Data Privacy Information Sheet:
Adaptive Email DLP (AEDLP)

The purpose of this page is to provide customers of Core Email Protection API with the information necessary to assess how the product can support and enhance their data privacy strategy.

Adaptive Email DLP (AEDLP) – Product Statement

AEDLP is a cloud-based data loss prevention tool that helps stop accidental data exposure and intentional data theft before it happens. It goes beyond traditional rule-based filters, using behavioral AI to learn your employees' trusted relationships and normal sending patterns, so it can catch misdirected emails, misattached files, and data exfiltration in real time.

Email Data Processed by AEDLP

AEDLP analyzes your organization's historical and real-time email data — entirely within your Proofpoint tenant — to understand how your users normally behave over email, so it can quickly flag anything unusual.

 

Data

Examples

Description

Extracted From

Email Header

 

N/A

The full email header including timestamp, email subject, and information on senders and recipients

Email header

Email Addresses

 

neha.patel@company.com

The full email header including timestamp, email subject, and information on senders and recipients

Email header / Outlook mail item object autocomplete list

Names

Neha Patel

Sender(s) and recipient(s) name

Email header / Outlook mail item object

Opening Salutations & Complimentary Closes

John

The names used within the email body text (if any) to address recipients: e.g., Hi John, please send...

Body text / Attachments

Attachment Information

2014-03-01 Mozambique Slides.ppt

Attachment name, metadata, file hash and content*

Attachments

Project Names and Identifiers

Tornado, [FID.192.7672]

Any project names or identifiers used within the email subject heading, body text, or attachment name (if any) e.g., Project Tornado

Body text / Subject heading / Attachment field / Attachments

Email Recall Indicator

neha.patel@company.com

The full email header including timestamp, email subject, and information on senders and recipients

Email header / Outlook mail item object autocomplete list

Links

www.company.com
<a href="www.malicious.com">www.safe.com</a>

Any links mentioned in the email, including any link attributes

Body text / Attachments

Phrases Indicating Malicious Intent

'Urgently wire transfer', 'change password', 'Microsoft'

Phrases that indicate a potential harmful threat and commonly impersonated brands

Body text / Attachments

Attachment indicator

...please find attached the tenancy agreement for 123 Fake St...

Keywords indicating that one or more files have been attached

Body text

Common file extensions

...Please find attached invoice.pdf ... I've sent over the prospectus as a zip file, there should be a pdf explaining...

Any file extension mentioned in the email

Body text

Phrases indicating the contents of attached files

...here is a draft of the presentation for the board, as well as our quarterly earnings report...

Phrases that indicate a potential harmful threat and commonly impersonated brands, or phrases that are commonly used in attacks.

Body text

Attachment recall indicator

...apologies, it looks like I sent the wrong file earlier...

Phrases suggesting files have been wrongly attached to a previous message in the thread

Body text

Aggregate data

Urgency score, spelling score, punctuation score, number of paragraphs, language of email, % likelihood that an image is impersonating a brand logo, topic classification, size of images

Proofpoint's machine learning models will scan emails and score/classify various criteria that are good indicators of an email attack. Only aggregate scores/classifications will be persisted, no additional sensitive data (other than that stated above) will be saved.

Body / Attachments / Images in email hosted on the internet

Any data defined by the customer as part of an Architect policy

Regular expression matches in email body or attachments, attachment metadata, etc.

Proofpoint custom policies will extract any data points from emails or attachments that have been defined as part of the condition set within an Architect policy.

Email header / Body text / Subject heading / Attachment field / Attachments

Data

Email Header

 

Examples

N/A

Description

The full email header including timestamp, email subject, and information on senders and recipients

Extracted From

Email header

Data

Email Addresses

 

Examples

neha.patel@company.com

Description

The full email header including timestamp, email subject, and information on senders and recipients

Extracted From

Email header / Outlook mail item object autocomplete list

Data

Names

Examples

Neha Patel

Description

Sender(s) and recipient(s) name

Extracted From

Email header / Outlook mail item object

Data

Opening Salutations & Complimentary Closes

Examples

John

Description

The names used within the email body text (if any) to address recipients: e.g., Hi John, please send...

Extracted From

Body text / Attachments

Data

Attachment Information

Examples

2014-03-01 Mozambique Slides.ppt

Description

Attachment name, metadata, file hash and content*

Extracted From

Attachments

Data

Project Names and Identifiers

Examples

Tornado, [FID.192.7672]

Description

Any project names or identifiers used within the email subject heading, body text, or attachment name (if any) e.g., Project Tornado

Extracted From

Body text / Subject heading / Attachment field / Attachments

Data

Email Recall Indicator

Examples

neha.patel@company.com

Description

The full email header including timestamp, email subject, and information on senders and recipients

Extracted From

Email header / Outlook mail item object autocomplete list

Data

Links

Examples

www.company.com
<a href="www.malicious.com">www.safe.com</a>

Description

Any links mentioned in the email, including any link attributes

Extracted From

Body text / Attachments

Data

Phrases Indicating Malicious Intent

Examples

'Urgently wire transfer', 'change password', 'Microsoft'

Description

Phrases that indicate a potential harmful threat and commonly impersonated brands

Extracted From

Body text / Attachments

Data

Attachment indicator

Examples

...please find attached the tenancy agreement for 123 Fake St...

Description

Keywords indicating that one or more files have been attached

Extracted From

Body text

Data

Common file extensions

Examples

...Please find attached invoice.pdf ... I've sent over the prospectus as a zip file, there should be a pdf explaining...

Description

Any file extension mentioned in the email

Extracted From

Body text

Data

Phrases indicating the contents of attached files

Examples

...here is a draft of the presentation for the board, as well as our quarterly earnings report...

Description

Phrases that indicate a potential harmful threat and commonly impersonated brands, or phrases that are commonly used in attacks.

Extracted From

Body text

Data

Attachment recall indicator

Examples

...apologies, it looks like I sent the wrong file earlier...

Description

Phrases suggesting files have been wrongly attached to a previous message in the thread

Extracted From

Body text

Data

Aggregate data

Examples

Urgency score, spelling score, punctuation score, number of paragraphs, language of email, % likelihood that an image is impersonating a brand logo, topic classification, size of images

Description

Proofpoint's machine learning models will scan emails and score/classify various criteria that are good indicators of an email attack. Only aggregate scores/classifications will be persisted, no additional sensitive data (other than that stated above) will be saved.

Extracted From

Body / Attachments / Images in email hosted on the internet

Data

Any data defined by the customer as part of an Architect policy

Examples

Regular expression matches in email body or attachments, attachment metadata, etc.

Description

Proofpoint custom policies will extract any data points from emails or attachments that have been defined as part of the condition set within an Architect policy.

Extracted From

Email header / Body text / Subject heading / Attachment field / Attachments

*Attachment content is analyzed only within your tenant and is never stored or shared outside your tenant.

AEDLP Data Processing Locations

Proofpoint assigns your tenant to a regional data center based on your organization's location or to the data center you chose to utilize. All AEDLP data processing happens there and remains in that location. For example, data in an EU-based tenant is processed in the EU for AEDLP.

How Proofpoint Retains Records

To protect organizations from email threats, Proofpoint analyzes the data collected through AEDLP and applies the results to its scanning and filtering process. All data collected is retained in an aggregated form until securely deleted.

Proofpoint’s Use of Subprocessors

Proofpoint utilizes subprocessors to provide its services. A comprehensive list of the subprocessors may be found on the Trust site.

Security

Proofpoint maintains a documented information security program that is aligned with the requirements of NIST 800-53 and ISO 27001. Security controls include:

Data in transit is protected using HTTPS/TLS, and data at rest is encrypted using AES 256. Access control mechanisms restrict physical and logical access to the facilities and infrastructure hosting the service. Proofpoint has policies and procedures for identifying and remediating vulnerabilities and runs a distributed security monitoring infrastructure with a 24/7 network operations center that responds to security alerts. The information security program undergoes an annual SOC 2 Type II audit covering the Availability, Confidentiality, and Security trust principles.

Data collected through AEDLP's product functionality is retained in aggregated form, encrypted at rest, until securely deleted. Processing and filtering results are only accessible to the customer's authorized personnel.

© 2026 Proofpoint. All rights reserved. The content on this site is intended for informational purposes only.
Last updated July 24, 2026.

Proofpoint Trust

Proofpoint helps companies protect their people from the ever-evolving threats in the digital ecosystem.