workforce ai security privacy datasheet.pdf
Workforce AI Security Privacy Data Sheet
This Privacy Data Sheet explains how Check Point Workforce AI Security processes personal data.
About Check Point Workforce AI Security
Check Point Workforce AI Security provides an enterprise GenAI security solution that empowers organizations to adopt GenAI tools safely and responsibly. It combines advanced data loss protection (DLP) and in-depth visibility into GenAI usage.
Key Capabilities include:
- GenAI Discovery & Risk Assessment – Provides comprehensive visibility into AI tools, agents, and AI-related activities across supported web and desktop applications, SaaS integrations, browser extensions, code assistants, AI agents, and Model Context Protocol (MCP) integrations, including shadow AI usage. Delivers insights into AI usage patterns, workflow context, data flows, and agentic behaviors, and automatically categorizes AI-related activities by use case (e.g., documentation, code generation, debugging, data analysis) to help security teams assess organizational risk and enforce acceptable use policies.
- Governance & Access Controls – Enables granular access and security policies for enterprise-managed and shadow AI applications. Governs SaaS integrations, agent actions, data types, and AI-related activities to help organizations manage AI usage in alignment with internal security and compliance policies.
- Inline Prompt & Data Protection – Helps prevent users from submitting prompts, pasting text, or sharing files and images containing customer-defined sensitive data with GenAI tools such as ChatGPT, Copilot, Gemini, and Claude. AI-powered contextual analysis helps identify sensitive content across predefined and custom data categories tailored to organizational requirements.
- GenAI-Aware DLP – Helps prevent sensitive data exposure through contextual DLP, file and image redaction, OCR, and runtime designed to enforce customer-defined policies before restricted agentic actions are executed.
How Does Check Point Comply with Applicable Data Protection Regulations?
At Check Point, ensuring customer privacy and security remains our foremost concern, with the trust our customers place in our services being one of our most valued assets.
- Security. As a leading AI-powered, cloud-delivered cyber security platform provider over the past decades, we acknowledge the significance of implementing rigorous security measures to safeguard our customers’ information.
- Privacy by Design. We operate under the principle of privacy by design. This means that we prioritize the protection of personal data and privacy throughout the entire lifecycle of our products and services. We treat personal data with the utmost care.
- Disaster Recovery. We maintain comprehensive plans and procedures for disaster recovery and business continuity.
- Transfers. To regulate the transfer of personal data between Check Point entities, Check Point has adopted an intercompany agreement for transfers of data, including the EU Standard Contractual Clauses and UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
What Types of Personal Data does Check Point Workforce AI Security Process?
- Information provided by the user, including prompts, copied text, file uploads, images, and related interactions with AI tools.
- Website classification data: Website URLs processed to determine whether a website constitutes an AI service, in accordance with customer security policies.
Why Does Check Point Workforce AI Security Process Personal Data?
Check Point Workforce AI Security processes personal data to enforce customer-defined data loss prevention (DLP) policies and provide visibility into GenAI tool usage. Prompts are scanned for sensitive content in accordance with customer-defined policies. By default, prompt content is not visible to the organization.
What is the Frequency and Duration of Processing?
Personal data may be processed by Check Point Workforce AI Security throughout the subscription term. Personal data is stored in Check Point cloud hosting environments, including infrastructure provided by third-party cloud service providers.
What are the Retention Periods?
| Data Type | Retention Period |
|---|---|
| Device Information | 90 days |
| Information provided by the user | 90 days |
Privacy Options
We provide the following configurations, empowering our customers to select their data and privacy preferences:
- The system honors user-level authorizations based on role-based access control (RBAC) settings.
- Customer administrators can configure which authorized personnel may review prompts flagged as high-risk, critical-risk, or otherwise matching customer-defined risk policies.
- Administrative actions and configuration changes relating to prompt visibility settings are logged and auditable.
Authorized Access to Personal Data
- Customer Access: Access to data is controlled by the Customer’s system administrator and is managed by the customer.
- Check Point Access: Access to any data is restricted to authorized representatives for necessary functions. This Privacy Data Sheet is a supplement to Check Point’s Privacy Policy.