AI inventory

DeepSeek

DeepSeek · Assistant · Confirmed · catalog deepseek. Seen by 4 lanes through 4 findings.

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Combined score
90
Critical 75 from the strongest lane + 15 for 3 more
People
2
Distinct identities across every lane
Seen by
4
Network, Purview DLP, SIEM, Endpoint
First seen
Aug 25, 2026
Last seen 2 d ago
networkno-entra-footprintlow-defender-scoredlphigh-impact-datanot-blockedcorroboratedsiemfixtureheavy-uploadendpoint
Evidence

Where it was seen

Strongest finding →
Network
Critical75

2 users, 275 MB up

Users
2
Uploaded
275 MB
Transactions
2130
Defender score
2/10
2 people · 2 d agoOpen finding →
Purview DLP
DeepSeek: sensitive data
High70

2 DLP events, 2 not blocked

Events
2
Not blocked
2
Blocked
0
Top types
All Full Names, Source Code
2 people · 4 d agoOpen finding →
SIEMSplunk (demo)
High62

220 events, 140 MB up via Splunk (demo)

Events
220
Uploaded
140 MB
Users
1
Sources
1
1 person · 2 d agoOpen finding →
Endpoint
Medium40

2 devices, 2 accounts

Devices
2
Accounts
2
Processes
0
Extensions
0
2 people · 2 d agoOpen finding →
Next steps

Recommended actions

  1. 01
    DeepSeek trains on customer data. Block the app or move users to a business tier that excludes training.
    NetworkPurview DLPSIEMEndpoint
  2. 02
    275 MB uploaded to DeepSeek in 30 days from 2 people. Check what data is leaving with Defender's file and session policies.
    Network
  3. 03
    DeepSeek shows up on the network but holds no Entra consent, so people are using personal accounts or no account at all. Conditional Access cannot see it; block or coach at the gateway with a Defender for Cloud Apps unsanction policy.
    Network
  4. 04
    Defender rates DeepSeek 2/10 on security, compliance, and legal criteria. Treat it as unsuitable for work data unless the vendor closes those gaps.
    Network
  5. 05
    Every DLP match for DeepSeek was audit or warn only (All Full Names, Source Code). The policy sees the data leaving and lets it go. Move the rule to Block for these information types, at least for uploads and pastes to unsanctioned AI sites.
    Purview DLP
  6. 06
    High-impact information types were involved (All Full Names, Source Code). Treat this as a data incident: confirm with the user what was pasted, and check the vendor's retention terms for the accounts involved.
    Purview DLP
  7. 07
    140 MB left for DeepSeek through Splunk (demo) in 30 days. Check the proxy or firewall for file uploads and pair this with a DLP rule for AI destinations.
    SIEM
  8. 08
    Splunk (demo) confirms what Microsoft 365 signals show for DeepSeek. Use the source list here to find the exact devices and network segments involved.
    SIEM
  9. 09
    Device telemetry names the exact machines and accounts reaching chat.deepseek.com. Use it to target coaching rather than blanket blocks.
    Endpoint
Who

People

PersonDepartmentSourcesSeen bySign-ins · 30 d
n/a
Network trafficAudit logSIEM logsDevice telemetry
Network · Purview DLP · SIEM · Endpoint0
n/a
Network trafficAudit logDevice telemetry
Network · Purview DLP · Endpoint0
Vendor

Policy notes

Trains on data
Yes
Enterprise tier
None
Org policy
None set

Data stored in the PRC; several governments and enterprises have banned it outright.

Exposure

Data it can reach

Files & sites
Lanes

Score by source

Each lane scores its own evidence. The combined score takes the strongest lane and adds five points per additional lane, capped at 100.