Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Cloudflare is the only vendor named a Visionary in 2026 SASE and SSE reports
Cloudflare has been recognized as the only vendor named a Visionary in both Gartner's 2026 Magic Quadrant reports for SASE Platforms and Security Service Edge. The company differentiates itself through unified architecture built on a single global network, contrasting with competitors' fragmented, acquisition-based platforms. Cloudflare emphasizes its leadership in emerging security challenges inc
AI15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Security researchers have identified 15 vulnerabilities in TP-Link devices that highlight significant security risks associated with automated zero-trust network provisioning processes. The findings use TP-Link, a major network device manufacturer, as a case study to demonstrate broader industry concerns about automated device onboarding and configuration.
How we’re rethinking work at Cloudflare with Cloudflare OS
Cloudflare's CIO describes the company's journey building 'Cloudflare OS,' an internal platform that enables employees to safely deploy AI agents while maintaining security controls. The initiative emerged from employee demand to use AI tools for transforming workflows, requiring Cloudflare to balance innovation enablement with data protection and access governance. The platform combines existing
The Agent Access Model
The Agent Access Model (AAM) proposes a new security framework for AI agents that addresses the inadequacies of existing Zero Trust controls designed for human users. Unlike BeyondCorp's identity-based approach, AAM requires authorizing every individual agent action against the specific task scope and accumulated state, rather than trusting the entire task execution. This shift is necessary becaus
Introducing the Cloudflare One stack: agent-powered deployment
Cloudflare has launched the Cloudflare One stack, an agent-powered toolkit designed to automate the configuration, deployment, and management of Zero Trust network architectures. The stack provides AI agents with structured knowledge and tools to handle complex migration tasks from legacy SASE vendors like Zscaler and Palo Alto Networks, reducing implementation timelines from months to hours. Buil
AIRoute public traffic to private applications with Cloudflare
Cloudflare is launching Application Services for Private Origins in closed beta, enabling enterprise customers to route public internet traffic to private applications without exposing them publicly. This capability extends Cloudflare's security, performance, and programmability services (WAF, bot management, rate limiting, caching, Workers) to private origins using existing private network connec
AIAzure IaaS: Defense in depth built on secure-by-design principles
Microsoft Azure IaaS implements a comprehensive security architecture combining defense-in-depth layering with Secure Future Initiative (SFI) principles across compute, networking, and storage infrastructure. Security is engineered from hardware roots of trust through virtualization boundaries, with protections enabled by default including network isolation, encryption, and DDoS mitigation. The pl
SOC 2 Type II in 90 Days — What's Actually Required
The unglamorous control matrix that drives 80% of audit findings.