Hello CheckMates,
We are currently exploring Check Point’s GenAI protection capabilities, especially focused on:
• Harmony Browse Extension
• Harmony DLP Cloud
• Infinity AI Copilot
• The newly open-sourced MCP Server
Our goal is to adopt GenAI tools like ChatGPT, Gemini, Claude, and even internal LLM portals securely — while meeting DLP, compliance, and automation needs.
Below are our key questions and use cases we would appreciate clarification or guidance on:
1. GenAI DLP with Harmony Browse
• GenAI protection is triggered only for whitelisted domains (e.g., chat.openai.com).
• The browser extension captures prompt inputs and file uploads before encryption.
• Harmony DLP Cloud applies AI-powered contextual analysis, beyond just keyword or regex.
Questions:
• Can we also monitor prompts and file uploads on internal AI portals?
• How deep is the contextual detection? Can it understand internal policy documents (e.g., NDA, HR policy)?
• Does the OCR feature also work for images embedded inside PDFs or Word files?
2. File Upload Interception
We understand the extension uses browser-based JavaScript to intercept file uploads before encryption.
Questions:
• Will this work on custom web apps with dynamic UIs (e.g., React)?
• Can we configure the extension to monitor custom form fields?
3. Without Browser Extension
We know that without the Harmony Browse extension, even with SSL inspection on NGFW, GenAI prompt-level visibility is not possible.
Question:
• Are there any other options for AI traffic inspection without an endpoint agent or extension?
4. Infinity AI Copilot Capabilities
We are looking into Copilot’s use for:
• Creating or editing security policies via chat
• Health check queries (CPU, memory, SecureXL)
• Scheduled or API-based automation
Questions:
• Can Copilot make changes directly to policy or objects via natural language?
• Can we integrate Copilot with tools like ServiceNow or use it for daily health reports?
5. MCP Server + LLM Integration
We found that MCP Server is now open source on GitHub. We’re considering using it with GPT, Claude, or local LLMs for:
• Rulebase search (e.g., “Show rules changed last 7 days”)
• Policy simulation (e.g., “What happens if we allow 10.0.0.0/24 outbound?”)
• Compliance mapping (e.g., PCI, SOC2 tags)
Questions:
• Do we need a separate LLM server along with MCP?
• Are there any integration guides, sample scripts, or LLM prompt templates?
• Can MCP support tasks like rule cleanup or optimization suggestions?
Additional Use Cases We’re Exploring:
• Blocking sensitive file uploads to ChatGPT (e.g., scanned payslips, ID cards)
• Detecting PII copy-paste into AI tools
• Using Copilot + MCP for rulebase audits and cleanup
Advance Thank you for your help in making AI usage secure and compliant.
Looking forward to your guidance!
Regards
@Chinmaya_Naik