Enterprise-grade Zero Trust defenses, now at no cost for public-interest teams
Organizations under Projects Galileo and Athenian face threats that rival those targeting large corporations, yet they operate with a fraction of the resources. Phishing campaigns aimed at stealing credentials and attacks disrupting access to critical systems are constant concerns. Historically, the defenses against these threats were priced for enterprises with deep pockets.
Cloudflare is changing that. The Cloudflare One Zero Trust suite is now available at no cost to teams that qualify for Project Galileo or the Athenian Project. This includes the same security and connectivity stack used by more than 10,000 customers to connect users and protect data, spanning email security, DNS filtering, and secure remote access.
Phishing defenses in depth
Sophisticated phishing often arrives as a malicious link in an email that appears to come from a trusted colleague. The target enters credentials on a lookalike login page, handing them to the attacker.
The first layer of defense is Cloudflare's Area 1 email security. Area 1 scans inbound mail for phishing campaigns and other threats, blocking malicious messages before they reach inboxes while letting legitimate mail through. Deployment takes minutes with DNS record changes and protects Microsoft 365, Gmail, or other email providers. As part of this announcement, Area 1 is included at no cost for Project Galileo and Athenian organizations.
When a dangerous link manages to slip through email or arrives via another channel, DNS-level filtering provides a second line of defense. Every outbound request to a website begins with a DNS query, and Cloudflare's security-focused resolver checks those queries against known malicious destinations. A dangerous link is stopped before the page can load; benign destinations resolve at speed. This DNS filtering can protect an entire office network with a single router change, or follow remote users via the WARP roaming client for coverage everywhere.
Access without legacy VPNs
Teams spread across geographies have long relied on legacy VPNs to reach internal tools. Those setups often slow users down, demand maintenance, and grant anyone on the network overly broad access to resources.
Cloudflare One offers a modern alternative. Administrators can run a traditional private network by deploying WARP on endpoints and connecting to Cloudflare's network via outbound-only Cloudflare Tunnel connections. That means no inbound firewall rules to configure, while users get a fast, dependable path to applications and services.
Granular permission controls allow administrators to determine exactly who can access each resource. This flexibility extends to partners and volunteers who may be unwilling or unable to install software on personal devices. With fully clientless access, teams authenticate using existing single sign-on providers — including consumer options like Google, Facebook, and LinkedIn — from any desktop or mobile browser. Every access attempt is logged, and admins can enforce application-specific policies without building custom development.
Securing every connection to the Internet
Phishing is only one attack vector. Malware hidden in downloads, ransomware from untrusted sources, and unencrypted DNS queries on hotel Wi-Fi can all compromise an organization. For journalists and researchers investigating sensitive topics, the risks are especially acute.
Cloudflare One wraps every outbound connection in an encrypted tunnel via the WARP agent. The Secure Web Gateway then filters that traffic for hidden threats. When a user reaches a malicious site, the gateway blocks the attempt and shows an explanation page. In the opposite direction, downloads are scanned for malware before a user can open a contaminated file.
The same infrastructure can be configured as a data-loss prevention layer. Administrators can build rules that flag uploads containing personal information or patterns specific to their operations. Policies can prevent accidental or malicious data exfiltration while restricting uploads to sanctioned destinations.
Built for teams without IT departments
The groups served by Project Galileo focus on journalism, artistic expression, human rights, and other causes with small budgets. The state and local governments in the Athenian Project work to protect U.S. elections. Neither has the resources of a Fortune 500 company to staff a dedicated IT security team.
Cloudflare One is designed to be configured and deployed in hours, not months, with policies that non-specialists can manage. Teams interested in getting started can lean on Cloudflare's Zero Trust Roadmap for guidance on the first, highest-impact steps and the expected time investment for each.
Existing qualified organizations can begin using Cloudflare One immediately. Teams that do not qualify but want to deploy the same Zero Trust controls can sign up at no cost for up to 50 users.



