Microsoft 365 to corporate tenants and blocks personal logins on the same domain.
  • Explaining detections. Zscaler shows which rule matched. Dopamine DLP adds a Dopamine Summary, a plain-language explanation of what was detected and why.
  • Network path. Zscaler sends inspected traffic through its cloud. dope.security flies direct to the destination, with up to 4x performance over legacy proxy SWGs, and the agent uses less than 100 MB of RAM.
  • Data at rest. Zscaler uses API scanning and DSPM. dope.security uses CASB Neural to find publicly or externally shared files containing PII, PCI, PHI, or IP in OneDrive and Google Drive, with one-click remediation.

The takeaway: Zscaler DLP is as complete as your decrypted traffic and your SKU list, while on-device DLP reads the prompt or the file before either question comes up.

Questions to ask before you renew Zscaler DLP

If Zscaler DLP is on your renewal list, these questions turn a vague feature comparison into numbers you can defend.

  • How long is our SSL bypass list, and what is on it? Every entry is a destination inline DLP does not read. Pay special attention to file sharing, collaboration, and AI desktop apps.
  • Which of our SKUs cover prompt-level DLP? Confirm whether the Data Protection add-on, AI Guard, and AI Scanning are on the contract or on the quote.
  • What happens to split-tunneled traffic? Anything that leaves outside the tunnel is outside inline DLP.
  • How many DLP alerts last quarter were real? False positive rates decide whether a DLP program survives contact with the help desk.
  • Can we block a personal ChatGPT account and allow the corporate one? Run it live. It is the fastest way to see whether AI governance is a control or a report.

For a wider market view, our roundup of the best data loss prevention tools puts Zscaler next to the field. We ran the same analysis on Forcepoint DLP, and our explainer on endpoint DLP vs network DLP covers the architecture trade in depth.

Staying, extending, or leaving

Stay on Zscaler DLP if nearly all of your traffic already routes through ZIA with a short bypass list, your contract already includes the Data Protection and AI add-ons, and your DLP team is staffed to tune dictionaries and classifiers. In that world the integration is worth a lot.

Start testing an alternative when the bypass list keeps growing, AI prompts and uploads have become a real path for data to leave, and the renewal quote for the AI add-ons landed before the budget did. The lowest-risk test is side by side. Keep Zscaler in place, deploy Dopamine DLP in Monitor mode on a pilot group, and compare what each catches in AI prompts and uploads over two weeks, including traffic that sits on the Zscaler bypass list. When you are ready to enforce, moving from Monitor to Block is a console setting, not a project.

Deployment is rarely the blocker. A healthcare organization replaced Zscaler with dope.security and documented the move in our healthcare Zscaler displacement case study. At the enterprise end, a Fortune 100 company scaled from 900 to more than 18,000 devices in weeks, deploying silently through Intune.

The bottom line on Zscaler DLP

Put simply: Zscaler DLP is a capable engine sitting behind a proxy, so its real coverage is whatever the proxy decrypts minus whatever your contract leaves out, and AI prompts sit right on both edges. If you want DLP that reads uploads and prompts on the device, understands content without a rulebook, and knows the difference between corporate and personal ChatGPT, that is what Dopamine DLP was built for. Read the introduction to Dopamine DLP, explore the Fly-Direct Secure Web Gateway it runs inside, or book a 20-minute demo and watch the personal ChatGPT test live.

Frequently Asked Questions

Is Zscaler DLP included with Zscaler Internet Access?

Not fully. Zscaler sells in stacked editions and add-ons, and prompt-level DLP requires the Data Protection add-on, while AI Guard and the AI Scanning platform are licensed separately. Check your contract line by line, because "ZIA with DLP" can mean very different coverage. dope.security includes Dopamine DLP prompt and upload inspection in the product rather than as an AI add-on.

Does Zscaler DLP work on endpoints?

Yes. Zscaler Endpoint DLP runs through Client Connector and covers device channels such as removable storage, network shares, printing, and native cloud sync apps. Inline web and SaaS DLP still depends on traffic being forwarded to the Zscaler cloud. dope.security inspects web uploads and AI prompts on the device itself.

Can Zscaler DLP inspect Microsoft 365 and Dropbox traffic?

Zscaler's documentation notes that certificate-pinned apps including Microsoft 365, WebEx, and Dropbox cannot be inspected through its proxy, so they are commonly bypassed. Bypassed traffic is outside inline DLP. Review your bypass list before assuming coverage, and consider an on-device approach for those channels.

Can Zscaler DLP stop data leaks to ChatGPT?

Zscaler offers shadow AI visibility and inline DLP for AI apps whose traffic passes through its proxy, with prompt-level DLP tied to the Data Protection add-on. Content inspection alone does not distinguish a corporate ChatGPT workspace from a personal account. dope.security pairs on-device prompt DLP with Cloud Application Control to block personal logins while allowing the corporate tenant.

What is the difference between Zscaler DLP and Zscaler CASB?

Zscaler DLP is the content inspection engine that decides whether data can leave. CASB covers SaaS visibility and control, including out-of-band API scanning of data already stored in sanctioned apps. Both share Zscaler's policy engine. dope.security splits the same jobs between Dopamine DLP for data in motion and CASB Neural for exposed files at rest.

What is the best Zscaler DLP alternative?

For teams whose main concern is data leaving through AI prompts, file uploads, and apps that end up on SSL bypass lists, dope.security is a strong alternative. Dopamine DLP inspects on the device, classifies with zero-retention LLM APIs, and runs in Block, Monitor, or Off under US Patent 12,464,023. It shares one agent and one console with the Fly-Direct SWG and CASB Neural.

Technology Solutions
Technology Solutions
Company
Company
Data Loss Prevention
Data Loss Prevention
← back to blog Home