Skip to main content

Frequently Asked Questions (FAQ)

FAQ covering intercept, sensitive data detection, deployment, policy, compliance (GDPR/HIPAA/PCI), SOC2, retention, DLP, GovCloud/FedRAMP.

GenAI service intercept

Which public GenAI services support prompt intercept?

F5 Workforce AI Security provides sensitive data detection on the most commonly used public GenAI services. To identify which services support prompt intercept, navigate to Public Services in the GOVERN section of the Admin UI. Services that display PROMPT INTERCEPT support can be fully monitored and governed with sensitive data controls. The Public Service Catalog is continuously updated as new services are discovered and evaluated for intercept capabilities.

How does sensitive data detection work?

Workforce AI Security uses two complementary mechanisms to detect sensitive data in prompts and responses. Content Controls inspect requests for risky patterns including harmful content, prompt injection, high-risk heuristics, code, and confidential data. PII Detection focuses specifically on personally identifiable information entities such as phone numbers, credit card numbers, email addresses, Social Security numbers, person names, and others. Organizations can filter PII entities by compliance category including GDPR, CCPA/CPRA, PCI/DSS, HIPAA, GLBA, and FERPA. Detection supports multiple actions including Monitor, Warn, Tag, Mask, Delete, Synthesize, and Block, allowing organizations to balance security requirements with user productivity.

How long is conversation data stored?

Workforce AI Security stores conversation data encrypted internally in a database with configurable retention periods. By default, data retention is set to indefinite, but organizations can adjust retention periods to align with their data governance policies. Organizations can also export this data to external telemetry destinations for independent management. Once exported to external destinations, the organization is responsible for securing and managing the data lifecycle. Workforce AI Security cannot delete information from customer-managed external destinations.

Where can log data be exported?

Workforce AI Security supports exporting telemetry data to multiple destination types including AWS S3 buckets, Splunk HEC indexes, and generic HTTPS endpoints. Organizations can configure telemetry destinations to export User Events and Audit Events automatically. Exported data is delivered in NDJSON format with gzip compression, organized by UTC timestamps for easy integration with SIEM and log management tools. The platform uploads new telemetry files every 15 minutes, providing near-real-time visibility into GenAI usage and policy enforcement across the organization.

Does Workforce AI Security act as a proxy for public services?

Yes, Workforce AI Security acts as a proxy for public GenAI services to intercept and govern requests before they reach external providers. This proxy architecture enables prompt inspection, sensitive data detection, content controls, and audit logging.

Is Workforce AI Security dependent on external DLP platforms?

No. Workforce AI Security performs all sensitive data detection and remediation natively within the platform. The system does not require or depend on external data leak protection platforms to identify and handle sensitive information in GenAI interactions. This integrated approach ensures consistent policy enforcement and reduces the complexity of managing multiple security tools.

What is the difference between prompt intercept and access control?

Workforce AI Security provides two levels of governance for public GenAI services. Services with PROMPT INTERCEPT support allow Workforce AI Security to inspect, log, and modify user prompts and AI responses. This enables sensitive data detection, content controls, and policy enforcement before requests reach the external service. Services with ACCESS CONTROL support can only be allowed or blocked based on policy. Workforce AI Security cannot record, evaluate, or prevent sensitive data from being transmitted to these sites. Organizations should remind users that ACCESS CONTROL sites do not provide the same level of data protection as PROMPT INTERCEPT sites.

Deployment and configuration

How long does it take to deploy Workforce AI Security?

With the proper technical resources on a call, Workforce AI Security can be deployed in less than an hour. The deployment process integrates with existing security infrastructure through SASE vendor-specific forward proxy chaining, proxy PAC distribution, or other network integration methods. Organizations can begin with monitoring-only configurations to understand GenAI usage patterns before progressively setting up stronger controls and policies.

How long does it take to add new services to the public service catalog?

Workforce AI Security can typically add new public GenAI services to the catalog in less than a day when requested. Organizations should submit the URL of the new service to Workforce AI Security for evaluation and inclusion. New services are initially added with ACCESS CONTROL support, with PROMPT INTERCEPT capabilities evaluated and added based on technical feasibility and customer demand.

How often is the public GenAI service list updated?

Workforce AI Security continuously updates the Public Service Catalog as new GenAI services are discovered or brought to the team's attention. Updates can occur at any time as the GenAI landscape evolves. Organizations using network redirection tools should plan to update their configurations periodically. This should happen no more than once per week, unless a specific service requires immediate governance. The Admin UI always reflects the current catalog, and admins can enable or disable services as they become available.

Can we redirect users from one public AI site to another?

Yes. Workforce AI Security provides the capability to redirect users from public GenAI sites to alternative destinations. Organizations can redirect users to a URL of their choice, including another public GenAI service. This feature is particularly useful for organizations that have purchased enterprise AI licenses. These organizations often want to steer users toward approved, contracted services instead of allowing access to unmanaged public tools.

Policy and governance

What HIPAA identifiers can be detected?

Workforce AI Security can detect multiple HIPAA-tagged PII entities. These include phone numbers, email addresses, Social Security numbers, passport numbers, driver's license numbers, medical license numbers, and other identifiers relevant to HIPAA compliance. Admins can filter PII entities by compliance category in the Admin UI to view and enable the specific HIPAA-related entities appropriate for their use case. Each entity can be individually enabled or disabled. A global action then applies to all enabled entities, including Monitor, Warn, Tag, Mask, Delete, Synthesize, or Block.

Can we add custom sensitive data types?

Custom sensitive data types are not currently supported. In the future, Workforce AI Security will add the capability for organizations to define and add their own fields to the existing PII Detection list. Organizations needing custom detection patterns should contact Workforce AI Security to discuss their specific requirements and timeline for this capability.

Can we control which LLM version users select on public GenAI tools?

No. Workforce AI Security does not currently have the capability to control which specific LLM version or model variant users select when interacting with public GenAI services. Organizations can control access to entire services through the Public Service Catalog. Granular model version control within those services is not supported at this time. The Claude Code Model Router is one exception. It lets admins map and redirect Claude Code's model requests to a specific private model family. That control is scoped to the Claude Code coding agent, not to public web GenAI tools.

Compliance and security

Does Workforce AI Security train on or store customer data?

Workforce AI Security does not train on customer data or retain information for training purposes. The platform stores user activity logs and conversation data to enable retrieval, auditing, and analytics for customers, with retention periods organizations can configure (see "How long is conversation data stored?" above).

What compliance frameworks are supported?

Workforce AI Security helps organizations meet obligations under multiple compliance frameworks. It does this by limiting personal and confidential data sent to external AI services and producing auditable records of usage. The platform provides relevant support for GDPR and CCPA/CPRA privacy regulations, plus HIPAA healthcare data protection. It also supports PCI DSS payment card security, GLBA financial services privacy, and FERPA education records protection. PII Detection entities are tagged with compliance category indicators to help organizations identify and enable detection for entities relevant to their regulatory requirements. The platform also supports organizational programs aligned with ISO 27001, NIST 800-53/171, DORA, and AI Act readiness.

What is Workforce AI Security's security certification status?

Workforce AI Security is SOC2 Type 1 certified, and SOC2 Type 2 certification is currently underway. These certifications reflect the platform's security controls for availability, confidentiality, and processing integrity. Organizations evaluating Workforce AI Security can request current certification documentation and audit reports through their account team.

Does Workforce AI Security support GovCloud or FedRAMP deployments?

Workforce AI Security does not currently support GovCloud or FedRAMP deployments. However, if customers require these specialized deployment environments, Workforce AI Security will work with them to set up the necessary compliance and infrastructure requirements to support their needs.

Access and features

Do all customers have access to all features?

Yes. Workforce AI Security operates with a single tier of service. All customers have access to the complete set of features and functionality offered by the platform. There are no feature restrictions or tiered licensing models. This includes public service governance, private model access, sensitive data detection, policy management, telemetry export, and all integration options.

Did this answer your question?