San Francisco, CA, USA
2009
  |  By Artificial Intelligence
Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale.
  |  By 1.1.1.1
On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.
  |  By Birthday Week
Twelve years ago, during Birthday Week 2014, we turned on Universal SSL and nearly doubled the number of encrypted sites on the web overnight, giving free TLS to every site behind Cloudflare, including the ones that never paid us a cent. Encryption stopped being an expensive, time-intensive undertaking and instead became the default. For Birthday Week this year, we are taking the next step on that path.
  |  By Agents
In 2023, Cloudflare declared itself free from CAPTCHAs with the launch of Turnstile, our privacy-first client-side challenge. Turnstile is free to use, works on any site (no need to proxy traffic through Cloudflare), and never asks a visitor to solve a puzzle. Now, we are launching Turnstile Spin, an agent-mediated end-to-end implementation of Turnstile.
  |  By Containers
On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised.
  |  By AI
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with analytics, or asking a remote server what to execute next. Pages load, products appear, and checkout works — yet the browser may be quietly doing something the site owner never authorized. That is the blind spot our Client-Side Security machine learning (ML) model is built to expose.
  |  By CASB
Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. When we launched Cloudflare CASB, a cloud access security broker, we wanted to provide security teams complete visibility into the posture of their SaaS applications before misconfigurations became incidents.
  |  By 1.1.1.1
1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. Cloudflare plans to achieve full post-quantum security by 2029. Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC.
  |  By Application Security
Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest, we start over, and the connection costs two round trips.
  |  By Artificial Intelligence
Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense. Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases.
  |  By Cloudflare
Tjeerd Jan van der Molen and Margot Schipper of Cloudflare introduce Cloudflare OS and show how it rewires the way everyone in a company can work with AI.
  |  By Cloudflare
Jose Dores of Cloudflare explains how programmable SASE gives organizations the fastest path to adopting AI safely, with security built for what comes next.
  |  By Cloudflare
Michael Gustafsson of Cloudflare shows how to ship AI agents on Cloudflare that are secure by default, so teams can build and deploy agents with confidence.
  |  By Cloudflare
Christiaan Smits of Cloudflare looks at how data sovereignty is evolving across EMEA and how organizations can navigate the changing landscape.
  |  By Cloudflare
It was just a little chat window in the corner of the screen. But behind it was a web of trusted connections reaching deep inside the enterprise. Here’s how attackers turned a trusted integration into a massive supply chain breach. Expand for more details and resources In August 2025, attackers tracked as UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration. This turned trusted connections to Salesforce environments into an attack path reaching hundreds of companies, including top-tier cybersecurity organizations.
  |  By Cloudflare
Oron Noah, VP of Product Extensibility & Partnership at Wiz, shares how the Cloudflare and Wiz partnership began and how their integration delivers better security outcomes — from code to production — by giving every team full visibility into their cloud environment.
  |  By Cloudflare
As cyber threats become more sophisticated, strategic partnerships are essential for robust defense. In this interview, we sit down with the team at SentinelOne to discuss how our integrated solutions provide end-to-end security for the modern enterprise.
  |  By Cloudflare
Check out this special video where we heard from Trey Guinn, one of our long-time Cloudflare volunteers who worked directly with organizations protected under Project Galileo.
  |  By Cloudflare
In this Women of Cloudflare segment, Cita James, Manager, People Team Business Partner at Cloudflare, shares her journey from Oklahoma City to Cloudflare’s People Team, working across Austin, Lisbon, London, and the EMEA region.
  |  By Cloudflare
How does your computer actually find data? JQ Lau from Cloudflare's hardware team explains the difference between CPU cache and memory with a simple analogy — and why it matters when you're designing servers for millions of requests.
  |  By Cloudflare
This whitepaper discusses the many challenges that DNS providers and users face including massive cyber attacks as well as performance and reliability issues, and how Cloudflare can help resolve these challenges, ensuring business continuity.
  |  By Cloudflare
Strategies for preventing data breaches, shadow APIs, abuse, and other common challenges.
  |  By Cloudflare
Organizations are facing economic uncertainty as the outlook grows more unpredictable. This uncertainty - often exemplified by shrinking budgets - puts pressure on CIOs and technical leaders to find new paths forward.
  |  By Cloudflare
Learn how Cloudflare is able to stop some of the most sophisticated DDoS attacks.
  |  By Cloudflare
This whitepaper discusses the growth of large scale DDoS attacks, how these attacks target as well as leverage DNS provider infrastructures, and how Cloudflare can help protect your business against the impact of such massive attacks.
  |  By Cloudflare
Growing a startup requires delivering excellent online experiences. In this guide, we share tips to help startups create the kind of high-performing, reliable, and secure websites and applications needed to do so.

Cloudflare is a global network designed to make everything you connect to the Internet secure, private, fast, and reliable.

Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare have all traffic routed through its intelligent global network, which gets smarter with each new site added. As a result, they see significant improvement in performance and a decrease in spam and other attacks.

The Integrated Global Cloud Network:

  • Zero Trust Services: Stop data loss, malware and phishing with the most performant Zero Trust application access and Internet browsing solution.
  • Website & App Performance: Speed up websites, apps, & APIs through our global network to optimize your content & deliver it closer to the users location.
  • Website & App Security: Protect websites & applications from bots, DDoS attacks & more. All while monitoring for suspicious activity & potential attacks.
  • Network Security & Performance: Networking solutions to connect, secure, & accelerate your networks — without the cost & complexity of managing legacy hardware.
  • Developer Platform: Deploy serverless code instantly across the globe to give it exceptional performance, reliability, & scale.
  • SASE - Cloudflare One: Zero Trust network-as-a-service platform to dynamically connect remote & on-site users to resources, with identity-based security controls.

A global network built for the cloud.