Provider evidence
Cloudflare One
Rather than building a security platform and adding network reach, or building a network and adding security, Cloudflare started as one of the internet’s largest content-delivery and DDoS-mitigation networks (founded 2009, public since 2019 on NYSE: NET) and extended that same global infrastructure - every product running in every data centre, not routed to a handful of regional security hubs - into a full SASE platform.
Technology vendor · UK entity not yet reviewed
Evidence profile: Sector evidence not yet reviewed; platform
Research only
https://www.cloudflare.com/saseThese capabilities use the same evidence as the provider shortlist and matching. A missing finding is not evidence that a provider lacks the capability.
Capability evidence
| Capability | Finding | Evidence and qualification |
|---|---|---|
| Fully managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| DIY / self-managed model | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Co-managed service | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-tenant MSP / white-label support | Partial | The Cloudflare Tenant API is a provisioning mechanism to help Channel and Alliance partners set up and manage Cloudflare accounts and services for their customers. The Tenant Platform gives partners per-customer account provisioning and delegated administration, which covers tenant isolation. No evidence found on the pages read of branded portals or white-label templates letting an MSP operate the platform under its own brand. Source · Evidence dated 2026-07-29 |
| Professional services and migration support | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| Last-mile circuit management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Lifecycle management | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible commercial model | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Encrypted overlay fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Dynamic path selection | Yes | Native, via the confirmed Argo Smart Routing capability, which dynamically routes traffic across Cloudflare's own network for optimal performance [33] Source · Evidence dated 2026-07-22 |
| Active-active link utilisation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Application-aware routing | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| QoS and traffic shaping | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Packet loss remediation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Local internet breakout | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| MPLS coexistence and migration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cellular and 5G support | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Cloud on-ramp | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Public cloud gateways | Yes | Instead of backhauling traffic through a central data center or maintaining dedicated MPLS circuits at every site, your traffic routes through the nearest Cloudflare data center where security policies apply inline. The enforcement points are Cloudflare's own data centres, not a third party's infrastructure that Cloudflare resells. The SASE page states Cloudflare delivers full SASE from 300+ cities and the network page states 337 cities and 8 regions. Source · Evidence dated 2026-07-29 |
| Private PoPs / dedicated PoPs | Partial | Choose the location of the data centers where your traffic is inspected. The Data Localization Suite offers regional control over which of Cloudflare's own data centres inspect traffic, which addresses sovereignty of the processing location. That remains region selection inside the shared multi-tenant network. No offer of customer-hosted or physically dedicated PoPs was found on the pages read. Source · Evidence dated 2026-07-29 |
| Private global backbone | Yes | Our backbone is a dedicated network, providing guaranteed network capacity and consistent latency between various locations. The same dated vendor post states the backbone comprises long-distance fibre optic cables connecting Cloudflare data centres across North America, South America, Europe and Asia, so it is intercontinental rather than national. Evidence is from a 2021 post; the SASE reference architecture read in 2026 does not use the word backbone. Source · Evidence dated 2026-07-29 |
| Regional breakout and data residency | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Multi-cloud transit fabric | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Flexible edge form factors | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| High availability design | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SLA-backed service fabric | Yes | backed by dependable SLAs, 100% uptime, and reliable service you can trust. Availability and 24/7/365 support commitments are published for Enterprise plans. The underlying contractual SLA document itself was not reachable, as two candidate SLA URLs returned 404, so change handling and latency, jitter and loss commitments could not be verified. Source · Evidence dated 2026-07-29 |
| Integrated next-generation firewall | Yes | Cloudflare One converges core SASE services such as zero trust network access (ZTNA), secure web gateway (SWG), cloud access security broker (CASB), network-as-a-service (NaaS), and firewall-as-a-service (FWaaS). Firewall, secure web gateway and DLP are converged into Cloudflare's own platform and delivered from its network rather than as a separate appliance or a resold third-party stack. Gateway documentation confirms packet-level network policies and full inspection of web request content. Intrusion prevention specifically was not confirmed by a verbatim sentence on the pages read. Source · Evidence dated 2026-07-29 |
| Full SASE platform | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| SSE ecosystem integration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Zero Trust Network Access | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Secure web gateway | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| CASB capability | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Data loss prevention | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Remote user access | Yes | See the published provider record for source context; confirm the scope for your deployment. |
| SOC/SIEM/SOAR integration | Yes | Native, well-evidenced via the confirmed, massive-scale, continuous global threat-telemetry operation (47.1 million DDoS attacks mitigated in 2025, 230 billion threats blocked daily per Cloudflare's own reporting) [33] [10] Not confirmed Source · Evidence dated 2026-07-22 |
| Centralised orchestration | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Customer portal and RBAC | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Observability and digital experience monitoring | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| APIs and automation | Not confirmed | See the published provider record for source context; confirm the scope for your deployment. |
| Managed service assurance | Partial | Award-winning, global, 24/7/365 email and emergency phone support (for Enterprise plans). Round the clock vendor support is published, but no statement was found describing a NOC and SOC proactively monitoring the customer service, owning incidents through to root cause analysis, or running structured service reviews and change governance. Source · Evidence dated 2026-07-29 |