A steward for your Cloudflare fleet.
Ask a question in plain language. See the answer across every zone you manage. Approve the fix, and let the server prove it landed. Nothing writes without you.
157 points of presence · …
Bright points are colos that served this zone; the arcs are the requests that missed cache and reached the origin. Load this page and the colo that served you lights up — the globe gets busier the more people are looking at it. Intensity is relative to the busiest colo in the window, never a raw request count.
Cloudflare's dashboard assumes one zone and one expert.
You have neither. You have forty zones across six clients and a support queue.
No single view
One dashboard per zone. To learn who is under attack you open forty tabs, or you don't look at all.
Answers take an afternoon
"Why is this site slow in Europe?" has a GraphQL query behind it that nobody on the team is going to write.
Changes are frightening
A WAF rule on a client's production site, typed at five o'clock, with no preview of what it blocks and no way back.
Create IP access rule
Challenge 34.165.86.164 — attacker: secrets & config scan
Structurally unable to touch your zones.
Not a policy, not a system prompt. Every function that can change Cloudflare is reachable from the execution core alone, so a prompt injected through a request path or a user agent cannot cause a write.
- Impact classified before you see it
Low, medium or high. A site-wide lockdown or an apex DNS deletion needs an explicit acknowledgement, not a click.
- Blast radius against real traffic
The proposed rule is evaluated against your last 24 hours before it exists, so you know what it would have blocked.
- Read back from Cloudflare
"Applied" means the server asked Cloudflare what the setting is now and received the answer it expected.
- Reversible, with the payload stored
Every change lands in the audit trail together with the instructions to undo it.
Ask the question you'd actually ask.
Nine attack categories, a composite severity score, and a classifier tuned hard against false positives, so a theme fetching its own assets is never called a CMS probe.
Scanning for exposed credential and config files — 39 distinct paths — 100% rejected.
Priced per workspace, by zones.
Every tier includes everything. No security feature is held back for a higher plan.
| Plan | From general availability | Included |
|---|---|---|
| Studioup to 25 zones | $49/mo | 3 members. Chat, globe, investigation, approvals, audit, alerts. |
| Agencyup to 100 zones | $149/mo | 10 members. Everything in Studio, plus client share links. |
| Fleet100+ zones | Talk to us | Unlimited members. Everything, plus priority support. |
Free during the beta, then 50% off your first year, locked. You bring your own Cloudflare token and Anthropic key, so model usage is billed to you by Anthropic at cost. We do not mark it up.
Twenty seats. Yours if it fits.
Free for the whole beta, then half price for your first year, locked. Two minutes of questions about what you run and what goes wrong, and if it's a fit you get a workspace.