The threat
Everyone is technical, so everyone pastes.
In a company of thirty there is no approval queue between an idea and a chat window, which is the advantage. It also means the exposure is not concentrated in one department where a policy could catch it.
-
Debugging with production data
The failing record is pasted because the failing record is the bug.
Trips GDPR / CCPA
-
Drafting a customer email or QBR
The account is pasted so the draft is specific rather than generic.
Trips Internal
-
Preparing an investor update
Unreleased figures are pasted to be turned into prose.
Trips Internal
-
Pasting a config or an env file
The fastest way to ask why a service will not start.
Trips Internal
Be careful with the last one. Our built-in key patterns match an AKIA access-key ID and a PEM private-key header, and nothing else — a pasted .env with a production password and a third-party token produces no event today. Secrets you actually hold are a custom pattern rule, not an assumption.
What’s specific here
What a team with no security hire can run.
The constraint that matters at this size is not budget. It is that nobody has a day a week to tune a DLP, so anything requiring one will be switched to log-only and forgotten.
-
01
Start log-only and look at it once
Two to four weeks of log-only on the whole company, then read the report. At thirty people that is a short list, and it tells you which two behaviours are worth a rule.
-
02
Write rules for what you actually hold
A customer-ID format, an internal project codename, a classification header. A pattern rule runs in the agent inside the deadline and can block; a rule described in words runs after the send and reports.
-
03
Code detection is not built, and we say so
There is a
codeDetectionsetting in the product's framework model and no capture path behind it yet. Large pasted code blocks are not flagged as a category today, and a vendor telling you otherwise has not read their own docs. -
04
The boundary protects you too
Findings leave the device; text does not. That means adopting this does not create a new place your customers'' data is stored, which is the question your first enterprise buyer will ask.
What it does here
Someone pastes a production record. Itzal stops it.
Nobody is going to stop using AI tools at a company this size, and a policy that pretends otherwise just moves the usage somewhere you cannot see. Itzal checks the text in the instant before it is sent.
The email is a pattern and the access-key ID is one of the two key formats that are built in. Your team gets a record saying what kind of value it was; the message itself never goes anywhere.
Illustration. The data shown is invented.
Rollout
Two weeks of log-only, then one afternoon of rules.
The constraint at this size is attention, not budget. This rollout is designed to need a total of about a day from one person, spread over six weeks.
-
00
Roll it to everyone, log only
No pilot group. At thirty people the whole company is the pilot, and a subset would just mean the interesting behaviour happened somewhere you were not looking.
-
01
Log-only, the whole company
Nothing is blocked and nobody has to be told to change anything. The output is a short list of what actually leaves, which is the thing worth reading.
-
02
Read it once, write two rules
The report is usually short and specific. A customer-ID format and a project codename cover most of it, and both are pattern rules that can block.
-
03
Warn
Warn rather than block first, even here. The dismissal rate tells you whether the two rules were right before anyone is stopped mid-sentence.
-
04
Block, and leave it
Enforcement on the two or three rules that earned it. The point of this shape is that it does not need revisiting until the company changes.
If every phase runs to its minimum How far it slides if they all run long
Straight answers
We are thirty people. Is this overkill?
The question is usually asked the other way round by the first enterprise customer who sends a security questionnaire. What this gives a small team is an answer to “what stops your engineers pasting our data into ChatGPT” that is a control rather than a policy document.
Will it flag source code?
Not as a category. codeDetection exists in the product''s framework model with no capture path behind it, and it is listed as not built. What does fire on a pasted file is whatever else is in it — an email, a customer ID, an AKIA key — or a custom rule you write.
Do we need someone to run it?
Run log-only for two to four weeks, read the report once, and write rules for the two things it surfaces. The deployment stages and what each is for are set out on the deployment page.