Security at Cloudflare: Audits, Transparency, and Incident Response

Cloudflare's security organization operates across three fronts: the expertise of its people, the external validation of its practices, and the transparency of its response to incidents. The goal is to make every interaction with the company's products and infrastructure feel reliable for customers.

Expertise and Continuous Improvement

The security team is responsible for a formally documented, risk-based security program. This includes reviewing and advising on infrastructure changes, identifying and treating vulnerabilities, managing access controls, enforcing encryption for data in transit and at rest, and detecting and responding to incidents. Team members also play an active role in the broader security community through conferences and meetups, sharing knowledge and gathering feedback that feeds back into product improvements.

Validation Through Audits and Certifications

To verify that its security practices meet industry standards, Cloudflare undergoes multiple third-party audits each year. The company maintains compliance with PCI DSS (as both a merchant and service provider), SOC 2 Type II, ISO 27001, and ISO 27701.

With its customer base expanding into more regulated industries, Cloudflare is also pursuing three additional standards this year:

  • FedRAMP: Listed as "In Process" on the FedRAMP Marketplace for an agency authorization at a Moderate impact level. The security assessment report is in its final phase, with an authorization to operate targeted for 2022.
  • ISO 27018: An extension to ISO 27001 that focuses on protecting personally identifiable information (PII) in cloud environments. The third-party assessment is complete; certification is expected within the month.
  • C5 (Cloud Computing Compliance Criteria Catalog): A standard from Germany's Federal Office for Information Security (BSI) that validates cloud services against a defined baseline security level. Third-party assessment is currently in progress.

Transparency as a Response Principle

Commitment to Customer Security

Handling Third-Party Risk

Customers often ask whether incidents affecting third-party vendors impact Cloudflare. Supply chain vulnerabilities such as SolarWinds and Log4j have prompted the company to build automation that sends inquiries to all critical vendors at once. During the containment phase of an incident, the third-party risk team uses this tooling to identify affected vendors and prioritize responses from production and security vendors. Information received from vendors is shared through Security Compliance forums, so other companies inquiring with the same vendors don't have to duplicate the work.

Operationalizing the Audit Process

Recurring audits are not treated as checkbox exercises. The security program is designed as a continuous loop: identify risks, form controls and processes to address them, operate those processes, evaluate their effectiveness through internal and external audits and tests, and make improvements to the information security management system (ISMS) based on those evaluations.

A few practices distinguish Cloudflare's approach from that of other companies:

  • Vendor security is integrated directly into incident response. For Log4j, the Vendor Security Team participated in response calls and provided regular updates on vendor status from the start.
  • Customer communication happens proactively, even when not legally required.
  • Custom-designed automation allows for rapid, bulk distribution of tailored questionnaires to vendors, which is more flexible than standard tools in the space.

Certifications and assessment results are made available to customers for download from their Cloudflare Dashboards or by request to their account team. Ongoing updates on certifications and reports are published on the Trust Hub.