DLP Test Samples
Download full dataset 2.1 MB

About DLP Samples

DLP Samples is a free, de-identified dataset for measuring the precision and recall of data loss prevention (DLP) tools. It contains 177 positive samples, which your DLP should detect, and 122 negative samples, which resemble sensitive data but should not be flagged.

What's inside

CategoryPositiveNegative
PII · North America1512
PII · LATAM1913
PII · Europe1513
PII · APAC5652
PCI & Banking135
API Keys & Secrets412
Passwords31
PHI64
Crypto Keys31
Global IDs70
Prompt injection109
ID images40
Confidential documents160
Personal documents60

Samples place sensitive entities in the context where they really appear (support tickets, source code, spreadsheets, screenshots, ID photos and business documents), so results reflect real-world detection rather than isolated patterns.

Measuring precision and recall

  1. Send every sample through the channel you want to test, such as a GenAI prompt, an AI agent workflow, a SaaS upload, email or an endpoint copy.
  2. Record which samples your DLP alerted on.
  3. Recall = positive samples detected ÷ all positive samples.
  4. Precision = correct alerts ÷ all alerts. Every alert on a negative sample lowers precision.

License and safety

The dataset is published under CC BY 4.0. All data is synthetic or fully de-identified and corresponds to no real person or account. Credentials in the samples are included only to test detection; do not attempt to use them.

Sponsorship

DLP Samples is sponsored by Nightfall AI. Sponsored content is labelled on the page.

Frequently asked questions

Is this real sensitive data?

No. Every sample is synthetic or fully de-identified test data, and corresponds to no real person or account. Identifier values in the global pack are widely published test values with valid check digits.

What is a negative sample?

A negative sample looks like sensitive data but is not, for example a transaction ID shaped like a credit card number that fails Luhn validation, or a config value shaped like an API key. A precise DLP tool should not flag it. Negative samples measure false positives, which is how you judge the noise in your DLP.

How do I measure DLP precision and recall with these samples?

Run every positive and negative sample through the channel you are testing and record whether your DLP alerted. Recall is detected positives divided by all positives. Precision is correct alerts divided by all alerts, including alerts on negative samples.

Which channels can I test?

Any channel your DLP covers: pasting into GenAI apps and AI agent prompts, uploads to SaaS apps and cloud drives, email attachments, browser uploads, clipboard and removable media on endpoints.

Can I use the samples commercially?

Yes. The dataset is published under CC BY 4.0. Use, share and adapt it, including commercially, with attribution to DLP Samples.

Are the API keys and passwords usable?

They are included only to test detection. Do not attempt to use any credential found in the samples.

Last updated 2026-09-28.