Trust as the Product
Cloudflare’s Privacy & Compliance Week begins tomorrow, with a series of announcements aimed at helping customers navigate a growing web of international data rules. For Cloudflare, this focus is not a new initiative but a return to the principle that defined the company from the start.
Before the business had a name, the founders settled on the word "trust" as the crux of their model. The reasoning was simple: if a company routes internet traffic on your behalf, it must be worthy of that responsibility. In the orientation session for new employees, one whiteboard is reserved for the word TRUST, written in capitals and underlined three times. It is the foundation on which the entire operation rests.
Fighting for Customers Early On
That commitment has led to decisions that other companies would not make. In January 2013, shortly after Cloudflare had fewer than 30 employees, the FBI arrived with a National Security Letter requesting information about a customer. The experience was intimidating, and the letter's gag order prohibited discussing it with anyone outside legal counsel.
Cloudflare chose to challenge the request. With the Electronic Frontier Foundation serving as attorneys, the company sued the United States government. It was not until 2017 that the gag expired, allowing the story to be told. The FBI ultimately withdrew the letter, and Congress has since tightened oversight of the law. The lesson, according to the company, is that law enforcement has a proper role, but it must not infringe on the basics of due process. Trust demands a challenge when it does.
Data Privacy as a Default
The same stance governs the commercial side. As the network grew, ad tech companies came calling, offering significant revenue in exchange for cookie-based tracking and retargeting of traffic. Those meetings were frequent in the early years but always ended with the same uneasy feeling. The co-founder's reply was concise: "It's not our data." Selling it would undercut customers who run their own ads and, more importantly, would fail the "creepiness test" of being an invisible service tracking users without consent.
Consequently, Cloudflare views any personally identifiable information passing through its network as a toxic asset. This creates a natural tension for a security company — blocking DDoS attacks requires knowing which IP addresses are hostile. The resolution has been investment in technologies like Universal SSL, Privacy Pass, Encrypted DNS, and ESNI, all of which are designed to keep private data away from prying eyes, including Cloudflare's own.
Privacy in the Company's DNA
The company may have been founded in California, but its perspective was global from the outset. Today, nearly half of its C-level executives are European, including the CTO, CIO, and CFO. This background shaped the first version of the Privacy Policy, written in early 2010 before any customer signed up. The founding document contained the statement: "Cloudflare will not sell, rent, or give away any of your personal information without your consent." While many tech giants have made their policies more flexible over time, Cloudflare has tightened its own. It holds to a list of positions it has never taken:
- Never turned over its own or customers' encryption or authentication keys.
- Never installed law enforcement software or equipment on its network.
- Never provided law enforcement with a feed of customer content.
- Never modified customer content at the request of a third party.
- Never altered DNS response destinations at the request of law enforcement.
- Never weakened, compromised, or subverted its own encryption.
For many companies, GDPR compliance was a struggle. For Cloudflare, it was comparatively straightforward because the regulation's core tenets — transparency and respect for personal data — were built in from the first line of code.
Killing the Cookie
The work, however, is ongoing. One long-standing annoyance was the _cfduid cookie, used since the earliest days for security functions. Its presence meant no Cloudflare customer could truly be cookie-free. Earlier this year, the engineering team was challenged to eliminate it, and this week the deprecation is being announced.
There are other improvements in the pipeline. Cloudflare already operates data centers that aggregate and process log data with geographic redundancy, but some customers want to ensure their data never leaves a specific region. The week's announcements include more granular control over data processing locations. Additionally, ongoing work in encryption and private DNS use — for example, ensuring that no DNS provider can see both who uses the service and where users are going — continues during Privacy & Compliance Week.
A Tool for Local Data Compliance
Customers are also facing more complex legal demands. The EU is expected to propose its new Digital Services Act this month, which will raise compliance standards for companies doing business in Europe. While internet giants may have the resources to adjust, smaller players will find it harder.
The company is responding with the Cloudflare Data Localization Suite, a set of tools giving customers control over where and how their data is processed. This includes improvements to Workers, the edge computing and storage platform, designed to support applications that keep user data within national or regional borders.
The model of shipping every customer record to a single data center in Ashburn, Virginia, regardless of where global users are located, appears dated. In the near term, regulation will likely mandate localized storage and processing. With a network already spanning more than 100 countries, Cloudflare's aim is to be ready for that future.



