Summary

  • What it says: Cloudflare is no longer just a CDN story. Its strength lies in its attempt to turn edge distribution, security policy, developer execution, and traffic control in the AI era into a single enterprise infrastructure fabric.
  • Main topic: Cloud service dependency; AI infrastructure economics
  • Context: Infrastructure / Company research / Global

The best way to understand Cloudflare is not as a content delivery network that added security features, but as a deliberate attempt to turn edge distribution into a universal control plane for three distinct layers of enterprise infrastructure: public Internet traffic, private user-application access, and developer execution. The company's messaging now reflects this ambition. It describes itself as a "connectivity cloud," claims to run "more than sixty services" on the same global network, and emphasizes a design where every service runs in every data center rather than on separate specialized stacks. This has economic significance.

A provider that can inspect, route, secure, and execute code on the same packet path can sell multiple higher-value controls from an already deployed footprint. In Cloudflare's case, that footprint spans about 335 cities in more than 125 countries according to current corporate pages, while the April 2026 network capacity update described a 500 Tbps network across more than 330 cities in more than 125 countries. Even the slight variations in numbers between pages are telling: the network is vast, constantly expanding, and presented as a living operational surface rather than a static map.

This thesis is also visible in the financial statements. During fiscal year 2025, Cloudflare generated $2.168 billion in revenue, up from $1.670 billion in 2024 and $1.297 billion in 2023. In the first quarter of 2026, revenue reached $639.8 million, up 34% year-over-year, while current remaining performance obligations also increased by 34%.

The number of paying customers grew to over 332,000 at the end of 2025, and large customers generating more than $100,000 in annualized revenue reached 4,298 at the end of fiscal 2025; the investor relations presentation subsequently reported "more than 4,400" large customers and that 42% of Fortune 500 companies were paying customers as of March 31, 2026. These are not the signs of a simple cache utility. These are the signs of a platform that sells more deeply into large organizations while maintaining a very broad self-serve and SMB funnel.

The important and non-obvious finding is that Cloudflare's infrastructural role has become more strategic as the Internet itself has fragmented. Businesses increasingly need a single fabric that can front websites and APIs, manage employee access, connect branches and data centers, terminate bot and DDoS traffic, host application logic near users, and increasingly, support AI inference and agent traffic. Cloudflare is attempting to be that fabric. Its advantage does not lie in the impossibility of copying any single one of these products.

Its advantage is that the company can deliver them over a single edge, a single control plane, and a single customer account. This reduces delivery friction for Cloudflare and integration friction for the customer. That mechanism is at the heart of the company's story.

The central question for investors, therefore, is not whether Cloudflare is a "leader" in a Gartner-style category. It is whether the company can continue to convert its network presence into software stickiness faster than the market commoditizes the underlying delivery. The evidence available so far indicates yes, but with important caveats. Revenue growth remains strong, enterprise penetration is increasing, international distribution is broad, and the platform's scope has expanded significantly.

However, gross margins are under pressure due to the company's investments in servers, network capacity, third-party technologies, and new AI-heavy workloads. Meanwhile, because the platform is shared by design, infrastructure failures and control-plane errors can spread to many services at once. Cloudflare's greatest strength and its greatest risk stem from the same architectural choice: one network, one stack, everywhere.

Business Model and Revenue Logic

Cloudflare's reported revenue still superficially resembles a classic subscription software business. The company states that substantially all of its revenue comes from subscriptions and support services recognized ratably. Customers receive continuous access to Cloudflare's network and products over the contract term, and the associated fixed consideration is typically recognized straight-line.

Yet the 2025 filing also makes clear that usage-based fees are part of the model, and the critical KPMG audit matter explicitly describes revenue as generated from "customers who have entered into contracts or pay-as-you-go arrangements" and consisting of subscription fees, support services fees, and usage-based fees. This is a crucial distinction. Cloudflare is neither a pure per-user SaaS company nor a pure usage-billed network utility. It is increasingly a hybrid recurring-and-usage model, which is exactly what you would expect from a platform spanning security controls, network transport, and developer workloads.

The revenue breakdown disclosed in the 2025 10-K shows how the company is diversifying. Regionally, the United States contributed 49% of revenue in 2025, EMEA 28%, Asia-Pacific 15%, and other geographies 8%. Management further stated that 51% of 2025 revenue came from international customers, up from 49% in 2024 and 48% in 2023. This is not a U.S.-centric software company with incidental overseas sales. It is a globally distributed business whose network proposition and regulatory posture matter in many jurisdictions.

The geographic breadth also explains why Cloudflare invests so much in local presence and data localization features: these are not afterthoughts but prerequisites for enterprise adoption outside the United States.

The customer-type split is equally revealing. In 2025, 74% of revenue came from direct customers and 26% from channel partners, versus 80% direct and 20% channel in 2024, and 84% direct and 16% channel in 2023. This growing partner share suggests an intentional go-to-market climb rather than a temporary anomaly. For Cloudflare, channel expansion can broaden enterprise coverage, improve international reach, and allow the company to penetrate accounts where systems integrators, service providers, or managed security partners control architectural decisions. The evidence proves that the channel is becoming structurally more important.

What it only suggests, without proving, is the margin effect. A larger channel share can accelerate sales efficiency and deal volume, but it can also compress economics if partner discounts rise faster than support leverage. Cloudflare does not publicly disclose channel gross margin, so the exact trade-off remains unknown.

The customer base itself is unusually broad for a company with genuine large-enterprise ambitions. Cloudflare had approximately 332,000 paying customers across more than 190 countries as of December 31, 2025, up from approximately 238,000 a year earlier, while the number of large customers generating more than $100,000 in annualized revenue rose from 2,756 in 2023 to 3,497 in 2024 and 4,298 in 2025. That combination matters. Many infrastructure companies must choose between long-tail self-serve acquisition and a concentrated enterprise go-to-market.

Cloudflare is attempting to keep both: a low-friction entry funnel with free and low-cost tiers, and an up-sell motion that converts a subset of accounts into multi-product enterprise relationships. The fact that 42% of Fortune 500 companies had become paying customers as of March 31, 2026 does not mean those companies are necessarily spending heavily, but it does indicate unusually broad logo penetration.

What Cloudflare does not disclose is just as important. The company does not break out revenue by product line for CDN, application security, Zero Trust, Workers, or AI. Investors therefore cannot directly prove how much of the top line still rests on traditional traffic acceleration economics versus the newer, higher-value software layers. This unknown is one of the most important interpretation gaps in the story.

What the filings prove is that Cloudflare's overall revenue is increasingly enterprise-facing: large customers keep rising, international enterprise reach is substantial, remaining performance obligations stood at $2.496 billion at the end of 2025, and 63% of that amount was expected to convert to revenue within 12 months. But the company's future multiple and strategic leverage will depend heavily on the hidden internal mix between commoditized delivery and higher-switching-cost control products.

The growth profile itself has remained strong by infrastructure company standards. Revenue grew 29% in 2024, 30% in 2025, and Q1 2026 showed 34% year-over-year growth. That acceleration is noteworthy because it came during a period when many enterprise software companies were decelerating under macro pressure. However, the mechanism of that growth matters more than the reported number. Cloudflare's own risk-factor and business-strategy discussions repeatedly reference its ability to retain and upsell paying customers, convert free to paid, expand the number of products sold per customer, and increase sales to large accounts.

That is a bundle-expansion strategy, not a pure traffic-growth strategy. Cloudflare is trying to grow account value by broadening its control over the request path and the customer's infrastructure surface.

The Economics of a Single Network Everywhere

Cloudflare's network architecture is the economic engine of the company, and the core architectural claim is simple: every service runs in every data center, and all customer traffic is processed at the location closest to its source rather than being backhauled to specialized inspection sites. Cloudflare calls this "one network everywhere," notes that single-pass inspection streamlines security, and emphasizes that its global network is interconnected with more than 13,000 service providers, cloud providers, and enterprise networks.

On the public-Internet side, the PeeringDB entry for AS13335 describes the network as a global anycast platform with open peering and automated IX peering available through Cloudflare's portal, while a Hurricane Electric BGP snapshot from June 2026 showed AS13335 announcing 5,543 prefixes and connected to 358 Internet exchange points. These third-party routing statistics are snapshots rather than accounting numbers, but they reinforce the official picture: Cloudflare has an unusually dense edge interconnection.

That interconnection has real economic consequences. In August 2024, Cloudflare stated that backbone capacity had grown by more than 500% since 2021, that it had completed a global backbone loop reaching six continents via terrestrial fiber and subsea cables, and that for intra-city and long-haul connectivity it manages dark fiber or leases wavelengths using DWDM.

The company explicitly argued that using its own backbone to carry cached traffic or to reach origin is often the most cost-effective method at its scale, and that carrying origin responses from AWS, Oracle, Alibaba, Google Cloud, or Azure over its own backbone gives it better control, reliability, and less reliance on the public Internet. This is a strong hint of Cloudflare's internal cost logic. The more traffic the company can carry over its own controlled paths and local peering, the less expensive transit it must buy in the most performance-sensitive parts.

The more important subtlety is that Cloudflare's network is no longer optimized just for caching. A traditional CDN can build a very solid business around storing and serving static content close to users. Cloudflare's architecture is more ambitious. The company asserts that every server runs its developer platform and security services, "not just caching." Workers runs in more than 330 cities by default, uses a CPU-time billing model rather than billing for idle time, and promises no cold starts. Durable Entities combine compute and storage for applications needing strong coordination. R2 offers entity storage with no egress fees.

Workers AI provides serverless inference on GPUs distributed across Cloudflare's network, and current product marketing states that over 50 models run near users across more than 200 cities. In other words, the network is transitioning from a distribution infrastructure to an execution infrastructure.

This shift explains both Cloudflare's strategic advantage and its margin tensions. On the one hand, once a company owns the request path at the edge, the incremental cost of attaching more software logic to that path can be much lower than selling a standalone point product with its own appliance footprint or a separate inspection network. That is especially true for adjacent services such as WAF, bot management, API protection, DNS, smart routing, Access, Gateway, and browser isolation. The packet is already there. Identity decision, security policy, and performance optimization can all happen in the same place.

On the other hand, not all edge workloads have CDN-like economics. AI inference, stateful compute, and storage coordination can be more hardware-hungry and cache-unfriendly than classical reverse-proxy traffic. The network becomes strategically richer, but not necessarily richer in short-term gross margin.

The financial statements confirm that Cloudflare is betting more on physical infrastructure. Capital expenditures reached $315.6 million in 2025, up from $185.0 million in 2024 and $114.4 million in 2023. Management itself presented the figure as representing 15% of revenue in 2025, up from 11% in 2024 and 9% in 2023. Gross property and equipment reached $998.1 million at the end of fiscal 2025, of which $726.8 million was servers and network infrastructure, a sharp increase from $488.8 million the year before. Depreciation of property and equipment rose to $167.5 million in 2025, up from $109.9 million in 2024.

These numbers are large enough to matter. Cloudflare remains a company with a software-like business model, but it is becoming progressively more capital-intensive for network expansion.

Management's accounting decisions provide a useful clue. In 2024, Cloudflare performed a useful-life assessment of servers and networking and extended it from four to five years, reducing 2024 depreciation expense by $21.1 million, primarily in cost of revenue. That tells two stories at once. First, the company believes its infrastructure can remain economically useful longer than previously estimated, which helps support free cash flow and margins. Second, the reported margin optics are somewhat sweetened by the revised depreciation assumptions rather than by operational efficiency alone.

Investors should therefore be careful not to treat the recent gross margin performance as a clean read on underlying network economics without adjusting for the accounting life revisions.

The gross margin pressure is already visible. Cloudflare's GAAP gross margin declined from 77% in 2024 to 75% in 2025, and management attributed the decline primarily to higher third-party technology service costs, higher colocation, network, and bandwidth costs, and higher depreciation from server purchases and deployments. In Q1 2026, GAAP gross margin fell further, from 75.9% in the prior-year quarter to 71.2%. The company did not break out that quarterly movement line by line in the press release, so it would be speculative to attribute it wholly to AI or GPU deployment.

But the evidence demonstrates that Cloudflare's next growth phase consumes more infrastructure cost than the last one. The old assumption that software at the edge scales with near-frictionless margins is too simplistic here.

That said, the company still shows significant operating leverage beneath the stock-based compensation. In 2025, GAAP operating margin was -10%, but non-GAAP operating margin was +14%, steady from 2024 and up from 9% in 2023. Free cash flow reached $260.6 million in 2025, a 12% margin, up from $166.9 million in 2024 and $119.5 million in 2023. The most accurate conclusion is therefore that Cloudflare's network expansion is marginally weighing on GAAP profitability, but the platform as a whole still appears capable of delivering attractive cash conversion if growth stays strong and infrastructure spending does not outpace software stickiness.

Product Strategy: From CDN to SASE and Developer Platform

Cloudflare's product portfolio is no longer organized around a single buyer profile. The company now sells to web teams, security teams, networking teams, and developers, often through the same account. Official product pages group the portfolio into application security, application performance, networking, SASE/Zero Trust, and developer services. On the security and networking side, Cloudflare offers L7 DDoS protection, WAF, API security, bot management, L3/4 DDoS protection, firewall as a service, Network Interconnect, and smart routing.

On the SASE side, Cloudflare One bundles ZTNA, secure web gateway, CASB, network as a service, FWaaS, RBI, DLP, email security, and digital experience monitoring. On the developer side, the company offers Workers, KV, Durable Entities, D1, R2, Vectorize, observability, containers, Workers AI, and AI Gateway. The relevant takeaway is not simply breadth. It is adjacency. Most of these services sit on the same traffic plane, authenticate the same users, or use the same account and network boundary.

Cloudflare's original business was built on easily adoptable web infrastructure: DNS, CDN, SSL, and DDoS protection. That distribution engine remains important. The public pricing page continues to offer a free tier, a Pro tier at $20 per month billed annually, a Business tier at $200 per month billed annually, and an enterprise quote tier for mission-critical applications. Even the free and low-cost tiers include core features such as DNS, unmetered DDoS protection, CDN, universal SSL, and graduated WAF access. That pricing architecture is not just a marketing choice.

It is a customer acquisition system that lowers the initial adoption cost and creates an upsell path. Few enterprise infrastructure vendors can claim both meaningful Fortune 500 penetration and a global self-serve funnel. Cloudflare manages it because it first operationalized distribution at the low end.

The most strategic initiative has been the build-out of Cloudflare One. The company's SASE page describes a platform that connects and protects workforces, branch offices, data centers, applications, and even AI agents over a single connectivity cloud. It emphasizes replacing VPN and MPLS, identity-driven Zero Trust access, deep visibility into generative AI usage, and a single control plane, data plane, and infrastructure layer.

The pricing for Cloudflare Access illustrates how the company tries to land and expand in this segment: a free tier for small teams or proofs of concept, a pay-as-you-go option at $7 per user per month, and custom contract pricing for full SSE/SASE deployments. This is a classic Cloudflare maneuver: use aggressively accessible packaging to install the control plane, then expand the account into larger architectural changes.

The developer platform is the other major strategic pillar. Workers pricing starts with a free tier and a paid tier with a $5 per month minimum, and the documentation explicitly states there are no additional costs for data transfer or bandwidth. The standard paid Workers plan includes 10 million requests per month and bills additional usage based on requests and CPU milliseconds, with no charge for wall-clock time waiting on I/O. R2 reinforces the same philosophy.

Standard storage is priced at $0.015 per GB-month, with per-request pricing for Class A and B operations, and the product page as well as the developer documentation emphasize no egress bandwidth charges. These are not incidental pricing details. They are direct attacks on three of the most resented economics of cloud infrastructure: overpriced per-user remote access, egress tolls, and the idle-competition and server-provisioning charges.

Cloudflare is also trying to make the edge developer experience feel less proprietary than it actually is. Workers supports common languages and frameworks, the runtime environment is designed for web interoperability, and Durable Entities, KV, and R2 can be explained in familiar software terms. R2 is compatible with S3-style paradigms. Yet there is still hidden lock-in. Durable Entities place stateful coordination inside Cloudflare's execution model. Access can become the policy gateway for internal applications. AI Gateway can become the central policy and spend-control layer for model providers.

When multiple functions of identity, network policy, storage, observability, and compute are anchored with the same provider, switching becomes much harder, even if each component is individually standards-compatible.

That is why customer dependence on Cloudflare is better understood as cumulative, not binary. A customer using only DNS and CDN has moderate switching costs. A customer using authoritative DNS, CDN, WAF, bot management, API protection, Access, Gateway, Magic WAN, Workers, KV, Durable Entities, and R2 has much higher switching costs, because it would need to recreate policies, peering and routing behaviors, execution logic, egress economics, storage patterns, and operational workflows across multiple replacement vendors.

Cloudflare itself markets the connectivity cloud precisely on this anti-sprawl principle: one control plane, one network, fewer vendors, less dashboard overhead, faster deployment. The company's economic ambition, therefore, is not just to sell more SKUs. It is to raise the cost of architectural backtracking.

AI extends this logic. Workers AI, AI Gateway, the acquisitions of Replicate and Human Native, and the company's positioning around the "agentic cloud" all point to the same destination: making Cloudflare the place where inference, policy, spend control, content access, and application execution converge. The Replicate acquisition was explicitly presented as a way to make more than 50,000 production-ready models available to Workers AI users and to add custom models and pipelines. Human Native was positioned as helping AI developers find, access, and purchase high-quality data through transparent channels.

There is no proof yet that this will become meaningful revenue soon. What is proven is that Cloudflare does not want AI to merely generate more traffic through the existing pipes. It wants AI to make the pipes themselves more strategic.

Market Position, Competition, and Pricing Power

Cloudflare competes across multiple adjacent markets, and that is one reason why simplistic peer comparisons are misleading. In traditional delivery and web performance, the most obvious public comps remain Akamai and Fastly. Akamai's 2025 revenue by solution category was $2.243 billion for security, $1.257 billion for delivery, and additional cloud computing-related revenues, while the company indicated that delivery revenue continued to face pricing and renewal pressure. Fastly's 2024 revenue was $543.7 million, of which $427.7 million came from network services and $103.0 million from security. Those numbers show two important things.

First, the CDN and edge-delivery market remains large, real, and competitive. Second, pure-play or legacy delivery revenue is under structural pricing pressure even for established players at scale. Cloudflare's strategic response has been to reduce the share of its narrative that depends on delivery alone and increase the share that depends on security, control, and execution.

In Zero Trust and SASE, Cloudflare faces another category of competitors. Zscaler's fiscal 2025 revenue reached $2.673 billion, of which approximately 98% was tied to subscription and support revenue, underscoring the scale that a dedicated cloud security platform can achieve. Cloudflare's differentiator here is not being larger than Zscaler in security-specific revenue; the public disclosures do not prove that. Its differentiator is architectural.

Cloudflare argues that first-generation SASE vendors often stitched together patchworks of proxies and acquisitions, whereas Cloudflare One is unified from conception on a single connectivity cloud. Whether that claim is fully true for every feature set is debatable, but the architectural pitch is consistent: Cloudflare believes SASE is more valuable when it is tied to the same edge that already faces the customer's public applications and developer traffic.

Cloudflare also competes indirectly with public cloud platforms. Its own backbone discussion calls out AWS, Oracle, Alibaba, Google Cloud Platform, and Azure as common origins of customer traffic that Cloudflare carries. That origin dependency means the hyperscalers remain partners in many deployments. But R2's no-egress design, Workers' CPU-time pricing, Smart Placement, and the edge execution model are also competitive responses to hyperscaler economics.

When Cloudflare says "say goodbye to egress fees" or offers "no additional cost for data transfer," it is attacking a standard industry pricing convention that has helped make centralized cloud very sticky and expensive. Cloudflare is not trying to replace all of hyperscale. It is selectively attacking the cost-and-latency penalties of centralized cloud architectures.

This is where pricing power becomes more nuanced than sticker prices suggest. At the low end, Cloudflare is not really showing classic pricing power; it is showing distribution power. The free tier, the cheap Pro tier, and the low-cost developer entry points are designed to make Cloudflare easy to adopt, not to maximize per-user or per-domain monetization. But at the enterprise level, pricing power can emerge from bundle replacement.

If Cloudflare can credibly replace pieces of CDN, DDoS, WAF, API security, bot management, VPN, SWG, CASB, branch networking, and some edge compute or storage categories with a single contract and a single operating model, then the relevant economic reference is not the price of one Cloudflare SKU. It is the total cost, complexity, and downtime risk of multiple existing stacks. That is why Cloudflare repeatedly markets against "technology sprawl," "vendor count," and "dashboard overhead." Those messages are essentially arguments for enterprise bundle-pricing power.

It would be wrong, however, to assume that Cloudflare has unconstrained pricing leverage. Akamai's filing explicitly states that delivery faces pricing pressure and customer do-it-yourself efforts. Fastly's smaller scale makes the same domain visibly price-competitive. Cloudflare's own public pricing is unusually transparent for self-serve products, which disciplines price increases. And the company's rapid expansion into adjacent categories means it often chooses penetration over margin maximization. Even the gross margin trend between 2025 and 2026 suggests Cloudflare is funding strategic breadth with real infrastructure spending.

The evidence therefore suggests that Cloudflare's best pricing power lies in enterprise bundles and architectural replacement, not in squeezing unit prices on commoditized edge primitives.

The most useful competitive conclusion is this: Cloudflare is better positioned when the purchasing decision is "which platform can simplify my Internet edge the most?" and less advantaged when the purchasing decision is "which vendor gives me the cheapest standalone CDN gigabyte-delivered or the most complete feature set in an isolated security category?" That is why the company keeps evolving its narrative from products to platform, and from edge speed to control. It knows that competing on point products is harder to defend than competing on platform adjacency.

Governance, International Footprint, and Risk Exposure

Cloudflare's international footprint is an asset, but not a frictionless one. The company states it serves customers in more than 190 countries, derives the majority of its revenue from international, and operates network locations in more than 330 cities and more than 125 countries. Its public office footprint extends across North America, Europe, the Middle East, and Asia-Pacific hubs, including Singapore, Beijing, Tokyo, Seoul, Sydney, and Bengaluru.

Its network and legal pages also emphasize the Data Localization Suite tools and granular controls over where data is inspected, reflecting the reality that multinational enterprises increasingly need location-sensitive infrastructure rather than a purely borderless cloud. In other words, Cloudflare's international scale is not just about selling abroad; it is about making the edge itself legible to sovereign and sectoral compliance requirements.

China is the clearest example of how that international footprint is partly mediated through partners. Cloudflare's China network documentation states that certain Cloudflare performance and security products run on mainland China data centers operated by JD Cloud. The FAQ explicitly notes that Cloudflare itself does not hold an MIIT license to provide CDN services in China, unlike JD Cloud. This arrangement is commercially useful because it extends Cloudflare's reach and performance inside China without requiring Cloudflare to be the licensed operator there. It is also strategically revealing.

In the most politically sensitive jurisdictions, Cloudflare's "global network" is sometimes a commercial and regulatory partnership model rather than a wholly owned control model. That creates opportunity, but also dependency on partners and local rules.

Governance is also more founder-controlled than a quick read of the stock symbol might suggest. Cloudflare has a dual-class stock structure in which each Class A share carries one vote and each Class B share carries ten votes. As of April 30, 2026, Matthew Prince held 25.69 million Class B shares and approximately 39.0% of total voting power, while Michelle Zatlyn held 9.02 million Class B shares and approximately 13.4% of total voting power. Executive officers and directors as a group controlled 52.4% of total voting power.

The proxy statement further disclosed that as of the 2026 record date, the co-founders controlled stockholder voting on key matters. That means Cloudflare is publicly listed, but strategic control remains genuinely founder-led. That can be positive for long-term infrastructure bets. It also significantly limits external shareholder influence.

The 2026 proxy is also significant because it included amendments related to the reclassification of stock and, in effect, preserving founder influence through a more complex structure. As of June 28, 2026, that proposal was still pending the June 30 annual meeting, so any assertion about definitive governance changes would be premature. But the fact that such proposals are on the table is itself a signal. Cloudflare's founders appear intent on retaining strategic leeway to pursue long-term infrastructure building without subjecting themselves to the normal cadence of public-market control discipline.

Investors can reasonably like or dislike that; what they cannot do is ignore it.

Operational risk is particularly significant for Cloudflare because the platform is shared. The company's own post-mortems show why. In June 2025, Cloudflare disclosed a significant service outage caused by a failure of the underlying storage infrastructure used by Workers KV; the company indicated that Workers KV served as critical infrastructure for many other Cloudflare products, affecting Workers KV itself, WARP, Access, Gateway, Images, Stream, Workers AI, Turnstile, AutoRAG, Zaraz, and parts of the dashboard.

In November 2025, Cloudflare experienced another widespread outage tied to a bug in the generation of Bot Management configuration. Earlier incidents include the June 2022 outage caused by a network configuration change and the July 2025 1.1.1.1 incident caused by topology changes. These incidents are not random footnotes. They reveal the structural downside of Cloudflare's "one network, one stack" model: common foundations can create common-mode failures.

The 2025 10-K makes this concentration risk even more concrete. It states that a large portion of the network infrastructure is maintained through a central colocation facility in the Portland, Oregon, metropolitan region, a second central colocation facility in Amsterdam providing some redundancy, and a limited number of other colocation facilities in the United States. Management explicitly warns that it does not control the operation of these third-party facilities and cites prior power outages at the central Portland-area site in November 2023 and March 2024.

It even notes that the failure of a central colocation facility for an extended period, particularly the U.S. central facility, could place significant strain on operations because redundant functionality is limited. This is a major watchpoint. Cloudflare's distributed edge is vast, but some of its control and support architecture is more concentrated than the front-end network map suggests.

Third-party dependency risk goes beyond facilities. The 2025 report also notes that a breach in a third-party chat agent integrated with Cloudflare's CRM in August 2025 exposed certain customer contact and support information, and separately indicates that the June 2025 Workers KV outage is a consequence of the underlying third-party storage infrastructure failure. This matters because Cloudflare partly markets itself as a simplifier of other people's dependencies. Yet its own platform still contains hidden vendor dependencies, and when those dependencies sit under shared services, the blast radius can be substantial.

The evidence demonstrates that some of Cloudflare's most impactful outages and exposures have third-party roots.

Regulatory and platform liability risks are also critical to Cloudflare's infrastructure role. The company is unusually exposed to litigation over the responsibilities of an intermediary when it accelerates, secures, enforces, or hosts problematic content. Its 2025 report states that it faces lawsuits over content available on its customers' websites, notes that courts in some countries have found that it could be held liable in certain circumstances, and cites an October 2025 Japanese court ruling holding it liable for damages in a copyright case that the company is appealing.

The report also notes that some governments, service providers, and other parties may blacklist or block Cloudflare's IP addresses because it can be difficult to identify the precise traffic source behind a reverse-proxy model. Cloudflare's Trust Hub and transparency documents emphasize that the company generally cannot remove content it does not host and that it publishes semi-annual transparency reports. That posture supports customer trust. It also keeps Cloudflare at the center of policy debates about intermediary liability.

A final risk point cuts the other way: customer concentration is low. Cloudflare reports that no single customer accounted for more than 10% of revenue in 2023, 2024, or 2025. That does not mean revenue is immune to an enterprise spending slowdown, but it does mean the company is not hostage to a single giant media or hyperscale account the way some traffic-based infrastructure vendors historically have been. Diversification is a genuine advantage here, particularly given Cloudflare's mix of long-tail and enterprise customers.

Evidence Register and Watchpoints

The strongest evidence supports a clear conclusion: Cloudflare now occupies a strategically important layer of Internet infrastructure, broader than a CDN and more horizontally distributed than a point-security vendor.

The evidence proves that the company has built an extremely large and densely interconnected edge network; that its business has rapidly grown to exceed $2.1 billion in annual revenue with over 332,000 paying customers; that international revenue represents more than half the total; that channel partners are growing in importance; that the company's product catalog spans public application traffic, private enterprise access, and developer execution; and that the founders still control the company's voting structure.

It also proves that Cloudflare's shared architecture can create cross-product outage blast radius, that physical and third-party dependencies remain significant despite the company's distributed marketing, and that margins are under pressure from heavier infrastructure investment.

The evidence strongly suggests, though does not fully prove, that Cloudflare's main moat is bundling and distribution rather than standalone product dominance. The company's "one network everywhere" architecture, self-serve funnel, transparent pricing, anti-egress-fee messaging, and integrated SASE and developer layers all point in this direction. The rising large-customer count, broad Fortune 500 penetration, and the company's explicit emphasis on reducing vendor sprawl suggest that account expansion and architectural consolidation are at work.

Public routing data and Cloudflare's own backbone disclosures also suggest a meaningful transport-cost and performance advantage from dense peering and owned or leased backbone capacity. But because Cloudflare does not break out revenue by product or gross margins by product, the market still cannot see exactly how much value comes from mature delivery categories versus newer, higher-leverage categories.

What remains unknown is almost as important. Public investors do not know the revenue contribution of Workers, R2, Workers AI, Zero Trust, or SASE as distinct product lines. They do not know the gross margin profile of AI inference or large-scale GPU deployment. They do not know whether the rising channel share is margin accretive or dilutive. They do not know the true depth of enterprise product penetration behind the Fortune 500 logo count. And they do not yet know, as of June 28, 2026, the final outcome of the 2026 governance proposals. These unknowns do not invalidate the thesis; they shape its risk premium.

The most important watchpoints for the next 12 to 36 months are the following:

Cloudflare's ability to maintain revenue growth above 20% (high-twenties) while the mix shifts toward larger enterprise and developer workloads. Fiscal 2025 revenue grew 30%, and Q1 2026 grew 34%, which is solid enough to preserve the platform narrative if sustained. A sharp deceleration would force investors to ask how much of the story is aspiration rather than monetized stickiness.

Gross margin stabilization after the current infrastructure cycle. GAAP gross margin went from 77% in 2024 to 75% in 2025 to 71.2% in Q1 2026. If new workloads such as AI inference and stateful compute permanently lower margin without commensurate pricing power, Cloudflare's valuation framework changes.

More visible materiality of SASE and developer-platform products to revenue. The architecture and product catalog are compelling, but the company still provides no product-level revenue breakdown. Investors should watch for any future disclosure, or indirect indicators such as enterprise customer case studies, large-customer growth, and continued product-focused acquisitions.

Efficiency improvement from the May 2026 AI-driven operating model restructuring without harming execution. Cloudflare stated it expects to reduce headcount by approximately 1,100 people and incur related charges of $140–150 million. That is a significant operational change, not a cosmetic adjustment.

Meaningful reduction in common-mode outage risk after the 2025 incidents. The re-architecture of Workers KV and repeated post-mortems show Cloudflare is working on the problem, but the company's architecture remains highly shared. Customers who run public traffic, private access, and application logic on a single provider will pay close attention.

Expanding regulatory and liability exposure around hosted content, reverse-proxy usage, and jurisdiction-specific enforcement. The Japan litigation example and the company's risk-factor language suggest this is not theoretical. If courts or regulators push intermediaries to act more like publishers or hosters, Cloudflare's trust and neutrality posture could come under real pressure.

Maintenance of stable founder control or its extension through revised stock-class mechanisms. Cloudflare's governance gives management unusual freedom to keep investing through cycles, but it also reduces external accountability. That trade-off will not disappear.

Sustaining commercial attractiveness in China and other partner-mediated geographies as geopolitical constraints shift. The JD Cloud arrangement is an efficient path to presence, but it also demonstrates that some strategic geographies cannot be served under Cloudflare's usual ownership model.

Ultimately, Cloudflare's market position is strongest when customers want to merge edge, security, access, and execution into a single programmable fabric. Its role in digital infrastructure is increasingly that of a strategic middle layer through which websites, APIs, employees, branch offices, and now AI agents can all be controlled. That is a more durable and valuable role than the label "CDN company" suggests. But it is also a role that demands flawless network reliability, disciplined capital deployment, and careful policy navigation. Cloudflare has already proven that it can build the footprint.

The next phase is proving that this footprint can support a broader software empire without losing the economics and the trust that made the footprint valuable in the first place.