For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | cancer diagnostics and genomic testing

Three reasons Veracyte and Cloudflare should talk.

Create a consistent security and performance layer for patient, provider, launch, browser, and email workflows as Veracyte scales new tests and AI-assisted diagnostics.

Cloudflare already protects veracyte.com. Veracyte is entering a launch cycle with 21% Q1 growth, 47,615 tests delivered, and raised 2026 guidance.

DNS / HTTP recon

Cloudflare headers are present on veracyte.com, while the public site links provider ordering and patient payment entry points; the...

CSP / page inspection

The homepage directly loads Five9, TrustArc, Google Tag Manager, YouTube, Facebook, LinkedIn, and other third-party origins; no CSP...

Official company source

Veracyte publicly describes a diagnostics platform using broad genomic and clinical data, AI-assisted data mining, multimodal...

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Protect patient and provider journeys

WAF + Bot Management + API Shield + Load Balancing What Cloudflare does

Use the proven apex deployment as the low-friction starting point to inventory and protect patient/provider entry points.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

02 Business outcome

Control Third-Party Browser Risk

Page Shield + Zaraz + Turnstile What Cloudflare does

Create visibility and policy around scripts touching patient and provider journeys, reduce uncontrolled client-side execution, and add privacy-preserving abuse controls where forms require them.

Bounded pilot

Monitor one high-value journey and move one eligible script or event flow.

Measure

Script inventory, main-thread time, page speed, policy alerts, conversion or completion.

03 Business outcome

Govern Diagnostics Data and AI at the Edge

Workers + AI Gateway + Queues + R2 What Cloudflare does

Explore a governed ingress, asynchronous processing, model-observability, and zero-egress object-storage pattern that augments the diagnostics platform rather than replacing clinical systems.

Bounded pilot

Route one non-sensitive model workflow through the governance layer for 30 days.

Measure

Model requests, token cost, cache rate, policy violations, p95 latency.

01
30-day DiscoverInventory Cloudflare-covered zones, linked patient/provider workflows, WP Engine origin exposure, cache hit ratio, scripts, and bot traffic;...
02
60-day ProvePilot WAF/Bot/API controls and Page Shield on a bounded public journey, then tune caching and origin isolation before Prosigna/TrueMRD...
03
Scale by evidenceUse measured results to evaluate Mimecast consolidation and a compliant Workers/Queues/R2/AI Gateway pattern for selected non-clinical or...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | enterprise AI application software

Three reasons C3 AI and Cloudflare should talk.

Add a security, performance, and governance layer around C3 AI's public and agentic surfaces while preserving its enterprise AI platform, starting with the public web estate and expanding through measured pilots.

Cloudflare can secure C3 AI's Vercel-hosted web estate and agentic ingress while preserving C3 AI as the enterprise AI platform. A leadership reset and an explicit move toward agentic software create a clean control-plane decision point.

DNS / HTTP recon

The apex is served by Vercel and identifies Next.js and Payload in headers; no cf-ray is present.

Official company source

C3 AI publicly markets an agentic AI platform, C3 Code, generative AI, and autonomous execution; public recon did not identify the...

Official company source

A current C3 AI platform role describes Kubernetes-on-customer-cluster patterns across AWS, Azure, and GCP.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Create a Cloudflare Front Door for the Vercel Estate

CDN + WAF + Bot Management + Workers What Cloudflare does

Start with a reversible front-door pilot that adds security controls and edge logic while preserving the existing web platform.

Bounded pilot

Build one non-critical service, telemetry stream, or document workflow with capped volume.

Measure

Unit cost, processing latency, retries, egress avoided, engineering time.

02 Business outcome

Govern the Agentic AI Control Plane

API Shield + WAF + AI Gateway + Enterprise MCP What Cloudflare does

Position Cloudflare around C3 AI, not against it: protect product ingress, authenticate machine clients, observe model traffic, and govern MCP access while C3 remains the enterprise AI system.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

03 Business outcome

Standardize the multi-cloud Kubernetes front door

Load Balancing + WAF + API Shield + Cloudflare Tunnel What Cloudflare does

Offer one ingress, API-security, and traffic-steering pattern across customer-managed clusters without changing C3 AI's application platform.

Bounded pilot

Place one non-critical service or cluster ingress behind the common policy layer.

Measure

Ingress latency, failover time, blocked requests, load balancers retired, SRE hours.

01
30-day DiscoverProxy one low-risk Vercel property, baseline performance and attacks, and validate rollback, cache behavior, and release workflows
02
60-day ProveExtend common policies to www/docs/developer, then migrate authoritative DNS after dependency and DNSSEC review
03
Scale by evidenceWith product-team discovery, pilot API Shield/AI Gateway/Enterprise MCP on a bounded agentic workflow and run an M365 email-security proof in...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | AI-powered programmatic advertising infrastructure

Three reasons PubMatic and Cloudflare should talk.

Reduce edge and control-plane fragmentation around PubMatic's advertising and agentic platforms, then use measured data economics to evaluate deeper infrastructure opportunities.

Cloudflare can collapse visible CloudFront, Akamai, NS1, and Apigee touchpoints onto one global network, reducing latency, policy handoffs, and cost without competing with... AgenticOS, more than 1,000 AI-powered deals, and 94.2 trillion quarterly impressions are raising the cost of fragmentation.

DNS / HTTP recon

CloudFront headers serve the apex, cdn.pubmatic.com points to Akamai edgekey, and authoritative DNS is on NS1.

Official company source

PubMatic reported 94.2 trillion Q1 impressions and 15.5 PB of new data processed daily, demonstrating the scale exposed to...

Official company source

PubMatic's 2022 engineering report documented 10+ production clusters, 1,000+ pods, and 150+ applications; current platform roles...

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Consolidate CloudFront, Akamai, and NS1 at the Edge

CDN + Cache Rules + Cloudflare DNS + Load Balancing + WAF What Cloudflare does

A phased domain-by-domain program can reduce three public-edge control planes while preserving PubMatic's advertising platform and measuring latency and reliability by region.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Protect network ingress from Layer 3 attacks

Magic Transit + DDoS Protection + Network Analytics What Cloudflare does

Start with one announced prefix or network-ingress path to absorb Layer 3 attacks before they consume protected capacity, without changing the advertising platform.

Bounded pilot

Protect one announced prefix or ingress path with documented rollback.

Measure

Mitigation time, attack traffic blocked, clean-traffic latency, protected origin capacity.

03 Business outcome

Reduce the cost of multi-cluster ingress

Load Balancing + WAF + DDoS Protection + Cloudflare Tunnel What Cloudflare does

Centralize external ingress, health steering, and attack absorption before traffic reaches clusters, reducing repeated controls and unnecessary pod scaling.

Bounded pilot

Place one non-critical service or cluster ingress behind the common policy layer.

Measure

Ingress latency, failover time, blocked requests, load balancers retired, SRE hours.

01
30-day DiscoverBaseline CloudFront/Akamai latency, cache, traffic, attacks, and cost; proxy a low-risk hostname and place API Shield discovery ahead of one...
02
60-day ProveExpand successful delivery and API policies, then migrate authoritative DNS with dual-operation and rollback controls
03
Scale by evidenceBenchmark an eligible telemetry/data path on Workers/Queues/R2/Pipelines and govern one bounded AgenticOS/MCP workflow through AI Gateway and...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | chronic pain neuromodulation and medical devices

Three reasons Nevro and Cloudflare should talk.

Secure and simplify Nevro's digital and email estate as Globus Medical integrates systems, processes, and customer journeys across the combined business.

Cloudflare provides an acquisition integration perimeter: one layer for the still-live Nevro web estate, patient and provider journeys, identity-aware access, email security, and... Globus is actively integrating Nevro systems, processes, and metrics while Nevro digital properties remain live.

Public technical evidence

The acquisition is complete; the live Nevro site redirects investor and leadership journeys to Globus, and Globus says Nevro is...

CSP / page inspection

The apex is an nginx service on a DigitalOcean address and the page loads 14 assets from nevro-production.b-cdn.net; no cf-ray is...

CSP / page inspection

The WordPress site serves patient/provider content and links HFX support resources; no CSP header or meta policy was found in recon.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Build an Acquisition Integration Perimeter

Access + Gateway + CASB + DLP What Cloudflare does

Use identity-aware access and data controls to stage migrations and third-party access.

Bounded pilot

Enroll one application and a small employee, partner, or contractor cohort.

Measure

Login success, access tickets, provisioning time, policy blocks, licenses retired.

02 Business outcome

Consolidate Bunny CDN and DigitalOcean Origin Delivery

CDN + Cache Rules + Load Balancing + WAF What Cloudflare does

Place one policy and cache layer in front of the WordPress origin, reduce origin exposure, and validate whether the separate asset CDN can be retired.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

03 Business outcome

Harden Patient and Provider Web Journeys

WAF + Bot Management + Page Shield + Turnstile What Cloudflare does

Protect forms and healthcare content from automated abuse and client-side script risk while preserving the current regulated content workflow.

Bounded pilot

Monitor one high-value journey and move one eligible script or event flow.

Measure

Script inventory, main-thread time, page speed, policy alerts, conversion or completion.

01
30-day DiscoverJointly inventory Nevro/Globus identities, domains, mail tenants, WordPress dependencies, regional properties, and regulated content owners;...
02
60-day ProvePilot Cloudflare in front of nevro.com with origin lock-down, cache and WAF controls, Page Shield, and measured rollback while preserving...
03
Scale by evidenceMigrate DNS/routing and eligible media, then make evidence-based decisions on Mimecast and Zero Trust consolidation aligned to the Globus...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | construction, civil engineering, and real estate development

Three reasons Obayashi USA and Cloudflare should talk.

Bring the North American web edge, authoritative DNS, and email threat protection into one control plane while preserving Microsoft 365 and supporting Obayashi's transformation goals.

Cloudflare can bring Azure CDN, NS1 DNS, application security, and Microsoft 365 threat protection into one operating plane while leaving Obayashi's applications and productivity... Obayashi's transformation plan calls for productivity gains and re-engineered processes across a $3B+ North American operation.

DNS / HTTP recon

The public www hostname is fronted by an Azure CDN CNAME; no cf-ray was observed during recon.

DNS / HTTP recon

Public NS records identify NS1 as the authoritative DNS provider.

DNS / HTTP recon

MX and SPF records identify Microsoft 365 as the mail platform; no separate email security gateway was visible in public MX records.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Consolidate the North American web edge

CDN / Cache Rules + WAF + Bot Management + Load Balancing What Cloudflare does

Put performance, application security, traffic steering, and origin protection under one policy layer without changing the application first.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Unify authoritative DNS with the application edge

Cloudflare Authoritative DNS + DNS Firewall What Cloudflare does

Reduce control-plane handoffs and manage DNS, application security, and failover from the same global network.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

03 Business outcome

Add pre-inbox protection to Microsoft 365

Cloudflare Email Security What Cloudflare does

Augment Microsoft 365 with phishing, business email compromise, and supplier-impersonation detection while leaving the mailbox platform in place.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

01
30-day DiscoverInventory zones, Azure CDN traffic, origins, mailboxes, and identity flows; pilot one low-risk hostname behind Cloudflare WAF and CDN with...
02
60-day ProveMigrate authoritative DNS after parallel validation, add Email Security ahead of Microsoft 365, and launch one contractor-access application...
03
Scale by evidenceMove production www traffic from Azure CDN after performance and security acceptance, then expand image optimization and Zero Trust policies...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | education technology and digital learning

Three reasons IXL Learning and Cloudflare should talk.

Use Cloudflare's Developer Platform to ship reusable learning services, govern new AI experiences, and consolidate eligible instructional video on Stream.

IXL already uses Cloudflare for its web edge, authoritative DNS, inbound email, and video. More than 18 million students, 200 billion questions answered, personalized learning, and overlapping video paths create clear platform leverage.

Official company source

Cloudflare serves ixl.com, and IXL publicly lists a portfolio spanning personalized learning, tutoring, languages, dictionaries,...

Official company source

IXL publicly centers personalized learning, recommendations, analytics, and its Real-Time Diagnostic for more than 18 million students.

CSP / page inspection

IXL's public CSP exposes Cloudflare Stream alongside Brightcove, Kaltura, and JW Player origins.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Build reusable learning services on the Developer Platform

Workers + Queues + R2 What Cloudflare does

Use Workers, Queues, and R2 to ship shared APIs, event pipelines, and content services close to learners without creating another regional infrastructure stack.

Bounded pilot

Monitor one high-value journey and move one eligible script or event flow.

Measure

Script inventory, main-thread time, page speed, policy alerts, conversion or completion.

02 Business outcome

Govern AI for personalized learning

AI Gateway + Workers AI + Vectorize What Cloudflare does

Add model observability, policy, caching, and retrieval controls for new AI-assisted learning features while preserving IXL's existing recommendation and diagnostic systems.

Bounded pilot

Route one non-sensitive model workflow through the governance layer for 30 days.

Measure

Model requests, token cost, cache rate, policy violations, p95 latency.

03 Business outcome

Consolidate instructional video on Stream

Stream + R2 What Cloudflare does

Benchmark instructional video classes and move eligible encoding, storage, and delivery to Stream while retaining specialized providers where requirements differ.

Bounded pilot

Move one image collection or video class while retaining the current path for rollback.

Measure

Bytes delivered, startup or load time, quality, transformations, cost per asset.

01
30-day DiscoverChoose one shared developer service, one new AI-assisted learning use case, and one instructional video class; define latency, quality,...
02
60-day ProveBuild the shared service with Workers and Queues, route one model workflow through AI Gateway, and compare Stream quality and operations with...
03
Scale by evidenceTurn successful pilots into reusable platform templates, expand AI governance to approved model workflows, and migrate additional eligible...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | digital reference, language learning, and ad-supported media

Three reasons Dictionary.com and Cloudflare should talk.

Unify high-volume content, advertising, account, DNS, and email workflows to improve resilience and simplify shared controls.

Cloudflare is already visible at the web edge and inbound email. Dictionary Media Group reaches 500M+ learners across content, games, apps, and ad-supported experiences.

DNS / HTTP recon

Route 53 nameservers are authoritative while Cloudflare headers and CNAMEs are observable on the web path.

CSP / page inspection

The homepage loads Google Ad Manager, Primis, and Amazon Ads, and the official footer reports more than 500 million learners...

DNS / HTTP recon

cdn.dictionary.com and assets.dictionary.com are public Cloudflare CNAMEs, and the homepage serves article, game, and brand media...

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Unify authoritative DNS and application delivery

Cloudflare Authoritative DNS + DNS Firewall What Cloudflare does

After operational and architectural validation, combine DNS, edge policy, and failover operations and remove an avoidable control-plane split.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

02 Business outcome

Protect ad-supported content from abusive automation

WAF + Bot Management + Turnstile What Cloudflare does

Distinguish useful crawlers and readers from scraping, credential attacks, and non-human traffic that can inflate origin and ad-operations costs.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

03 Business outcome

Optimize the reference-media pipeline

Images + R2 + CDN / Cache Rules What Cloudflare does

Standardize responsive image delivery, cache rules, and zero-egress object storage for eligible media while preserving the editorial and product stack.

Bounded pilot

Move one image collection or video class while retaining the current path for rollback.

Measure

Bytes delivered, startup or load time, quality, transformations, cost per asset.

01
30-day DiscoverConfirm ownership and scope of the observed Cloudflare edge and MX paths, inventory Route 53 zones and ad integrations, and baseline bots,...
02
60-day ProvePilot bot controls on selected search or account endpoints, test image optimization on one content class, and route one non-critical event...
03
Scale by evidenceMigrate authoritative DNS after parallel validation, expand successful bot and media policies, and extend email controls only after...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | multifamily real estate investment, development, and property management

Three reasons Essex Property Trust and Cloudflare should talk.

Add a consistent security and performance layer around Essex's resident acquisition experience, then simplify DNS and email controls without forcing an application-platform rewrite.

Cloudflare can wrap Essex's Vercel and Sitecore-backed leasing experience with consistent security and performance, then consolidate DNS, email, and media controls without forcing... Digital leasing supports 63,077 apartment homes and a $1.887B revenue portfolio.

DNS / HTTP recon

Vercel headers and DNS are visible on the public site, which exposes apartment search, contact, and resident entry journeys.

Official company source

The media hostname points to sitecoreproxy.io and the official site publishes image-rich apartment and community experiences.

DNS / HTTP recon

Authoritative NS records use GoDaddy domaincontrol.com nameservers.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Protect the Vercel resident-acquisition edge

WAF + Bot Management + Turnstile + Load Balancing What Cloudflare does

Add consistent application security, bot controls, and traffic management in front of the existing Vercel application without replacing Vercel.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Optimize community media at the edge

Images + R2 + CDN / Cache Rules What Cloudflare does

Augment Sitecore with responsive transformations, modern formats, cache controls, and optional zero-egress storage for eligible derivatives and campaign assets.

Bounded pilot

Move one image collection or video class while retaining the current path for rollback.

Measure

Bytes delivered, startup or load time, quality, transformations, cost per asset.

03 Business outcome

Move authoritative DNS off registrar infrastructure

Cloudflare Authoritative DNS + DNS Firewall What Cloudflare does

Place DNS on the same global control plane as application protection and traffic steering, reducing registrar dependency for production operations.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

01
30-day DiscoverBaseline Vercel traffic, bot and form abuse, Sitecore media bytes, DNS inventory, and lead-routing failures; place one campaign or low-risk...
02
60-day ProveExpand WAF and bot policies to public search and forms, test Images on selected community assets, and validate Email Security with the...
03
Scale by evidenceMigrate authoritative DNS after parallel testing, deploy resilient lead-routing components, and retain Vercel, Sitecore, and Mailgun wherever...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | Property and casualty insurance

Three reasons California Casualty and Cloudflare should talk.

Modernize application delivery and email security around policyholder journeys through phased, measurable changes that preserve the existing application architecture.

Cloudflare offers one migration path from the visible Azure Front Door and Mimecast layers to integrated delivery, application protection, email security, and resilient catastrophe... Quote, account, claims, and catastrophe journeys are trust-critical for the affinity groups California Casualty serves.

DNS / HTTP recon

Azure Front Door is identified by both the www CNAME and x-azure-ref response header; no cf-ray was observed on the apex during recon.

Official company source

California Casualty publicly exposes quote and claims journeys, including an online non-customer claim submission path; the private...

DNS / HTTP recon

Microsoft 365 is identified by MX and SPF, while Mimecast is identified by the public SPF record.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Modernize the public edge

Cloudflare CDN + WAF + DDoS Protection + Load Balancing What Cloudflare does

A controlled edge migration can combine delivery, application security, DDoS protection, and traffic steering while preserving Microsoft-hosted origins.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Protect quote, account, and claims journeys

Bot Management + API Shield + Turnstile + Rate Limiting What Cloudflare does

Apply bot, abuse, and API controls to the highest-value customer journeys after endpoint discovery.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

03 Business outcome

Evaluate email-security consolidation

Cloudflare Area 1 Email Security + DMARC Management What Cloudflare does

Run a detection and operational comparison against the identified Mimecast path before any replacement decision.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

01
30-day DiscoverInventory Azure Front Door routes, security policies, traffic, origins, and Mimecast scope; deploy Cloudflare in a non-production or low-risk...
02
60-day ProveMove a low-risk public route, enable managed WAF and DDoS controls, and run Area 1 in evaluation mode alongside the existing mail path
03
Scale by evidenceExpand successful edge controls to quote and claims routes, decide email-security scope from comparative results, and document rollback and...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | Consumer financial services

Three reasons Oportun and Cloudflare should talk.

Simplify application delivery, reduce client-side complexity, and extend consistent controls to customer and workforce workflows.

Cloudflare already fronts oportun.com. Six consecutive profitable quarters and the new Column partnership create a rare change window.

CSP / page inspection

Cloudflare protects the apex while WP Engine and a CloudFront distribution are also visible in headers, CSP, and page assets.

CSP / page inspection

The live CSP and HTML expose a broad client-side set including Medallia, VWO, Amplitude, Tealium, Adobe, Google, Meta, and others.

CSP / page inspection

Cloudinary is identified in both the CSP and loaded page assets while Cloudflare protects the site edge.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Consolidate overlapping delivery layers

Cloudflare CDN + Cache Reserve + Tiered Cache + Argo Smart Routing What Cloudflare does

Extend the web edge to reduce redundant caching paths and simplify delivery while retaining the chosen origin platform where needed.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Reduce third-party script drag

Cloudflare Zaraz + Web Analytics + Page Shield What Cloudflare does

Move eligible tags off the main thread, govern script changes, and monitor client-side supply-chain risk.

Bounded pilot

Monitor one high-value journey and move one eligible script or event flow.

Measure

Script inventory, main-thread time, page speed, policy alerts, conversion or completion.

03 Business outcome

Consolidate image transformation and delivery

Cloudflare Images + Image Resizing What Cloudflare does

A measured image migration can remove a separate transformation and delivery path and keep optimization on the edge.

Bounded pilot

Move one image collection or video class while retaining the current path for rollback.

Measure

Bytes delivered, startup or load time, quality, transformations, cost per asset.

01
30-day DiscoverBaseline cache paths, CloudFront and Cloudinary traffic, client-side scripts, bot events, and identified SaaS access; identify service timelines
02
60-day ProvePilot direct Cloudflare caching for one CloudFront-served asset group and move a low-risk tag or image class to Zaraz or Cloudflare Images
03
Scale by evidenceRetire validated overlap, expand API and bot controls to discovered member flows, and extend identity-aware access and SaaS posture controls...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | Graph database and AI infrastructure software

Three reasons Neo4j and Cloudflare should talk.

Create a simpler global delivery and security plane across application, authentication, origin, and SaaS workflows.

Cloudflare already fronts neo4j.com. Fivefold cloud growth, a $100M GenAI commitment, and the GraphAware acquisition are expanding both traffic and integration surface.

DNS / HTTP recon

Cloudflare fronts the root while CloudFront appears in root headers and the www, auth, assets, and media CNAMEs.

Official company source

A current Neo4j Aura role states the service operates more than 800 Kubernetes clusters across multiple cloud providers.

CSP / page inspection

auth.neo4j.com uses CloudFront, login.neo4j.com uses Auth0, and the public page loads console.neo4j.io; private API topology was...

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Remove duplicate CDN layers

Cloudflare CDN + Tiered Cache + Cache Reserve + Argo Smart Routing What Cloudflare does

Serve eligible web and asset traffic directly through the Cloudflare platform, preserving AWS origins while reducing cache layering.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Create one ingress layer for Aura Kubernetes

Load Balancing + WAF + DDoS Protection + Cloudflare Tunnel What Cloudflare does

Use one global policy and traffic layer ahead of multicloud clusters to simplify ingress, protect origins, and standardize failover.

Bounded pilot

Place one non-critical service or cluster ingress behind the common policy layer.

Measure

Ingress latency, failover time, blocked requests, load balancers retired, SRE hours.

03 Business outcome

Extend edge controls to auth and console APIs

API Shield + Bot Management + DDoS Protection + Rate Limiting What Cloudflare does

Inventory and protect authentication and console-facing APIs at the edge with schema, mTLS, abuse, and rate controls suited to a global developer platform.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

01
30-day DiscoverMap Cloudflare and CloudFront hostnames, cache behavior, AWS ALB origins, auth and console flows, and current edge policies
02
60-day ProveMove one assets or media hostname from layered CloudFront delivery to direct Cloudflare delivery and test API controls on a non-critical endpoint
03
Scale by evidenceRetire validated CDN overlap, protect selected auth or console APIs, pilot private origin connectivity, and start one AI Gateway governance test
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | Synthetic biology and genomics

Three reasons Twist Bioscience and Cloudflare should talk.

Modernize global application delivery and unify DNS, API, ecommerce, image, and email protection around Twist's digital ordering experience through bounded migrations.

Cloudflare can replace the visible Akamai delivery layer and unify DNS, API, ecommerce, image, and email protection around Twist's global ordering experience through bounded,... Customers increasingly enter Twist through catalogs, codon tools, ecommerce, and APIs.

DNS / HTTP recon

www and images use Akamai edgekey CNAMEs, the apex is in Akamai address space, and no cf-ray was observed during recon.

CSP / page inspection

api.twistbioscience.com is public, and the homepage loads ecommerce.twistdna.com, catalog.twistdna.com, and...

DNS / HTTP recon

The domain's authoritative nameservers are Amazon Route 53 awsdns hostnames.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Modernize global application delivery

Cloudflare CDN + WAF + DDoS Protection + Load Balancing What Cloudflare does

A phased route migration can consolidate delivery and application security while preserving current origins and customer-ordering applications.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Protect API and ordering workflows

API Shield + Bot Management + Turnstile + Rate Limiting What Cloudflare does

Discover schemas and traffic first, then apply mTLS, schema validation, bot, and abuse controls to selected order and integration endpoints.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

03 Business outcome

Unify DNS and application delivery

Cloudflare Authoritative DNS + DNSSEC + Load Balancing + Health Checks What Cloudflare does

Move DNS through a staged secondary or delegated approach, then manage traffic steering and application security from one control plane.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

01
30-day DiscoverInventory Akamai properties and service commitments, Route 53 zones, origin dependencies, API and ordering endpoints, image traffic, and...
02
60-day ProveProxy a low-risk content or image route through Cloudflare, import DNS records without changing authority, test API discovery, and run Area 1...
03
Scale by evidenceMove validated www or image traffic, stage authoritative DNS cutover with rollback, enable selected API controls, and decide email-security...
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | AI-first governance, risk, and compliance software

Three reasons MetricStream and Cloudflare should talk.

Unify authoritative DNS with application security, email protection, client-side risk controls, and governed AI delivery.

Cloudflare already provides MetricStream's authoritative DNS. MetricStream's May 2026 release added assistants, semantic search, document reasoning, and AI-assisted workflows for 1M+ professionals.

DNS / HTTP recon

Cloudflare provides authoritative DNS, while the apex is delivered by Pantheon and Varnish without a cf-ray header.

Public technical evidence

MetricStream's May 2026 product update describes embedded assistants, semantic search, survey autofill, and document reasoning...

DNS / HTTP recon

Microsoft 365 is the inbound mail platform; SPF also authorizes HubSpot, Salesforce, and OpenAir senders.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Unify DNS and public application security

Cloudflare CDN + WAF + Bot Management + DDoS Protection What Cloudflare does

This is a low-friction next step: preserve Pantheon as origin while adding one security and delivery control plane at the edge.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Govern the AI-first GRC model layer

AI Gateway + Workers AI + Workers What Cloudflare does

AI Gateway can centralize model observability, rate controls, caching, and provider policy while Workers AI offers an additional inference path for suitable workloads.

Bounded pilot

Route one non-sensitive model workflow through the governance layer for 30 days.

Measure

Model requests, token cost, cache rate, policy violations, p95 latency.

03 Business outcome

Unify inbound email defense and sender governance

Cloudflare Email Security + DMARC Management What Cloudflare does

A single email-security and authentication program can protect Microsoft 365 while reducing spoofing and configuration risk across several authorized SaaS senders.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

01
30-day DiscoverConfirm zones and products currently in use; Measure Pantheon traffic, cacheability, bots, and origin load
02
60-day ProvePilot Cloudflare application security on a low-risk hostname; Run an email-security evaluation against Microsoft 365
03
Scale by evidenceRoute one non-sensitive model workflow through AI Gateway; Benchmark one document pipeline on Workers, Queues, and R2
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | semiconductor memory and AI infrastructure

Three reasons SK hynix America and Cloudflare should talk.

Place a consistent security and delivery layer in front of the Microsoft-hosted web estate, then simplify company-branded DNS and mail controls without disrupting semiconductor operations.

Cloudflare can place one globally consistent security and delivery layer in front of the Microsoft-hosted web estate, then simplify branded DNS, email protection, and partner access... Record 2025 revenue and the $500B+ SK Group and NVIDIA AI initiative are increasing global partner visibility and digital dependence.

CSP / page inspection

The apex is on a Microsoft-owned address and page assets load from Azure Edge; no cf-ray was observed.

DNS / HTTP recon

Public NS lookup returned only ns.hynix.com.

DNS / HTTP recon

Inbound MX records expose a self-hosted antispam and vmail topology; SPF also authorizes Toast.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Put one security edge in front of the Microsoft-hosted website

Cloudflare CDN + WAF + Bot Management + DDoS Protection What Cloudflare does

Cloudflare can sit in front of the existing Microsoft origin and consolidate caching, application security, bot controls, and DDoS protection without requiring an origin migration.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Remove the single observed authoritative DNS dependency

Cloudflare Authoritative DNS + DNSSEC What Cloudflare does

A managed anycast authoritative service can improve external DNS resilience and change control while leaving internal DNS architecture untouched.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

03 Business outcome

Add cloud-native protection ahead of the current mail gateways

Cloudflare Email Security + DMARC Management What Cloudflare does

Cloudflare Email Security can be evaluated as an additional detection layer while the team preserves its current mail-routing requirements.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

01
30-day DiscoverInventory public zones and Microsoft origins; Proxy a low-risk hostname through Cloudflare
02
60-day ProveDesign authoritative DNS migration and rollback; Evaluate Email Security ahead of the current gateways
03
Scale by evidencePilot Workers-based localization or routing; Benchmark an owned image and video workflow
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | enterprise SSD and NAND storage research and development

Three reasons SK hynix Memory Solutions America and Cloudflare should talk.

Unify public web security, email protection, and DNS on Cloudflare, then modernize the public web estate without touching product research and development systems.

Cloudflare can directly consolidate the visible Sucuri, Mimecast, and Network Solutions layers, modernizing SKHMS's public edge and email security while keeping product R&D systems... SKHMS is positioning 245TB NAND storage for AI and cloud data centers while its public stack remains fragmented.

DNS / HTTP recon

The apex explicitly returns Sucuri/Cloudproxy and uses a Sucuri-owned address.

DNS / HTTP recon

Both inbound MX records and the SPF record identify Mimecast.

DNS / HTTP recon

The domain delegates to two worldnic.com nameservers associated with Network Solutions.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Modernize the public edge with one Cloudflare stack

Cloudflare CDN + WAF + Bot Management + DDoS Protection What Cloudflare does

This is a publicly visible migration that can combine web security, CDN, bot controls, TLS, and analytics on one network.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Consolidate Mimecast email protection

Cloudflare Email Security + DMARC Management What Cloudflare does

Cloudflare Email Security is a clean, testable consolidation candidate for phishing, BEC, link, attachment, and sender-domain protection.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

03 Business outcome

Move public DNS off Network Solutions

Cloudflare Authoritative DNS + DNSSEC What Cloudflare does

DNS consolidation creates a common change, security, and observability layer with the replacement application edge.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

01
30-day DiscoverCapture a Sucuri feature and service commitments baseline; Stand up Cloudflare DNS records without changing delegation
02
60-day ProveMigrate authoritative DNS from Network Solutions; Run a Cloudflare Email Security proof of value against Mimecast
03
Scale by evidenceEnable Page Shield monitoring; Rebuild one public section on Workers with managed images
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | engineering and scientific consulting

Three reasons Exponent and Cloudflare should talk.

Unify application delivery, email protection, DNS, and client-side security, beginning with a measured application-edge pilot.

Cloudflare provides a clear consolidation path across Fastly, Proofpoint, Route 53, and client-side media services, beginning with a measurable application-edge migration and... Exponent's 949 technical professionals handle sensitive client, employee, personal, and health information across 90+ disciplines.

DNS / HTTP recon

Fastly appears consistently across CNAME, response headers, and address ownership.

DNS / HTTP recon

Exponent's inbound MX records point to Proofpoint, and the FY2025 10-K reports 1,212 employees.

DNS / HTTP recon

All observed authoritative nameservers are Amazon Route 53 awsdns hosts.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Unify application delivery and security

Cloudflare CDN + WAF + Bot Management + DDoS Protection What Cloudflare does

A controlled hostname pilot can compare cache performance and origin offload while adding integrated application security on the same edge.

Bounded pilot

Proxy one low-risk hostname or route with the current origin preserved for rollback.

Measure

p95 latency, cache hit ratio, origin offload, blocked attacks, operating cost.

02 Business outcome

Evaluate integrated email security

Cloudflare Email Security + DMARC Management What Cloudflare does

Proofpoint is a publicly visible consolidation target; Cloudflare can combine inbound protection, BEC defense, and sender-domain controls.

Bounded pilot

Run a 30-day parallel evaluation for one mail domain or user cohort.

Measure

Detection lift, false positives, analyst time, mailbox cost, user-reported misses.

03 Business outcome

Bring Route 53 DNS into the same control plane

Cloudflare Authoritative DNS + DNSSEC What Cloudflare does

DNS migration can simplify vendor ownership and align zone changes, security policy, and application cutovers with the Cloudflare edge.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

01
30-day DiscoverCollect Fastly service commitments, traffic, cache, and security baselines; Move a low-risk hostname through Cloudflare
02
60-day ProveRun Proofpoint and Cloudflare Email Security in comparative evaluation; Validate mailbox economics with actual counts
03
Scale by evidenceEnable Page Shield in monitor mode; Pilot selected expert videos on Stream
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services
For CIO / CTO / CISO / Chief Product & AI Officers
Executive decision brief | multi-cancer early detection and precision oncology

Three reasons GRAIL and Cloudflare should talk.

Unify DNS, identity-aware access, email protection, browser security, and the planned Epic integration on one network.

Cloudflare already protects grail.com. Galleri volume grew 50% year over year, FDA review is progressing, and broad Epic integration is planned by year-end 2026.

Official company source

GRAIL announced planned Galleri integration through Epic Aura, with broad availability expected by the end of 2026.

DNS / HTTP recon

Cloudflare protects the apex, but authoritative DNS remains on four Amazon Route 53 nameservers.

Official company source

A current GRAIL enterprise AI infrastructure role calls for an internal platform using Amazon EKS, Bedrock, and related AWS services.

What to prove together

Prioritized by business impact and strength of public evidence.

01 Business outcome

Secure the planned Epic integration at the API edge

API Shield + Workers + WAF + Rate Limiting What Cloudflare does

API Shield and Workers can provide schema validation, mutual TLS where appropriate, rate controls, routing, and observability for the planned integration.

Bounded pilot

Discover one bounded API or agent workflow, then enforce schema, identity, and rate policy.

Measure

Discovered endpoints, blocked abuse, policy coverage, origin load, p95 latency.

02 Business outcome

Unify edge delivery and authoritative DNS

Cloudflare Authoritative DNS + DNSSEC What Cloudflare does

Moving authoritative DNS into the Cloudflare platform reduces split administration and aligns zone changes with edge policy and incident response.

Bounded pilot

Import one low-risk zone, validate records, DNSSEC, and rollback before delegation.

Measure

Query latency, availability, change time, failed lookups, retired DNS cost.

03 Business outcome

Govern the new EKS and AI platform edge

Cloudflare Tunnel + Access + API Shield + AI Gateway What Cloudflare does

Build private application access, API controls, and model observability into the platform pattern before usage and cluster dependencies scale.

Bounded pilot

Place one non-critical service or cluster ingress behind the common policy layer.

Measure

Ingress latency, failover time, blocked requests, load balancers retired, SRE hours.

01
30-day DiscoverConfirm current edge and security products, zones, and operating ownership; Document WP Engine origin, cache, WAF, and bot posture
02
60-day ProveMigrate an initial public DNS zone; Extend Email Security across Google and authorized senders
03
Scale by evidenceMap Epic Aura data flows and regulatory requirements; Prototype a non-production API path with API Shield and Workers
BaselineCurrent vendor run-rate + egress/compute + operating hours.
ValueRetired overlap + avoided load/incidents + hours returned.
DecisionAnnualized pilot delta - Cloudflare run-rate - one-time migration cost.
ProtectWAF, DDoS, bot, API and email security
AccelerateCDN, DNS, load balancing and smart routing
ConnectZero Trust, private access and secure networking
BuildWorkers, R2, AI and developer services