Cloudflare Access
Zero Trust Network Access that replaces your VPN. Enforce identity, device posture, and context-aware policies before any user reaches an internal application — without a client agent.
- Agentless access via Cloudflare Tunnel — no open inbound ports
- SSO with any IdP: Okta, Azure AD, Google, GitHub, and more
- Device posture checks — OS version, disk encryption, certificates
- App Launcher portal for a consumer-grade user experience
- SSH & RDP browser rendering — no client required
Application → internal.example.com Policy → Allow Rule: Email domain @example.com AND Device posture: Managed device AND Country: US, CA, GB Session duration → 8h IdP → Okta SAML
Cloudflare Gateway
A Secure Web Gateway that filters DNS, HTTP, and network traffic — blocking malware, phishing, shadow IT, and data exfiltration before it happens.
DNS Filtering
Block malicious, phishing, and unwanted domains at the resolver level — before a TCP connection is made. Works with WARP or any DNS-over-HTTPS client.
HTTP Inspection
Decrypt and inspect HTTPS traffic. Apply allow/block policies by URL, category, application, or data pattern — without installing a proxy appliance.
Data Loss Prevention
Detect and block sensitive data (PII, credentials, source code) leaving your organization — in uploads, downloads, and API responses.
CASB
Scan connected SaaS apps for misconfigurations, over-sharing, and shadow data. Supports Google Workspace, Microsoft 365, GitHub, and more.
Analytics & Logs
Full request logs with Logpush to your SIEM. Build dashboards in your existing tooling or use Cloudflare's built-in analytics.
Network Firewall
Layer 4 filtering for TCP/UDP traffic. Create network policies that block or allow connections by IP, port, SNI, and geo.
WARP & Cloudflare Tunnel
Connect users to your private network and expose internal services to the internet — all through Cloudflare's network, with no open firewall ports.
- WARP client for Windows, macOS, iOS, Android, Linux
- Split tunneling — route only corporate traffic through Cloudflare
- Cloudflare Tunnel: outbound-only encrypted connection from your server
- WARP Connector for site-to-site connectivity
- Magic WAN for replacing MPLS/SD-WAN at scale
# Expose a local service — no inbound ports $ cloudflared tunnel create my-app $ cloudflared tunnel route dns my-app app.example.com $ cloudflared tunnel run my-app ⛅️ Tunnel: my-app Route: app.example.com → localhost:3000 Status: Connected (2 replicas)
Cloudflare Email Security (Area 1)
Stop phishing, Business Email Compromise, and malicious attachments before they reach the inbox — using ML models that pre-scan the web for attack infrastructure.
Phishing Prevention
Pre-emptive scanning of attack infrastructure days before emails are sent. Catches novel campaigns that signature-based tools miss.
BEC Protection
Detect impersonation, display-name spoofing, and lookalike domains used in Business Email Compromise attacks.
Malicious Attachments
Sandbox attachments and links in real time, blocking malware and credential-harvesting pages before they load.
API or MX Mode
Deploy as an MX record or via API integration with Microsoft 365 & Google Workspace — no agent, no rerouting of mail flow needed.
Remote Browser Isolation
Execute all web code in Cloudflare's network, not on the user's device. Streams pixels to the browser — malware, ransomware, and zero-days never reach the endpoint.
- Clientless isolation — works in any browser, no plugin required
- Agentless access to internal apps without exposing them to the internet
- Disable copy/paste, printing, file downloads per policy
- Seamlessly integrates with Gateway HTTP policies
- Near-native performance using Cloudflare's global network
How it works
Web content executes on Cloudflare's edge. A compressed, read-only visual stream is sent to the user's browser.
- Zero malicious code on endpoint
- Full DLP controls over sessions
- Works with any SaaS or internal app
Replace your VPN. Start free today.
Cloudflare Zero Trust free plan supports up to 50 users — no credit card required.