DeepSeek: sensitive data
Purview DLP DeepSeek · Assistant · DLP target chat.deepseek.com
Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
70
High
People
2
Named in DLP events
Not blocked
2
2 DLP events · 30 days
Blocked
0
Policy stopped these
dlphigh-impact-datanot-blockedcorroborated
Next steps
Recommended actions
- 01DeepSeek trains on customer data. Block the app or move users to a business tier that excludes training.
- 02Every DLP match for DeepSeek was audit or warn only (All Full Names, Source Code). The policy sees the data leaving and lets it go. Move the rule to Block for these information types, at least for uploads and pastes to unsanctioned AI sites.
- 03High-impact information types were involved (All Full Names, Source Code). Treat this as a data incident: confirm with the user what was pasted, and check the vendor's retention terms for the accounts involved.
Purview
What went in and what stopped it
Audit only · 2
08-1609-14
Information types
| Type | Events | Matches |
|---|---|---|
| All Full Names | 1 | 30 |
| Source Code | 1 | 1 |
Policies
Endpoint DLP - Source code1
Endpoint DLP - Customer data1
Activities
TextPastedToBrowser1
FileUploadedToCloud1
Destinations
chat.deepseek.com2
Applications
chrome.exe1
msedge.exe1
Files involved1
Same app, other lanes
Related findings
Who
People
Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.
| Person | Department | Source | Sign-ins · 30 d | Granted |
|---|---|---|---|---|
| n/a | Audit log | 0 | No direct grant | |
| n/a | Audit log | 0 | No direct grant |
Why
Evidence
- dlp_activity · Sep 10, 20262 DLP events for DeepSeek by 2 people in 30 days: 0 blocked, 0 warned, 0 overridden, 2 audit only; types: All Full Names, Source Code
Detail
{ "domains": [ { "count": 2, "domain": "chat.deepseek.com" } ], "byAction": { "warn": 0, "audit": 2, "block": 0, "unknown": 0, "override": 0 }, "policies": [ { "name": "Endpoint DLP - Source code", "count": 1 }, { "name": "Endpoint DLP - Customer data", "count": 1 } ], "applications": [ { "count": 1, "application": "chrome.exe" }, { "count": 1, "application": "msedge.exe" } ], "sensitiveTypes": [ { "name": "All Full Names", "count": 1, "matches": 30 }, { "name": "Source Code", "count": 1, "matches": 1 } ] } - dlp_audit · Sep 5, 2026TextPastedToBrowser to chat.deepseek.com by [email protected]: Source Code ×1 (audit)
Detail
{ "policies": [ "Endpoint DLP - Source code" ], "recordId": "ual-0103", "application": "chrome.exe" } - dlp_audit · Sep 10, 2026FileUploadedToCloud 'pricing-model.xlsx' to chat.deepseek.com by [email protected]: All Full Names ×30 (audit)
Detail
{ "policies": [ "Endpoint DLP - Customer data" ], "recordId": "ual-0104", "application": "msedge.exe" } - corroborationAlso found by another lane (mdca:40311)
Detail
{ "findingKey": "mdca:40311" } - corroborationAlso found by another lane (mde:deepseek)
Detail
{ "findingKey": "mde:deepseek" }