Cloudflare Security PostureSecurity Engineering

Overview

  • ExecutivePosture at a glance
  • EstateCross-domain comparison

Detail

  • DomainsPer-zone assessments
  • MethodologyEvidence and limits
Reports
12
Latest window
Jul 25, 2026
Cloudflare Security PostureSecurity Engineering

Overview

  • ExecutivePosture at a glance
  • EstateCross-domain comparison

Detail

  • DomainsPer-zone assessments
  • MethodologyEvidence and limits
Reports
12
Latest window
Jul 25, 2026
⌘K
v1.0 · 30-day window

Methodology

How to read these numbers

Every figure in the assessments carries a provenance label. This page explains those labels, the scope of the evidence, and what the reports deliberately do not claim.

Evidence window ending Jul 25, 2026

Confidence

What each label means

The distinction is load-bearing: a confirmed figure and a derived figure warrant different decisions.

Confirmed

Read directly from a Cloudflare API response or analytics dataset over the stated window. Reproducible from the same query.

Derived

Computed from confirmed figures under assumptions stated at the point of use — bot-score banding, for example. The assumption travels with the number.

Not measured

Named explicitly rather than estimated. Where a rule body or threshold was unreadable, the assessment says so instead of inferring it.

Scope

Boundaries of the evidence

Stated up front so a figure is not carried further than it can support.

Read-only by construction
Assessments were produced from read operations against the Cloudflare API. No configuration was changed, no rule was toggled, and no traffic was generated as part of the review.
One zone per report
Each assessment is scoped to a single Cloudflare zone so its findings stand alone. Estate-level documents compare those reports; they do not re-derive their figures.
A 30-day evidence window
Every figure covers the same trailing 30 days. Shorter-lived events inside that window are visible in volume totals but not isolated.
Ratios exclude unscored traffic
Human-versus-bot shares are expressed against scored traffic only. Cached edge hits never reach the bot engine, and including them would flatten every ratio toward "unknown".
What the reports do not establish
The assessments measure what Cloudflare caught. They do not measure what a second vendor caught independently — which is precisely why the transition plan requires a parallel run before anything is retired.

Presentation layer

What this dashboard does and does not do

This application reads the Markdown assessments and renders them. It does not edit them, generate summaries of them, or convert them to another format on disk. Where the dashboard shows a chart, the chart is a view of the report's own figures — and until the charts are wired to the reports, they are explicitly marked as sample data.

If a number here and a number in a report ever disagree, the report is correct.

Open the report library

Source

Estate and executive documents

Executive report

Cloudflare Estate Protection & DataDome Transition — CTO Report

Jul 25, 2026·13 min read
Estate comparison

Estate-Wide Cloudflare Security Comparison — PeopleFinders Domain Portfolio

Jul 25, 2026·10 min read