The Cloudflare global network
One of the world's largest networks — running every service in every data center.
Cloudflare's connectivity cloud
- ZTNA (with MCP Server Portals)
- SWG (with AI Usage Controls)
- CASB (with AI Posture Management)
- Email Security
- Data Loss Prevention
- Remote Browser Isolation
- Digital Experience Monitoring
- WAF with Rate Limiting
- Firewall for AI
- API Protection
- Load Balancing
- Bot Management (with AI Crawl Control)
- L7 DDoS Protection
- CDN and DNS
- Origin Shield
- Serverless compute
- AI inference
- Full stack applications
- Object & key-value storage
- SQL database
- Media optimization and delivery
- Agentic SDK and Workflows
- AI Gateway
Cloudflare Programmable Global Network
Protect & accelerate your applications
Toggle each service to see how it changes a request's journey
Global Content Delivery
CDN
Cloudflare caches your content at 330+ cities worldwide, serving each visitor from the nearest edge instead of a round-trip to your origin.
Application Security Suite
WAF & App Security
Your origin is hit by injection attacks, malicious bots, and request floods all at once. Cloudflare's WAF, Bot Management, and Advanced Rate Limiting stop each threat at the edge — turn the suite on to see the origin go from overwhelmed to protected.
Unmetered DDoS Mitigation
DDoS Protection
Cloudflare's anycast network absorbs volumetric floods across hundreds of data centers, keeping your origin online while real users still get through.
Automatic TLS 1.3 Encryption
SSL / TLS
Edge certificates are issued and renewed automatically with zero manual work, while a long-lived Cloudflare Origin certificate secures the back-end leg.
Zero Trust on Cloudflare
Step through the global architecture and each Zero Trust service
SASE Reference Architecture
Overview
Employees in the office, remote workers, and contractors all connect through the Cloudflare global network. Every request is verified and inspected by Cloudflare's Zero Trust services before reaching self-hosted apps, cloud infrastructure, or SaaS.
Zero Trust Network Access
ZTNA
Replace the VPN with identity- and posture-aware access. Every connection to a private application is authenticated against your identity provider and checked for device health before access is granted.
- Entra ID single sign-on
- Multi-factor authentication
- WARP enrolled
- Disk encrypted
- OS up to date
- User in allowed group
- Connecting from allowed country
Secure Web Gateway
Secure Web Gateway
A cloud firewall for all outbound traffic. DNS, network, and HTTP policies filter malware and phishing, decrypt and inspect TLS, and enforce acceptable-use rules wherever the user is.
- Block malware & phishing domains
- Block by content category
- TLS decryption
- Block risky file types
- Tenant / app control
- L4 firewall policies
- Allow only sanctioned traffic
Cloud Access Security Broker
CASB
Connect to your SaaS apps over API to continuously scan for misconfigurations, risky data sharing, and shadow IT — surfacing prioritized findings without sitting inline.
- Detect misconfigurations
- Find public / over-shared files
- Discover shadow IT
- Continuous SaaS security checks
- DLP scans of data at rest
Data Loss Prevention
Data Loss Prevention
Inspect data in motion against predefined and custom profiles. Sensitive content — PII, financial records, source code — is logged or blocked before it can leave for an unapproved destination.
- Predefined profiles (PII, PCI, financial)
- Custom regex & keywords
- Exact data match
- Allow low-risk data
- Log & alert
- Block sensitive uploads
Remote Browser Isolation
Browser Isolation
A user opens a risky link. Cloudflare recognizes the risk and fetches and runs the site's active code in a remote browser inside its own network — streaming back only a safe pixel/DOM representation. Malicious code executes in Cloudflare, never on the endpoint.
- Remote browser fetches & renders the page
- Active code executes in Cloudflare, not on device
- Safe pixel / DOM stream to the device
- Zero-day threats never reach the endpoint
- Block copy / paste, printing & downloads
Build on Cloudflare
Reference architectures — each slide is a use case built from developer services
Web application
Full-stack app
Serve a front-end and its API from one platform. Pages hosts static assets while Workers run server logic, reading and writing to D1 for relational data, KV for sessions, R2 for user uploads, and Durable Objects for coordination — all bound directly, no connection strings.
Retrieval-augmented generation
AI RAG chatbot
Build a grounded AI assistant. A Worker embeds the user's question with Workers AI, finds relevant chunks in Vectorize, pulls source documents from R2, and calls the LLM — all routed through AI Gateway for caching, rate limiting, and observability.
Stateful edge coordination
Real-time collaboration
Power multiplayer docs, chat, or games. Workers terminate WebSocket connections and route each client to a single Durable Object per room, which acts as the single-writer coordinator and stores consistent state right next to the compute.
Event-driven processing
Async media pipeline
Accept uploads without blocking the user. An ingest Worker stores the original in R2 and drops a job on Queues; a consumer Worker processes batches asynchronously, transcoding and optimizing with Stream and Images.
Connect existing databases
Legacy DB acceleration
Bring your existing Postgres or MySQL to the edge. Hyperdrive pools connections and caches queries so globally distributed Workers get fast, local-feeling access to a regional database — without rearchitecting your data layer.