Secure your Cloudflare surface
WAF rules in log-only mode, flexible TLS, dangling DNS, and API tokens with global scope. We don’t connect to Cloudflare to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.
Book a Demo[01] What This Surface Exposes
Where Cloudflare goes wrong
Cloudflare goes wrong after incidents: a rule switched to log-only during an investigation is rarely switched back.
- WAF and rate-limiting rules disabled or left in log-only after an investigation
- SSL/TLS mode set to Flexible, leaving the origin leg unencrypted
- DNS records pointing at decommissioned origins, open to subdomain takeover
- API tokens scoped to all zones and all permissions instead of the specific zone in use
- Origin IPs reachable directly, bypassing the proxy and every protection attached to it
[02] What We Secure
What we watch, catch and fix on Cloudflare
On Cloudflare we monitor for silent downgrades in rule posture and test origin exposure from outside rather than inferring it from configuration.
- Rule posture monitored for silent downgrades, which is how protection quietly disappears after an incident
- Dangling DNS detection across every zone, because subdomain takeover is cheap to exploit and easy to miss
- Origin exposure tested from outside, not inferred from configuration
- Token scope and age inventoried against what each integration actually needs
- Certificate and TLS configuration checked against your own standard rather than a generic default
[03] Where It Lands
Where Cloudflare lands in your registers
Every cloud resource we discover becomes an entry in your asset register with an owner, a criticality rating, and its data classification. Access reviews cover the IAM principals attached to it, and the risk register carries the mapping between the asset and the risks it actually carries — so a public bucket is a named risk against a named asset, not a line item in a scan report.
[04] How We Engage
On Cloudflare specifically
On Cloudflare, we restore rule enforcement, correct TLS mode, and remove dangling records under agreed authority. Origin lockdown and token re-scoping across integrations we plan with you to avoid breaking live traffic.
Platform licence
Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.
- Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
- Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
- Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
- Unlimited integrations and unlimited users, with anything missing built within two weeks
Managed service
Every tool you connect through Konfirmity comes under our care, with our team doing the work.
- Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
- Incident response led by us, with containment coordinated with your team
- Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
- Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it
[05] Cloudflare FAQs
Can Konfirmity detect subdomain takeover risk?
Yes, and it is one of the first things we check. Konfirmity scans every zone for DNS records pointing at decommissioned origins, which is the condition an attacker needs for subdomain takeover. These records are cheap to exploit, easy to create by accident, and almost never noticed without automated checking.
What Cloudflare permissions do you need?
Konfirmity needs we use an API token scoped to read zone settings, DNS records, WAF configuration and firewall rules for the zones you nominate. We specifically avoid global API keys, which carry full account access and cannot be scoped, and we will flag any of your own integrations still using one.