Cloudflare Gateway makes blocking a category one click, which is why so many startups believe their AI problem is solved. Their own Gateway logs usually disagree. This guide shows how to make them talk.
Category blocking is real protection against the obvious tools. It is also where the visibility usually stops.
The audit matches raw hostnames against a register updated daily, with 3,900+ tools mapped to the model provider behind them. That is how a "productivity" subdomain gets identified as the AI feature it is.
An 80-person SaaS startup, full Zero Trust rollout, WARP on every laptop, AI category blocked for six months. Sample data; the sequence is the point.
The CTO bet a security engineer lunch that the audit would come back empty. They exported 30 days of Gateway DNS logs, 92,000 lines with user emails, and uploaded them.
17 AI tools, all reached, none in the blocked category at the time of use. Twelve were AI features inside tools the company itself had sanctioned: the design suite, the CRM, two note-taking apps, the video platform.
A meeting-bot transcriber was attending calls on a founder's personal account, categorized as "conferencing", training terms unstated. The blocked category never had a say.
The shape of the finding: blocked consumer chatbot, allowed embedded-AI subdomains. Category policy caught line four and missed the rest.
Gateway writes DNS queries and HTTP requests as separate log streams. Either works; DNS is broader, HTTP is deeper.
Uploads are read once and discarded. Only hostnames, identities and timestamps feed the report; reports live 90 days and are deletable earlier.
The startup's twelve embedded findings were not exotic. They are what every modern SaaS stack now looks like.
Vendors bolt AI onto existing products via ai., copilot. or assistant. hostnames. The parent domain stays "productivity"; the feature's hostname is where the AI lives.
The contract predates the feature. Nobody re-reviewed terms when the AI assistant appeared in the sidebar, and our analysis finds 85.5% of AI tools say nothing about training anyway.
Depth-aware entries mean ai.vendor.com can carry its own verdict while vendor.com stays unflagged. The methodology page shows the walk-up logic.
| Report section | With Gateway DNS or HTTP logs |
|---|---|
| Summary tiles | Full totals across allowed and blocked traffic. |
| Tool table | Every matched tool, including embedded-AI subdomains, with dated training verdicts. |
| Per-user table | User emails from WARP enrollment: the cleanest identity column of any source in this series. |
| Blocked vs allowed | Resolver decisions preserved, so category-block effectiveness is measurable. |
| Sanctioned split | Your approved list vs observed, which is where embedded AI inside sanctioned SaaS becomes visible as its own line. |
| CSV + PDF | Full-report tier, ready for the risk register and the board. |
The sample evidence pack shows exactly how embedded-AI findings render: the tool table, the sanctioned split, the per-user emails. Sample data, no signup.
Block-verdict hostnames from the report CSV become custom Gateway rules. Blocking ai.vendor.com while keeping vendor.com is exactly the granularity category policy lacks.
High attempt counts against blocked chatbots mean staff need a sanctioned one. Enterprise tier, no-training terms, on the approved list before the next run.
Same window monthly. Embedded-AI count and sanctioned share are the two numbers startup boards actually track. Costs live on the pricing page.
Block-first cultures should still read detect before you block: the startup's real exposure was in tools no block rule had ever considered.
DNS for breadth, HTTP for hit fidelity. If unsure, DNS: it covers every enrolled device and app, and the files are smaller.
That is the exact case this guide's scenario covers. Category blocks miss embedded and uncategorized AI; the audit measures what actually got through.
Yes, as the per-user table's identities, in your account only. The uploaded file itself is discarded after the run.
Yes. Any CSV with a header row parses, whatever path it took out of Cloudflare.
They are outside Gateway's view and the audit's frame. Note the enrollment scope in your findings, or audit the office network's DNS separately.
Monthly while headcount and tooling churn. Small teams often fit the free tier's cadence; growing ones graduate to a plan allowance.
Because Gateway exports keep resolver decisions, the audit doubles as a scorecard for the blocking you already do.
Allowed AI tools divided by total AI tools observed. The startup's leak rate was 17 of 18: one blocked chatbot, seventeen allowed somethings. Most teams guess the inverse.
Blocked resolutions per week against AI domains. Rising pressure with no sanctioned alternative predicts workarounds: personal hotspots, home laptops, pasted screenshots.
Matched tools living on subdomains of sanctioned SaaS, as a share of all findings. This is the number that reframes the meeting from "block harder" to "review terms".
Zero Trust deployments concentrate ownership, which makes this the fastest audit loop in the series.
Exports the log slice and later writes the precision rules. In many startups this is one person and one afternoon, end to end.
Reads the tiles and the embedded share, decides which vendors get a terms review. The annotated report tour is the fastest way to prep that read.
Takes the control-verdict list into renewal conversations: enterprise tier, no-training clause, SSO. The audit's dated verdicts are the negotiating leverage.
Total elapsed time for the startup in the scenario: 40 minutes of work, one lunch lost, twelve vendor terms reviews that were overdue anyway.
Export thirty days of Gateway DNS, upload, and see the free totals. If it comes back empty, you earned the bragging rights.
Run the free audit