Summer 2026
Posted on 2/9/2026
CDN, cybersecurity, and serverless computing platform
No salary listed
Company Historically Provides H1B Sponsorship
Austin, TX, USA
Hybrid
Bachelor's, Master's
| , |
See people who can refer or advise you
Preparing a concise company summary based on the provided Cloudflare description.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salaries
Take-what-you-need paid vacation policy
Comprehensive health plans and benefits
Paid maternity and paternity leave
Commuter and ride share options
Returnships
Palo Alto Networks and Cloudflare are competing for market share in the growing cybersecurity sector, which is projected to grow at an 11.9% compound annual growth rate through 2033. Palo Alto Networks generated $3 billion in revenue during its fiscal 2026 third quarter, whilst Cloudflare posted $696.1 million in Q2. Palo Alto is profitable, though its latest quarter included merger and acquisition expenses. Cloudflare continues to report operating losses. Cloudflare is growing faster at 36% year-over-year revenue growth compared to Palo Alto's 31%, though Palo Alto's growth includes $388 million from recent acquisitions of CyberArk and Chronosphere. Palo Alto trades at a 25 price-to-sales ratio compared to Cloudflare's 41. Palo Alto projected $3.35 billion in Q4 revenue at midpoint, suggesting 12% sequential growth, whilst Cloudflare guided for $736.5 million, implying 6% quarter-over-quarter growth.
Cloudflare says EmDash Version 1.0 is releasing soon. Cloudflare's EmDash CMS, the spiritual successor to WordPress, is set for version 1.0 after successful deployment to their high traffic blog. Cloudflare disclosed that EmDash Version 1.0 is coming soon. EmDash is Cloudflare's modern content management system that is designed to be immune to the kinds of vulnerabilities and performance bottlenecks that have plagued WordPress for decades. Why Version 1.0 is A big deal. A 1.0 release is a big deal because it generally means that the software has progressed from a testing phase to condition where it's trustworthy and ready to deploy in the real world. When EmDash was launched it was described as version "0.1.0 preview" and as an "early developer beta" which meant it was not yet ready to be deployed on a production site. That's coming to an end soon. Cloudflare announced that it has successfully migrated their blog to EmDash. EmDash - The spiritual successor to WordPress. EmDash launched on April 1st, proclaiming itself as the spiritual successor to WordPress, a claim that provoked a strong reaction from WordPress co-founder Matt Mullenweg. At launch, EmDash was nowhere near any kind of successor to WordPress or any other mature content management system because it was still in developer preview and not yet ready for production sites. Cloudflare's initial announcement explained: "WordPress powers over 40% of the Internet. It is a massive success that has enabled anyone to be a publisher, and created a global community of WordPress developers. But the WordPress open source project will be 24 years old this year. Hosting a website has changed dramatically during that time. When WordPress was born, AWS EC2 didn't exist. In the intervening years, that task has gone from renting virtual private servers, to uploading a JavaScript bundle to a globally distributed network at virtually no cost. It's time to upgrade the most popular CMS on the Internet to take advantage of this change. Our name for this new CMS is EmDash. We think of it as the spiritual successor to WordPress. It's written entirely in TypeScript. It is serverless, but you can run it on your own hardware or any platform you choose. Plugins are securely sandboxed and can run in their own isolate, via Dynamic Workers, solving the fundamental security problem with the WordPress plugin architecture. And under the hood, EmDash is powered by Astro, the fastest web framework for content-driven websites." That may change very soon as Cloudflare recently hinted that version 1 was imminent. Screenshot of EmDash perfect CWV score. Cloudflare's successful deployment of EmDash. Cloudflare posted an article to their blog that detailed the blogs migration to EmDash. The migration happened in stages, ending in a full rollout on August 12th. This is a milestone event because it demonstrates that Cloudflare trusts EmDash in a live production environment. The main concern for Cloudflare was whether the blog could scale and rolling it out to their blog was the test that would show whether or not it can work. Cloudflare explained: "Our biggest concerns were whether our proposed EmDash setup could handle the traffic we saw on the Cloudflare Blog. The traffic pattern to our blog is incredibly varied. Normal load sits in the neighborhood of 75 requests per second (RPS), but also spikes up to over 5,000 RPS. Some of these spikes line up with the publishing times of new posts, meaning those posts went viral and attracted a lot of attention. Others happen during all points of the day and night, which likely means folks are sending some extra traffic our way, just to see what happens. Performance also matters for our systems (and our readers). Cloudflare is a web performance company, after all, so the speed at which a page loads becomes incredibly important. ... Ensuring zero downtime for our readers was a non-negotiable requirement, alongside guaranteeing a seamless fallback mechanism if something went wrong at the last minute." Their first test, during Agents Week in the beginning of August went well, serving as many as 450 RPS (request for pages per second) and was able to manage a 28,000 RPS DDoS attack. They admit to discovering there were still some issues on the editing side that needed fixing. The biggest issue was around post scheduling, an issue they expect to be resolved soon. Version 1 rolling out soon. The article ended with a word of thanks to the team working behind the scenes to make EmDash happen and to announce that version 1.0 is coming soon. Cloudflare wrote: "We want to give a heartfelt thank you to the EmDash team, who made this migration about as smooth as possible and were incredibly receptive to our feedback. This is how Customer Zero is supposed to work, and it's incredibly gratifying to share an inside look into that process with all of our readers as well. If you're in the market for a new CMS, try out EmDash today. It's pretty amazing and - with the upcoming launch to v1 - it'll be getting even better soon." The upcoming 1.0 release is an important milestone that moves their spiritual successor to WordPress toward a more mature CMS that Cloudflare has now tested on its own high-traffic blog under real-world conditions.
Gartner Magic Quadrant for Cloud-Native Application Platforms 2026: AWS and Google named Leaders, Cloudflare a Challenger. News | 25.08.2026 Analysis of the Gartner Magic Quadrant for Cloud-Native Application Platforms, August 2026 Gartner has published the Magic Quadrant for Cloud-Native Application Platforms, August 2026, evaluating 12 technology providers across their ability to execute and completeness of vision. Amazon Web Services (AWS) and Google are positioned as Leaders, while Cloudflare is named a Challenger. According to Gartner, cloud-native application platforms provide managed application runtime environments and integrated capabilities for managing application lifecycles in the cloud. These platforms are designed to simplify application deployment and operation by reducing the need for development teams to manage underlying infrastructure and containers. The market is evolving beyond traditional application runtimes. Gartner highlights the growing importance of serverless computing, containerized workloads, AI inference and agentic AI capabilities, integration with databases and developer tools, governance, high availability and disaster recovery. Gartner Magic Quadrant: AWS, Google and Cloudflare. * Leaders: Alibaba Cloud, Amazon Web Services, Google, Microsoft and Red Hat * Challengers: Cloudflare and Oracle * Visionaries: Vercel * Niche Players: Netlify, Render, Tencent Cloud and Upsun Key trends in Cloud-Native Application Platforms. Gartner notes that cloud-native application platforms are increasingly becoming integrated environments that combine infrastructure abstraction, standardized runtimes, governance guardrails and operational controls. For software engineering teams, the key capabilities evaluated in the report include: * Cloud-native runtimes: Managed environments for deploying and running modern applications without directly managing underlying infrastructure. * Serverless and containers: Support for serverless functions and containerized workloads on abstracted infrastructure. * AI and agentic workloads: Capabilities for AI inference, AI application development and agentic AI frameworks. * Developer experience: Tools and services that enable teams to build, deploy and operate applications with less infrastructure expertise. * Governance and operations: Monitoring, observability, cost management, platform engineering and operational controls. * High availability: Automated failover, backup and disaster recovery capabilities for business-critical applications. Gartner also points to the growing importance of multiplatform strategies. Organizations can combine comprehensive cloud platforms with more specialized solutions to leverage different strengths across application architectures. Analysis of vendor solutions. Amazon Web Services (AWS). Position: Leader Amazon Web Services is positioned as a Leader in the Gartner Magic Quadrant for Cloud-Native Application Platforms. AWS provides a broad platform covering serverless functions with AWS Lambda, serverless containers with AWS Fargate, managed application deployment with AWS Elastic Beanstalk and a growing set of AI capabilities. Gartner highlights recent AWS innovations including Lambda Managed Instances for steady-state workloads and Lambda Durable Functions for resilient, stateful orchestration. AWS has also expanded its generative and agentic AI capabilities through agentic developer tooling, Amazon Bedrock AgentCore and AI-driven observability in Amazon CloudWatch. According to Gartner, AWS's key strengths include the breadth of its portfolio across infrastructure, platform and AI layers, support for mission-critical workloads and enterprise-grade operational capabilities. AWS services are designed to support highly scalable and fault-tolerant applications across serverless, container and AI environments. Gartner also notes that the breadth and granularity of the AWS portfolio can increase evaluation and governance complexity for some customers. Organizations may require architecture guidance to manage service dependencies, cost visibility and consistent platform adoption at scale. For organizations looking to modernize applications or build AI-enabled cloud-native workloads, AWS provides a broad foundation covering infrastructure, application platforms and AI services. Google. Position: Leader Google is positioned as a Leader in the Gartner Magic Quadrant. Its offering includes Google Cloud services such as Cloud Run, Firebase and Gemini Enterprise Agent Platform, providing serverless, containerized and agentic deployment options. Gartner also highlights Application Design Center, which helps teams design, standardize and deploy template-driven applications on Google Cloud. The platform combines developer-oriented services with capabilities for application modernization and AI-enabled development. Among Google's strengths, Gartner highlights its open-source-first strategy and alignment with widely adopted technologies including Kubernetes, TensorFlow and Knative. The report also points to Google's partner-led ecosystem and flexible pricing models, including consumption-based, subscription-based and outcome-based approaches. Google's fully managed services, including Cloud Run and Firebase, can help developers and enterprises experiment with and adopt cloud services quickly, supporting rapid prototyping and incremental application development. At the same time, Gartner notes that the breadth of Google's cloud-native and AI capabilities can make the portfolio more difficult for buyers to navigate. Customers may need guidance in determining how Cloud Run, Firebase, Gemini Enterprise Agent Platform and Google AI Studio fit together for different application and AI development scenarios. Cloudflare. Position: Challenger Cloudflare is positioned as a Challenger in the Gartner Magic Quadrant for Cloud-Native Application Platforms. In 2026, Cloudflare expanded its Workers platform beyond lightweight edge functions with Cloudflare Containers and the Agents SDK. Cloudflare Containers support more resource-intensive workloads, custom runtimes and existing container images, while the Agents SDK introduces capabilities for stateful AI agents. Cloudflare has also introduced CPU-time billing designed to charge for active CPU cycles rather than idle time while agents wait for large language model responses. Gartner additionally highlights Cloudflare R2, which eliminates data egress costs, and the Cloudflare Data Localization Suite, addressing requirements around data sovereignty and distributed application architectures. Among Cloudflare's strengths, Gartner highlights its unified Connectivity Cloud architecture, global network and positioning as a neutral multicloud overlay. This approach can help organizations deliver applications, security and edge workloads consistently across heterogeneous cloud environments. Gartner also notes that Cloudflare may be less suitable for complex enterprise architectures requiring deep back-end control, traditional application migration paths or highly customized runtime topologies. Organizations should therefore validate observability, debugging and operational-control requirements for complex modernization projects. What the Gartner Magic Quadrant means for Cloud-Native Application strategy. The Gartner analysis illustrates the increasing convergence of cloud application platforms, serverless computing, containers and AI. Modern platforms are expected not only to run applications but also to support AI inference, agentic workloads, developer automation, governance and operational management. The positioning of AWS and Google as Leaders reflects the breadth of their cloud-native application capabilities and ability to address diverse enterprise requirements. Cloudflare's Challenger position highlights a different approach focused on a globally distributed architecture, edge execution, security and a multicloud application layer. For enterprises, the optimal platform depends on application architecture, AI requirements, infrastructure strategy, operational model, data residency requirements and the level of control required over the underlying environment. A structured architecture assessment can help identify which platform or combination of platforms best fits a particular workload. Build your cloud-native and AI application strategy with softprom. Softprom works with leading cloud and technology providers to help organizations evaluate, design and implement cloud-native application architectures. Its expertise covers cloud migration, application modernization, AI workloads, serverless and container platforms, multicloud architectures and the integration of cloud-native technologies into existing IT environments. Frequently asked questions. Gartner defines cloud-native application platforms as managed application runtime environments with integrated capabilities for managing application lifecycles in the cloud. They enable application deployment and operation without requiring development teams to provision infrastructure or manage containers directly. GARTNER is a registered trademark and service mark, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.
Cloudflare saved login profiles: 5 per device, and 3 docs that never mention them. Cloudflare shipped browser-stored login profiles on 21 August 2026. The docs a security reviewer would read are silent on them. * Read time - 10 min * Word count - 1.6K * Sections - 9 * FAQs - 8 Founder & Director · August 24, 2026 Summary. On 21 August 2026 Cloudflare added saved login profiles to the dashboard sign-in page. A profile stores an email address, a login method and the last-used profile locally in the browser, and a device can hold up to 5 of them. Selecting one prefills the email field for a password login or resumes the associated SSO or social login flow. The changelog post links to exactly two documentation pages. Neither mentions saved profiles. The login page carries a "Last updated Apr 20, 2026" stamp, four months before the change; the dashboard SSO page was updated on 14 August 2026, one week before it. Dashboard SSO is free on every plan tier, from the $0 Free plan to Business at $250/mo billed monthly, so this affects paid and unpaid Cloudflare accounts alike. That gap is the story. A credential-hint cache landed on the authentication path of a control plane that fronts DNS, WAF and Zero Trust policy, and the three pages an access reviewer would open next are silent about it. What actually shipped. The changelog post is short and specific. Cloudflare states that after a successful sign-in, "users can choose to save a login profile on that device. Saved profiles store the email address, login method, and last-used profile locally in the browser." Three details carry the operational weight: Saved profiles appear directly on the login page, before authentication. Selecting one "can prefill the email field for password logins or resume the associated SSO or social login flow." Up to five login profiles can be saved per device, and profiles can be removed from the list at any time. Nothing here is a credential store. The changelog does not claim profiles hold passwords, tokens or session cookies, and eCorpIT found no source that says they do. What they hold is the pairing of a work email address with the authentication method behind it, sitting in browser storage on whatever machine the sign-in happened on. The documentation gap, page by page. eCorpIT fetched the Cloudflare Fundamentals pages that an access review would touch, in Markdown, on 24 August 2026, and searched each for any mention of saved or login profiles. The result is uniform. The dashboard SSO page is the one that matters most, because it is the page the changelog itself points at and because it was edited on 14 August 2026, only seven days before the feature went out. It carries a "Limitations" section listing four things dashboard SSO does not support: plus-addressed emails such as [email protected], a separate email-based policy on the Zero Trust SSO application that does not match the SSO domain policy, multiple Zero Trust domain policies, and deleting the auto-generated allow email domain policy. Saved login profiles are not among them, in either direction. The page neither permits nor restricts them. Cloudflare's own Log in to Cloudflare page still describes exactly three sign-in options as of its 20 April 2026 revision: email and password, Single Sign-On, and social login with Apple, Google or GitHub. A returning user in late August 2026 sees a fourth affordance on that screen that the page does not document. Why this lands harder on SSO-enforced domains. Dashboard SSO at Cloudflare is domain-wide by design, and the docs say so plainly. The enable step carries a caution that enabling SSO for an email domain "will apply globally to all users with that domain, regardless of which accounts those users have access to. All users will be required to authenticate via the specified identity provider, including users registered on Cloudflare prior to the domain being configured for SSO." So the population that can save a profile is the entire email domain, not a team you picked. The prerequisites reinforce how broad that is: you must control the email domain and prove it with a TXT record, public providers such as @gmail.com are not allowed, and every user with that domain must be an employee, which is why Cloudflare excludes university domains like @harvard.edu. You must also be a Super Administrator with API access, and a Cloudflare Zero Trust organization must exist, at any tier including Free. Set the two facts side by side. Enrolment in SSO is an administrator decision applied to every address in the domain. Saving a login profile is an end-user decision applied to one browser. eCorpIT found no documented administrator control that disables, restricts or audits saved profiles for an SSO-enforced domain, and no documented way to see which devices hold one. If such a control exists, it is not on the SSO page, the login page, the roles page or the account security page. The practical shape of the risk is mundane rather than dramatic: a shared workstation, a contractor laptop, a kiosk in a support room. The profile does not sign anyone in on its own. It does tell whoever opens that browser which corporate email addresses administer Cloudflare there, and which identity provider stands behind them. That is reconnaissance handed over before any authentication challenge, and it is the same category of exposure covered in its note on device code phishing controls in Entra, Okta and Google Workspace. Who should care, and how to tell if that is you. Check three things. First, whether your organisation has an enabled SSO connector on a verified domain, which you can confirm from the connector list in the dashboard or the sso_connectors API. Second, whether Cloudflare dashboard access is reached from shared or unmanaged devices anywhere in your estate. Third, whether your browser fleet policy clears site data on exit for dash.cloudflare.com. If the answers are yes, yes and no, saved profiles change your exposure and no Cloudflare document currently tells you by how much. Cost is not the filter here. Dashboard SSO is listed as available on Free, Pro, Business and Enterprise plans, and Cloudflare's plans page shows the Free plan at $0/month, Pro at $25/mo billed monthly, and Business at $200/mo billed annually or $250/mo billed monthly, with the Zero Trust tier free forever for teams under 50 users as of 24 August 2026. A two-person startup on the Free plan gets the same login screen as an enterprise. What to do now. Treat this as a browser-storage question, not a Cloudflare question, because that is where the data sits. Clear existing profiles on any shared device. The changelog confirms saved profiles can be removed from the profile list at any time, which is the only removal mechanism Cloudflare documents. Add dash.cloudflare.com to the on-exit site-data clearing list in your managed browser policy. That is enforceable from your MDM today and does not wait on a Cloudflare feature. Keep the bypass path intact and tested, because it is unrelated to profiles and far more likely to hurt you. Cloudflare documents two ways back in if SSO breaks: add a backup identity provider such as Cloudflare One-time PIN, or disable dashboard SSO. The SSO page also warns that deleting the auto-generated allow email domain policy locks your administrators out of the dashboard entirely. Test the backup IdP before you need it. Re-check the login page in a few weeks. Cloudflare ships documentation and product on separate cadences, which eCorpIT saw again in the Cloudflare One client 2026.7.1343.0 known-issue fork and in the Wrangler optional OAuth scopes gap. The reference page usually catches up. Until it does, the changelog is the only authority on what a saved profile contains. The real cost here is not the feature. It is that an access review run against Cloudflare's documentation in the last week of August 2026 would not know the feature exists. India-specific considerations. For teams operating under India's Digital Personal Data Protection Act 2023, a work email address stored in a browser is personal data held on an endpoint, and the storage sits outside the Cloudflare account boundary an audit usually scopes. Organisations building consumer identity flows face the same question one layer down, which is why eCorpIT cover passkeys versus SMS OTP for Indian WebAuthn migrations separately. The control that matters is endpoint browser policy, and it belongs in the same register as your other device hardening entries. Faq. How eCorpIT can help. eCorpIT is an ISO 27001:2022 certified, CMMI Level 5 engineering organisation, and its senior-led identity teams run access reviews across cloud control planes where the product ships faster than the documentation. eCorpIT map who can reach each console, from which devices, under which identity provider, and eCorpIT design applications aligned with DPDP Act 2023 requirements. If your Cloudflare estate has grown past the point where anyone can name every Super Administrator, book an access review with its identity team.
AI agents got their own browser and a wallet this week. Back to the full index of posts from the shop.All posts Cloudflare built AI agents a browser and a wallet this week, and a critical bug in Ray is a reminder that AI security is mostly boring plumbing work. Cloudflare built AI agents their own browser. Cloudflare shipped something called Kitesurf this week, and it is basically a browser built from scratch just for AI agents. Not a tweaked version of Chrome. A whole new engine, written in Rust, compiled down to WebAssembly, running right inside Cloudflare's Workers platform. It uses somewhere around 3 to 7 times less CPU and memory than Chromium, and it still passes over 235,000 web platform tests. Here is why that matters. Right now if you want an agent to browse the web, click buttons, fill out forms, you are usually spinning up a full headless Chrome instance somewhere. That is heavy. It costs money, it is slow to start, and it does not scale cheap when you have thousands of agents running at once. A lean engine built for exactly this job changes the math on what "an agent browsing the internet all day" actually costs. My take: this is infrastructure most folks will never think about, but it is the kind of unglamorous plumbing that decides whether agent browsing becomes normal or stays a novelty. If Cloudflare's numbers hold up outside a demo, expect other agent products to quietly build on top of this instead of rolling their own browser stack. Now your AI agent can just pay for things. Alongside Kitesurf, Cloudflare pushed out x402, an open payment protocol that lets a server respond with an HTTP 402 status, that is the old "Payment Required" code nobody ever used, and have an agent pay for the resource on the spot. Usually in stablecoin, on chains like Base, Ethereum, or Solana. The agent pays, gets a receipt, retries the request, done. Cloudflare says more than 20 companies are already plugged into this. Why this matters is pretty simple. Once agents can pay for API calls, content, or services without a human clicking approve on every transaction, you get a real economy of machines transacting with machines. That is a bigger deal than another chatbot feature. It is the plumbing for agents actually doing commerce on their own. My take: I like the idea in theory, but handing an autonomous agent a wallet is exactly the kind of thing that goes great until the one time it does not. Spend limits and guardrails better be rock solid before this shows up outside of Cloudflare's demo, because an agent buying way more than it needed is a believable headline six months from now. A nasty bug in the AI framework half of silicon valley runs on. CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17. It is a critical remote code execution flaw in Ray, the open source framework that companies like Amazon, Apple, and OpenAI use to scale their machine learning workloads across clusters. Federal civilian agencies got until August 20 to patch it. That deadline has already passed. This one matters because Ray sits underneath a lot of AI training and inference infrastructure that people never see. When a framework that widely used has an actively exploited remote code execution bug, that is not a niche library problem. It is a crack in the foundation a good chunk of the AI industry is standing on. My take: everybody spends so much time worrying about whether the model itself is safe and not nearly enough time worrying about whether the servers running the model are patched. This is a reminder that AI security is mostly boring, unsexy stuff like dependency management, not some sci-fi alignment problem. Go check if your Ray cluster is patched. Describe the workflow you want gone. Building something similar? Tell Random Llama Software, LLC what your team is burning time on, and Random Llama Software, LLC will tell you if custom software is the fix.