Languages
use cases
Modernize applications
Modernize security
Modernize networks
CxO topics
Industries
Resources
Engage
products
SASE and workspace security
Application security
Application performance
Networking
plans & pricing
Global services
documentation
Products
Artificial Intelligence
Compute
Media
Storage & database
Plans & Pricing
Partnership Types
Build
Explore
Support
Company info
Trust, Privacy, & Safety
Public Interest
Cloudflare Gateway
How it works
Analyst reports
Use cases
Pricing
Case studies
Product tour
Product guides
Reference architecture
Professional Services
Whitepapers
Webinars
Developer docs
Industry use case
A cloud-native, low-latency Secure Web Gateway (SWG)
With visibility into approximately 20% of the web, Cloudflare’s unmatched network scale protects employee Internet browsing and blocks breach-causing threats.
No more traffic backhauling. Our single-pass inspection is 50% faster than SWG alternatives.
Cloudflare's DNS and HTTP telemetry and threat detection models catch more risks.
Stack in-line Zero Trust services to provide holistic Internet traffic visibility across users, devices, and locations.
Streamline policy building and auditing with predefined categories.
Our Secure Web Gateway runs everywhere in Cloudflare’s global network, letting you inspect traffic wherever employees work.
It also runs in-line with our data loss prevention and remote browser isolation — offering secure browsing with no disruptions.
ANALYST RECOGNITION
“Algolia is growing pretty fast. We needed a way to have visibility across our corporate network without slowing things down for our employees. Gateway gave us a simple way to do that.”
Director of Infrastructure & Security
TOP GATEWAY USE CASES
Protect “work-from-anywhere” users from malware, ransomware, and other online cyber threats.
Defend against cyber threats, enforce acceptable use, and optimize visitor experiences on guest WiFi networks.
Regain full forward-proxy visibility and control over sensitive data and source code across web, SaaS, and private applications.
Free Plan
forever
Best for teams under 50 users or enterprise proof-of-concept tests.
Pay-as-you-go
per user/month (paid annually)
Best for teams over 50 users solving narrow SSE use cases and do not require enterprise support services.
Contract Plan
Best for organizations building toward a full-featured SSE or SASE deployment that also desire maximum support.
Threat Protection
Block by ransomware, phishing, DGA domains, DNS tunneling, C2 & botnet, and more.
Filter by security or content category. Deploy via our device client or via routers for locations.
Control traffic based on source, destination country, domains, hosts, HTTP methods, URLs, and more. Unlimited TLS 1.3 inspection.
Allow or block traffic based on ports, IPs, and TCP/UDP protocols.
Scan uploaded / downloaded files across types (PDFs, ZIP, RAR, etc.).
Detection via our own machine learning algorithms and third-party threat feeds.
All functionality available for IPv4 and IPv6 connectivity.
Create network policies to manage and monitor SSH access to your applications.
Secure connectivity for DNS filtering directly from offices.
Up to 3 locations
Up to 50 locations
Up to 250 locations
Render all browser code at the edge, instead of locally, to mitigate threats. Deploy with or without a device client. Selectively control what activity to isolate and when.
Add-on
Stop phishing and business email compromise.
Apply HTTP policies at the browser level by configuring a PAC file. Apply filters without deploying client software on user devices.
Dedicated range of IPs (IPv4 or IPv6) geolocated to one or more Cloudflare network locations.
Core Capabilities
10 user limit
No user limit
Dependable service level agreements (SLA) for paid plans with 100% uptime and reliable service you can trust.
100% uptime guarantee (SLA)
Support options vary by plan type. Various professional advisory and hands-on implementation services available as add-on to Contract plans.
Community forums and Discord server
Chat and ticket support
Phone, chat, and ticket support; professional services available (add-on)
Zero Trust logs are stored for a varying period of time based on the plan type and service used. Contract users can export logs via Logpush.
Up to 24 hours
Up to 30 days
Up to 6 months; Logpush to SIEM/cloud storage
Securely connects resources to Cloudflare without a publicly routable IP address. Does not require VM infrastructure and has no throughput limitations.
Securely and privately sends traffic from end user devices to Cloudflare’s global network. Enables capabilities like building device posture rules or enforcing filtering policies anywhere. Self-enroll or deploy via MDM.
ZTNA provides granular identity- and context-based access to all your internal self-hosted, SaaS, and non-web (e.g., SSH) resources.
SWG protects against ransomware, phishing, and other threats using L4-7 network, DNS, and HTTP filtering policies for faster, safer Internet browsing.
Provides user-centric visibility into device, network, and application performance across your Zero Trust organization.
Provides network traffic visibility and real-time alerts for unified insights into network activity. Available for free to everyone.
CASB continuously monitors SaaS apps at rest to detect potential data exposure due to misconfigurations or weak posture findings.
Up to 2 read-only API integrations
Unlimited out-of-band integrations (add-on)
DLP detects sensitive data in transit and at rest across web, SaaS, and private apps with controls or remediation guides to stop leakage or exposure.
Limited predefined profiles
Full-featured (add-on)
Log Explorer provides native log storage, retention, and analytics of HTTP and security event logs. Learn more
PRICING
RBI layers additional threat defense and data protection controls across browsing activities by running all browser code on Cloudflare's global network.
Email security helps block and isolate multichannel phishing threats, including malware and business email compromise.
Cloudflare One is our single-vendor SASE platform that converges Zero Trust security services from the plans above with Network services — including Magic WAN and Firewall.
Access Controls
Custom application and private network policies, plus policy tester. Supports temporary authentication, purpose justification, and any IdP-provided auth method.
Protect self-hosted, SaaS, and non-web (SSH, VNC, RDP) apps, internal IPs and hostnames, or any arbitrary L4–7 TCP or UDP traffic.
Authenticate via enterprise and social IdPs, including multiple IdPs concurrently. Can also use generic SAML and OIDC connectors.
Configure contextual access based on IdP groups, geolocation, device posture, session duration, external APIs, etc.
Verify device posture using third-party endpoint protection provider integrations.
Clientless access for web apps and browser-based SSH or VNC.
Privileged SSH and VNC access through in-browser terminal.
Split tunneling for local or VPN connectivity.
Customizable app launcher for all apps, including bookmarks to apps outside of Access.
Service token support for automated services.
Configure local domain fallback. Define an internal DNS resolver to resolve private network requests.
Automate deployment of Cloudflare resources and connections.
Certificate-based auth for IoT and other mTLS use cases.
Data Protection
Set least-privilege policies per application to ensure users only access data they need.
Allow or block uploads / downloads of files based on Mime type.
Allow or block traffic to specific apps or app types.
Add Cloudflare CASB to detect if misconfigurations in SaaS applications leak sensitive data. View full list of supported integrations.
Unlimited out-of-band integrations
Inspect HTTP(S) traffic and files for the presence of sensitive data. Free tier includes predefined profiles like financial info, while full-featured contract plans also include custom profiles, custom datasets, OCR, DLP logs, and more.
Restrict download, upload, copy/paste, keyboard input, and printing actions within isolated webpages and applications. Prevent data leakage onto local devices, and control user inputs on suspicious websites. Deploy with or without a device client.
SaaS App Protection
All access controls, data controls, and threat protection capabilities (as outlined in prior sections) apply consistently across SaaS apps.
Allow traffic only to corporate tenants of SaaS apps. Prevent leakage of sensitive data to personal or consumer tenants.
Review apps your end users visit. Set approval status for those apps.
Integrate with your most-used SaaS apps (e.g., Google Workspace, Microsoft 365) to scan, detect, and monitor for security issues. View full list of supported integrations.
API integrations continuously monitor SaaS apps for suspicious activities, data exfiltration, unauthorized access, and more.
Identify inappropriate file sharing behaviors within your most used SaaS apps.
Discover misconfigurations and incorrect user permissions within SaaS apps. Immediately action surfaced security findings with step-by-step remediation guides.
Stop phishing and business email compromise with Cloudflare’s email security.
Visibility
On contract plans, DNS logs are stored 6 months, and HTTP and network logs for 30 days.
24 hours
30 days
6 months
Comprehensive details for all requests, users, and devices, including block reasons. Block policy decisions are stored for a week, and authentication logs for 6 months.
Audit logs for the connection status of tunnels and for when a new DNS record is registered for an app.
Track usage and review approval status across applications end users visit.
Full replay of all commands run during an SSH session. Provides SSH visibility at a network layer.
Passively monitor private network traffic to catalog discovered apps and users who access them.
By default, logs will not store any employee PII (source IP, user email, user ID, etc.) and will be unavailable to all roles in your organization.
Provides predictive, historical, and real-time intelligence around application outages, network issues, and performance slow-downs to keep users productive. View capabilities.
Findings are security issues detected within SaaS applications that involve users, data at rest, and other configuration settings. Free tier includes basic findings, while Contract plans include deeper details about each instance.
Top-level findings only
Detailed findings
PII can be redacted from logs for all permission roles except for those specially designated.
Integrations with analytics and SIEM tools like Sumo Logic, Splunk, and Datadog.
Built-in support for one or more storage destinations concurrently including AWS, Azure, Google Cloud, and any S3-compatible API.
Network Performance and Connectivity On-ramps
50 ms away from 95% of the Internet-connected population globally.
Anycast network spanning 330 cities in 125 countries with 388 Tbps of network edge capacity.
13,000 interconnects, including major ISPs, cloud services, and enterprises.
Network architected so that every service operating at the edge is built to run in every data center and be available to every customer.
All traffic is processed in a single pass at the data center closest to its source. No backhauling.
Optimized routes to avoid congestion issues.
Available across all major OSes (Win, Mac, iOS, Android, Linux, ChromeOS).
Default mode sends traffic through WireGuard tunnels to enable the full range of security functionality.
Use DoH mode to only enforce DNS filtering policies, or use proxy mode to filter traffic only to specific apps.
Deploy to your entire device fleet via MDM tools. Or, users can download the device client themselves to self-enroll.
Connect resources to Cloudflare without a publicly routable IP address. Deploy via UI, API, or CLI.
Modernize branch office security with approachable initial steps like location-based DNS filtering.
See how Cloudflare protects users, apps, and networks from multi-channel phishing.
Walk through key capabilities in a simulated dashboard, exploring workflows across 25+ short demo videos.
Cloudflare Gateway is a cloud-native, low-latency Secure Web Gateway (SWG) that protects employees' Internet browsing from threats. It inspects browser traffic without introducing latency by backhauling traffic, since the inspection takes place on the Cloudflare global network. The result is secure browsing without disruptions.
Cloudflare Gateway runs everywhere in Cloudflare's global network, allowing it to inspect traffic no matter where employees are working, without disrupting their work. It also works in-line with other Cloudflare services like data loss prevention (DLP) and remote browser isolation for comprehensive protection.
Cloudflare Gateway is 50% faster than SWG alternatives, blocks both known and unknown threats using advanced threat detection, and provides holistic visibility into Internet traffic across all users, devices, and locations.
Cloudflare Gateway protects against these types of attacks by using proactive filtering and inspection policies across a wide range of security categories.
Gateway is designed to protect users regardless of their location. It can secure distributed remote offices with DNS filtering or more advanced inspections, keeping remote workers safe on the open web.
Someone from Cloudflare will be in touch with you shortly.
In submitting this form, you agree to receive information from Cloudflare related to our products, events, and special offers. You can unsubscribe from such messages at any time. We never sell your data, and we value your privacy choices. Please see our Privacy Policy for information.