Yes, if implemented without category-based policy controls.
Indiscriminate decryption of all encrypted traffic, including healthcare portals, personal banking sessions, and legal communications, can conflict with HIPAA, GDPR, and applicable financial privacy regulations.
MITRE M1020 explicitly advises against decrypting sensitive or privacy-related traffic to maintain compliance. The solution is selective decryption policies that distinguish inspectable business traffic from regulated sensitive categories.
Fidelis applies DSI session metadata analysis to regulated traffic instead of full decryption. Metadata analysis delivers meaningful threat detection through TLS handshake signals, JA3 fingerprints, and behavioral patterns, without exposing protected content. Security coverage and regulatory compliance coexist under the same policy framework.
