Identity, device posture, network access, web filtering, data protection, AI controls — delivered from every Cloudflare PoP, programmable from end to end.
Open the dashboard →Work moved out of the walled castle: users, data, apps, and clouds are everywhere — and every point solution added to chase them made operations slower.
Employees, apps, and data lived inside a walled castle. Dedicated private connectivity led back to the data center, and security enforced at the perimeter.
Storage and compute migrated to cloud, SaaS became core business infrastructure, and remote/hybrid work became normal — while network and security lagged behind.
Teams added SD-WAN, VPN, SWG, CASB, DLP, RBI, WAF, and ZTNA one by one. Risk escalated, agility dropped, and costs rose across old and new stacks.
Cloudflare One consolidates security and networking on programmable cloud-native services that connect users, devices, networks, applications, and data.
Connecting any source to any destination from anywhere, with commodity Internet as the underlay.
The diagram shows what connects. This table answers what to pick.
| On-ramp | Routes what | Identity-aware | Install | Best for | Main limits |
|---|---|---|---|---|---|
| WARP client | Device DNS, HTTP/HTTPS, optionally broader L4 | Yes (per user/device) | Per device (MDM/Intune at scale) | Managed laptops/desktops, full Zero Trust posture | Needs client; HTTPS inspection requires root cert + TLS decrypt |
| DNS location | DNS only | Network/source-IP based | None | Offices, branches, simple DNS filtering | No HTTP inspection; no per-user context by default |
| Proxy endpoint (PAC) | Browser HTTP/HTTPS via PAC | Yes (auth endpoints) | Browser/PAC config, no agent | VDI, locked-down endpoints, legacy proxy migration | Browser only; no UDP, no HTTP/3, no non-browser apps |
| Cloudflare Mesh | Subnet/network traffic, server-initiated | Network-level | One Linux gateway per subnet | Servers, IoT, routers, whole subnets — no per-device install | Not per-device endpoint visibility |
| Cloudflare WAN | Whole-branch / whole-DC L3 | Network-level | Router/appliance via IPsec, GRE, or CNI | Branch offices, data centers, site-to-site | Network-level context; CNI requires a provisioned interconnect |
Each deep page separates configured account evidence from documented capability and planned proof paths, so the demo never overstates what is live.
Verify identity + device + context. Grant access to one app, not the network. Augments or replaces VPN.
$ EXPLORE ZTNA → SWGCyber threat defense at DNS, network, HTTP, and egress layers. Block phishing, ransomware, and shadow IT.
$ EXPLORE SWG → RBIRisky web content executes in Cloudflare — never in the user's browser. Protect data-in-use without sacrificing UX.
$ EXPLORE RBI → CASBMultimode CASB — inline + API + SaaS posture in one engine. Surface shadow IT and prevent exfiltration.
$ EXPLORE CASB → DLPPredefined + custom profiles, Exact Data Match, and Microsoft Information Protection labels — inline and at rest.
$ EXPLORE DLP → AI SECDiscover workforce AI, protect application-to-model traffic, and govern the tools agents can reach.
$ EXPLORE AI SECURITY → EMAILAdd phishing, BEC, malicious-link, and campaign-response controls around Microsoft 365 or Google Workspace.
$ EXPLORE EMAIL → DEXEnd-to-end visibility into how users actually experience your apps — endpoint, network, and app-layer telemetry in one view.
$ EXPLORE DEX →Start with one high-value path, prove policy and visibility, then expand across users, apps, data, branches, and clouds.
"Securing Cloudflare with our own services is the most effective way not only to protect our business, but also to innovate for our customers."