cloudflare-one

8 posts

cloudflare

Cloudflare is the only vendor named a Visionary in 2026 SASE and SSE reports (opens in new tab)

Cloudflare argues that SASE and SSE are entering a major transition driven by AI agents, shadow applications, post-quantum threats, and increasingly distributed workforces. It presents Cloudflare One as a unified, programmable platform designed to address these pressures without the fragmented architectures, complex deployments, and hidden costs associated with legacy vendors. The company cites its recognition as a Visionary in both Gartner’s 2026 SASE and SSE Magic Quadrants as validation of this approach. ## The SASE Market’s Architectural Gap - Many SASE platforms are assembled through mergers and acquisitions, creating disconnected products and difficult deployments. - Cloudflare’s “connectivity cloud” uses one global network to connect and protect employees, AI agents, and infrastructure. - AI security has focused primarily on human interactions with generative AI, leaving autonomous agents and MCP server sprawl insufficiently governed. - Cloudflare claims its SASE platform provides shared visibility and policy controls for both humans and AI agents, including limits on AI inference costs. - Post-quantum protection is presented as an immediate requirement against “harvest-now, decrypt-later” attacks, rather than a future concept. - Cloudflare emphasizes predictable SASE bundles instead of charging separately for advanced capabilities or remote and office use cases. ## Technological Pressures Reshaping SASE - **AI-generated applications:** Employees can rapidly create internal “vibe-coded” tools without IT oversight. SASE platforms will need to automatically apply zero trust access, WAF, API protection, and DLP. - **Autonomous AI agents:** Future systems must issue narrowly scoped credentials for individual tasks, evaluate agent intent, and detect abnormal tool-call activity. - **Post-quantum agility:** Organizations need adaptable post-quantum encryption now, while standards continue to evolve. Cloudflare says it aims to deliver a fully quantum-secure SASE platform by 2028. - **Architectural consolidation:** Genuine platform consolidation requires shared code, control, data, and infrastructure planes—not merely multiple products marketed as a single platform. - These changes are described as current customer requirements rather than distant predictions. ## Cloudflare’s Unified Architecture - Cloudflare says it built its SASE platform from the ground up on a single global network rather than combining unrelated security products. - A composable architecture allows new security capabilities to be introduced without waiting for lengthy integration cycles. - Administrators can use familiar SASE policies to secure human AI prompts, AI-agent connections, and MCP servers. - New AI applications can inherit existing zero trust controls instead of requiring security to be retrofitted later. ## Easier SASE Deployment - Legacy platforms often route traffic through multiple inspection points, producing “tromboning,” capacity-planning challenges, and complicated operations. - Cloudflare claims every service runs across its network, eliminating specialized appliance silos and reducing deployment complexity. - Common tasks—such as extending zero trust to an application, adding DLP to Gateway traffic, or connecting an office—are intended to take days or weeks rather than months or years. - The platform is positioned as operating more like a modern SaaS service than a collection of separately managed security engines. ## Programmable SASE - Cloudflare distinguishes true programmability from basic GUI automation and APIs layered over inflexible products. - Its SASE platform runs alongside the company’s edge developer platform, allowing customers to integrate custom code directly into the security fabric. - This design is intended to let organizations enrich access decisions with real-time signals and adapt policies to their own requirements. Cloudflare’s recommendation is effectively to choose SASE platforms built on unified, composable infrastructure that can govern people, applications, and autonomous agents together. Organizations should prioritize integrated policy enforcement, native post-quantum readiness, predictable pricing, and genuine programmability over loosely bundled legacy products.

cloudflare

Introducing the Cloudflare One stack- agent-powered deployment (opens in new tab)

Cloudflare’s One stack is a pair of agent skills designed to help organizations evaluate, migrate to, deploy, and operate Cloudflare One Zero Trust environments. It combines expert-curated guidance, migration logic, decision trees, and API tooling so agents can understand existing networks, recommend architectures, and safely implement changes. The goal is to reduce migrations that traditionally take months to a more guided and automated process. ## The Challenge of Zero Trust Migration - Teams must first understand their existing environment, including: - Applications and connectivity requirements - Authentication and authorization policies - Traffic flows - Assumptions embedded in current security and routing rules - Agents can automate many security workflows, but lack organization-specific knowledge about network topology and vendor configurations. - Cloudflare’s stack supplies the structured context and prescriptive guidance needed for agents to work more effectively with security infrastructure. ## What the Cloudflare One Stack Provides - The stack consists of two lightweight skill files: - `cloudflare-one` for general Cloudflare One planning, deployment, management, and troubleshooting - `cloudflare-one-migration` for translating and migrating from legacy SASE vendors - It incorporates knowledge gathered from Cloudflare employees with extensive customer deployment experience. - When combined with Cloudflare’s code mode MCP server, agents receive a typed interface to the Cloudflare API. - Agents can inspect live accounts and make changes through Cloudflare-recommended workflows rather than arbitrary API calls. ## Covered Cloudflare One Capabilities - VPN replacement and remote access through Cloudflare Access - User, device, network, and data security through Cloudflare Gateway - Connectivity using Cloudflare Tunnel, Mesh, and WAN - Migration from vendors such as Zscaler and Palo Alto Networks - Network diagram interpretation and generation - Translation of concepts between competing SASE platforms - Troubleshooting and operations using Digital Experience Monitoring and automated rule recommendations ## Guided Deployment and Migration - For VPN replacement, the agent can: - Inventory existing VPN applications - Determine the required connectivity model - Map applications to Access, Tunnel, or Mesh - Recommend a deployment sequence that reduces cutover disruption - Produce a configuration summary for human review - For Zscaler Private Access migrations, the agent can: - Convert application definitions into Cloudflare Access applications - Translate user groups and policies - Create equivalent resources through the Cloudflare API - Summarize completed work and identify items needing manual review - The migration logic is based on Cloudflare’s Descaler and Deskope programs, which have migrated enterprise customers from Zscaler and Netskope in hours rather than months. ## Operations and Troubleshooting - The stack can recommend security rules based on live account traffic. - It can automatically migrate Zscaler Private Access applications into self-hosted Cloudflare Access applications. - Agents can investigate anomalies in secure web gateway HTTP logs and create rules to address user issues. - The Digital Experience Monitoring toolkit can report on user stability and help improve latency in important scenarios. Cloudflare positions the One stack as a way to make Zero Trust deployment more accessible and repeatable. Organizations can use the skills with their existing agents, add internal context, and combine them with API tooling—but should still review generated plans and configurations before applying changes.

cloudflare

From the endpoint to the prompt: a unified data security vision in Cloudflare One (opens in new tab)

Cloudflare One presents data security as a unified problem spanning networks, SaaS applications, endpoints, and AI prompts. Its strategy is to follow data wherever it moves, combining visibility, policy controls, and enforcement rather than relying on siloed products. The latest updates extend this model from browser-based RDP clipboard controls to SaaS operation logging, endpoint DLP, and Microsoft 365 Copilot scanning. ### Browser-Based RDP Clipboard Controls - Administrators can control whether users copy or paste data between local devices and browser-based RDP sessions. - Policies can be directional and context-specific: - Allow copying into a remote session for productivity. - Block copying sensitive information out to unmanaged endpoints. - The feature is configured through Access Application Policies for browser-based RDP applications. - Granular controls aim to reduce risky workarounds such as screenshots, manual retyping, or use of unsanctioned tools. ### Operation-Level Visibility in SaaS Logs - Cloudflare’s operation-mapping process interprets HTTP request details as recognizable actions, such as `SendPrompt` in ChatGPT. - Related operations are grouped into higher-level Application Controls such as “Share” or “Upload.” - These mapped operations now appear automatically in log events for matching SaaS traffic. - Log details include both the application control and the specific operation, helping teams investigate activity and refine policies more quickly. ### Endpoint DLP for Data in Use - The Cloudflare One Client now provides Endpoint DLP enforcement, beginning with clipboard-based data movement. - This protects sensitive content after it leaves a browser or managed SaaS application and enters the operating system clipboard. - The feature addresses risks such as copying customer records or proprietary code into personal tools or unauthorized AI assistants. - Organizations can extend existing Gateway, DLP, CASB, and API-based controls without deploying a separate endpoint agent. ### Microsoft 365 Copilot Scanning - API CASB can now analyze Microsoft 365 Copilot activity for data-security risks. - Scanning covers Copilot chats and uploads that match configured DLP detection profiles. - Findings include contextual information such as referenced files, matching DLP profiles, and interaction metadata. - This extends Cloudflare’s existing API integrations for OpenAI ChatGPT, Anthropic Claude, and Google Gemini. Cloudflare’s recommendation is effectively to treat data movement as one continuous security problem: control access in transit, monitor activity in SaaS, enforce protections on endpoints, and inspect how data is used in AI prompts. Together, these capabilities are intended to keep policy attached to the data rather than limited to a particular application or product boundary.

cloudflare

How Automatic Return Routing solves IP overlap (opens in new tab)

Cloudflare’s Automatic Return Routing (ARR) addresses overlapping private IP ranges by routing return traffic based on the tunnel that initiated a connection, rather than relying solely on destination IPs. This allows identical networks to coexist without NAT, VRFs, or manually maintained route mappings. ARR is being introduced as an optional Closed Beta capability for Cloudflare One customers. ## The Ambiguity of Overlapping Private Networks - Public Internet routing assumes each IP address identifies one logically unique destination. - Private networks often reuse the same ranges, such as `10.0.1.0/24`, creating ambiguity when connected through Cloudflare. - Common causes include: - Mergers and acquisitions involving duplicate internal addressing. - Extranets connecting partners or vendors with conflicting IP schemes. - Repeated “cookie-cutter” architectures across branches or customer deployments. - If two sites use the same source IP, return traffic cannot be distinguished by a conventional routing table and may be sent to the wrong site. ## Limitations of Traditional Solutions - **Virtual Routing and Forwarding (VRF):** - Separates overlapping networks with independent routing tables. - Adds operational overhead. - Route leaking between VRFs becomes complex and brittle at scale. - **Network Address Translation (NAT):** - Maps overlapping ranges to unique managed addresses. - Works reliably but requires administrative mappings for every site or partner. - Cloudflare designed ARR to eliminate this per-site configuration for common use cases such as Internet and private data center access. ## How Automatic Return Routing Works - ARR replaces ambiguous route-based decisions with stateful flow tracking. - When a packet begins a flow, Cloudflare records the specific connection or tunnel that delivered it. - Supported originating connections include: - IPsec tunnels - GRE tunnels - Network Interconnects - For subsequent packets, Cloudflare checks whether they match an existing flow. - Existing flows reuse their stored forwarding decisions instead of being evaluated from scratch. - New flows are processed through the relevant Cloudflare One components—such as Gateway, DLP, and Firewall—and ARR records the initiating tunnel. - Return traffic is then sent back through that same tunnel, answering “where did this conversation originate?” rather than “which network owns this IP?” ## Practical Implication ARR enables overlapping private networks to communicate through Cloudflare One without NAT or complex VRF designs. It is intended as a zero-touch approach to reducing routing administration, and is available initially in Closed Beta.

cloudflare

Stop reacting to breaches and start preventing them with User Risk Scoring (opens in new tab)

Cloudflare is adding User Risk Scores to Cloudflare One so access decisions can reflect a user’s recent behavior, not just identity and device posture. The system continuously combines security signals, assigns a deterministic risk level, and applies adaptive access policies in real time. This is intended to replace slow, manual incident response with continuous, automated protection. ## Continuous User Risk Scoring - Risk scores identify behaviors associated with compromised accounts or insider threats, including: - Impossible travel - Failed login attempts - Malware detections - Risky browsing - Data loss prevention (DLP) violations - Outdated or insecure devices - Cloudflare Access and Gateway provide internal telemetry such as login activity, location, malware events, and sensitive-data triggers. - Integrations with CrowdStrike and SentinelOne add third-party device and security signals. - Administrators choose which behaviors to monitor and assign each a low, medium, or high risk level. - A user’s score is based on the highest-risk enabled behavior detected during the relevant period. - Investigators can manually reset a score after reviewing an incident while retaining its historical record. ## Adaptive Access Policies - User Risk Score is now available as a condition in Cloudflare Access policies. - Organizations can create global or application-specific controls, such as: - Blocking high-risk users from financial applications - Requiring medium-risk users to authenticate with a physical security key - Automated enforcement reduces the delay involved in revoking sessions or changing identity-provider groups manually. - Policies can limit damage while allowing lower-risk users to continue working. ## Dynamic Enforcement and Integrations - Access can be revoked during an active session when a user’s risk increases. - Access is automatically restored when the score falls after investigation and clearance. - Cloudflare plans to explore enforcing step-up MFA during active sessions when risk changes. - Through the Shared Signals Framework, Cloudflare can send risk information to Okta so users restricted on the network are also restricted at the SSO entry point. Cloudflare recommends using User Risk Scores to make zero trust access continuously adaptive rather than evaluating users only at login. Existing customers can configure the feature in the Cloudflare One dashboard, while larger organizations can integrate partner telemetry through a ZTNA pilot.

cloudflare

The truly programmable SASE platform (opens in new tab)

Cloudflare argues that true SASE programmability goes beyond APIs, Terraform, webhooks, and alerts. It means intercepting security events, enriching them with external context, and making real-time decisions through custom logic. By running Cloudflare One and its Developer Platform on the same global edge network, Cloudflare aims to let customers apply programmable, low-latency policies without stitching together separate infrastructure. ## What “Programmability” Means - Traditional programmability supports configuration and automation, such as sending Slack alerts when policies trigger. - True programmability allows security systems to: - Inspect an event before access is granted. - Query external systems for additional context. - Make or change an access decision in real time. - Example: a request to a regulated application could be checked against a learning management system to confirm that the user’s compliance training is current. Expired or missing certification would result in denial and redirection to training. ## Cloudflare’s Programmable SASE Architecture - Cloudflare’s network spans more than 330 cities and reaches approximately 95% of Internet-connected users within 50 milliseconds. - Cloudflare One and the Developer Platform run on the same infrastructure and use shared network primitives. - This enables Workers to extend inline services such as Access without requiring separate cloud infrastructure. - Customers can: - Call external risk APIs. - Add dynamic request headers. - Validate browser attributes. - Route traffic according to custom business logic. - Running custom logic at the edge reduces latency and avoids the operational overhead of webhook-based integrations and disconnected systems. ## Custom Actions in Security Policies - Conventional gateways generally limit policy outcomes to actions such as allow, block, isolate, or quarantine. - Cloudflare is expanding policies to support managed and custom actions. - Potential uses include: - Injecting headers based on user identity claims. - Obtaining real-time verdicts from external risk engines. - Restricting access based on location or working hours. - Updating risk lists based on scheduled analysis of user activity. - Custom actions can invoke a Worker when a Gateway HTTP policy matches, giving the code access to request context and allowing decisions in milliseconds. - Managed actions will offer templates for common use cases such as IT service management, redirects, and compliance workflows. ## Automated Device Session Revocation - One customer needed periodic re-authentication for Cloudflare One Client users, similar to traditional VPN session expiration. - Cloudflare’s built-in session controls were application-specific rather than global and time-based. - The customer implemented a scheduled Worker that: - Queries the Cloudflare Devices API. - Handles cursor-based pagination to retrieve registrations. - Calculates how long each device has been inactive. - Deletes registrations exceeding a configured inactivity threshold. - Forces affected users to authenticate again through their identity provider. - The example also supports environment-based configuration and a dry-run mode for testing before revocations are applied. Cloudflare’s recommendation is to treat SASE policies as programmable decision points rather than fixed allow-or-block rules. Combining Cloudflare One with edge Workers can provide faster, more context-aware security automation while reducing integration complexity.

cloudflare

Modernizing with agile SASE: a Cloudflare One blog takeover (opens in new tab)

The post argues that changing work patterns, AI agents, and Internet-based perimeters require organizations to move beyond fragmented legacy networks toward “agile SASE.” It presents Cloudflare One as a composable platform that combines networking and security on a global connectivity cloud, using single-pass processing to avoid service-chaining bottlenecks. Cloudflare positions this architecture as a faster path to modernization, beginning with focused use cases rather than a large-scale “big bang” migration. ## The Case for Agile SASE - Hybrid work and AI-driven traffic are making traditional corporate perimeters and office-based networks obsolete. - Legacy firewalls, VPN concentrators, and hardware appliances create a “fragmentation penalty.” - Technical debt accumulates through: - Conflicting firewall rules - Manual patching - Aging hardware - Infrastructure unable to handle AI-scale traffic - First-generation SASE platforms often shifted fragmentation from physical hardware into isolated cloud and operational silos. - The resulting problem is not a shortage of security data, but difficulty enforcing consistent policies across a borderless enterprise. ## Cloudflare One’s Single-Pass Architecture - Cloudflare describes zero trust as the security model and Cloudflare One as the platform for implementing it. - The platform converges networking and security through a global connectivity cloud spanning more than 300 cities. - Security checks can run simultaneously on every server rather than processing traffic sequentially through separate services. - This avoids service chaining, which can introduce latency and operational complexity. - Cloudflare frames the result as a programmable, composable platform rather than a collection of acquired or loosely connected tools. ## Five Themes for Network Modernization The company’s planned technical series focuses on: - **A new network standard:** Building a programmable, future-ready Internet foundation. - **Identity beyond passwords:** Combining human and device verification instead of relying only on credentials. - **Signal over noise:** Using AI to convert large volumes of security data into actionable guidance. - **The autonomous edge:** Improving performance and reducing friction as part of the security strategy. - **A unified vision:** Showing how enterprises and partners can standardize on Cloudflare One at scale. ## Programmability and Developer Integration - Cloudflare One runs alongside Cloudflare Workers, allowing teams to write code that responds to security events in real time. - This extends policy enforcement beyond simple allow/block decisions. - Organizations can automate more sophisticated security and operational workflows. - Cloudflare argues that this flexibility helps technology teams support faster business growth while improving protection. ## Practical Starting Points The post recommends beginning with focused modernization projects: - **Remote access:** Replace maintenance-heavy VPNs with clientless access and faster zero trust adoption. - **Email protection:** Detect phishing, Business Email Compromise, and related multi-channel threats with AI-powered controls. - **DNS filtering:** Block malicious websites for hybrid workers using DNS protection based on the 1.1.1.1 resolver. - **AI governance:** Identify shadow AI usage and control how organizational data enters generative and agentic AI systems. - **Branch networking:** Treat offices and coffee-shop workspaces as remote sites, reducing dependence on dedicated hardware. Organizations evaluating SASE should favor platforms that provide consistent policy enforcement, programmable controls, and incremental adoption. Cloudflare’s recommended entry point is to start with a specific need—such as VPN replacement or AI governance—and expand toward a unified connectivity and security architecture.

cloudflare

Cloudflare One is the first SASE offering modern post-quantum encryption across the full platform (opens in new tab)

Cloudflare says Cloudflare One is now the first SASE platform to provide standards-compliant post-quantum hybrid ML-KEM encryption across Secure Web Gateway, Zero Trust, and WAN connectivity. The update extends protection to Cloudflare IPsec and Cloudflare One Appliance, addressing both current “harvest now, decrypt later” attacks and future quantum threats. The appliance support is generally available in version 2026.2.0, while Cloudflare IPsec is in closed beta. ## Post-Quantum Cryptography Is an Immediate Concern - NIST has set 2030 as the target for phasing out RSA and elliptic-curve cryptography in favor of post-quantum algorithms. - Cryptographic migrations can take decades, as demonstrated by vulnerabilities involving deprecated algorithms such as MD5. - Organizations face “harvest now, decrypt later” attacks, in which encrypted traffic is collected today for future decryption. - Cloudflare argues that built-in crypto agility makes it easier for enterprises to upgrade algorithms without redesigning remote-access and WAN infrastructure. ## Two Required Cryptographic Migrations - **Key establishment:** ML-KEM is becoming the standard post-quantum mechanism for establishing shared encryption keys. - Cloudflare uses hybrid ML-KEM, combining ML-KEM with classical ECDHE. - This approach protects against harvested traffic, requires no specialized hardware like quantum key distribution, and has limited performance impact. - More than 60% of human-generated TLS traffic reaching Cloudflare is already protected by hybrid ML-KEM. - **Digital signatures:** Post-quantum signatures protect against server impersonation but are larger than current ECC signatures. - Their migration is considered less urgent because they primarily defend against active quantum adversaries, which do not yet exist. - Cloudflare’s current IPsec work therefore focuses on post-quantum key establishment rather than signatures. ## Post-Quantum Protection for Cloudflare IPsec - Cloudflare upgraded its IPsec products to support hybrid ML-KEM within IKEv2. - Cloudflare IPsec creates encrypted tunnels from customer networks to Cloudflare’s global network. - IP Anycast routes tunnels to the nearest data center and automatically redirects traffic if a location becomes unavailable. - The service supports site-to-site WAN connectivity as well as outbound Internet connections. - Cloudflare One Appliance, which establishes Cloudflare IPsec connections, supports the upgrade starting with version 2026.2.0. - The Cloudflare IPsec upgrade remains in closed beta. ## Limitations of Earlier IPsec Approaches - IPsec has historically evolved differently from TLS because it is commonly used between devices from the same vendor, making interoperability less central. - RFC 8784 proposed combining long-lived pre-shared keys with Diffie-Hellman exchange. - While this can help protect against harvest-now-decrypt-later attacks, it does not provide forward secrecy against quantum attackers. - Quantum key distribution is also impractical for many enterprise environments because it requires specialized physical connectivity. Cloudflare’s recommendation is to begin post-quantum migration now, starting with hybrid ML-KEM for key establishment across Internet access, Zero Trust, and WAN connections.