← Back to Cloudflare One
AI SEC

AI Security

Govern workforce AI, model traffic, and agent tools at the boundary each path actually crosses.

One network · three AI boundaries

Three AI traffic paths. Three places to protect them.

Model traffic flows through Cloudflare AI Gateway; workforce AI flows through the SASE / SWG layer; agents reach tools through MCP server portals. Same network, three different control points.

Note — AI Gateway (apps → models) and SASE / SWG (employees → SaaS AI) are different Cloudflare products — both say "gateway" in places, but they are distinct.

01Live demo · model traffic

Point every client at one governed front door.

One front door for every model call — chat UI, curl, or coding agent. AI Gateway handles routing, safety, DLP, caching, budgets, and logs as config, not app code.

Human lane: the Chat UI Worker page is Access-protected by one-time PIN email and injects the Run token server-side. Machine lane: curl and coding agents skip the Worker and call the Authenticated Gateway directly with the Run token. The raw gateway URL is not a bypass — the token is enforced on every call.

01
One door, every client

Chat UI, curl, or coding agent — all through the same gateway. Same routing, guardrails, and logs. The only code is the front-door Worker.

02
Config, not code

Routing, rate limits, DLP, Guardrails, caching, budgets — all dashboard toggles. Identity decides the model roster via metadata.useremail.

03
Logs tell the full story

Identity, model, cost, cache status, Guardrails result — all live in AI Gateway logs, with payload logging off by default.

Guided runbook

Stand up the governed front door

~15 min · 0 lines of app logic · dashboard toggles
CONFIGURE

Gateway in path

1 click Create the gateway, then point every client at it. The only code change is the base URL:

api.openai.com → gateway.ai.cloudflare.com/v1/…/compat
APPLY

Turn on controls

toggles Routing, fallback, Guardrails, DLP, caching, budgets — dashboard config, no code, no redeploy.

VERIFY

Read the logs

instant Identity, model, cost, cache, Guardrails result — live in AI Gateway logs and User Insights.

MAKE IT MANDATORY

Force the door

SASE Block direct AI access so employees can only use this sanctioned path. See workforce AI ↑

02Capability · workforce AI

Discover and sanction workforce AI before writing policy.

Gateway shows which AI SaaS employees use. Administrators classify those applications, then apply the least disruptive control to the action and data at risk.

Open Zero Trust insights ↗
Guided runbook

Build and verify a workforce AI control

CONFIGURE

Route and decrypt

Enable Gateway HTTP filtering, install the Cloudflare root certificate, and apply TLS decryption to supported AI applications.

EXAMPLE CONTROL

Stop sensitive prompts

Create an HTTP policy where application is Claude, operation is SendPrompt, and the DLP profile matches Credentials and Secrets.

VERIFY

Prove the decision

Submit harmless synthetic data, then confirm the block page and matched DLP profile in Gateway HTTP logs.

BOUNDARY

Transit is not posture

Gateway governs traffic in motion. Connect CASB separately for sanctioned OpenAI, Anthropic, Gemini, or Copilot tenant posture and data at rest.

03Configured · agents and tools

One MCP portal connects agents to two attached tool servers.

MCP server portals govern agent entry and tools. Code Mode is a portal capability—not a network hop; each upstream uses OAuth, Gateway routes upstream traffic, and response DLP watches data returning from tools. Use standard sensitive-data profiles because AI prompt profiles do not apply to portal traffic.

Open MCP dashboard ↗
01
Portal entry

OpenCode connects through the opencode-team-access Access application to the Access-protected OpenCode Worker that hosts the portal. Code Mode is enabled in the dashboard.

02
Attached upstreams

Cloudflare DEX MCP is READY with 18 tools; Atlassian is READY with 31 tools.

03
Protected return path

Gateway routing is enabled. Response-side DLP blocks Credentials and Secrets from the configured upstream hosts.

Guided runbook

Publish and verify agent tool access

CONFIGURE

Publish one governed endpoint

Add remote HTTP MCP servers, create a portal hostname, and require Access authentication for the portal.

REDUCE SCOPE

Allowlist tools

Select only the tools and prompts each audience needs instead of exposing every upstream capability by default.

VERIFY

Trace each invocation

Connect an MCP client, call an allowed tool, then confirm server, capability, status, and duration in portal logs.

BOUNDARY

Protect the direct URL too

A portal policy does not protect an upstream server's direct URL. Secure that endpoint with Access or its own OAuth layer.

Built by Rodrigo Nobre with Cloudflare Workers