← Back
Application Security

Connect, protect, perform — without compromise.

One breach can cost billions. One outage can cost the quarter. One bot army can drain your inventory before you've finished your coffee. Cloudflare blocks the attacks before they reach your code — every layer, every request, every day.

$100K+/hour
revenue loss during downtime — DDoS attacks now peak at 5.6 Tbps, overwhelming traditional scrubbing before you can react
Hours vs. Weeks
attackers weaponize zero-days in hours (Log4Shell, MOVEit) — your patching cycle takes weeks, leaving a critical exposure window
Shadow endpoints
78% of orgs have undocumented APIs handling auth, payments, PII — attackers find them first, automate credential stuffing and exfiltration
explore the layers
DDoS Protection

When the flood comes, you're already behind the dam.

DDoS attacks don't ask permission. They show up in volume, at any layer, at any hour. Cloudflare's network absorbs them automatically — no rules to write, no pages to wake up to. Your origin keeps serving real users while the attack hits a wall it can't break.

Volumetric flood · absorbed at the edge illustrative · the wall doesn't move
attack volume hitting edge 5.6 Tbps
reaching your origin 0 bps
No attack traffic tax Blocked DDoS traffic doesn't create mitigation overage charges — unmetered DDoS protection is included at every plan tier.
58x headroom
329 Tbps network capacity vs. 5.6 Tbps largest attack on record — autonomous mitigation in seconds, zero service degradation
Predictable billing
DDoS mitigation is unmetered — malicious traffic absorbed at the edge doesn't create overage charges. Pay for clean traffic, not the flood.
Full-stack defense
Network (L3), transport (L4), and application (L7) layer protection — comprehensive coverage at every attack vector
Security Rules

Defense in depth — managed by Cloudflare, customized by you.

Layered defense · request → managed → custom → rate-limit → origin → data-scan
Actions per rule: block managed challenge log skip (custom rules)
Managed Rules · Signature-based

We write them. We update them. You stay protected.

Deterministic patterns — regex, string & structural matches — authored by Cloudflare and OWASP.

New signatures ship within hours of a CVE — the network is patched while teams are still triaging.

⚡ Zero-day CVEs (e.g. Log4Shell) Network-wide patch in minutes · industry avg: 60+ days to patch
Custom Rules · Your policy + ML signals

Your rules. ML signals included.

Combine standard request fields — geo, path, headers — with ML-inferred signals like the WAF Attack Score.

  • 1–20 Attack
  • 21–50 Likely attack
  • 51–80 Likely clean
  • 81–99 Clean
The score informs — you set the threshold and choose the action.
Rate Limiting Rules · Advanced

Count what matters. Stop abuse at the edge.

Count by anything: cookie, API key, JA3/JA4 fingerprint, ASN, JSON fields. Each key gets its own budget.

Count only what matters — 4xx-only for credential stuffing, or complexity-based so a GraphQL bomb costs more than a static asset.

🚪 5 logins/min per IP — block 10m Credential-stuffing fraud: $6B+/yr in e-commerce losses (Forrester)
Sensitive Data Detection

Stop the leak before it lands.

Scans response bodies (text, HTML, JSON, XML up to 1 MB) for PII, financial data, and secrets leaving your origin — including responses from cache and Workers.

Detection runs off the response path — zero added latency. Action is always log (the response has already been sent), so you get full visibility into what slipped through your code.

💳 Credit card numbers (PCI) PCI-DSS non-compliance: $5K–$100K/month in fines per merchant (Visa)
Zero engineering lift
Edge-enforced security with no code changes, SDK integration, or application server dependencies
Global in <60s
CVE patches deployed network-wide in under a minute — closing the exposure window before attackers exploit it
Unified control plane
Managed, custom, and rate-limiting rules configured from a single dashboard — no vendor sprawl
Bot Management & AI Crawl Control

Automation isn't one bucket anymore.

Malicious bots get a score. Sessions get verified. AI crawlers get classified by intent — search, agent, or training. Business value gets surfaced. Then you decide what happens: allow, challenge, or block — all at the edge, no code changes needed.

The Bot Score illustrative · every request lands somewhere on 1–99
Bot Score

Every request scored 1–99.

ML + heuristics + behavioral signals Score available as cf.bot_management.score — route into WAF rules, rate limits, or transform rules
Threshold rules, not binary blocks Block=1, challenge 2–29, trust ≥30. Tunable per route, no redeploy
Precursor + JS Signals

Catch what static signals miss.

Precursor: session-based detection Flags early-session abuse patterns before bots reach sensitive endpoints
JS detections + browser fingerprinting Catches headless browsers and proxy farms that pass every static check
Precursor trace tool
BotBase + Verified Bots

Allow the good ones. Block the fakes.

15,000+ bot + AI agent signatures Verified by behavior and detection IDs — not just User-Agent headers
Impersonator detection Reverse DNS classification catches bots claiming to be Googlebot or GPTBot
AI Crawl Control

Classify AI crawlers by intent. Act on each.

Search · Agent · Training Dedicated dashboard — allow, block, or manage each intent category independently
Five focused dashboard areas Overview · Metrics · Security · Optimization · Signals
AI Crawl Control Five dashboard areas — one place to understand and act on every AI crawler hitting your zone
01 Overview Operator snapshot
02 Metrics Volume & trends
03 Security Allow · block · manage
04 Optimization Reduce crawl waste
05 Signals robots.txt · policy
Classify by intent: Search Agent Training
Score abuse
ML + heuristics + behavioral signals on every request — before it reaches your origin
Classify intent
AI crawlers sorted by purpose — search, agent, or training — with policy signal context
Act on value
Allow, challenge, or block by category, score threshold, or business value. No code changes.
AI Application Services

Protect what AI takes. Protect what users send.

Two traffic directions face different risks. Cloudflare gives each direction its own signals, policy, and outcome.

01 · Govern content access

Know which AI crawler arrived—and what job it came to do.

AI Crawl Control turns a generic bot request into a deliberate content decision.

Open AI Crawl Security ↗
OBSERVE

See demand and value

Compare crawlers, operators, paths, bytes transferred, and referral traffic.

WHO IS TAKING?
DECIDE

Separate Search, Agent, and Training

In Security Settings, allow useful discovery while treating agent actions and model training as different jobs.

WHAT IS THE PURPOSE?
ACT

Choose the right outcome

Allow, block, use Redirects for AI Training, deploy AI Labyrinth, or offer Pay Per Crawl and x402 access.

ALLOW · BLOCK · DIRECT · CHARGE
SUPPORTING SIGNALS

Content Signals publish intent; Web Bot Auth verifies legitimate bots; agent-readiness insights and the Analytics API provide evidence. Pay Per Crawl remains a private-beta capability.

02 · Protect the AI endpoint

Turn prompt risk into application security policy.

AI Security for Apps supplies LLM-specific context. Your WAF custom rules and Rate limiting decide what happens next.

IDENTIFY

Mark the prompt endpoint

Save the operation in Web Assets and apply the managed cf-llm label.

WHERE DO PROMPTS ENTER?
DETECT

Understand the risk

Detect Prompt injection, PII in prompts, Unsafe topics, and organization-specific Custom topics.

WHAT DID CLOUDFLARE SEE?
ENFORCE + TUNE

Observe before you block

Validate sampled traffic, then apply a narrow WAF rule or rate limit and tune it with analytics evidence.

WHAT SHOULD POLICY DO?

Four ways Cloudflare detects prompt risk

PROMPT → MANAGED DETECTORS → cf.llm FIELDS → WAF → APPLICATION MODEL

Injection scoringLower score · higher risk

METHODPattern risk

OUTPUT1–99 risk score

Fuzzy PIIEntities inside natural language

METHODEntity recognition

OUTPUTMatched PII categories

Unsafe taxonomyBuilt-in safety categories

METHODFixed S1–S14 taxonomy

OUTPUTMatched categories

Zero-shot topicsSemantic match · No custom training

METHODIntent comparison

OUTPUTScore per custom topic

Cloudflare runs managed scoring, entity recognition, and topic classification. WAF acts on those fields before an allowed request reaches your application model.

cf.llm.prompt.injection_scorecf.llm.prompt.pii_categoriescf.llm.prompt.unsafe_topic_categoriescf.llm.prompt.custom_topic_categories
API Shield

>50% of Internet traffic are API calls — and that's where the breach starts.

APIs run your revenue: checkout, login, payments, partner integrations, mobile apps. They're also the shortest path to your data — machine-readable, often undocumented, and rarely covered by the same controls as your website. API Shield protects the surface your business actually runs on: it discovers every endpoint you have, validates every request that comes in, and stops sensitive data from leaking out — without a single change to your code.

Discover · Validate · Scan illustrative · request in, response out
API Discovery

Find what you didn't know you had.

🔍 Shadow APIs auto-catalogued Shadow & undocumented APIs are the #1 root cause of API breaches (OWASP API Top 10)
🔓 Flag publicly-exposed internal APIs Admin panels, debug endpoints, internal tools — discovered before they're exploited
Schema Validation

Reject what doesn't fit.

📐 Block requests that don't match your OpenAPI / GraphQL schema Stops Broken Object Property Authorization (OWASP API #3) — the spec you already have becomes an edge-enforced firewall
🚫 Block extra or missing fields Stops mass-assignment attacks · zero origin code changes
Sensitive Data Detection

Stop the leak before it lands.

💳 Credit card numbers (PCI) PCI-DSS non-compliance: $5K–$100K/month in fines per merchant (Visa)
🔑 API keys / secrets in responses Avg cost when secrets leak: $4.88M per incident (IBM 2024)
Edge-enforced
schema, auth, and rate checks run at the edge — zero changes to your app
Bring your spec
OpenAPI / GraphQL schemas you already have
Compliance
PCI · HIPAA · GDPR signal coverage out of the box
▸ There's more
Not every rule blocks. Some shape the traffic.
Beyond Security Rules, Cloudflare's Rules family redirects URLs, rewrites paths, modifies headers, sets cache, and runs edge snippets — no app deploy required.
The bottom line

Cyber security is a board-level conversation.
We keep it a quiet one.

One breach. One outage. One wave. The cost is real — and it shows up on the board's agenda. Cloudflare runs every layer of defense at the edge so the next attack stays a non-event, not a headline.

Layered at the edge
DDoS, WAF, Bot Management, API Shield, Edge Rules — all at the edge, zero code changes
Less stack, more security
every layer at the edge means no integration tax, no per-vendor licensing, no finger-pointing during incidents
Always learning
every attack on Cloudflare's network sharpens defenses for everyone — 215B blocked last quarter, all feeding the rules
1 dashboard
DDoS · WAF · Bot Management · API Shield · every layer in one place
Create your Cloudflare account
Sign up, add a domain, and start exploring every layer at the edge.
Get started ↗