Cloudflare adds Vectrix to its Zero Trust stack for SaaS app security

Cloudflare has acquired Vectrix, a security vendor focused on detecting misconfigurations, data exposure, and other risks inside SaaS applications. The Vectrix team will join Cloudflare and its technology will be folded into the Cloudflare Zero Trust platform, with general availability expected later this year.

The acquisition addresses a blind spot that has widened as SaaS adoption has accelerated. IT and security teams now rely on Google Workspace, Microsoft Teams, Workday, Salesforce, and a long tail of other cloud services, each with its own security model. Keeping track of who has access to what—and whether data is inadvertently exposed—across a handful of these tools is a burden most teams are not equipped for.

An API-driven approach to CASB

Vectrix builds what Cloudflare describes as an API-driven Cloud Access Security Broker (CASB). Instead of sitting in the network path, the service connects to organization-approved SaaS apps through OAuth 2.0 or vendor marketplace integrations. That means no agents to install, no network changes, and no performance impact. In practice, the setup is fast enough that Cloudflare says it typically takes less than 15 minutes from account creation to first findings.

Once connected, the service continuously scans for issues and alerts teams to problems such as:

  • Files or folders shared publicly in apps like Dropbox
  • Suspicious user activity, such as permission changes in Workday outside business hours
  • Misconfigurations like publicly accessible Zoom recordings
  • Compliance violations, including unauthorized changes to Bitbucket branch permissions
  • Shadow IT, flagged when employees sign up for unapproved apps with work email addresses

Not all risks are complex. An early Vectrix customer, for example, asked for help detecting public Google Calendars after an employee shared a calendar containing sensitive meeting links and passcodes. The ability to spot and remediate that kind of exposure in a few clicks is precisely the type of workflow the platform aims to support.

Correlating signals across apps

The value of an API-driven CASB increases with the number of integrations a team deploys. With broader coverage, patterns that would be invisible in a single app start to emerge. A user attempting to disable two-factor authentication across multiple SaaS services could signal a need for more security training. A group of users granting sensitive permissions to an unapproved third-party app could indicate a phishing campaign. The more applications under management, the more context the platform provides.

Where CASB fits in Cloudflare Zero Trust

Cloudflare intends to make CASB one component of a unified Zero Trust platform, alongside its existing products: Access for ZTNA, Gateway for secure web gateway, and Browser Isolation. The company outlines several ways these services will reinforce each other:

  • Shadow IT: Gateway can discover which SaaS apps are in use and block unapproved ones, while CASB protects data in sanctioned services.
  • Secure access: Access can enforce device policy for entry into SaaS apps, while CASB verifies the app remains configured for the organization's approved authentication method.
  • Data control: Browser Isolation can prevent copy/paste or printing of sensitive data, while CASB checks that data has not been modified to be shared publicly from within the app.

Early beta access for the CASB functionality is available through Cloudflare's waitlist. Additional details on the acquisition are posted on Cloudflare's blog.