DLP Inspection Where Your Agents Run: Extending Symantec DLP to Tetrate Agent Router

Broadcom and Tetrate are bringing enterprise DLP inline at Agent Router—same policies, same console, new channel

  • Symantec DLP and Tetrate Agent Router are teaming up to inspect agentic AI traffic that bypasses traditional email, web, and endpoint controls.
  • Existing DLP policies, detection mechanisms, and incident response workflows extend directly to AI channels without needing a separate management console.
  • Centralized router inspection covers four key transaction points, requiring zero SDKs or code changes to individual agents.
  • Local detection capabilities run alongside the Agent Router data plane to ensure raw prompts, model responses, and tool payloads remain entirely inside the enterprise's trust boundary.

Agentic AI has opened a data channel that existing data loss prevention (DLP) controls were never built to see. An agent pulls records over a tool call, hands them to a model as context, acts on what the model returns, and passes the result on to other tools—service-to-service, at machine speed, in API payloads that look like any other JSON. None of it passes through an inbox, a browser, or an endpoint, so the email, web, and endpoint DLP already in place never sees it. And none of it is an attack. No prompt injection, no jailbreak, no compromised credential—just agents doing the job they were given, with regulated data in hand. That is what makes agentic data loss different from every channel a DLP program already covers.

Consider a customer-operations agent handling a billing dispute. It pulls a customer record over a tool call—name, card on file, twelve months of history. It sends that context to an LLM to reason about a fair remedy. The model replies with a refund recommendation and a drafted apology email that quotes the customer's card number back, because the card number was in the context it was given. The agent then passes that draft to a third-party email tool. Four places where regulated data could leave the enterprise, in a few seconds, with no human review.

That is the channel Broadcom and Tetrate are working to close. Together they are bringing Symantec Data Loss Prevention to Tetrate Agent Router: Agent traffic crossing the router—prompts on their way to a model, model responses coming back, tool-call arguments, and tool results—is inspected inline against the DLP policies an enterprise already runs, with detection inside the customer's own boundary. The integration is available in preview.

What Symantec DLP inspects: The four interception points

With Symantec DLP inline at Tetrate Agent Router, agent traffic is inspected at four interception points. Here’s the order the transaction crosses them:

DLP Inspection Where Your Agents Run: Extending Symantec DLP to Tetrate Agent Router

The agent's final step (the outbound email-tool call carrying that draft) crosses the first checkpoint again. An agent may loop between the LLM and its tools many times in one interaction; every iteration crosses the same interception points. DLP inspects the data boundary, not the human.

The inspection leverages the same detection mechanisms the DLP program already trusts. Exact Data Matching means the card number in that drafted email is matched against actual customer data fingerprints. Indexed Document Matching recognizes an enterprise's own documents when fragments come back inside a tool result. More than 300 content identifiers cover the regulated data types already policed on email and endpoints. The policies are the ones already written, tuned, and defended in audit.

In the scenario above, the card number is matched when the model's response is inspected, and the incident is raised there. In prevent mode the violating exchange is blocked inline with a clear policy message—and because tool-call arguments are inspected too, the agent's attempt to hand that draft to the email tool is stopped at the same boundary. The incident lands in the DLP incident queue the response team already works with, with the match evidence responders already know how to read, and reaches the SIEM through the same export path as email, web, and endpoint incidents. The customer still gets their refund. The card number stays home.

Two layers, two jobs

The integration works because each side does the job it is built for.

Tetrate Agent Router is the enforcement point, the router in the path of AI, LLM, and MCP traffic. Joint customers already run it for reasons that have nothing to do with DLP: unified access to models across providers, intelligent routing with automatic failover when a provider degrades, token-level cost visibility and controls, MCP tool connectivity, and transaction-level observability of what agents are actually doing. It is built on Envoy AI Gateway, which Tetrate co-created and maintains. Agent Router Service is the fast path for evaluation and development; Agent Router Enterprise adds a customer-controlled data plane and is the recommended production shape.

Symantec DLP is the detection and decision engine where classification, policy authoring, incident management, and response workflow are managed from Enforce on-premises or the DLP Cloud Console, whichever the program runs today.

The division is deliberate. Agent Router does not replace enterprise DLP: Symantec DLP remains the classification, detection, policy, incident, and decision system, and Agent Router is the AI/MCP enforcement point. For security teams the operating model reduces to a sentence—same policies, same console, new channel. AI becomes another channel in the DLP program already running, not a parallel program with its own console and its own gaps.

Agent Router Enterprise also ships native AI Guardrails—runtime policy enforcement at the gateway. The two layers are complementary rather than competing: gateway-native guardrails handle fast, local controls, while Symantec DLP brings the enterprise detection depth, unified policy management, and incident workflow that a regulated DLP program requires behind them. Most regulated environments will want both.

Mechanically, the two connect over Envoy's standard external processing (ext_proc) interface. Agent Router calls the DLP Traffic Extension, which submits content for detection and returns an allow or block decision, no modifications to the router core. MCP payloads are scanned today as request and response content.

Why the router is the right checkpoint

Most joint customers did not adopt Agent Router for security; platform engineering adopted it for routing, failover, cost attribution, and observability. That decision quietly created something security teams have been missing: a single point where all agent traffic already converges.

The alternative is instrumenting agents one at a time—an SDK in every framework, a library upgrade for every team building agents, a review for every new tool server. That cannot keep pace with how fast agents are being built. Enforcement at the router requires nothing from those teams: no code changes, no SDK, no per-agent rollout. The DLP Traffic Extension doing the work is not new: it is already deployed in production against Envoy-based gateways.

If your agents route through Agent Router, they are in scope. That is the entire onboarding story.

Your data plane, your boundary

For production, the recommended shape is Tetrate Agent Router Enterprise with a customer-controlled data plane (on-premises or distributed across your environments) with Symantec's Distributed Detection Service (DDS) running alongside it in your infrastructure.

That architecture has one property that matters more than any feature: Raw prompts, model responses, and tool payloads never leave your trust boundary. 

  • Content is scanned in your environment, no cloud round-trip needed. 

  • The Agent Router management plane receives only configuration, health, and approved metadata, never raw payloads. 

  • Data sovereignty is an architecture, not a configuration option.

Figure 1: All agent traffic converges at Tetrate Agent Router inside the customer boundary, where the router calls the DLP Traffic Extension over ext_proc and the extension enforces via DLP REST APIs against DDS.
Figure 1: All agent traffic converges at Tetrate Agent Router inside the customer boundary, where the router calls the DLP Traffic Extension over ext_proc and the extension enforces via DLP REST APIs against DDS.

For teams that want a managed detection backend, the Cloud Detection Service (CDS) offers a Broadcom-hosted alternative suited to remote and lower-volume scanning, subject to limits on data scanning volume. Both backends expose the same DLP REST APIs and the same detection capabilities. Switching is a configuration change (not a code change), and either console governs both.

Day 1: Monitor. Day 2: Prevent.

The rollout arc is deliberately unexciting.

Day 1 is monitor mode. The recommended starting point. Every prompt, response, tool call, and tool result crossing Agent Router is inspected against policy and incidents are generated; nothing is blocked and no agent behavior changes. Most teams discover surprises in the first week: an agent quoting sensitive data back in responses, a tool server returning far more than the agent asked for, regulated data nobody expected inside a tool result. That visibility is the point.

Day 2 is prevent mode. Once policies are tuned against observed traffic, violating requests and responses are blocked inline with a clear policy message, and the incident record shows exactly what was stopped and why.

In-line redaction of AI traffic at the gateway is planned as a future enhancement; today the enforcement decision at the router is allow or block, with full incident capture either way.

Getting started

The Symantec DLP integration with Tetrate Agent Router is available in preview, and the joint work is continuing—deeper MCP awareness and expanded provider coverage are on the roadmap.

If your organization is adopting agentic AI on Tetrate Agent Router, or evaluating how your DLP program extends to agent traffic, contact your Broadcom or Tetrate account team to discuss early access.

Your agents are already making thousands of calls on your behalf. The question is whether anyone is checking what crosses the wire. Now, at the router they already pass through, with the DLP program you already own, someone is.

You might also enjoy

Upcoming Events

See what's next

Threat Updates

Get the latest