
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Mon, 06 Apr 2026 23:41:03 GMT</lastBuildDate>
        <item>
            <title><![CDATA[Helping protect journalists and local news from AI crawlers with Project Galileo]]></title>
            <link>https://blog.cloudflare.com/ai-crawl-control-for-project-galileo/</link>
            <pubDate>Tue, 23 Sep 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ We are excited to announce that Project Galileo will now include access to Cloudflare's Bot Management and AI Crawl Control services. ]]></description>
            <content:encoded><![CDATA[ <p></p><p>We are excited to announce that <a href="https://www.cloudflare.com/galileo/"><u>Project Galileo</u></a> will now include access to Cloudflare's <a href="https://www.cloudflare.com/application-services/products/bot-management/"><u>Bot Management</u></a> and <a href="https://developers.cloudflare.com/ai-crawl-control/"><u>AI Crawl Control</u></a> services. Participants in the program, which include roughly 750 journalists, independent news organizations, and other non-profits supporting news-gathering around the world, will now have the ability to <a href="https://www.cloudflare.com/the-net/building-cyber-resilience/regain-control-ai-crawlers/"><u>protect their websites from AI crawlers</u></a>—for free. </p><p>Project Galileo is Cloudflare's free program to help protect important civic voices online. Launched in 2014, it now includes more than 3,000 organizations in 125 countries, and it has served as the foundation for other free Cloudflare programs that help protect <a href="https://www.cloudflare.com/athenian/"><u>democratic elections</u></a>, <a href="https://blog.cloudflare.com/project-cybersafe-schools/"><u>public schools</u></a>, <a href="https://blog.cloudflare.com/heeding-the-call-to-support-australias-most-at-risk-entities/"><u>public health clinics</u></a>, and other <a href="https://www.cloudflare.com/press-releases/2022/project-safekeeping-zero-trust-for-critical-infra/"><u>critical infrastructure</u></a>.  </p><p>Although we think all Project Galileo participants will benefit from these additional free services, we believe they are essential for news organizations. </p><p>News organizations, particularly local news, are facing significant challenges in transitioning to the <a href="https://blog.cloudflare.com/content-independence-day-no-ai-crawl-without-compensation/"><u>AI-driven web</u></a>. As people increasingly turn to AI models for information, less of their web traffic is making it to the actual website where that information originated. Industries, like news organizations, that rely on user traffic to generate revenue are increasingly at-risk. </p><p>Allowing news organizations to monitor and control how AI crawlers are interacting with their websites, will help them better protect their content and make more informed decisions about engaging with AI companies. Ultimately, our goal is to provide the tools news organizations need to negotiate fair compensation for their work.  </p>
    <div>
      <h3>Traffic and the news</h3>
      <a href="#traffic-and-the-news">
        
      </a>
    </div>
    <p>AI is fundamentally changing how traffic flows on the Internet. Cloudflare recently <a href="https://blog.cloudflare.com/ai-search-crawl-refer-ratio-on-radar/#how-does-this-measurement-work"><u>published data</u></a> that <a href="https://blog.cloudflare.com/content-independence-day-no-ai-crawl-without-compensation/"><u>shows</u></a> with Open AI its 750 times more difficult for website owners to get the same volume of traffic than it was with previous Google search. With Anthropic, it's 30,000 times more difficult. </p><p>News organizations rely on traffic to not only connect with their readers, but also generate revenue from subscriptions, advertising, e-commerce, and licensing. The CEO of the Financial Times recently <a href="https://www.theguardian.com/media/2025/sep/06/existential-crisis-google-use-ai-search-upended-web-publishers-models"><u>stated</u></a> that AI had caused a ''pretty sudden and sustained' decline of 25% to 30% in traffic to its articles arriving via search engines." </p><p>Potential losses of user traffic and revenue come at an already precarious time for the news industry. It is well-documented that small, independent newspapers and news radio stations continue to face significant financial pressure, particularly in the United States. According to recent US Congressional <a href="https://www.judiciary.senate.gov/imo/media/doc/2024-01-10_-_testimony_-_coffey.pdf"><u>testimony</u></a>, more than two newspapers closed per week in 2024 with one third of the country's newspapers set to close before the beginning of 2025. <a href="https://localnewsinitiative.northwestern.edu/projects/state-of-local-news/2024/report/#executive-summary"><u>A 2024</u></a> report by the Northwestern Local News Initiative reported more than 206 US counties were without any local news source, and 1,561 had only one.  </p><p>Recent funding <a href="https://www.nytimes.com/2025/08/26/us/politics/public-broadcast-cuts.html"><u>cuts</u></a> to the <a href="https://www.nytimes.com/2025/09/13/us/politics/public-broadcasting-cuts.html"><u>Corporation for Public Broadcasting and National Public Radio</u></a>, which provided grants, programing, and other support to public news stations around the US, have put further strain on these organizations with <a href="https://radio.wpsu.org/2025-09-11/penn-state-plans-close-wpsu-board-committee-rejects-transfer-whyy"><u>more closures expected</u></a>. </p>
    <div>
      <h3>Giving control back to journalists</h3>
      <a href="#giving-control-back-to-journalists">
        
      </a>
    </div>
    <p>An important first step in helping journalists and news organizations adapt to the AI-driven web is providing tools to help them monitor and control AI models' access to their content. </p><blockquote><p>“In an era defined by AI and digital disruption, providing robust tools to independent media isn’t just support - it’s a lifeline” - Meera, CEO <a href="https://internews.org/">Internews</a> Europe</p></blockquote><blockquote><p>"Independent publishers need tools that are easy to use and affordable, so they can focus on growing their business. LION appreciates the security and protection Cloudflare has provided our members through Project Galileo for years, and we're excited to see more resources now available to help members manage the rapidly evolving landscape of digital security."  - Sarah Gustavus Lim, <a href="https://lionpublishers.com/">LION</a> Membership Director </p></blockquote><p>Cloudflare <a href="https://www.cloudflare.com/application-services/products/bot-management/"><u>Bot Management</u></a> and <a href="https://developers.cloudflare.com/ai-crawl-control/"><u>AI Crawl Control</u></a> were designed for exactly these purposes. Bot management is a security tool that uses machine learning to analyze web traffic to distinguish between good bots, like search engine crawlers, and bad bots that attack websites or steal credentials. It allows website owners to block bad bots from reaching their websites, while making sure helpful bots can continue to do their work.</p><p>AI Crawl Control provides similar tools to identify and manage AI crawlers. Cloudflare uses a variety of techniques to identify and categorize crawlers (HTTP header, heuristics, and other behavior) giving website owners the ability to analyze their activity by type (e.g. AI search, AI scraper), where they are coming from (Google, OpenAI, Anthorpic, etc.), and what content they are accessing. Here’s the kind of data that Cloudflare’s AI Crawl Control tool can provide (using the <a href="http://radar.cloudflare.com"><u>radar.cloudflare.com</u></a> domain) as an example:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/r4I2STKojUo1fBuXWWokG/b0f01faa2f48f6047b7ceb00e6bb84e6/image1.png" />
          </figure>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6YxdJKNg3NbJeYELrRZ2cg/8ada51524091a526bafabcb2ad306492/image2.png" />
          </figure><p>Cloudflare combines these insights with easy-to-use controls that allow website owners to make informed decisions about whether to make their data available, including to only certain types of bots or to individual AI companies. This would, for example, allow a local newspaper to decide to <a href="https://www.cloudflare.com/learning/ai/how-to-block-ai-crawlers/">block all AI crawlers</a> and maintain direct connection to their readers via their own website, <a href="https://www.cloudflare.com/learning/ai/how-to-prevent-web-scraping/">block only AI scrapers </a>while allowing AI search crawlers that refer traffic, or negotiate and sell exclusive access to their content to a single AI company. The following image shows how AI Crawl Control lets users allow or block access on a crawler-by-crawler basis:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/11AY83EbOO6wV8102Hy6wm/62e9d5a14626b080d7ee51bff011597a/image4.png" />
          </figure><p>We think the ability to control and monitor AI crawler activity will provide immediate help to news organizations looking to protect their content and understand how models are using their data. </p><p>We also think it will provide longer term insights that will allow news organizations to negotiate mutually beneficial relationships with AI companies over time.  </p><blockquote><p>"Independent media's ability to fulfill its democratic function by gathering news and distributing trusted information depends on generating revenues free from political or business influence. By monitoring and monetizing the crawling of publisher's sites, media can protect their intellectual property while developing new revenue streams to support their quality journalism." - Ryan Powell, Head of Innovation and Media Business at <a href="https://ipi.media/">International Press Institute</a></p></blockquote>
    <div>
      <h3>A free press, if we can keep it</h3>
      <a href="#a-free-press-if-we-can-keep-it">
        
      </a>
    </div>
    <p>Journalism is part of the foundation of free society and democratic governance. It helps hold power accountable and provides a voice to the marginalized and underrepresented. It also protects the free and open markets that allow startups to challenge powerful incumbents.  </p><p>Local news in particular helps create shared identity. Not only by covering community events, high school sports, farmers markets, and new businesses, but also providing essential transparency and oversight over local officials, school boards, public safety events, and elections. </p><p>Helping protect journalists and news organizations online has always been part of Cloudflare's mission. We see it as essential to our business and the future of the Internet.  </p><p>If you are interested in learning more about <a href="https://www.cloudflare.com/galileo/"><u>Project Galileo</u></a>, sign up today. If you are interested in helping build a better Internet, <a href="https://www.cloudflare.com/careers/"><u>come join us</u></a>.
</p> ]]></content:encoded>
            <category><![CDATA[Birthday Week]]></category>
            <category><![CDATA[Project Galileo]]></category>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Bot Management]]></category>
            <category><![CDATA[AI]]></category>
            <guid isPermaLink="false">1aO7Ty9ZIj6nSXApr9xgmu</guid>
            <dc:creator>Patrick Day</dc:creator>
            <dc:creator>Jocelyn Woolbright</dc:creator>
        </item>
        <item>
            <title><![CDATA[Free access to Cloudflare developer services for non-profit and civil society organizations]]></title>
            <link>https://blog.cloudflare.com/expanding-startups-for-nonprofits/</link>
            <pubDate>Mon, 22 Sep 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ We're expanding Cloudflare for Startups to include non-profits, civil society, and public interest orgs. ]]></description>
            <content:encoded><![CDATA[ <p>We are excited to announce that non-profit, civil society, and public interest organizations are now eligible to join <a href="https://www.cloudflare.com/forstartups/"><u>Cloudflare for Startups</u></a>. Under this new program, participating organizations will be eligible to receive up to $250,000 in Cloudflare credits — these can be used for a variety of our <a href="https://www.cloudflare.com/developer-platform/products/"><u>developer</u></a> and core products, including databases &amp; storage, compute services, AI, media, and performance and security.</p><p>Non-profit organizations and startups have a lot in common. In addition to being powered by small groups of dedicated, resilient, and creative people, they are constantly navigating funding shortages, staffing challenges, and insufficient tools. Most importantly, both are unrelenting in their efforts to do more with less; maximizing the impact of every dollar spent and hour invested.</p><p>Cloudflare's developer services and our startup programs were designed for exactly these challenges. Our goal is to make it easier for anyone to write code, build applications, and launch new ideas anywhere in the world. Put another way, we want to help small teams have a global impact.</p><p>All are welcome to apply. The application period for this new program will open today and runs until December 1. After the closing of the application period, Cloudflare will review the applications we’ve received and make award decisions based on project description, requirements, and impact. </p><p>If you are a non-profit organization interested in working with Cloudflare to build new, innovative full-stack applications that are secure, performant, near-infinite scale, and optimized for AI training, inference, and security for free, <a href="https://www.cloudflare.com/forstartups/"><u>apply today!</u></a></p>
    <div>
      <h3>Coming together in a challenging year</h3>
      <a href="#coming-together-in-a-challenging-year">
        
      </a>
    </div>
    <p>2025 has been a difficult year for non-profits. According to a <a href="https://cep.org/wp-content/uploads/2025/05/NVP_State-of-Nonprofits_2025.pdf"><u>recent survey</u></a> of non-profit leaders, decreased government funding, an uncertain economic environment, and greater demand for services have made it increasingly difficult for many organizations to operate. Although some <a href="https://cep.org/blog/a-wave-forming-funders-taking-action-in-response-to-a-challenging-context/"><u>private foundations</u></a> have responded by increasing their grant making and other contributions, significant gaps remain. </p><p>We also know that the non-profit sector has significant tech needs. The <a href="https://www.nten.org/"><u>Nonprofit Technology Network (NTEN)</u></a> reports that almost half of non-profits surveyed believed that they spent too little on technology, with 77% reporting the primary barrier was lack of available budget. Only 14% reported receiving grants to specifically help with technology projects. </p><p>Many organizations are facing difficult choices. And, sadly, many have been forced to discontinue operations.</p><p>However, we have also seen remarkable resilience and determination first-hand. Many of the organizations we work with <a href="https://www.cloudflare.com/galileo/"><u>regularly</u></a> are doing the incredibly difficult work of diversifying their funding, reshaping their organizations, and finding new ways to accomplish their missions — including greater emphasis on and investment in new technologies. We also continue to see dynamic growth of new non-profit startups working to step in and fill gaps to help solve problems in new, innovative ways.</p><p>We want to help. </p>
    <div>
      <h3>Cloudflare is the place for startups</h3>
      <a href="#cloudflare-is-the-place-for-startups">
        
      </a>
    </div>
    <p>Cloudflare is the best place on the Internet to build and launch a startup. In part because our developer tools were designed to help small teams build big things. Building on Cloudflare's network provides direct access to scalable computing power, storage, media, and AI needed to build full-stack applications. And, because applications built with Cloudflare are automatically deployed to our global network, developers can spend less time worrying about infrastructure and performance and more time on their ideas.</p><p>More than 4,000 startups have received free credits since Cloudflare launched its <a href="https://www.cloudflare.com/forstartups/"><u>startup program</u></a> during 2024’s Birthday Week. Since 2024, 175 startups in 23 countries have also participated in Cloudflare's <a href="https://www.cloudflare.com/lp/workers-launchpad/"><u>Workers Launchpad Program</u></a>, which provides even more support and resources including hands-on assistance and training from Cloudflare engineers, introductions to our venture capital partners, and opportunities to present at Cloudflare <a href="https://cloudflare.tv/shows/workers-launchpad-demo-day"><u>Demo Days</u></a>.</p>
    <div>
      <h3>Impact organizations are often start-ups, too</h3>
      <a href="#impact-organizations-are-often-start-ups-too">
        
      </a>
    </div>
    <p>Regardless of their size, non-profits and startups often share a similar mentality. They tend to be mission-driven, operate with limited resources, and are constantly forced to innovate and adapt to survive. </p><p>Above all, they rely on small teams to make an outsized impact.</p><p>We understand these challenges. Our developer services were designed to allow small teams to focus on ideas and code instead of the time-consuming aspects of managing a global network, security, and scaling. Building directly on the Cloudflare Network allows developers to instantly scale and deploy new technologies all over the world. </p><p>One example of a non-profit organization already building on Cloudflare is <a href="https://www.kendra.io/"><u>Kendraio</u></a>. An independent non-profit organization that has built an open source, integration platform designed to help others solve problems. Kendraio creates user-friendly tools with customizable interfaces and no-code logic, allowing anyone to build complex functions across different applications. Their work on pilot projects demonstrates this, including a knowledge <a href="https://www.linkedin.com/company/steppingstonesapp/"><u>graph</u></a> for diplomats working on nuclear disarmament, a shared wholesale <a href="https://www.linkedin.com/company/culturebanked/"><u>database</u></a> for independent bookstores, and a <a href="https://medium.com/kendraio/exploring-a-news-subscription-service-with-kendraio-7c4b9e42653e"><u>dashboard</u></a> to simplify news subscriptions for readers and publishers.</p>
    <div>
      <h3>Interested? Here’s how to apply </h3>
      <a href="#interested-heres-how-to-apply">
        
      </a>
    </div>
    <p>The application period to join Cloudflare's first class of non-profit organizations participating in Cloudflare for Startups is open now, and will close on December 1, 2025.</p><p>Cloudflare's Impact and Startup teams will review the applications and select a cohort of non-profit, civil society, and public interest organizations to participate in the program.  These organizations will have the opportunity to receive up to $250,000 in Cloudflare credits, which can be used for certain usage-based services including databases &amp; storage, compute services, AI, media, and performance &amp; security tools. For full details, visit <a href="https://www.cloudflare.com/forstartups/"><u>cloudflare.com/forstartups</u></a>. </p><p>To qualify, organizations should meet the following criteria:</p><ul><li><p>Be a registered 501(c)(3) non-profit organization or equivalent</p></li><li><p>Provide a description of the tool you plan to build or scale with Cloudflare. </p></li></ul><p>Applications for Cloudflare's first class of non-profit startup participants are open until December 1, 2025. This will be our first non-profit class to join our Startups program. However, we hope there will be more to follow. Keep checking the Cloudflare blog for more updates.</p><p><b><u>To apply, simply visit our application </u></b><a href="https://www.cloudflare.com/forstartups/"><b><u>page </u></b></a><b><u>and select the non-profit checkbox.</u></b>



</p> ]]></content:encoded>
            <category><![CDATA[Developers]]></category>
            <category><![CDATA[Cloudflare for Startups]]></category>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Birthday Week]]></category>
            <guid isPermaLink="false">49Ryz8XdOxW5QYrD9VsjbZ</guid>
            <dc:creator>Patrick Day</dc:creator>
            <dc:creator>Jocelyn Woolbright</dc:creator>
        </item>
        <item>
            <title><![CDATA[Control content use for AI training with Cloudflare’s managed robots.txt and blocking for monetized content]]></title>
            <link>https://blog.cloudflare.com/control-content-use-for-ai-training/</link>
            <pubDate>Tue, 01 Jul 2025 10:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare is making it easier for publishers and content creators of all sizes to prevent their content from being scraped for AI training by managing robots.txt on their behalf.  ]]></description>
            <content:encoded><![CDATA[ <p>Cloudflare is giving all website owners two new tools to easily control whether AI bots are allowed to access their content for model training. First, customers can let Cloudflare <b>create and manage a robots.txt file</b>, creating the appropriate entries to let crawlers know not to access their site for AI training. Second, all customers can choose a new option to <a href="https://www.cloudflare.com/learning/ai/how-to-block-ai-crawlers/">block AI bots</a> <b>only on portions of their site that are monetized through ads</b>.</p>
    <div>
      <h2>The new generation of AI crawlers</h2>
      <a href="#the-new-generation-of-ai-crawlers">
        
      </a>
    </div>
    <p>Creators that monetize their content by showing ads depend on traffic volume. Their livelihood is directly linked to the number of views their content receives. These creators have allowed crawlers on their sites for decades, for a simple reason: search crawlers such as <code>Googlebot</code> made their sites more discoverable, and drove more traffic to their content. Google benefitted from delivering better search results to their customers, and the site owners also benefitted through increased views, and therefore increased revenues.</p><p>But recently, a new generation of crawlers has appeared: bots that crawl sites to gather data for training AI models. While these crawlers operate in the same technical way as search crawlers, the relationship is no longer symbiotic. AI training crawlers use the data they ingest from content sites to answer questions for their own customers directly, within their own apps. They typically send much less traffic back to the site they crawled. Our <a href="https://radar.cloudflare.com/"><u>Radar</u></a> team did an analysis of crawls and referrals for sites behind Cloudflare. As HTML pages are arguably the most valuable content for these crawlers, we <a href="https://blog.cloudflare.com/ai-search-crawl-refer-ratio-on-radar/"><u>calculated crawl ratios</u></a> by dividing the total number of requests from relevant user agents associated with a given search or AI platform where the response was of <code>Content-type: text/html</code> by the total number of requests for HTML content where the <code>Referer</code>: header contained a hostname associated with a given search or AI platform. As of June 2025, we find that Google crawls websites about 14 times for every referral. But for AI companies, the <a href="https://radar.cloudflare.com/ai-insights#crawl-to-refer-ratio"><u>crawl-to-refer ratio</u></a> is orders of magnitude greater. In June 2025, <b>OpenAI’s crawl-to-referral ratio was 1,700:1, Anthropic’s 73,000:1</b>. This clearly breaks the “crawl in exchange for traffic” relationship that previously existed between search crawlers and publishers. (Please note that this calculation reflects our best estimate, recognizing that traffic referred by native apps may not always be attributed to a provider due to a lack of a <code>Referer</code>: header, which may affect the ratio.)</p><p>And while sites can use robots.txt to tell these bots not to crawl their site, most don’t take this first step. We found that only about <a href="https://radar.cloudflare.com/ai-insights#ai-user-agents-found-in-robotstxt"><b><u>37% of the top 10,000 domains currently have a robots.txt file</u></b></a>, showing that robots.txt is underutilized in this age of evolving crawlers.</p><p>That’s where Cloudflare comes in. Our mission is to help build a better Internet, and a better Internet is one with a huge thriving ecosystem of independent publishers. So, we’re taking action to keep that ecosystem alive.</p>
    <div>
      <h2>Giving ALL customers full control</h2>
      <a href="#giving-all-customers-full-control">
        
      </a>
    </div>
    <p>Protecting content creators isn’t new for Cloudflare. In July 2024, we gave everyone on the Cloudflare network a simple way to <a href="https://blog.cloudflare.com/declaring-your-aindependence-block-ai-bots-scrapers-and-crawlers-with-a-single-click/"><u>block all AI scrapers with a single click</u></a> for free. We’ve already seen <b>more than 1 million customers enable this feature</b>, which has given us some interesting data.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2B8KAmaP6DrMEMW5YSjLYP/d9eb0f67a998b730373a27aa707ade9d/image5.png" />
          </figure><p>Since our last update, we can see that <code><b>Bytespider</b></code><b>, our previous top bot, has seen traffic volume decline 71.45% since the first week of July 2024</b>. During the same time, we saw an increased number of <code>Bytespider</code> requests that customers chose to specifically block. In contrast, <code>GPTBot</code> traffic volume has grown significantly as it has become more popular, now even surpassing traffic we see from big traditional tech players like Amazon and ByteDance.</p><p>The share of sites accessed by particular crawlers has gone down across the board since our last update. Previously, <code>Bytespider</code> accessed &gt;40% of websites protected by Cloudflare, but that number has dropped to only 9.37%. <code><b>GPTBot</b></code><b> has taken the top spot for most sites accessed</b>, but while its request volume has grown significantly (noted above), the share of sites it crawls has actually decreased since last year from 35.46% to 28.97%, with an increase in customers blocking.</p><table><tr><td><p>AI Bot</p></td><td><p>Share of Websites Accessed</p></td></tr><tr><td><p>GPTBot</p></td><td><p>28.97%</p></td></tr><tr><td><p>Meta-ExternalAgent</p></td><td><p>22.16%</p></td></tr><tr><td><p>ClaudeBot</p></td><td><p>18.80%</p></td></tr><tr><td><p>Amazonbot</p></td><td><p>14.56%</p></td></tr><tr><td><p>Bytespider</p></td><td><p>9.37%</p></td></tr><tr><td><p>GoogleOther</p></td><td><p>9.31%</p></td></tr><tr><td><p>ImageSiftBot</p></td><td><p>4.45%</p></td></tr><tr><td><p>Applebot</p></td><td><p>3.77%</p></td></tr><tr><td><p>OAI-SearchBot</p></td><td><p>1.66%</p></td></tr><tr><td><p>ChatGPT-User</p></td><td><p>1.06%</p></td></tr></table><p>And while AI Search and AI Assistant crawling related activity has exploded in popularity in the last 6 months, we still see their total traffic pale in comparison to AI training crawl activity, which has seen a <b>65% increase in traffic over the past 6 months</b>.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7nOWMQs8IzgS3RfrXHaVT1/b1b31024a92b70a3f39083b376bb3934/image4.png" />
          </figure><p>To this end, we launched <a href="https://blog.cloudflare.com/cloudflare-ai-audit-control-ai-content-crawlers/"><u>free granular auditing</u></a> in September 2024 to help customers understand which crawlers were accessing their content most often, and created simple templates to block all or specific crawlers. And in December 2024, we made it easy for publishers to automatically block <a href="https://blog.cloudflare.com/ai-audit-enforcing-robots-txt/"><u>crawlers that weren’t respecting robots.txt</u></a>. But we realized many sites didn’t have the time to create or manage their own robots.txt file. Today, we’re going two steps further.</p>
    <div>
      <h2>Step 1: fully managed robots.txt</h2>
      <a href="#step-1-fully-managed-robots-txt">
        
      </a>
    </div>
    <p>When it comes to managing your website’s visibility to search engine crawlers and other bots, the <code>robots.txt</code> file is a key player. This simple text file acts like a traffic controller, signaling to bots which parts of the website they should or should not access. We can think of <a href="https://www.cloudflare.com/learning/bots/what-is-robots-txt/"><u>robots.txt</u></a> as a "Code of Conduct" sign posted at a community pool, listing general dos and don'ts, according to the pool owner’s wishes. While the sign itself does not enforce the listed directives, well-behaved visitors will still read the sign and follow the instructions they see. On the other hand, poorly-behaved visitors who break the rules risk <a href="https://blog.cloudflare.com/ai-audit-enforcing-robots-txt/"><u>getting themselves banned</u></a>. </p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6oGxSRxy3sU88o4TZP7p42/aea1d7bbf5e57eb133ce8cdfae88dc37/image2.png" />
          </figure><p>What do these files actually look like? Take Google’s as an example, visible to anyone at <a href="https://www.google.com/robots.txt"><u>https://www.google.com/robots.txt</u></a>. Parsing its contents, you'll notice four directives in the set of instructions: <b>User-agent</b>, <b>Disallow</b>, <b>Allow</b>, and <b>Sitemap</b>. In a <code>robots.txt</code> file, the <b>User-agent</b> directive specifies which bots the rules apply to. The <b>Disallow</b> directive tells those bots which parts of the website they should avoid. In contrast, the <b>Allow</b> directive grants specific bots permission to access certain areas. Finally, the<a href="https://www.sitemaps.org/index.html"> <b>Sitemap</b> directive</a> shows a bot which pages it can reach, so that it won’t miss any important pages. The <a href="https://www.ietf.org/"><u>Internet Engineering Task Force (IETF)</u></a> formalized the definition and language for the Robots Exclusion Protocol in <a href="https://datatracker.ietf.org/doc/html/rfc9309"><u>RFC 9309</u></a>, specifying the exact syntax and precedence of these directives. It also outlines how crawlers should handle errors or redirects while stressing that compliance is <i>voluntary</i> and does not constitute access control. </p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/79JML5EIN1f4NVzRankehO/20a2c99ccaca62e7718c9d66bb8585d5/image10.png" />
          </figure><p>Website owners should have agency over AI bot activity on their websites. We mentioned that only 37% of the top 10,000 domains on Cloudflare even have a robots.txt file. Of those robots files that do exist, few include Disallow directives for the <a href="https://radar.cloudflare.com/ai-insights#ai-bot-crawler-traffic"><i><u>top</u></i><u> AI Bots</u></a> that we see on a daily basis.  For instance, as of publication, <a href="https://radar.cloudflare.com/explorer?dataSet=robots_txt&amp;groupBy=user_agents%2Fdirective&amp;filters=directive%253DDISALLOW"><code><u>GPTBot</u></code><u> is only disallowed in 7.8% of the robots.txt files</u></a> found for the top domains; <code>Google-Extended</code> only shows up in 5.6%; <code>anthropic-ai</code>, <code>PerplexityBot</code>, <code>ClaudeBot</code>, and <code>Bytespider</code> each show up in under 5%. Furthermore, the difference between the 7.8% of Disallow directives for <code>GPTBot</code> and the ~5% of Disallow directives for other major AI crawlers suggests a gap between the desire to <a href="https://www.cloudflare.com/learning/ai/how-to-prevent-web-scraping/">prevent your content from being used for AI model training</a> and the proper configuration that accomplishes this by calling out bots like <code>Google-Extended</code>. (After all, there’s more to stopping AI crawlers than disallowing <code>GPTBot</code>.)</p><p>Along with viewing the most active bots and crawlers, Cloudflare Radar also shares weekly updates on how websites are handling <a href="https://radar.cloudflare.com/ai-insights?cf_target_id=3D982CE3E88C4E32F9D4AA79E7869F7C#ai-user-agents-found-in-robotstxt"><u>AI bots in their robots.txt files</u></a>. We can examine two snapshots below, one from <a href="https://radar.cloudflare.com/ai-insights?dateStart=2025-06-23&amp;dateEnd=2025-06-24"><u>June 2025</u></a> and the other from <a href="https://radar.cloudflare.com/ai-insights?dateStart=2025-01-26&amp;dateEnd=2025-02-01"><u>January 2025</u></a>:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/30Wc2jLvDqSMBKF5QxU2yc/f18b44d8ba9d11687c0224b40cf12675/image6.png" />
          </figure><p><sub><i>Radar snapshot from the week of June 23, 2025, showing the top AI user agents mentioned in the Disallow directive in robots.txt files across the top 10,000 domains. The 3 bots with the highest number of Disallows are GPTBot, CCBot, and facebookexternalhit.</i></sub></p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/T9krKSMLRud7sYgG7ahei/8632afeba6d22baa304ae9fd901e187a/image9.png" />
          </figure><p><sub><i>Radar snapshot from the week of January 26, 2025, showing the top AI user agents mentioned in the Disallow directive in robots.txt files across the top 10,000 domains. The 3 bots with the highest number of Disallows are GPTBot, CCBot, and anthropic-ai.</i></sub></p><p>From the above data, we also observe that fewer than 100 new robots.txt files have been added among the top domains between January and June. One visually striking change is the ratio of dark blue to light blue: compared to January, there is a steep decrease in “Partially Disallowed” permissions; websites are now flat-out choosing “Fully Disallowed” for the top AI crawlers, including <code>GPTBot</code>, <code>CCBot</code>, and <code>Google-Extended</code>. This underscores the changing landscape of web crawling, particularly the relationship of trust between website owners and AI crawlers.</p>
    <div>
      <h3>Putting up a guardrail with Cloudflare’s managed robots.txt</h3>
      <a href="#putting-up-a-guardrail-with-cloudflares-managed-robots-txt">
        
      </a>
    </div>
    <p>Many website owners have told us they’re in a tricky spot in this new era of AI crawlers. They’ve poured time and effort into creating original content, have published it on their own sites, and naturally want it to reach as many people as possible. To do that, website owners make their sites accessible to search engine crawlers, which index the content and make it discoverable in search results. But with the rise of AI-powered crawlers, that same content is now being scraped not just for indexing, but also to train AI models, often without the creator’s explicit consent. Take <code>Googlebot</code>, for example: it’s an absolute requirement for most website owners to allow for SEO. But Google crawls with user agent <code>Googlebot</code> for both SEO <i>and</i> AI training purposes. Specifically disallowing <a href="https://developers.google.com/search/docs/crawling-indexing/google-common-crawlers#google-extended"><code><u>Google-Extended</u></code></a> (but not <code>Googlebot</code>) in your robots.txt file is what communicates to Google that you do not want your content to be crawled to feed AI training.</p><p>So, what if you don’t want your content to serve as training data for the next AI model, but don’t have the time to manually maintain an up-to-date robots.txt file? <b>Enter Cloudflare’s new managed robots.txt offering.</b> Once enabled, Cloudflare will automatically update your existing robots.txt or create a robots.txt file on your site that includes directives asking popular AI bot operators to not use your content for AI model training. For instance, <b>Cloudflare’s managed robots.txt signals your preference to </b><code><b>Google-Extended</b></code><b> and </b><a href="https://support.apple.com/en-us/119829"><code><b><u>Applebot-Extended</u></b></code></a><b>, amongst others, that they should not crawl your site for AI training,</b> while keeping your domain(s) SEO-friendly.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2SLxL9LMN1IK2WXOIq8ezP/786db3e1cbc24b1cce4c337b8136d3a7/image3.png" />
          </figure><p><sup><i>Cloudflare dashboard snapshot of the new managed robots.txt activation toggle </i></sup></p><p>This feature is available to all customers, meaning anyone can <a href="https://developers.cloudflare.com/bots/additional-configurations/managed-robots-txt/"><u>enable this today</u></a> from the Cloudflare dashboard. Once enabled, website owners who previously had no robots.txt file will now have Cloudflare’s managed bot directives live on their website. What about website owners who already have a robots.txt file? The contents of Cloudflare’s managed robots.txt will be <i>prepended</i> to site owners’ existing file. This way, their existing Block directives – and the time and rationale put into customizing this file – are honored, while still ensuring the website has AI crawler guardrails managed by Cloudflare.</p><p>As the AI bot landscape changes with new bots on the rise, Cloudflare will keep our customers a step ahead by updating the directives on our managed robots.txt, so they don’t have to worry about maintaining things on their own. Once enabled, customers won’t need to take any action in order for any updates of the managed robots.txt content to go live on their site. </p><p>We believe that managing crawling is key to protecting the open Internet, so we’ll also be encouraging every new site that onboards to Cloudflare to enable our managed robots.txt. When you onboard a new site, you’ll see the following options for managing AI crawlers:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6l4RpmHHf0OGP44XyDnZra/66c30bb8080d3107ab93af55dc6a8c6e/Screenshot_2025-06-30_at_3.59.54%C3%A2__PM.png" />
          </figure><p>This makes it effortless to ensure that <b>every new customer or domain onboarded to Cloudflare gives clear directives to how they want their content used.</b></p>
    <div>
      <h3>Under the hood: technical implementation</h3>
      <a href="#under-the-hood-technical-implementation">
        
      </a>
    </div>
    <p>To implement this feature, we developed a new module that intercepts all inbound HTTP requests for <code>/robots.txt</code>. For all such requests, we’ll check whether the zone has opted in to use Cloudflare’s managed robots.txt by reading a value from our <a href="https://blog.cloudflare.com/introducing-quicksilver-configuration-distribution-at-internet-scale/"><u>distributed key-value store</u></a>. If they have, the module then responds with the Cloudflare’s managed robots.txt directives, prepended to the origin’s robot.txt if there is an existing file. We prepend so we can add a generalized header that instructs all bots on the customers preferences for data use, as defined in the <a href="https://www.ietf.org/archive/id/draft-it-aipref-attachment-00.html#name-introduction"><u>IETF AI preferences proposal</u></a>. Note that in robots.txt, the <a href="https://datatracker.ietf.org/doc/html/rfc9309#section-2.2.2"><u>most specific match</u></a> <i>must</i> always be used, and since our disallow expressions are scoped to cover everything, we can ensure a directive we prepend will never conflict with a more targeted customer directive. If the customer has <i>not</i> enabled this feature, the request is forwarded to the origin server as usual, using whatever the customer has written in their own robots.txt file. (While caching origin's robots.txt could reduce latency by eliminating a round trip to the origin, the impact on overall page load times would be minimal, as robots.txt requests comprise a small fraction of total traffic. Adding cache update/invalidation would introduce complexity with limited benefit, so we prioritized functionality and reliability in our implementation.)</p>
    <div>
      <h2>Step 2: block, but only where you show ads</h2>
      <a href="#step-2-block-but-only-where-you-show-ads">
        
      </a>
    </div>
    <p>Adding an entry to your robots.txt file is the first step to telling AI bots not to crawl you. But robots.txt is an honor system. Nothing forces bots to follow it. That’s why we introduced our <a href="https://blog.cloudflare.com/declaring-your-aindependence-block-ai-bots-scrapers-and-crawlers-with-a-single-click/"><u>one-click managed rule</u></a> to block all AI bots across your zone. However, some customers want AI bots to visit certain pages, like developer or support documentation. For customers who are hesitant to block everywhere, we have a brand-new option: let us detect when ads are shown on a hostname, and we will block AI bots ONLY on that hostname. Here’s how we do it.</p><p>First, we use multiple techniques to identify if a request is coming from an AI bot. The easiest technique is to identify well-behaved crawlers that publicly declare their user agent, and use dedicated IP ranges. Often we work directly with these bot makers to add them to our <a href="https://radar.cloudflare.com/traffic/verified-bots"><u>Verified Bot list</u></a>.</p><p>Many bot operators act in good faith by publicly publishing their user agents, or even <a href="https://blog.cloudflare.com/verified-bots-with-cryptography/"><u>cryptographically verifying their bot requests</u></a> directly with Cloudflare. Unfortunately, some attempt to appear like a real browser by using a spoofed user agent. It's not new for our global machine learning models to recognize this activity as a bot, even when operators lie about their user agent. When bad actors attempt to crawl websites at scale, they generally use tools and frameworks that we’re able to fingerprint, and we use Cloudflare’s network of over 57 million requests per second on average, to understand how much we should trust the fingerprint. We compute global aggregates across many signals, and based on these signals, our models are able to consistently and <a href="https://blog.cloudflare.com/declaring-your-aindependence-block-ai-bots-scrapers-and-crawlers-with-a-single-click/"><u>appropriately flag traffic from evasive AI bots</u></a>.</p><p>When we see a request from an AI bot, our system checks if we have previously identified ads in the response served by the target page. To do this, we inspect the “response body” — the raw HTML code of the web page being sent back.  After parsing the HTML document, we perform a comprehensive scan for code patterns commonly found in <a href="https://support.google.com/adsense/answer/9183549?hl=en#:~:text=An%20ad%20unit%20is%20one,flexibility%20in%20terms%20of%20customization."><u>ad units</u></a>, which signals to us that the page is serving an ad. Examples of such code would be:</p>
            <pre><code>&lt;div class="ui-advert" data-role="advert-unit" data-testid="advert-unit" data-ad-format="takeover" data-type="" data-label="" style=""&gt;
&lt;script&gt;
....
&lt;/script&gt;
&lt;/div&gt;</code></pre>
            <p>Here, the div-container has the <code>ui-advert</code> class commonly used for advertising. Similarly, links to commonly used ad servers like Google Syndication are a good signal as well, such as the following:</p>
            <pre><code>&lt;link rel="dns-prefetch" href="https://pagead2.googlesyndication.com/"&gt;

&lt;script async src="https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-1234567890123456" crossorigin="anonymous"&gt;&lt;/script&gt;</code></pre>
            <p>By streaming and directly parsing small chunks of the response using our ultra-fast <a href="https://blog.cloudflare.com/html-parsing-2/#lol-html"><u>LOL HTML parser</u></a>, we can perform scans without adding any latency to the inspected response.</p><p>So as not to reinvent the wheel, we are adopting techniques similar to those that ad blockers have been using for years. Ad blockers fundamentally perform two separate tasks to block advertisements in a browser. The first is to block the browser from fetching resources from ad servers, and the second is to suppress displaying HTML elements that contain ads. For this, ad blockers rely on large filter lists such as <a href="https://easylist.to/index.html"><u>EasyList</u></a> that contain both so-called URL block filters that match outgoing request URLs against a set of patterns, and block them if they match one of the filters, and CSS selectors that are designed to match HTML ad elements.</p><p>We can use both of these techniques to detect if an HTML response contains ads by checking external resources (e.g. content referenced by HREF or SCRIPT tags) against URL block filters, and the HTML elements themselves against CSS selectors. Because we do not actually need to block every single advertisement on a site, but rather detect the overall presence of ads on a site, we can achieve the same detection efficacy when shrinking the number of CSS and URL filters down from more than 40,000 in EasyList to the 400 most commonly seen ones to increase our computational efficiency.</p><p>Because some sites load ads dynamically rather than directly in the returned HTML (partially to avoid ad blocking), we enrich this first information source with data from <a href="https://developers.cloudflare.com/fundamentals/reference/policies-compliances/content-security-policies/"><u>Content Security Policy (CSP)</u></a> reports. The Content Security Policy standard is a security mechanism that helps web developers control the resources (like scripts, stylesheets, and images) a browser is allowed to load for a specific web page, and browsers send reports about loaded resources to a CSP management system, which for many sites is Cloudflare’s <a href="https://developers.cloudflare.com/page-shield/"><u>Page Shield</u></a> product. These reports allow us to relate scripts loaded from ad servers directly with page URLs. Both of these information sources are consumed by our <a href="https://www.cloudflare.com/en-gb/learning/security/glossary/what-is-endpoint/"><u>endpoint management service</u></a>, which then matches incoming requests against hostnames that we already know are serving ads.</p><p>We do all of this on every request for any customer who opts in, even free customers. </p><p>To enable this feature, simply navigate to the <a href="https://dash.cloudflare.com/?to=/:account/:zone/security/bots/configure"><u>Security &gt; Settings &gt; Bots</u></a> section of the Cloudflare dashboard, and choose either <code>Block on pages with Ads</code> or <code>Block Everywhere</code>.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/yoGKnsD7fuG9K8MysCMHl/91fb4bb69625d8c85a8dcf4cfb21f6de/unnamed__1_.png" />
          </figure>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/64xCpJrlgY1WtsNI0CeeT5/975e6a329b605e11445faafa038181aa/unnamed__2_.png" />
          </figure>
    <div>
      <h2>The AI bot hunt: finding and identifying bots</h2>
      <a href="#the-ai-bot-hunt-finding-and-identifying-bots">
        
      </a>
    </div>
    <p>The AI bot landscape has exploded and continues to grow with an exponential trajectory as more and more operators come online. At Cloudflare, our team of security researchers are constantly identifying and classifying different AI-related crawlers and scrapers across our network. </p><p>There are two major ways in which we track AI bots and identify those that are poorly behaved:</p><p>1. Our customers play a crucial role by directly submitting reports of misbehaved AI bots that may not yet be classified by Cloudflare. (If you have an AI bot that comes to mind here, we’d love for you to let us know through our <a href="https://docs.google.com/forms/d/14bX0RJH_0w17_cAUiihff5b3WLKzfieDO4upRlo5wj8/"><u>bots submission form</u></a> today.) Once such a bot comes to our attention, our security analysts investigate to determine how it should be categorized.</p><p>2. We’re able to derive insights through analysis of the massive scale of our customers’ traffic that we observe. Specifically, we can see which AI agents visit which websites and when, drawing out trends or patterns that might make a website owner want to disallow a given AI bot. This bird’s-eye view on abusive AI bot behavior was paramount as we started to determine the content of a managed robots.txt.</p>
    <div>
      <h2>What’s next?</h2>
      <a href="#whats-next">
        
      </a>
    </div>
    <p>Our new <a href="https://developers.cloudflare.com/bots/additional-configurations/managed-robots-txt/"><u>managed robots.txt</u></a> and blocking AI bots on pages with ads features are available to <i>all Cloudflare customers</i>, including everyone on a Free plan. We encourage customers to start using them today – to take control over how the content on your website gets used. Looking ahead, Cloudflare will monitor the <a href="https://ietf-wg-aipref.github.io/drafts/draft-ietf-aipref-vocab.html"><u>IETF’s pending proposal</u></a> allowing website publishers to control how automated systems use their content and update our managed robots.txt accordingly. We will also continue to provide more granular control around AI bot management and investigate new distinguishing signals as AI bots become more and more precise. And if you’ve seen suspicious behavior from an AI scraper, contribute to the Internet ecosystem by <a href="https://docs.google.com/forms/d/14bX0RJH_0w17_cAUiihff5b3WLKzfieDO4upRlo5wj8/"><u>letting us know</u></a>!</p> ]]></content:encoded>
            <category><![CDATA[Pay Per Crawl]]></category>
            <category><![CDATA[AI]]></category>
            <category><![CDATA[Bots]]></category>
            <category><![CDATA[Impact]]></category>
            <guid isPermaLink="false">44HBJInoaQRMqVRmSaqjg6</guid>
            <dc:creator>Jin-Hee Lee</dc:creator>
            <dc:creator>Dipunj Gupta</dc:creator>
            <dc:creator>Brian Mitchell</dc:creator>
            <dc:creator>Reid Tatoris</dc:creator>
            <dc:creator>Henry Clausen</dc:creator>
        </item>
        <item>
            <title><![CDATA[Celebrate Micro-Small, and Medium-sized Enterprises Day with Cloudflare ]]></title>
            <link>https://blog.cloudflare.com/celebrate-micro-small-and-medium-sized-enterprises-day-with-cloudflare/</link>
            <pubDate>Fri, 27 Jun 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[ To celebrate United Nations Micro, Small, and Medium Sized Enterprises Day, Cloudflare is sharing success stories of small businesses building and growing on our platform. ]]></description>
            <content:encoded><![CDATA[ <p>On June 27, the United Nations celebrates <a href="https://www.un.org/en/observances/micro-small-medium-businesses-day"><u>Micro-, Small, and Medium-sized Enterprises Day</u></a> (MSME) to recognize the critical role these businesses play in the global economy and economic development. According to the <a href="https://openknowledge.worldbank.org/entities/publication/50dccfb5-81ec-4d9e-a1d9-3b9c266ab2f2?utm_source=chatgpt.com"><u>World Bank</u></a> and the <a href="https://www.un.org/en/observances/micro-small-medium-businesses-day"><u>UN</u></a>, small and medium-sized businesses make up about 90 percent of all businesses, between 50-70 percent of global employment, and 50 percent of global GDP. They not only drive local and national economies, but also sustain the livelihoods of women, youth, and other groups in vulnerable situations. </p><p>As part of MSME Day, we wanted to highlight some of the amazing startups and small businesses that are using Cloudflare to not only secure and improve their websites, but also build, scale, and deploy new serverless applications (and businesses) directly on Cloudflare's global network. </p>
    <div>
      <h2>A startup for startups</h2>
      <a href="#a-startup-for-startups">
        
      </a>
    </div>
    <p>Cloudflare <a href="https://blog.cloudflare.com/cloudflare-winner-of-the-2009-harvard-busines/"><u>started</u></a> as an idea to provide better security and performance tools for everyone. Back in 2010, if you were a large enterprise and wanted better performance and security for your website, you could buy an expensive piece of on-premise hardware or contract with a large, global <a href="https://www.cloudflare.com/learning/cdn/what-is-a-cdn/"><u>Content Delivery Network (CDN)</u></a> provider. Those same types of services were not only unaffordable for most website owners or smaller businesses, but also generally unavailable, as they typically demanded expensive on-premise hardware or direct server access that most smaller operations lacked. Cloudflare launched, fittingly <a href="https://blog.cloudflare.com/reflections-on-techcrunch-disrupt-launch/"><u>at a startup competition</u></a>, with the goal of making those same types of tools available to everyone.</p><p>As Cloudflare has grown, we have <a href="https://blog.cloudflare.com/cloudflares-commitment-to-free/"><u>continued</u></a> to highlight how our millions of free customers, many of them individual developers, <a href="https://blog.cloudflare.com/expanding-cloudflares-startup-program/"><u>startups</u></a>, and <a href="https://blog.cloudflare.com/how-cloudflare-helps-protect-small-businesses/"><u>small businesses</u></a>, drive our network, company, and mission. They help keep our costs low, allow us to interconnect with more networks, and help us build better products.   </p><p>Over the last 12 months, we have put even more of an emphasis on supporting startup and small business communities by expanding free <a href="https://www.cloudflare.com/developer-platform/products/"><u>developer tools</u></a>, which make it easier for anyone to build full stack, <a href="https://ai.cloudflare.com/"><u>AI-enabled applications</u></a> directly on Cloudflare's network, and investing in programs like <a href="https://www.cloudflare.com/forstartups/"><u>Cloudflare for Startups</u></a>, <a href="https://www.cloudflare.com/lp/workers-launchpad/"><u>Workers Launchpad</u></a>, and the <a href="https://blog.cloudflare.com/en-us/launchpad-cohort4-dev-starter-pack/"><u>Dev Alliance</u></a>. For example:  </p><ul><li><p>More than 3,000 startups are receiving free credits to build and scale their applications directly on Cloudflare's global network using our developer services. </p></li><li><p>In 2024 alone, 122 startups in 22 countries were accepted into Cloudflare's Launchpad Program, which provides additional infrastructure, tools, and community support to help entrepreneurs scale their applications and businesses, including access to Cloudflare <a href="https://cloudflare.tv/shows/workers-launchpad-demo-day"><u>demo days</u></a>. </p></li><li><p>Since 2022, Cloudflare has worked with over 40 venture capital partners to secure more than $2 billion in potential financing for companies participating in our startup programs. </p></li></ul><p>With the right tools in hand, entrepreneurs are turning ideas into real world impact, and we’re honored to support them. </p>
    <div>
      <h2>Spotlighting innovation across the globe</h2>
      <a href="#spotlighting-innovation-across-the-globe">
        
      </a>
    </div>
    <p>Cloudflare proudly supports over hundreds of thousands of small businesses that are using our services, including SaaS startups, health and wellness providers, real estate firms, local retailers, and global service providers. Here are just a few examples of these amazing new companies.  </p>
    <div>
      <h3>Built with Cloudflare: European startups </h3>
      <a href="#built-with-cloudflare-european-startups">
        
      </a>
    </div>
    <table><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Flotiq/"><u>Flotiq (Poland)</u></a></p></td><td><p>A scalable headless CMS for developers that generates fully documented APIs, delivered worldwide using Workers and Pages.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Capgo/"><u>Capgo (Estonia)</u></a></p></td><td><p>Enables mobile developers to push live updates without app store delays, with Workers &amp; R2 distributing updates at the edge.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/CurrencyAPI/"><u>CurrencyAPI (UK)</u></a></p></td><td><p>Offers real-time and historical exchange rate data for 150+ currencies, using Workers to ensure fast, reliable API access. </p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/EmbedNotionPages.com/"><u>Embed Notion Pages (Netherlands)</u></a></p></td><td><p>Turns Notion pages into embeddable web content, dynamically rendered and cached with Workers and Pages.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Webstudio/"><u>Webstudio (Germany)</u></a></p></td><td><p>An open-source visual site builder delivering fast, global performance through Pages and Workers.</p></td></tr><tr><td><p><a href="http://pullpi.io"><u>Pullpi.io (Spain)</u></a></p></td><td><p>Streamlines code review workflows to reduce tech debt, with Workers helping automate and scale delivery.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/specsavers"><u>Specsavers (UK)</u></a></p></td><td><p>A global optical retailer modernizing its frontend architecture using Pages and Workers for faster, scalable web experiences.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/NuxtHub/"><u>NuxtHub (France)</u></a></p></td><td><p>A full-stack platform for Nuxt developers to build, store, and deploy apps with ease and integrated with Workers, Pages, and more.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Starterindex"><u>Starterindex (Romania)</u></a></p></td><td><p>A curated directory of startup tools, served instantly worldwide with Pages and Workers.</p></td></tr><tr><td><p><a href="https://unfetch.com/"><u>Unfetch (Italy)</u></a></p></td><td><p>Builds AI-native productivity tools that are fast, modular, and edge-ready using Cloudflare to support performance and flexibility.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/capawesome"><u>Capawesome (Germany)</u></a></p></td><td><p>Offers open-source Capacitor plugins for mobile developers, with docs and assets served quickly via Workers and Pages.</p></td></tr></table>
    <div>
      <h3>Built with Cloudflare: Asia-Pacific businesses </h3>
      <a href="#built-with-cloudflare-asia-pacific-businesses">
        
      </a>
    </div>
    <table><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Atlas/"><u>Atlas Kitchen (Singapore)</u></a></p></td><td><p>No-code storefronts for food brands, delivering ultra-low latency and handling high traffic with Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Qwilr/"><u>Qwilr (Australia)</u></a></p></td><td><p>Creates interactive sales documents that load fast and stay secure globally using Workers, KV, and R2.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Joystick/"><u>Joystick (Hong Kong)</u></a></p></td><td><p>Multiplayer game SDK and backend platform providing low-latency previews and real-time APIs with Workers and Pages.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/TripTech/"><u>TripTech (Australia)</u></a></p></td><td><p>Powers transport apps with geolocation-aware content and secure APIs, ensuring uptime even in remote areas via Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/SlidesAI/"><u>SlidesAI (India)</u></a></p></td><td><p>AI-driven presentation builder handling high-volume rendering quickly using Pages and Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/FynLink"><u>FynLink (India)</u></a></p></td><td><p>Provides tools for logistics companies to monitor vehicle fleets, manage drivers, and improve fuel efficiency. </p></td></tr><tr><td><p><a href="https://subjective.candra.dev/"><u>Subjective (Australia)</u></a></p></td><td><p>Social platform focused on meaningful questions, fast-loading and globally accessible with Pages and Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/IDM"><u>IDM (India)</u></a></p></td><td><p>Provides secure identity infrastructure with high-performance APIs and built-in protection using Workers and R2.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/DaySchedule"><u>DaySchedule (India</u></a>)</p></td><td><p>AI-powered scheduling tool delivering fast booking and timezone handling at Cloudflare’s edge. </p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Ambie"><u>Ambie (Taiwan)</u></a></p></td><td><p>Ambient audio streaming with ultra-low latency for mobile and desktop users, powered by Workers and R2.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/homely"><u>Homely (Australia)</u></a></p></td><td><p>Property search platform delivering fast, map-based listings and seamless mobile experience via Pages and Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/dgm"><u>MKLabs (South Korea)</u></a></p></td><td><p>Digital garden showcasing creative web projects, hosted and powered for speed on  Pages and Workers.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/boxhero"><u>BoxHero (South Korea)</u></a></p></td><td><p>Inventory management app delivering fast UIs and APIs globally using Workers, R2, and Pages.</p></td></tr><tr><td><p><a href="https://workers.cloudflare.com/built-with/projects/Milkshake/"><u>Milkshake (Australia) </u></a></p></td><td><p>Mobile-friendly mini websites from Instagram bios, powered by Workers for routing and Pages for hosting.</p></td></tr></table><p>Cloudflare is also working with our civil society partners in the Asia-Pacific region to help provide security training for new businesses. For example, in 2025, we partnered with <a href="https://www.cyberpeace.org/about-us"><u>Cyberpeace</u></a>, a leading nonprofit organization in India, to host a webinar focused on <a href="https://www.cloudflare.com/learning/security/what-is-cyber-resilience/">building cyber resilience</a>. The session included a live onboarding session, training on security services, and information on the most common cyber threats. Our first session attracted over 95 participants, and due to the high demand, Cloudflare is planning to host an additional in-person training session later this year. Stay tuned for more details!</p>
    <div>
      <h2>Helping protect small businesses (and a new security guide!)</h2>
      <a href="#helping-protect-small-businesses-and-a-new-security-guide">
        
      </a>
    </div>
    <p>It is incredible to see all the innovative ways companies are building new ideas with Cloudflare. However, as a startup originally designed to protect other startups, we know security remains one of the most pressing concerns for any small business. According to the <a href="https://www.fcc.gov/communications-business-opportunities/cybersecurity-small-businesses"><u>U.S. Federal Communications Commission</u></a>, theft of digital information has surpassed physical theft as the most commonly reported fraud for small businesses. In 2025 so far, Cloudflare has mitigated over three million <a href="https://developers.cloudflare.com/ddos-protection/about/attack-coverage/"><u>Layer 3 (network layer) DDoS attacks</u></a> targeting small businesses protected by our network.</p><p>This year, to help celebrate MSME day, Cloudflare is continuing our efforts to provide training and capacity building for our small business partners by releasing a brand new Cloudflare Small Business Security Guide. The guide includes step-by-step instructions that will allow anyone to better understand cyber security services and protect their business and customers from common cyberattacks. For more information, visit the <a href="https://www.cloudflare.com/small-business/"><u>Cloudflare for Small Businesses</u></a> page to download the guide today. </p><p>Cloudflare will always make robust security services available to any small business that needs them, free of charge. It is a fundamental part of our mission to help build a better Internet and our identity as a company. </p><p>If you are building a small business and need access to better developer or security services, getting started with Cloudflare is simple, fast, and straightforward. <a href="https://www.cloudflare.com/plans/free/"><u>Signing up for a Free plan</u></a> takes only minutes and can instantly provide access to the tools you need to secure and accelerate your web presence and keep your small business thriving.</p> ]]></content:encoded>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Developers]]></category>
            <category><![CDATA[Free]]></category>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">RZxPGrzjOiPmMdVhXUdSi</guid>
            <dc:creator>Jocelyn Woolbright</dc:creator>
            <dc:creator>Smrithi Ramesh</dc:creator>
            <dc:creator>Patrick Day</dc:creator>
        </item>
        <item>
            <title><![CDATA[Celebrating 11 years of Project Galileo’s global impact]]></title>
            <link>https://blog.cloudflare.com/celebrating-11-years-of-project-galileo-global-impact/</link>
            <pubDate>Thu, 12 Jun 2025 10:00:00 GMT</pubDate>
            <description><![CDATA[ June 2025 marks the 11th anniversary of Project Galileo, Cloudflare’s effort to protect vulnerable public interest organizations from cyber threats. ]]></description>
            <content:encoded><![CDATA[ <p>June 2025 marks the 11th anniversary of <a href="https://www.cloudflare.com/galileo/"><u>Project Galileo</u></a>, Cloudflare’s initiative to provide free cybersecurity protection to vulnerable organizations working in the public interest around the world. From independent media and human rights groups to community activists, Project Galileo supports those often targeted for their essential work in human rights, civil society, and democracy building.</p><p>A lot has changed since we marked the <a href="https://blog.cloudflare.com/pt-br/celebrating-10-years-of-project-galileo/"><u>10th anniversary</u></a> of Project Galileo. Yet, our commitment remains the same: help ensure that organizations doing critical work in human rights have access to the tools they need to stay online.  We believe that organizations, no matter where they are in the world, deserve reliable, accessible protection to continue their important work without disruption.</p><p>For our 11th anniversary, we're excited to share several updates including:</p><ul><li><p>An interactive <a href="https://radar.cloudflare.com/reports/project-galileo-11th-anniv"><u>Cloudflare Radar report</u></a> providing insights into the cyber threats faced by at-risk public interest organizations protected under the project. </p></li><li><p>An expanded commitment to digital rights in the Asia-Pacific region with two new Project Galileo partners.</p></li><li><p><a href="https://www.cloudflare.com/project-galileo-case-studies/"><u>New stories </u></a>from organizations protected by Project Galileo working on the frontlines of civil society, human rights, and journalism from around the world.</p></li></ul>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3xVNGtdTOw6NXqSfzU7Up1/8a2cbe643108fa97a4d14af477a6cb80/image3.png" />
          </figure>
    <div>
      <h2>Tracking and reporting on cyberattacks with the Project Galileo 11th anniversary Radar report </h2>
      <a href="#tracking-and-reporting-on-cyberattacks-with-the-project-galileo-11th-anniversary-radar-report">
        
      </a>
    </div>
    <p>To mark Project Galileo’s 11th anniversary, we’ve published a <a href="https://radar.cloudflare.com/reports/project-galileo-11th-anniv"><u>new Radar report</u></a> that shares data on cyberattacks targeting organizations protected by the program. It provides insights into the types of threats these groups face, with the goal of better supporting researchers, civil society, and vulnerable groups by promoting the best cybersecurity practices. Key insights include:</p><ul><li><p>Our data indicates a growing trend in DDoS attacks against these organizations, becoming more common than attempts to exploit traditional web application vulnerabilities.</p></li><li><p>Between May 1, 2024, to March 31, 2025, Cloudflare blocked 108.9 billion cyber threats against organizations protected under Project Galileo. This is an average of nearly 325.2 million cyber attacks per day over the 11-month period, and a 241% increase from our 2024 Radar report. </p></li><li><p>Journalists and news organizations experienced the highest volume of attacks, with over 97 billion requests blocked as potential threats across 315 different organizations. The peak attack traffic was recorded on September 28, 2024. Ranked second was the Human Rights/Civil Society Organizations category, which saw 8.9 billion requests blocked, with peak attack activity occurring on October 8, 2024.</p></li><li><p>Cloudflare onboarded the <a href="https://investigatebel.org/en"><u>Belarusian Investigative Center</u></a>, an independent journalism organization, on September 27, 2024, while it was already under attack. A major application-layer DDoS attack followed on September 28, generating over 28 billion requests in a single day. </p></li><li><p>Many of the targets were investigative journalism outlets operating in regions under government pressure (such as Russia and Belarus), as well as NGOs focused on combating racism and extremism, and defending workers’ rights.</p></li><li><p><a href="https://t4p.co/"><u>Tech4Peace</u></a>, a human rights organization focused on digital rights, was targeted by a 12-day attack beginning March 10, 2025, that delivered over 2.7 billion requests. The attack saw prolonged, lower-intensity attacks and short, high-intensity bursts. This deliberate variation in tactics reveals a coordinated approach, showing how attackers adapted their methods throughout the attack.</p></li></ul><p>The full Radar report includes additional information on public interest organizations, human and civil rights groups, environmental organizations, and those involved in disaster and humanitarian relief. The dashboard also serves as a valuable resource for policymakers, researchers, and advocates working to protect public interest organizations worldwide.</p>
    <div>
      <h2>Global partners are the key to Project Galileo's continued growth</h2>
      <a href="#global-partners-are-the-key-to-project-galileos-continued-growth">
        
      </a>
    </div>
    <p>Partnerships are core to Project Galileo success. We rely on <a href="https://www.cloudflare.com/galileo/"><u>56 trusted civil society organizations</u></a> around the world to help us identify and support groups who could benefit from our protection. With our partners' help, we’re expanding our reach to provide tools to communities that need protection the most. Today, we’re proud to welcome two new partners to Project Galileo who are championing digital rights, open technologies, and civil society in Asia and around the world. </p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6Jg4RyM682Ykduf5EKGmXe/c0a8a797a1f889d0a1e02b68115238f9/Screenshot_2025-06-11_at_14.13.51.png" />
          </figure><p><a href="https://engagemedia.org/"><u>EngageMedia</u></a> is a nonprofit organization that brings together advocacy, media, and technology to promote digital rights, open and secure technology, and social issue documentaries. Based in the Asia-Pacific region, EngageMedia collaborates with changemakers and grassroots communities to protect human rights, democracy, and the environment.</p><p>As part of our partnership, Cloudflare participated in a 2025 Tech Camp for Human Rights Defenders hosted by EngageMedia, which brought together around 40 activist-technologists from across Asia-Pacific. Among other things, the camp focused on building practical skills in digital safety and website resilience against online threats. Cloudflare presented on common attack vectors targeting nonprofits and human rights groups, such as DDoS attacks, phishing, and website defacement, and shared how Project Galileo helps organizations mitigate these risks. We also discussed how to better promote digital security tools to vulnerable groups. The camp was a valuable opportunity for us to listen and learn from organizations on the front lines, offering insights that continue to shape our approach to building effective, community-driven security solutions.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4tX9mgOO8Ss3Wp41E6xj8Q/33e88d0736cf403882b2cef590b2f9bb/Screenshot_2025-06-11_at_14.14.04.png" />
          </figure><p>Founded in 2014 by leaders of Taiwan’s open tech communities, the <a href="https://ocf.tw/en/"><u>Open Culture Foundation </u></a>(OCF) supports efforts to protect digital rights, promote civic tech, and foster open collaboration between government, civil society, and the tech community. Through our partnership, we aim to support more than 34 local civil society organizations in Taiwan by providing training and workshops to help them manage their website infrastructure, address vulnerabilities such as DDoS attacks, and conduct ongoing research to tackle the security challenges these communities face.</p>
    <div>
      <h2>Stories from the field  </h2>
      <a href="#stories-from-the-field">
        
      </a>
    </div>
    <p>We continue to be inspired by the amazing work and dedication of the organizations that participate in Project Galileo. Helping protect these organizations and allowing them to focus on their work is a fundamental part of helping build a better Internet. Here are some of their stories:</p><ul><li><p><a href="https://fairfuturefoundation.org/"><u>Fair Future Foundation</u></a> (Indonesia): non-profit that provides health, education, and access to essential resources like clean water and electricity in ultra-rural Southeast Asia. </p></li><li><p><a href="https://yihr.org/"><u>Youth Initiative for Human Rights</u></a> (Serbia): regional NGO network promoting human rights, youth activism, and reconciliation in the Balkans.</p></li><li><p><a href="https://investigatebel.org/en"><u>Belarusian Investigative Center</u></a> (Belarus): media organization that conducts in-depth investigations into corruption, sanctions evasion, and disinformation in Belarus and neighboring regions. </p></li><li><p><a href="https://gcef.ca/en/"><u>The Greenpeace Canada Education Fund (GCEF)</u></a> (Canada): non-profit that conducts research, investigations, and public education on climate change, biodiversity, and environmental justice. </p></li><li><p><a href="https://insightcrime.org/"><u>Insight Crime</u></a> (LATAM): nonprofit think tank and media organization that investigates and analyzes organized crime and citizen security in Latin America and the Caribbean. </p></li><li><p><a href="http://diez.md"><u>Diez.md</u></a> (Moldova): youth-focused Moldovan news platform offering content in Romanian and Russian on topics like education, culture, social issues, election monitoring and news. </p></li><li><p><a href="https://engagemedia.org/"><u>EngageMedia</u></a> (APAC): nonprofit dedicated to defending digital rights and supporting advocates for human rights, democracy, and environmental sustainability across the Asia-Pacific. </p></li><li><p><a href="https://pussyriot.love/"><u>Pussy Riot</u></a> (Europe): a global feminist art and activist collective using art, performance, and direct action to challenge authoritarianism and human rights violations. </p></li><li><p><a href="https://www.ilrc.org/"><u>Immigrant Legal Resource Center</u></a> (United States): nonprofit that works to advance immigrant rights by offering legal training, developing educational materials, advocating for fair policies, and supporting community-based organizations.</p></li><li><p><a href="https://5wf.org/"><u>5W Foundation</u></a> (Netherlands): wildlife conservation non-profit that supports front-line conservation teams globally by providing equipment to protect threatened species and ecosystems.</p></li></ul><p>These case studies offer a window into the diverse, global nature of the threats these groups face and the vital role cybersecurity plays in enabling them to stay secure online. Check out their stories and more: <a href="http://cloudflare.com/project-galileo-case-studies/"><u>cloudflare.com/project-galileo-case-studies/</u></a></p>
    <div>
      <h2>Continuing our support of vulnerable groups around the world </h2>
      <a href="#continuing-our-support-of-vulnerable-groups-around-the-world">
        
      </a>
    </div>
    <p>In 2025, many of our Project Galileo partners have faced significant funding cuts, affecting their operations and their ability to support communities, defend human rights, and champion democratic values. Ensuring continued support for those services, despite financial and logistical challenges, is more important than ever. We’re thankful to our civil society partners who continue to assist us in identifying groups that need our support. Together, we're working toward a more secure, resilient, and open Internet for all. To learn more about Project Galileo and how it supports at-risk organizations worldwide, visit <a href="https://cloudflare.com/galileo"><u>cloudflare.com/galileo</u></a>.</p> ]]></content:encoded>
            <category><![CDATA[Project Galileo]]></category>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">7mDMJrIALhItjbx62fNSv4</guid>
            <dc:creator>Jocelyn Woolbright</dc:creator>
        </item>
        <item>
            <title><![CDATA[Email Security now available for free for political parties and campaigns through Cloudflare for Campaigns]]></title>
            <link>https://blog.cloudflare.com/email-security-now-available-for-free-for-political-parties-and-campaigns/</link>
            <pubDate>Mon, 17 Mar 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ We’re excited to announce that Cloudflare for Campaigns now includes Email Security, adding an extra layer of protection to email systems that power political campaigns. ]]></description>
            <content:encoded><![CDATA[ <p>At Cloudflare, we believe that every political candidate — regardless of their affiliation — should be able to run their campaign without the constant worry of cyber attacks. Unfortunately, malicious actors, such as nation-states, financially motivated attackers, and hackers, are often looking to disrupt campaign operations and messaging. These threats have the potential to interfere with the democratic process, weaken public confidence, and cause operational challenges for campaigns of all scales.</p><p>In 2020, in partnership with the non-profit, non-partisan <a href="https://defendcampaigns.org/"><u>Defending Digital Campaigns</u> </a>(DDC), we launched <a href="https://www.cloudflare.com/campaigns/usa/"><u>Cloudflare for Campaigns</u></a> to offer a free package of cybersecurity tools to political campaigns, especially smaller ones with limited resources. Since then, we have helped over 250 political campaigns and parties across the US, regardless of affiliation.</p><p>This is why we are excited to announce that we have extended our Cloudflare for Campaigns product suite to include <a href="https://www.cloudflare.com/zero-trust/products/email-security/"><u>Email Security</u></a>, to secure email systems that are essential to safeguarding the integrity and success of a political campaign. By preventing phishing, spoofing, and other email threats, it helps protect candidates, staff, and supporters from cyberattacks that could compromise sensitive data.</p>
    <div>
      <h3>The front line of protection is email security  </h3>
      <a href="#the-front-line-of-protection-is-email-security">
        
      </a>
    </div>
    <p><a href="https://www.cloudflare.com/learning/access-management/phishing-attack/"><u>Phishing attacks</u></a> on political campaigns have been a major cybersecurity threat in recent years, often leading to data breaches, leaks, and misinformation. In 2016,<a href="https://www.washingtonpost.com/world/national-security/how-the-russians-hacked-the-dnc-and-passed-its-emails-to-wikileaks/2018/07/13/af19a828-86c3-11e8-8553-a3ce89036c78_story.html"> <u>attackers targeted</u></a> Democratic National Committee (DNC) staff with <a href="https://www.cloudflare.com/learning/access-management/spear-phishing/"><u>spear phishing emails</u></a> disguised as Google security alerts, allowing hackers to access thousands of emails. In 2018, Russian intelligence agents<a href="https://www.npr.org/2018/07/26/632897181/russian-agents-unsuccessfully-tried-to-hack-sen-claire-mccaskills-campaign"> <u>attempted to infiltrate</u></a> Senator Claire McCaskill's re-election campaign by sending emails to her staff, urging them to change their passwords. </p><p>This unsettling trend has affected political parties as well. In 2020, the Republican Party of Wisconsin fell <a href="https://cyberscoop.com/wisconsin-gop-alleges-late-race-hack-cost-party-2-3-million-from-fund-to-reelect-trump/"><u>victim to a phishing attack</u></a> that resulted in hackers stealing $2.3 million. </p><p>During the<a href="https://blog.cloudflare.com/securing-the-inboxes-of-democracy/"> <u>2022 US midterm elections</u></a>, Cloudflare safeguarded the email inboxes of more than 100 campaigns, election officials, and public organizations involved in the election process. These ranged from first-time candidates in local races to seasoned incumbents at the national level. In the three months leading up to the 2022 midterms, Cloudflare processed over 20 million emails and successfully blocked around 150,000 phishing attempts targeting campaign staff. </p><p>During the <a href="https://blog.cloudflare.com/exploring-internet-traffic-shifts-and-cyber-attacks-during-the-2024-us-election/"><u>2024 US election</u></a>, we actively protected state and local election offices, political campaigns, state parties, independent media, and voting rights organizations. In addition, we safeguarded the inboxes of hundreds of political campaigns, ensuring secure and uninterrupted communications to help campaigns focus on their message and outreach without the fear of cyberattack derailing their efforts. Over the course of the year, Cloudflare:</p><ul><li><p>Scanned 5.7 million emails for campaigns and political parties </p></li><li><p>Blocked 400,000 malicious messages before they reached campaign staff and teams</p></li><li><p>Detected and blocked 21,000 suspicious emails</p></li><li><p>Prevented 14,000 unique spoofing attempts</p></li></ul>
    <div>
      <h3>Providing tools to help political campaigns and parties stay secure online </h3>
      <a href="#providing-tools-to-help-political-campaigns-and-parties-stay-secure-online">
        
      </a>
    </div>
    <p>We launched <a href="https://blog.cloudflare.com/introducing-cloudflare-for-campaigns/"><u>Cloudflare for Campaigns in 2020</u></a> to help political campaigns stay online amid cyber attacks. US campaign finance laws prohibit corporations from donating money or services to federal candidates or parties. However, we partner with Defending Digital Campaigns (DDC), approved by the Federal Election Commission, to offer free and discounted cybersecurity services. Through DDC, we provide tailored security solutions for resource-limited campaigns and parties facing heightened cyber threats.</p><blockquote><p><i>"DDC is thrilled that Cloudflare is expanding their product offerings to campaigns with the addition of Email Security. This will expedite robust protections from the real and serious threats posed by phishing. Now campaigns, in concert with the DDoS protection Cloudflare provides via Cloudflare for Campaigns, will be able to easily enable a suite of core protections. This new offering further exemplifies Cloudflare's extraordinary and generous commitment to protecting campaigns. Cloudflare has been one of DDC’s core partners since we were founded."</i><i><b>  </b></i><b>– Michael Kaiser, President &amp; CEO of Defending Digital Campaigns</b></p></blockquote><p>Over five years, our partnership has strengthened protections against DDoS attacks and web vulnerabilities. However, campaigns have frequently asked for help combating malicious emails that target campaign staff. </p><p><a href="https://www.cloudflare.com/press-releases/2022/cloudflare-to-acquire-area-1-security/"><u>Cloudflare acquired Area 1 Security in 2022</u></a> to enhance its Zero Trust platform by integrating an email security solution that proactively identifies and blocks phishing threats before they reach users' inboxes. Before the acquisition, Area 1 provided low-cost email security to political campaigns with direct FEC approval. </p><p>Fast-forward to 2025, and we are excited to officially integrate Email Security into our full Cloudflare for Campaigns portfolio to better protect US political parties and campaigns.</p>
    <div>
      <h3>Access free Email Security for your political campaign or party with Cloudflare for Campaigns </h3>
      <a href="#access-free-email-security-for-your-political-campaign-or-party-with-cloudflare-for-campaigns">
        
      </a>
    </div>
    <p>Under this program, <a href="https://www.cloudflare.com/zero-trust/products/email-security/"><u>Cloudflare Email Security</u></a> is available starting today and includes: </p><ul><li><p><b>Phishing protection</b>: AI-powered threat detection that automatically identifies and blocks malicious emails before they reach their target</p></li><li><p><b>Email authentication</b>: Built-in support for <a href="https://www.cloudflare.com/learning/email-security/dmarc-dkim-spf/"><u>DMARC, DKIM, and SPF</u></a> to prevent email spoofing</p></li><li><p><b>Real-time monitoring</b>: Continuous scanning for suspicious activities and anomalies</p></li><li><p><b>Seamless integration</b>: Easily integrates with existing email providers without disrupting workflows</p></li><li><p><b>Insightful reporting</b>: Actionable analytics and reports to track security events and improve defenses</p></li></ul><p>At Cloudflare, we are committed to helping build a better Internet — one where election campaigns can operate securely, free from the threat of cyber attacks. </p><p>Current campaigns and political parties that are protected under Cloudflare for Campaigns will receive an email with information on how to enable Email Security. If you are a campaign or a political party interested in applying for the project to get access to the full suite of products, please visit <a href="https://www.cloudflare.com/campaigns/usa/"><u>https://www.cloudflare.com/campaigns/usa</u></a>.</p> ]]></content:encoded>
            <category><![CDATA[Security Week]]></category>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Email Security]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">1vrjPL7SVTINpzIEqARhsx</guid>
            <dc:creator>Jocelyn Woolbright</dc:creator>
            <dc:creator>Ayush Kumar</dc:creator>
        </item>
        <item>
            <title><![CDATA[Helping civil society monitor cyber attacks with the CyberPeaceTracer and Cloudflare Email Security ]]></title>
            <link>https://blog.cloudflare.com/helping-civil-society-monitor-attacks-with-the-cyberpeacetracer-and-cloudflare-email-security/</link>
            <pubDate>Mon, 17 Feb 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[ We’re proud to collaborate with CyberPeace Institute by powering its latest initiative, the CyberPeace Tracer, a platform that enables civil society organizations to proactively report cyber threats. ]]></description>
            <content:encoded><![CDATA[ <p>Civil society organizations have always been at the forefront of humanitarian relief efforts, as well as safeguarding civil and human rights. These organizations play a large role in delivering services during crises, whether it is <a href="https://www.cloudflare.com/case-studies/awaq-ongd/"><u>fighting climate change</u></a>, <a href="https://www.cloudflare.com/case-studies/valdosta-amateur-radio-club/"><u>support during natural disasters</u></a>, <a href="https://www.cloudflare.com/case-studies/hera-digital-health/"><u>providing health services to marginalized communities</u></a> and <a href="https://www.cloudflare.com/project-galileo-case-studies/"><u>more. </u></a></p><p>What do many of these organizations have in common? Many times, it’s cyber attacks from adversaries looking to steal sensitive information or disrupt their operations. Cloudflare has seen this firsthand when providing free cybersecurity services to vulnerable groups through programs like <a href="https://www.cloudflare.com/galileo/"><u>Project Galileo,</u></a> and found that in aggregate, organizations protected under the project experience an average of 95 million attacks per day. While cyber attacks are a problem across all industries in the digital age, civil society organizations are disproportionately targeted, many times due to their advocacy, and because attackers know that they typically operate with limited resources. In most cases, these organizations don’t even know they have been attacked until it is too late. </p><p>Over the last 10 years of Project Galileo, we’ve had the opportunity to work more closely with leading civil society organizations. This has led to a number of exciting new partnerships, including our work with the <a href="https://cyberpeaceinstitute.org/"><u>CyberPeace Institute</u></a>. That’s why we’re excited to share work on a new resource, the <a href="https://cyberpeacetracer.ngo/"><u>CyberPeace Tracer</u></a>. This resource will enable researchers, civil society, governments, and other organizations to understand threats and data-driven insights about the cyber threat landscape of the vulnerable communities we serve.</p>
    <div>
      <h3>Partnership with CyberPeace Institute </h3>
      <a href="#partnership-with-cyberpeace-institute">
        
      </a>
    </div>
    
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/A2J1R7yr7kojfk6xCcsC0/4f029ea06f2d10fde4228ace88ba400b/Screenshot_2025-02-17_at_18.04.04.png" />
          </figure><p>The CyberPeace Institute is an independent non-profit based in Switzerland, dedicated to making cyberspace safer and more equitable for everyone. The Institute works closely with partners to minimize the impact of cyberattacks on people’s lives worldwide. In addition to partnerships, the organization provides independent <a href="https://cyberpeaceinstitute.org/cyber-incident-tracers/"><u>data-driven insights on the threat landscape</u></a>, from the global healthcare system to cyber attacks during the Russian government's invasion of Ukraine. By analyzing these attacks, they are able to highlight real-world consequences, expose violations of international laws and norms, and promote responsible behavior online.</p><p>Cloudflare's work with the CyberPeace Institute started in 2022 when the organization joined Project Galileo.Through the program, Cloudflare was proud not only to help protect the CyberPeace website, but also provide <a href="https://blog.cloudflare.com/democratizing-access-to-zero-trust-with-project-galileo/"><u>Zero Trust tools</u></a> that secure access to internal applications for the institute's global workforce. In addition to participating in Project Galileo, CyberPeace has also joined as an official partner, alongside more than 53 civil society organizations that help us identify organizations in need of protection.</p><p>As the CyberPeace Institute helped us grow Project Galileo, they also tested out new features including <a href="https://developers.cloudflare.com/email-security/"><u>Cloudflare Email Security</u></a>, a Cloudflare product designed to help protect against phishing and ransomware attacks. Testing the product for their organizations, they found that our approach to proactively detect and block malicious email, and ease of deployment with no need for hardware or extra software, would benefit the wider community they serve. With this in mind, CyberPeace came to us with an idea: they saw the potential to extend Email Security to smaller organizations that don’t have the same technical tools or budget to protect themselves. </p><p>Through our unique partnership, the CyberPeace Institute onboards its network of NGOs with Cloudflare Email Security, serving as a central hub to aggregate real-time data on email threats. This information powers a live dashboard, providing other organizations with visibility into phishing campaigns that could impact the broader community. One key challenge in tracking targeted phishing attacks is that many incidents go unreported, or victims may not realize they have been compromised until much later. By having a partner serve as a centralized point of contact, it helps ensure that insights into phishing attempts at one NGO can help protect others before the attack spreads. </p>
    <div>
      <h3>CyberPeace Tracer</h3>
      <a href="#cyberpeace-tracer">
        
      </a>
    </div>
    <p>The <a href="https://cyberpeacetracer.ngo/analysis"><u>CyberPeace Tracer </u></a>shares vulnerabilities and threats faced by the community of NGOs, developed by the CyberPeace Institute. The CyberPeace Tracer gathers and analyzes data on cyberattacks and disinformation campaigns targeting NGOs, non-profits, and charities that address global societal challenges. The goal is to better understand the scale and impact of these threats to inform the public, so that organizations can become aware of emerging threats and take action to improve their defenses.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3TvamEbkKLmzwwRmGBSfyO/e9538a60967b4384e184c437206b081e/image3.png" />
          </figure><p>For the Tracer, CyberPeace partners and collects data directly from partners who monitor a predefined set of NGO domains. The dashboards detail publicly disclosed software and hardware vulnerabilities that can be exploited against monitor NGOs, malware infections detected, and analysis of phishing attacks that reveal trends and attacker tactics. The Tracer breaks out incidents by sector, including organizations working in health, development, food, water, energy, human rights, women’s rights and more. On the <a href="https://cyberpeacetracer.ngo/analysis/phishing-threats"><u>phishing dashboard</u></a>, users can filter by country, identify the top phishing subject lines that NGOs received, as well as the top five threats that were blocked by the Email Security product. </p><p>Our collaboration with CyberPeace strengthens defenses against phishing by allowing the CyberPeace Institute to analyze flagged emails, helping to identify and disrupt malicious domains and ongoing threats. By analyzing past incidents, we have found that organizations can learn from others’ experiences and implement best practices to reduce the likelihood of future attacks and data breaches, especially in a sector where many times, attacks go unreported. </p>
    <div>
      <h3>Strengthening cyber security resources for vulnerable communities</h3>
      <a href="#strengthening-cyber-security-resources-for-vulnerable-communities">
        
      </a>
    </div>
    <p>This is an exciting development for strengthening reporting on cyber attacks to non-profits, enabling them to collaborate on solutions, share threat intelligence, and build stronger defenses across the sector. We encourage NGOs who are interested in onboarding to Cloudflare Email Security through the CyberPeace Institute to visit <a href="https://cyberpeaceinstitute.org/cloudflare-area-1/"><u>cyberpeaceinstitute.org/cloudflare-area-1/</u></a>. If you are looking for protection under Project Galileo, apply at <a href="https://www.cloudflare.com/galileo/"><u>cloudflare.com/galileo/</u></a>.</p> ]]></content:encoded>
            <category><![CDATA[Impact]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Project Galileo]]></category>
            <category><![CDATA[Policy & Legal]]></category>
            <guid isPermaLink="false">1dxYqaMbG63psPH7NGAf1O</guid>
            <dc:creator>Jocelyn Woolbright</dc:creator>
        </item>
    </channel>
</rss>