Cloudflare
cloudflare.com
Detected Vendor Stack
Our Apps for Your Stack
Ticket sidebar app for scanning support replies, security responses, macros, and AI claims.
CRM card and workflow webhook for scanning sales/security claims and customer-facing AI language.
Jira-targeted program blueprint exporter with native issue types, epics, components, and story templates.
Enterprise Onboarding
SSO / Identity Provider
SAML 2.0 and OIDC sign-in via your Okta tenant. Works with Okta Universal Directory, lifecycle management, and Okta Verify MFA.
Configured as enterprise OIDC via `org_sso_configs` with your Okta issuer URL, client ID, and secret. SAML support requires tenant-side SP metadata.
Authentication features(7 available · 2 provisioning)TOTP / Authenticator AppPasskeys (WebAuthn)Magic Link / PasswordlessEncrypted Backup Codes+3 more
Users are automatically created in the platform on first SSO login — no manual invitation required. Org membership and role are assigned from IdP attributes.
Automated user lifecycle management — create, update, and deprovision accounts directly from your IdP. Supports Okta, Entra ID, and OneLogin SCIM connectors.
GitHub Signals
CI security tooling
Codebase
AI repos
AI Attack Surface
agents.cloudflare.com → 104.18.5.191 (+1)
ai.cloudflare.com → 104.18.11.114 (+1)
api.cloudflare.com → 104.19.192.29 (+5)
labs.cloudflare.com → 104.18.8.81 (+1)
Website Tech Stack
Job Posting Intelligence
Trust Scanner
0
Public Surface
0
AI Language
0
Legal Clarity
0
Security Trust
38
Consistency
100
Remediation Opportunity
Trust Scanner · ATG Scorecard
Cloudflare · public trust surface
Public trust surface scored 6 with 61 positive detectors out of 99 across 23 pages. Higher remediation scores mean more visible work remains.
6
weak
Public Surface
Whether trust, legal, security, AI, methodology, and contact surfaces are discoverable and coherent.
0% signal
AI Language
Whether AI claims are specific, bounded, and tied to engineering evidence rather than generic positioning.
0% signal
Legal Clarity
Whether privacy, terms, contract, data-processing, and customer-facing boundaries are clear enough to review.
0% signal
Security Trust
Whether public trust artifacts explain controls, evidence, limitations, and escalation paths without oversharing.
0% signal
Consistency
Whether public claims, caveats, service language, and trust artifacts agree across the site.
38% signal
Remediation Opportunity
Whether the public surface makes the next improvement work obvious, scoped, and evidence-backed.
100% signal
Public-signal caveat
Based on public website signals and observed artifacts, not proof of any organization's internal security maturity.
Observed artifacts · 57 of 57
Top finding
highMissing Secure SDLC
Describe the lifecycle controls that support secure development.
24 more findings
Missing Vulnerability Disclosure
Publish the disclosure path and safe-harbor terms together.
Missing Security Contact
Expose a clear public security contact or disclosure mailbox.
Missing Security Whitepaper
Provide a public security whitepaper when the product depends on trust-sensitive claims.
Missing Incident Communication
Document how customers are notified and where public incident updates live.
Missing Status Page
Link the status page from the trust surface if it is part of the buyer review path.
Missing Privacy Policy
Clarify what personal data you collect, process, retain, and disclose.
Missing Data Breach Notice
Explain how breach notification works and who is notified.
Missing Subprocessors List
Publish a current subprocessor or vendor list with update cadence.
Missing Model Card or System Card
Publish a model or system card if the site makes substantial AI claims.
Missing AI Evaluation or Safety Report
Provide a public evaluation or safety summary when AI claims are central.
Public claim inconsistency
Align the claim language, then back it with one source of truth and a clear caveat.
Trust center missing privacy policy
Link the privacy policy directly from the trust center and footer.
Missing Footer Cross-links
Add footer links that make trust artifacts easy to reach.
Missing Incident History
If incident history is public, link it clearly from the trust surface.
Missing Postmortems
Document post-incident learning when public postmortems exist.
Missing Attestation Summary
Summarize the attestation in public-safe language and link the source artifact.
Security page missing contact path
Expose a security contact, safe-harbor path, or security.txt reference.
Missing Cookie Preferences
Expose a visible cookie-preferences control if tracking cookies are used.
Missing Data Retention Policy
State how long data is kept and what triggers deletion or archival.
Missing Data Sharing Notice
Clarify which parties receive data and why.
Missing Data Residency Policy
State where data is stored and whether region selection is supported.
Missing Acceptable Use Policy
Clarify prohibited and abusive use patterns in public-facing terms.
Missing Output Moderation Policy
Explain how outputs are filtered, blocked, or escalated.
Missing Unsupported Maturity Phrasing
Ground broad maturity language in observable public evidence.
Dimension maturity
Scanned 2026-07-04 · rules vtrust-scanner-rules.v1 · 25 artifacts probed