Cloudflare
Cloudflare is a CDN and security platform offering DDoS protection, Web Application Firewall (WAF), SSL/TLS encryption and threat-intelligence features to websites and applications. The feature sections below are vendor-style descriptions carried from an earlier draft and not re-checked against current Cloudflare docs.
Company facts
- Founded 2009-07-26 by Matthew Prince, Lee Holloway and Michelle Zatlyn; HQ San Francisco; Prince is CEO and co-chair; IPO 2019-09-13 (NYSE: NET) (Wikipedia, secondary).
- 2025: revenue 102M, 5,156 employees (Wikipedia).
- Developer and AI products: Workers (serverless), Zero Trust, 1.1.1.1 resolver, WARP, Workers AI (GPU inference); launch years (2017, 2020, 2019, 2023) are from the earlier draft and not verified. Cloudflare Sandboxes support Cursor Cloud Agents (newsroom, 2026).
- Acquisitions: Replicate (Nov 2025), Human Native (Jan 2026), Astro (Jan 2026), VoidZero (Jun 2026) (Wikipedia).
- Incidents: global outages on 2025-11-18 and 2025-12-05 affected many major services (Wikipedia).
- Newsroom, as of 2026-10-05: Basin data platform (2026-10-01), post-quantum public certificate authority (2026-09-29), Deutsche Telekom partnership, FedRAMP High authorization, a $2.175B convertible notes offering.
Core Architecture
Cloudflare operates as a reverse proxy, positioning itself between users and origin servers. The vendor describes this as keeping origin server IPs from being targeted directly.
Primary Security Features
DDoS Protection
- Multi-layer protection across OSI Layers 3, 4, and 7
- Vendor describes DDoS protection as unmetered (not verified)
- Layer-specific products:
- Layer 7 DDoS for application-layer attacks
- Spectrum for Layer 4 (UDP/TCP) protection
- Magic Transit for Layer 3 (network layer) protection
- Vendor claims it distinguishes legitimate from malicious traffic (not verified)
Web Application Firewall (WAF)
- Protects against SQL injection, cross-site scripting (XSS), OWASP Top 10 threats
- Every request inspected against rule engine and threat intelligence database
- Customizable rules to block, challenge, or log suspicious requests
SSL/TLS Encryption
- Free SSL/TLS certificates with automatic encryption
- Supports TLS 1.2 and TLS 1.3
- Keyless SSL: Organizations maintain control of TLS private keys while leveraging Cloudflare infrastructure
- Authenticated Origin Pulls: Ensure requests originate from Cloudflare network only
Rate Limiting
- Throttle traffic based on granular request data (headers, API tokens)
- Protect sensitive endpoints (login pages, payment gateways)
- Defend against brute-force attacks
API Shield
- Positive security model: Only valid API traffic permitted
- Schema validation
- Mutual TLS (mTLS) authentication
- JSON Web Token (JWT) validation
- Rate limiting and abuse detection
Bot Management
- Identify and mitigate malicious bot traffic
- Prevent denial-of-service attacks
- Protect against automated threats
Advanced Protection Features
Under Attack Mode
- Automatically engages additional security challenges (JavaScript challenges, CAPTCHAs)
- Verifies visitors are legitimate human users
Data Loss Prevention (DLP)
- Defines profiles to identify sensitive data within network traffic
- Apply Gateway policies to allow, block, or isolate traffic matching specific data patterns
Cloud Access Security Broker (CASB)
- Integrates via APIs with SaaS applications
- Scans storage and configurations for misconfigurations
- Detects publicly exposed sensitive data
Mutual TLS (mTLS) Authentication
- Enable mTLS for hostnames and API endpoints
- Ensures only devices with valid certificates access protected resources
- Provides additional authentication layer for sensitive applications and APIs
Integrated Protection Model
Cloudflare’s architecture features:
- Vendor positioning (not verified here): single-pass inspection of security and performance services, coverage across OSI layers, and threat-intelligence updates drawn from attacks seen across its network.
Use Cases
- Website Security: DDoS mitigation and WAF protection for traditional websites
- API Protection: API Shield for securing REST/GraphQL APIs
- Enterprise Connectivity: Magic Transit and private networks
- SaaS Security: CASB for cloud application security
- Sensitive Data: DLP for protecting personally identifiable information (PII)
- Bot Mitigation: Prevent scraping and unauthorized automation
Vendor-claimed advantages (not independently verified)
- Global network reach and low-latency protection
- Threat intelligence from a large base of protected websites
- Unified security and performance platform
- Free tier options for basic protection (see the vendor pricing page)
Edge Computing Integration
Cloudflare’s infrastructure enables:
- Application execution at edge locations
- Reduced latency for end users
- Geographically distributed computing
- Seamless integration with security services
See Also
- Cursor (Cloudflare Sandboxes host Cursor Cloud Agents)
- Cap’n Proto
Sources
- https://en.wikipedia.org/wiki/Cloudflare (secondary, accessed 2026-10-05)
- https://www.cloudflare.com/press-releases/ (accessed 2026-10-05)
Open items
- Security feature descriptions below the company facts are carried from the earlier draft and not re-checked against current Cloudflare docs; plan tiers deliberately not listed.