Siberson
Partnership Contact Request a Demo
Resources · Free tool

DLP Test Tool

Check whether your Data Loss Prevention policies actually catch sensitive data on the web channel. Generate synthetic test data, scan text against production-grade detectors, and post a controlled payload to see if it is blocked — all from your browser.

Nothing is stored Synthetic data only No sign-up Runs in your browser

Ready-made datasets for the sensitive-data types Turkish and international policies care about most. Every value is fabricated but structurally correct — T.C. Kimlik and Vergi Kimlik numbers carry valid check digits, IBANs pass mod-97, card numbers pass Luhn and come from the card schemes' published test ranges. Copy a set into an email, a web form or a chat window and watch what your DLP does.

These identifiers are generated, not collected. They are valid in format so detection engines recognise them, and they belong to no real person, account or card. Never test with production data.

Coverage

What the tool can produce and detect

Turkish identifiers are first-class here, not an afterthought — which is where most international DLP test tools stop short.

Türkiye identifiers

T.C. Kimlik No and Vergi Kimlik No with valid check digits, TR IBAN with mod-97 validation, mobile numbers, licence plates and city data.

Payment card data

Visa, Mastercard, Amex and Troy numbers from published test ranges, Luhn-valid, with expiry and CVV for PCI DSS policy testing.

International PII

US Social Security numbers, EU IBANs, EU VAT numbers, passports, driving licences, dates of birth, email addresses and phone numbers.

Health data

US National Provider Identifiers with Luhn validation and ICD-10 diagnosis codes for HIPAA and patient-record policies.

Secrets and credentials

AWS access key shapes, API tokens, JWTs and private-key block headers — the exfiltration path that matters most in GenAI and developer workflows.

Network and infrastructure

IPv4 addresses and host identifiers, for policies that treat internal topology as sensitive.

Who uses it

Built to be shared

The tool is public and free. Use it in your own environment, in a customer's, or in front of a room.

Security teams

Validate that a newly written web-channel policy fires before you switch it from monitor to block, and re-run it after every policy change or agent upgrade.

Partners and resellers

Demonstrate detection live during a POC or a customer workshop without ever touching production data, and hand the link over so the customer can repeat it themselves.

Any DLP vendor's customers

Nothing here is Verikor-specific. The datasets and the channel test work against any DLP, CASB or secure web gateway — which makes it a fair way to compare them.

FAQ

Questions about DLP testing

What is a DLP test tool?
A DLP test tool lets you deliberately move realistic but fake sensitive data through a channel your Data Loss Prevention system is supposed to watch, so you can confirm the policy actually fires. Testing matters because DLP failures are silent: a misconfigured rule looks identical to a rule that has nothing to catch. This tool covers the web channel — form posts and file uploads over HTTP and HTTPS — plus the data generation and pattern analysis that go with it.
Is the test data real?
No. Every value is generated on the fly in your browser. Identifiers are structurally valid so that detection engines recognise them — T.C. Kimlik numbers satisfy the official check-digit rules, IBANs pass mod-97, card numbers pass Luhn — but they are not issued to anyone, and card numbers come from the ranges the card schemes publish for testing. Never substitute production data.
Do you store anything I submit?
No. The sample library, the generator and the pattern tester never make a network request at all — they run entirely in your browser. The web channel test is the only feature that sends anything, and only when you press the button. The receiving endpoint counts the bytes it received, returns that number, and discards the body: it is never written to disk, never logged and never forwarded. Nothing is placed in cookies or local storage either.
How do I test the plain HTTP channel?
From a terminal, using the ready-made curl command in the Web channel test tab. Browsers block a page loaded over HTTPS from opening a plain-HTTP connection, so an in-page button cannot do it. Running the two curl commands side by side — one over TLS, one in the clear — is also the cleanest way to prove whether your gateway is inspecting encrypted traffic or only the unencrypted kind.
My test was not blocked. What does that mean?
It means the request left the machine and reached the destination without interruption. That is not automatically a failure: your policy may be in monitor mode, this destination may be allow-listed, or the rule may not cover the data type you sent. Check the DLP console for an alert on the same timestamp. An alert with no block means detection works and enforcement is off; no alert at all means the pattern was not detected.
My test was blocked. Was it definitely the DLP?
Not necessarily. A failed request only tells you that something in the path stopped it. That could be your DLP agent, a secure web gateway, a CASB, a corporate proxy, a browser extension or a firewall rule. Confirm it in the agent or gateway log before you record the result — attributing a block to the wrong control is the most common mistake in a DLP validation exercise.
How often should DLP policies be re-tested?
At minimum after every policy change, every agent or gateway upgrade, and every time a new channel is opened to users. Beyond that, a quarterly regression run across your top data types is a reasonable baseline for most organisations, and it is what auditors increasingly expect to see evidenced under KVKK, ISO 27001 and PCI DSS. Use the generator's seed field so each run is reproducible.
Can I use this with a DLP product that is not Siberson?
Yes. Nothing in the tool depends on Siberson Verikor DLP. The datasets are plain text, the channel test is an ordinary form post, and the pattern tester runs standard detection logic. It works the same against any endpoint DLP, network DLP, CASB or secure web gateway, and it is deliberately built so partners and prospective customers can use it without a licence or a sign-up.

Detection is only half the job

Siberson Verikor DLP inspects the web, email, endpoint and cloud channels with the same checksum-aware detection you just tried — and enforces on it. See it against your own data.

Request a DemoExplore Verikor DLP