Detecting input of sensitive data into websites

This page includes the following topics:

About detecting input of sensitive data into websites

You can configure FortiMail Browser Security to detect when an end-user enters sensitive data into a website, and to then warn the end-user about the potential dangers.

  • This functionality is available for domain-based, category-based, and group-based website rules.

  • When a warning is displayed to an end-user about detection of sensitive data, an entry is also added to the Extension Activity log. For details, see Events Page.

  • The warning that is displayed is a warning only - it doesn't prevent the entry of the sensitive data into the website.

Note: Although the functionality described on this page can be used on all types of websites, the functionality was developed primarily for Generative AI websites. Full support for non-Generative AI sites will be added in the future. Until then, some unexpected behavior may occur with non-generative AI sites.

Monitored data types

FortiMail Browser Security detects - and then displays a warning - when the following types of data are entered into a website:

1

Credit card numbers

2

Email addresses

3

US Social Security Numbers

4

Phone numbers

5

IP addresses

6

URLs

7

AWS keys and tokens

8

Keys and tokens

9

Sensitive financial identifiers

Note: In most scenarios, warnings to end-users will be triggered - and then displayed - only if the sensitive text to detect is accompanied by additional "context" text.

Configuring detection of inputting sensitive data into websites

For details on how to configure the detection of entry of sensitive data into websites, see Website Rules.