Overview
DTEX TLS inspection for AI gives security teams direct user, website, network, and file attribution for HTTPS traffic. That includes GenAI prompt usage and HTTP POST upload information, where a lot of DLP questions now start.
Modern browsing is built to resist inspection. Uploads, webmail, file sharing, and AI tools often move through HTTPS/TLS, so traditional network controls can miss tool calls, model responses, and uploaded files.
DTEX works at the system level across HTTPS connections, instead of being tied to one browser or application. Users cannot disable or bypass it. Administrators can exclude specific destinations or processes when they need to.
What You'll Learn
- What DTEX TLS inspection captures from website traffic, including full URL query strings, referrer information, packet sizes, port numbers, IPs, HTTP POST upload information, and GenAI prompt usage.
- How TLS inspection supports prompt-level DLP, shadow AI visibility, and guardrails across AI tools.
- How the DTEX forwarder redirects HTTPS requests, creates domain-specific substitute certificates, then decrypts and re-encrypts traffic within the local client session.
- How DTEX TLS inspection differs from browser extensions and API hooking for HTTPS visibility.
Frequently Asked Questions
What does DTEX TLS inspection capture from HTTPS website traffic?
DTEX TLS inspection captures user, website, network, and file attribution for HTTPS traffic. It can capture full URL query strings, referrer information, packet sizes, port numbers, IPs, HTTP POST upload information, and GenAI prompt usage.
How does DTEX use TLS inspection for AI security?
DTEX uses TLS inspection to give visibility into GenAI prompt usage, model responses, and uploaded files sent over HTTPS/TLS. This supports prompt-level DLP, shadow AI visibility, and guardrails across AI tools.
Why does generative AI change DLP visibility?
Most GenAI tools operate over HTTPS/TLS by default. Tool calls, model responses, and uploaded files can stay hidden from traditional network controls, especially across uploads, webmail, file sharing, and AI tools.
How does DTEX TLS inspection work?
DTEX TLS inspection works at the system level across HTTPS connections. The DTEX forwarder redirects HTTPS requests, creates domain-specific substitute certificates, then decrypts and re-encrypts traffic within the local client session.
Can users disable or bypass DTEX TLS inspection?
No. Users cannot disable or bypass DTEX TLS inspection. Administrators can exclude specific destinations or processes when needed.
How is DTEX TLS inspection different from browser extensions or API hooking?
DTEX TLS inspection works at the system level across HTTPS connections, rather than only specific applications. That gives HTTPS visibility beyond browser extensions or API hooking.
Ready to Learn More?
See how the DTEX Platform helps teams detect and mitigate insider risk. Request a demo.
