Putting cloud misconfiguration guards directly in the API path
Cloudflare has acquired Kivera, a cloud security, data protection, and compliance company, and will fold its technology into the Cloudflare One SASE platform. The addition gives Cloudflare One customers inline, preventive controls for cloud services—blocking misconfigurations before they reach the cloud provider rather than alerting on them after the fact.
The move targets a well-documented weakness in cloud security: most breaches trace back to configuration errors, not provider vulnerabilities. Gartner projects that through 2027, 99% of records compromised in cloud environments will result from user misconfigurations and account compromise. CrowdStrike's 2023 Cloud Risk Report backs that up, showing a 95% increase in cloud exploitation from 2021 to 2022 and a 288% jump in cases where attackers directly targeted cloud infrastructure. In a Thales survey of nearly 3,000 IT and security professionals across 18 countries, 44% reported a data breach, with misconfigurations and human error cited as the leading cause at 31% of incidents.
Kivera's approach is to sit as an intelligent proxy between the customer and their cloud APIs, inspecting cloud API traffic and enforcing policy-based rules on every interaction. That enables several capabilities when combined with Cloudflare One:
- One-click security: Immediate prevention of common breach causes like accidental public access or policy drift.
- Enforced cloud tenant control: Boundaries around cloud resources and tenants keep sensitive data within the organization.
- Data exfiltration prevention: Rules that stop data from being sent to unauthorized destinations.
- Shadow cloud infrastructure reduction: Every interaction with a cloud provider is checked against preset standards.
- Compliance acceleration: Automatic assessment and enforcement of common regulatory frameworks.
- DevOps flexibility: Bespoke controls enforced independently of the public cloud setup and deployment toolchain, limiting vendor lock-in.
- Complementary alerting: Acting as a first line of defense, which reduces the alert volume for teams already using CSPM tools or Cloud Native Application Protection Platforms (CNAPPs).

Why preventive controls matter
Traditional Cloud Security Posture Management (CSPM) tools detect misconfigurations after they occur, flooding security teams with alerts that require time-consuming remediation loops between security and development. On average, it takes 207 days to identify these breaches and another 70 days to contain them. Inline controls change that equation: instead of discovering a misconfiguration in an audit, the policy blocks it at the point of deployment.
The complexity of modern cloud environments makes this particularly valuable. AWS alone offers 373 services with 15,617 actions and 140,000+ parameters, making manual oversight impractical. That complexity is compounded by rapid cloud adoption, decentralized management across teams, CI/CD velocity, and a general shortage of cross-functional security skills.
Several specific vulnerability classes are common attack vectors:
- Unrestricted tenant access: Without limits on approved tenants, IP addresses, and service destinations, data exfiltration becomes easier.
- Exposed access keys: Unencrypted or loosely restricted keys can be exploited to steal or delete data.
- Excessive account permissions: Over-privileged accounts magnify the impact of any single compromise.
- Inadequate network segmentation: Poorly managed security groups let attackers move laterally.
- Improper public access: Services or storage unintentionally exposed to the internet invite unauthorized access.
- Shadow cloud infrastructure: Abandoned or unapproved cloud instances become footholds for attackers.
Where this fits in Cloudflare One
Cloudflare One already provides secure access and data controls for cloud and SaaS apps. Adding Kivera extends the platform's SASE scope from user-facing applications to the infrastructure services themselves. Combined with the earlier acquisition of BastionZero—a Zero Trust infrastructure access company—Cloudflare One now covers both the connection to infrastructure resources and the configuration of those resources' cloud APIs.
All of these inline protections operate with single-pass inspection, which Cloudflare reports is 50% faster than Secure Web Gateway (SWG) alternatives. The unified platform approach also means customers can consolidate IT security tooling, covering cloud control, access management, and threat and data protection in one place.
For enterprises using CSPM or CNAPP tools, the Kivera integration is designed to work alongside rather than replace those products—reducing the noise those tools generate by preventing errors from ever reaching the cloud configuration in the first place.
Cloudflare One gains preventive cloud controls
Cloudflare has acquired Kivera, a cloud security provider, and will fold its technology directly into Cloudflare One rather than offering it as a separate product. The integration is expected to run through the end of 2024 and into early 2025.
The acquisition targets a specific weakness in how many organizations handle cloud security. Traditional cloud-native application protection platforms (CNAPPs) typically identify misconfigurations only after a deployment is live. Kivera's approach is different: its inline controls sit in the path between a developer and the cloud provider's API, validating every configuration change before it's applied. Teams can use policy to block risky settings outright or require manual approval before a change goes through.
That Secure Web Gateway integration is a key part of the plan. By tying Kivera's controls into Cloudflare One, policy enforcement can incorporate user identity and device posture, not just the contents of a particular cloud request. For example, an admin could allow a legitimate configuration change from a known user on a managed device, while flagging the same request from an unregistered user for review.
The aim is a tighter loop between prevention and attack response. Kivera's inline guardrails aim to stop misconfigurations before they reach the cloud provider, cutting down on the alert noise security teams have to triage after the fact. Cloudflare also positions the tooling as useful for meeting compliance and regulatory requirements by enforcing guardrails that prevent configuration drift.
An October 2023 Gartner report on cloud security controls notes that CNAPPs, which largely focus on detection and remediation, haven't fully addressed the misconfigurations that lead to breaches.
Kivera will join Cloudflare and focus on integrating its preventive controls directly into the Cloudflare One platform. Cloudflare is seeking early access testers to provide feedback on the integrated offering.



