A federal court in California has handed Cloudflare a decisive win in a copyright case that tested the limits of intermediary liability for infrastructure providers. In Mon Cheri Bridals, LLC v. Cloudflare, Inc., the U.S. District Court for the Northern District of California granted Cloudflare’s motion for summary judgment, finding that no reasonable jury could hold the company liable for contributory copyright infringement merely because its CDN and security services sat in front of infringing websites.

The plaintiffs, an online wedding dress retailer, sued Cloudflare after discovering that other websites had used its copyrighted product photos without permission. Instead of pursuing claims against the website operators or their hosting providers, the plaintiffs aimed at Cloudflare, arguing that the company’s CDN and pass-through security services—most offered for free—materially contributed to the infringement.

A Theory That Didn’t Hold Up

The court rejected the plaintiffs’ theory on several grounds. First, it noted that Cloudflare’s services were not necessary to the infringement and did not “significantly magnify” it. The websites at issue would have functioned perfectly well without Cloudflare in the path, and the company neither hosted the infringing content nor helped users find it.

Second, the court recognized that Cloudflare’s caching services could not have stopped the infringement. As the court explained, “removing material from a cache without removing it from the hosting service would not prevent the direct infringement from occurring.” In other words, even if Cloudflare had purged its cache of the images, the source content on the origin servers would remain untouched and publicly accessible.

The court also took note of Cloudflare’s abuse reporting system, which routes copyright complaints to the hosting providers and website operators who actually have the ability to take infringing content offline. The court found that this process puts copyright holders in the same position they would be in if the websites weren’t using Cloudflare’s services—nothing more, nothing less.

One Statutory Argument Left Unaddressed

Cloudflare had also argued that the Digital Millennium Copyright Act’s safe harbor provisions independently shielded it from liability. The court sidestepped that question entirely, deciding the case solely on the contributory infringement claim. The fact that the court didn’t need to reach the DMCA argument underscores how thin the plaintiffs’ case was on the merits.

The ruling clarifies an important distinction in online intermediary liability: a service that merely improves performance or security for a website does not become responsible for that website’s content violations. That distinction has been a point of tension in copyright litigation, especially given that U.S. copyright law’s statutory damages provisions can produce astronomical awards when content is distributed online at scale. That financial exposure has made infrastructure providers an attractive target for plaintiffs fishing for deep pockets.

Abuse Processes Designed for the Right Actors

Cloudflare’s position has always been that it is not the right entity to police online infringement. The company doesn’t host the content in question, doesn’t aggregate or promote it, and doesn’t help users find it. Its abuse system, therefore, is designed to act as a connector: it takes copyright claims and routes them to the parties with actual control over the content—the hosting providers and website operators.

The court’s ruling affirms that this approach aligns with the legal realities of how different layers of the Internet operate. Not every service provider has the same ability—or responsibility—to address problematic content. The decision could discourage future suits of this nature, which have historically burdened infrastructure providers with disputes between third parties over content they merely pass through.