The purpose of this page is to provide customers of Core Email Protection API with the information necessary to assess how the product can support and enhance their data privacy strategy.
Adaptive Email DLP (AEDLP) – Product Statement
AEDLP is a cloud-based data loss prevention tool that helps stop accidental data exposure and intentional data theft before it happens. It goes beyond traditional rule-based filters, using behavioral AI to learn your employees' trusted relationships and normal sending patterns, so it can catch misdirected emails, misattached files, and data exfiltration in real time.
Email Data Processed by AEDLP
AEDLP analyzes your organization's historical and real-time email data — entirely within your Proofpoint tenant — to understand how your users normally behave over email, so it can quickly flag anything unusual.
Data
Examples
Description
Extracted From
Email Header
N/A
The full email header including timestamp, email subject, and information on senders and recipients
Email header
Email Addresses
neha.patel@company.com
The full email header including timestamp, email subject, and information on senders and recipients
Email header / Outlook mail item object autocomplete list
Names
Neha Patel
Sender(s) and recipient(s) name
Email header / Outlook mail item object
Opening Salutations & Complimentary Closes
John
The names used within the email body text (if any) to address recipients: e.g., Hi John, please send...
Body text / Attachments
Attachment Information
2014-03-01 Mozambique Slides.ppt
Attachment name, metadata, file hash and content*
Attachments
Project Names and Identifiers
Tornado, [FID.192.7672]
Any project names or identifiers used within the email subject heading, body text, or attachment name (if any) e.g., Project Tornado
Body text / Subject heading / Attachment field / Attachments
Email Recall Indicator
neha.patel@company.com
The full email header including timestamp, email subject, and information on senders and recipients
Email header / Outlook mail item object autocomplete list
Links
www.company.com
<a href="www.malicious.com">www.safe.com</a>
Any links mentioned in the email, including any link attributes
Body text / Attachments
Phrases Indicating Malicious Intent
'Urgently wire transfer', 'change password', 'Microsoft'
Phrases that indicate a potential harmful threat and commonly impersonated brands
Body text / Attachments
Attachment indicator
...please find attached the tenancy agreement for 123 Fake St...
Keywords indicating that one or more files have been attached
Body text
Common file extensions
...Please find attached invoice.pdf ... I've sent over the prospectus as a zip file, there should be a pdf explaining...
Any file extension mentioned in the email
Body text
Phrases indicating the contents of attached files
...here is a draft of the presentation for the board, as well as our quarterly earnings report...
Phrases that indicate a potential harmful threat and commonly impersonated brands, or phrases that are commonly used in attacks.
Body text
Attachment recall indicator
...apologies, it looks like I sent the wrong file earlier...
Phrases suggesting files have been wrongly attached to a previous message in the thread
Body text
Aggregate data
Urgency score, spelling score, punctuation score, number of paragraphs, language of email, % likelihood that an image is impersonating a brand logo, topic classification, size of images
Proofpoint's machine learning models will scan emails and score/classify various criteria that are good indicators of an email attack. Only aggregate scores/classifications will be persisted, no additional sensitive data (other than that stated above) will be saved.
Body / Attachments / Images in email hosted on the internet
Any data defined by the customer as part of an Architect policy
Regular expression matches in email body or attachments, attachment metadata, etc.
Proofpoint custom policies will extract any data points from emails or attachments that have been defined as part of the condition set within an Architect policy.
Email header / Body text / Subject heading / Attachment field / Attachments
Data
Email Header
Examples
N/A
Description
The full email header including timestamp, email subject, and information on senders and recipients
Extracted From
Email header
Data
Email Addresses
Examples
neha.patel@company.com
Description
The full email header including timestamp, email subject, and information on senders and recipients
Extracted From
Email header / Outlook mail item object autocomplete list
Data
Names
Examples
Neha Patel
Description
Sender(s) and recipient(s) name
Extracted From
Email header / Outlook mail item object
Data
Opening Salutations & Complimentary Closes
Examples
John
Description
The names used within the email body text (if any) to address recipients: e.g., Hi John, please send...
Extracted From
Body text / Attachments
Data
Attachment Information
Examples
2014-03-01 Mozambique Slides.ppt
Description
Attachment name, metadata, file hash and content*
Extracted From
Attachments
Data
Project Names and Identifiers
Examples
Tornado, [FID.192.7672]
Description
Any project names or identifiers used within the email subject heading, body text, or attachment name (if any) e.g., Project Tornado
Extracted From
Body text / Subject heading / Attachment field / Attachments
Data
Email Recall Indicator
Examples
neha.patel@company.com
Description
The full email header including timestamp, email subject, and information on senders and recipients
Extracted From
Email header / Outlook mail item object autocomplete list
Data
Links
Examples
www.company.com
<a href="www.malicious.com">www.safe.com</a>
Description
Any links mentioned in the email, including any link attributes
Extracted From
Body text / Attachments
Data
Phrases Indicating Malicious Intent
Examples
'Urgently wire transfer', 'change password', 'Microsoft'
Description
Phrases that indicate a potential harmful threat and commonly impersonated brands
Extracted From
Body text / Attachments
Data
Attachment indicator
Examples
...please find attached the tenancy agreement for 123 Fake St...
Description
Keywords indicating that one or more files have been attached
Extracted From
Body text
Data
Common file extensions
Examples
...Please find attached invoice.pdf ... I've sent over the prospectus as a zip file, there should be a pdf explaining...
Description
Any file extension mentioned in the email
Extracted From
Body text
Data
Phrases indicating the contents of attached files
Examples
...here is a draft of the presentation for the board, as well as our quarterly earnings report...
Description
Phrases that indicate a potential harmful threat and commonly impersonated brands, or phrases that are commonly used in attacks.
Extracted From
Body text
Data
Attachment recall indicator
Examples
...apologies, it looks like I sent the wrong file earlier...
Description
Phrases suggesting files have been wrongly attached to a previous message in the thread
Extracted From
Body text
Data
Aggregate data
Examples
Urgency score, spelling score, punctuation score, number of paragraphs, language of email, % likelihood that an image is impersonating a brand logo, topic classification, size of images
Description
Proofpoint's machine learning models will scan emails and score/classify various criteria that are good indicators of an email attack. Only aggregate scores/classifications will be persisted, no additional sensitive data (other than that stated above) will be saved.
Extracted From
Body / Attachments / Images in email hosted on the internet
Data
Any data defined by the customer as part of an Architect policy
Examples
Regular expression matches in email body or attachments, attachment metadata, etc.
Description
Proofpoint custom policies will extract any data points from emails or attachments that have been defined as part of the condition set within an Architect policy.
Extracted From
Email header / Body text / Subject heading / Attachment field / Attachments
*Attachment content is analyzed only within your tenant and is never stored or shared outside your tenant.
AEDLP Data Processing Locations
Proofpoint assigns your tenant to a regional data center based on your organization's location or to the data center you chose to utilize. All AEDLP data processing happens there and remains in that location. For example, data in an EU-based tenant is processed in the EU for AEDLP.
How Proofpoint Retains Records
To protect organizations from email threats, Proofpoint analyzes the data collected through AEDLP and applies the results to its scanning and filtering process. All data collected is retained in an aggregated form until securely deleted.
Proofpoint’s Use of Subprocessors
Proofpoint utilizes subprocessors to provide its services. A comprehensive list of the subprocessors may be found on the Trust site.
Security
Proofpoint maintains a documented information security program that is aligned with the requirements of NIST 800-53 and ISO 27001. Security controls include:
Data in transit is protected using HTTPS/TLS, and data at rest is encrypted using AES 256. Access control mechanisms restrict physical and logical access to the facilities and infrastructure hosting the service. Proofpoint has policies and procedures for identifying and remediating vulnerabilities and runs a distributed security monitoring infrastructure with a 24/7 network operations center that responds to security alerts. The information security program undergoes an annual SOC 2 Type II audit covering the Availability, Confidentiality, and Security trust principles.
Data collected through AEDLP's product functionality is retained in aggregated form, encrypted at rest, until securely deleted. Processing and filtering results are only accessible to the customer's authorized personnel.
© 2026 Proofpoint. All rights reserved. The content on this site is intended for informational purposes only.
Last updated July 24, 2026.
Proofpoint Trust
Proofpoint helps companies protect their people from the ever-evolving threats in the digital ecosystem.