Cloudflare

Cloudflare is a CDN and security platform offering DDoS protection, Web Application Firewall (WAF), SSL/TLS encryption and threat-intelligence features to websites and applications. The feature sections below are vendor-style descriptions carried from an earlier draft and not re-checked against current Cloudflare docs.

Company facts

  • Founded 2009-07-26 by Matthew Prince, Lee Holloway and Michelle Zatlyn; HQ San Francisco; Prince is CEO and co-chair; IPO 2019-09-13 (NYSE: NET) (Wikipedia, secondary).
  • 2025: revenue 102M, 5,156 employees (Wikipedia).
  • Developer and AI products: Workers (serverless), Zero Trust, 1.1.1.1 resolver, WARP, Workers AI (GPU inference); launch years (2017, 2020, 2019, 2023) are from the earlier draft and not verified. Cloudflare Sandboxes support Cursor Cloud Agents (newsroom, 2026).
  • Acquisitions: Replicate (Nov 2025), Human Native (Jan 2026), Astro (Jan 2026), VoidZero (Jun 2026) (Wikipedia).
  • Incidents: global outages on 2025-11-18 and 2025-12-05 affected many major services (Wikipedia).
  • Newsroom, as of 2026-10-05: Basin data platform (2026-10-01), post-quantum public certificate authority (2026-09-29), Deutsche Telekom partnership, FedRAMP High authorization, a $2.175B convertible notes offering.

Core Architecture

Cloudflare operates as a reverse proxy, positioning itself between users and origin servers. The vendor describes this as keeping origin server IPs from being targeted directly.

Primary Security Features

DDoS Protection

  • Multi-layer protection across OSI Layers 3, 4, and 7
  • Vendor describes DDoS protection as unmetered (not verified)
  • Layer-specific products:
    • Layer 7 DDoS for application-layer attacks
    • Spectrum for Layer 4 (UDP/TCP) protection
    • Magic Transit for Layer 3 (network layer) protection
  • Vendor claims it distinguishes legitimate from malicious traffic (not verified)

Web Application Firewall (WAF)

  • Protects against SQL injection, cross-site scripting (XSS), OWASP Top 10 threats
  • Every request inspected against rule engine and threat intelligence database
  • Customizable rules to block, challenge, or log suspicious requests

SSL/TLS Encryption

  • Free SSL/TLS certificates with automatic encryption
  • Supports TLS 1.2 and TLS 1.3
  • Keyless SSL: Organizations maintain control of TLS private keys while leveraging Cloudflare infrastructure
  • Authenticated Origin Pulls: Ensure requests originate from Cloudflare network only

Rate Limiting

  • Throttle traffic based on granular request data (headers, API tokens)
  • Protect sensitive endpoints (login pages, payment gateways)
  • Defend against brute-force attacks

API Shield

  • Positive security model: Only valid API traffic permitted
  • Schema validation
  • Mutual TLS (mTLS) authentication
  • JSON Web Token (JWT) validation
  • Rate limiting and abuse detection

Bot Management

  • Identify and mitigate malicious bot traffic
  • Prevent denial-of-service attacks
  • Protect against automated threats

Advanced Protection Features

Under Attack Mode

  • Automatically engages additional security challenges (JavaScript challenges, CAPTCHAs)
  • Verifies visitors are legitimate human users

Data Loss Prevention (DLP)

  • Defines profiles to identify sensitive data within network traffic
  • Apply Gateway policies to allow, block, or isolate traffic matching specific data patterns

Cloud Access Security Broker (CASB)

  • Integrates via APIs with SaaS applications
  • Scans storage and configurations for misconfigurations
  • Detects publicly exposed sensitive data

Mutual TLS (mTLS) Authentication

  • Enable mTLS for hostnames and API endpoints
  • Ensures only devices with valid certificates access protected resources
  • Provides additional authentication layer for sensitive applications and APIs

Integrated Protection Model

Cloudflare’s architecture features:

  • Vendor positioning (not verified here): single-pass inspection of security and performance services, coverage across OSI layers, and threat-intelligence updates drawn from attacks seen across its network.

Use Cases

  • Website Security: DDoS mitigation and WAF protection for traditional websites
  • API Protection: API Shield for securing REST/GraphQL APIs
  • Enterprise Connectivity: Magic Transit and private networks
  • SaaS Security: CASB for cloud application security
  • Sensitive Data: DLP for protecting personally identifiable information (PII)
  • Bot Mitigation: Prevent scraping and unauthorized automation

Vendor-claimed advantages (not independently verified)

  • Global network reach and low-latency protection
  • Threat intelligence from a large base of protected websites
  • Unified security and performance platform
  • Free tier options for basic protection (see the vendor pricing page)

Edge Computing Integration

Cloudflare’s infrastructure enables:

  • Application execution at edge locations
  • Reduced latency for end users
  • Geographically distributed computing
  • Seamless integration with security services

See Also

Sources

Open items

  • Security feature descriptions below the company facts are carried from the earlier draft and not re-checked against current Cloudflare docs; plan tiers deliberately not listed.