
Work Here?
Company Historically Provides H1B Sponsorship
Preparing a concise company summary based on the provided Cloudflare description.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$5.4B
Above
Industry Average
Funded Over
9 Rounds
Competitive salaries
Take-what-you-need paid vacation policy
Comprehensive health plans and benefits
Paid maternity and paternity leave
Commuter and ride share options
Returnships
Cloudflare has released Clef, a pair of open-weight decision models designed to rival TypeSafe's Jev. The models can answer yes/no, multiple choice, and ranking questions, but unlike Jev, they can process images and video alongside text. Clef uses post-trained versions of Qwen3.8-27B and Qwen3.5-9B as its backbone. Cloudflare claims its models outperform Jev in three out of four benchmark areas, though these results are self-reported and unverified. The models support a 64,000-token context window and are available via Cloudflare's Workers AI at $0.24 per million tokens, nearly six times Jev's price. They can also be downloaded from Hugging Face under Apache-2.0 licence. Running Clef locally requires significant hardware: 41GB VRAM for Clef-flash and 85GB for the full model. The API is Jev-compatible, allowing drop-in replacement.
Cloudflare has launched its Data Platform under the new brand name Basin, moving from beta to general availability. The platform rebrands Cloudflare Pipelines, R2 Data Catalog, and R2 SQL as Basin Pipelines, Basin Catalog, and Basin SQL. Basin offers serverless data management built on Apache Iceberg, positioning itself against hyperscaler services from Amazon, Google, and Azure. Cloudflare emphasises the platform's lack of lock-in and absence of egress fees for data movement across cloud regions. However, fees do exist. Whilst querying data using external tools like DuckDB, Snowflake, or Spark carries no transfer charges, Cloudflare charges for delivering data through Basin Pipelines after the included allowance. The platform allows companies to store data in R2 Data Catalog and process it with Basin SQL or various external query engines.
Cloudflare to launch post-quantum certificates for websites. Cloudflare plans post-quantum certificates via its new public CA. Network infrastructure provider Cloudflare announced plans to become a public Certificate Authority (CA). The company intends to issue both classic TLS certificates and post-quantum Merkle Tree Certificates (MTC). At the time of writing, Cloudflare does not issue publicly trusted certificates itself. The company has applied to include its own root certificates in the trust programs of Chrome, Apple, Microsoft, and Mozilla. In parallel, Cloudflare signed an agreement to acquire trusted root key material from GlobalSign. The company expects to close the deal within two months, subject to customary conditions. The existing root certificate will enable support for older smartphones, operating systems, and other devices that no longer receive updates. The new root is intended to go through inclusion procedures for current browser and platform root programs. Issuance of classic certificates will begin after completing the relevant trust procedures. The company plans to issue the first production MTCs in the first quarter of 2027. Cloudflare intends to provide standard certificates of this type free of charge. Why MTC. TLS certificates allow a browser to verify a website's authenticity before establishing a secure connection. Today's infrastructure relies on digital signatures based on classical public-key cryptography. Future sufficiently powerful quantum computers could, in theory, break some algorithms used today. One option for protection is to switch to post-quantum signatures. According to Cloudflare, they are roughly 40 times larger than classical ones, which significantly increases data volumes during TLS handshakes and in certificate transparency logs. Google does not plan to add traditional X.509 certificates with post-quantum cryptography to the Chrome Root Store. Instead, the company is developing a separate Chrome Quantum-resistant Root Store and Root Program based on MTC. Merkle Tree Certificates aggregate certificate issuance into a structure based on a Merkle tree. The certificate authority does not need to sign each entry separately: a client can verify inclusion in the log using a compact proof and a signed tree state. MTC also integrate a certificate transparency mechanism. This reduces the amount of post-quantum signatures and keys that must be transmitted during the TLS handshake. Cloudflare tested the technology with Chrome. In 2026, Cloudflare and Google ran an MTC experiment. For it, the company deployed a test certificate authority and issued certificates for a portion of domains on Cloudflare's free tier. Fifty percent of Chrome Beta 146 users in the experiment received them. In total, the system processed billions of MTCs. In the main scenario, a TLS handshake with a so-called landmark-relative MTC required transmitting one public key, one signature, and an inclusion proof smaller than 1 KB. According to Cloudflare, a TLS handshake with a landmark MTC was 9% faster at the median than with a classic certificate chain. The company noted that most of the difference was due to the absence of an intermediate certificate, and the experiment used classical, not post-quantum, signatures. In August, Cloudflare began winding down the experiment. The company now plans to move from test infrastructure to full-scale MTC issuance within its own public certificate authority. The transition will take years. The new system does not mean an immediate shift away from regular TLS certificates. Cloudflare expects the classic Web PKI to remain in use for many years, so the future CA will support both types of certificates. The company has set a goal of achieving full post-quantum protection for its products by 2029. It already uses a hybrid post-quantum key exchange for a significant share of TLS traffic, but transitioning to quantum-resistant authentication remains a separate task. In May, Quantus developers said the crypto market is not ready for the quantum threat. Read more in the special section "Quantum & After" about whether it is possible to hack the quantum internet and profit from the technologies. Found a mistake in the text? Select it and press CTRL+ENTER
Cloudflare to launch public Certificate Authority service. Wed, 30th Sep 2026 (Today) Cloudflare intends to become a public Certificate Authority, expanding the pool of issuers that provide the digital certificates used to secure websites. Its planned service would issue both traditional TLS certificates and post-quantum Merkle Tree Certificates from the same system. The company said this is designed to let website operators manage existing encryption and newer post-quantum formats without changing tools or rebuilding systems. Certificate Authorities sit at the centre of the web's trust model. They verify website identities and allow browsers to establish encrypted connections. Cloudflare argued that this role is concentrated among a small number of issuers, leaving the internet exposed if one provider suffers an outage or security breach. The announcement also reflects a broader industry push to prepare for the possibility that quantum computers could eventually break widely used cryptographic methods. Although the timing remains uncertain, companies that run internet infrastructure have been testing replacements designed to withstand more advanced forms of computing. "Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet," said Matthew Prince, Chief Executive Officer and Co-Founder of Cloudflare. "Upgrading the web's security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet. By balancing support for older devices with brand-new, post-quantum tech, we're providing a permanent safety net-so the Internet stays fast, reliable and secure for all devices, no matter what comes next," Prince added. Legacy support One immediate obstacle for any new Certificate Authority is browser and device trust. To address that, Cloudflare plans to acquire an established root certificate, which browsers, operating systems and devices use to decide whether to trust certificates issued by an authority. If completed, that would allow certificates issued by Cloudflare to be recognised by older hardware and software, including devices that no longer receive updates. It has also applied to be included in the root programmes run by Chrome, Apple, Microsoft and Mozilla, which govern trust in new certificate issuers. That dual-track approach matters because compatibility remains a practical concern for website operators. Many still need to support older smartphones, embedded systems and ageing operating systems, even as the industry discusses a shift to post-quantum cryptography. Post-quantum path Cloudflare plans to issue production Merkle Tree Certificates following earlier work with Chrome. MTCs are designed to prove that a certificate has been recorded in a trusted log while reducing the amount of cryptographic data exchanged during a connection. That feature is intended to make post-quantum methods easier to deploy at internet scale. The company presented the planned service as a single system for both current and next-generation certificates. That contrasts with the prospect of running parallel systems or forcing abrupt migrations, either of which could complicate adoption for hosting providers, developers and site owners. Cloudflare also outlined a broader set of measures tied to post-quantum readiness. These include quantum downgrade protection for IPsec, which it described as a way to stop attackers from weakening encryption on network infrastructure; tools to show whether web traffic is protected against future quantum decryption; and AI-based software to identify older cryptography in codebases. Market context Cloudflare has been part of web encryption infrastructure for more than a decade through its Universal SSL service, which distributed free TLS certificates to websites. Free and automated certificate issuance has since become standard across much of the web, but the market remains dominated by a limited number of issuers. By entering that market directly as a public Certificate Authority, Cloudflare would move from distributing certificates issued within the existing system to becoming one of the trust anchors itself. That would place it in more direct competition with established certificate providers and give it a stronger role in how post-quantum standards are introduced on the web. Cloudflare said it would start issuing classical certificates after completing the relevant browser root acceptance processes. Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.
Cloudflare to launch public Certificate Authority service. Wed, 30th Sep 2026 (Today) Cloudflare intends to become a public Certificate Authority, expanding the pool of issuers that provide the digital certificates used to secure websites. Its planned service would issue both traditional TLS certificates and post-quantum Merkle Tree Certificates from the same system. The company said this is designed to let website operators manage existing encryption and newer post-quantum formats without changing tools or rebuilding systems. Certificate Authorities sit at the centre of the web's trust model. They verify website identities and allow browsers to establish encrypted connections. Cloudflare argued that this role is concentrated among a small number of issuers, leaving the internet exposed if one provider suffers an outage or security breach. The announcement also reflects a broader industry push to prepare for the possibility that quantum computers could eventually break widely used cryptographic methods. Although the timing remains uncertain, companies that run internet infrastructure have been testing replacements designed to withstand more advanced forms of computing. "Twelve years ago, Cloudflare made encryption free and automatic for millions of websites. Today, we're taking the next step by building an open, transparent and reliable Certificate Authority for the entire Internet," said Matthew Prince, Chief Executive Officer and Co-Founder of Cloudflare. "Upgrading the web's security before quantum computers can break it is one of the biggest coordination challenges in the history of the Internet. By balancing support for older devices with brand-new, post-quantum tech, we're providing a permanent safety net-so the Internet stays fast, reliable and secure for all devices, no matter what comes next," Prince added. Legacy support One immediate obstacle for any new Certificate Authority is browser and device trust. To address that, Cloudflare plans to acquire an established root certificate, which browsers, operating systems and devices use to decide whether to trust certificates issued by an authority. If completed, that would allow certificates issued by Cloudflare to be recognised by older hardware and software, including devices that no longer receive updates. It has also applied to be included in the root programmes run by Chrome, Apple, Microsoft and Mozilla, which govern trust in new certificate issuers. That dual-track approach matters because compatibility remains a practical concern for website operators. Many still need to support older smartphones, embedded systems and ageing operating systems, even as the industry discusses a shift to post-quantum cryptography. Post-quantum path Cloudflare plans to issue production Merkle Tree Certificates following earlier work with Chrome. MTCs are designed to prove that a certificate has been recorded in a trusted log while reducing the amount of cryptographic data exchanged during a connection. That feature is intended to make post-quantum methods easier to deploy at internet scale. The company presented the planned service as a single system for both current and next-generation certificates. That contrasts with the prospect of running parallel systems or forcing abrupt migrations, either of which could complicate adoption for hosting providers, developers and site owners. Cloudflare also outlined a broader set of measures tied to post-quantum readiness. These include quantum downgrade protection for IPsec, which it described as a way to stop attackers from weakening encryption on network infrastructure; tools to show whether web traffic is protected against future quantum decryption; and AI-based software to identify older cryptography in codebases. Market context Cloudflare has been part of web encryption infrastructure for more than a decade through its Universal SSL service, which distributed free TLS certificates to websites. Free and automated certificate issuance has since become standard across much of the web, but the market remains dominated by a limited number of issuers. By entering that market directly as a public Certificate Authority, Cloudflare would move from distributing certificates issued within the existing system to becoming one of the trust anchors itself. That would place it in more direct competition with established certificate providers and give it a stronger role in how post-quantum standards are introduced on the web. Cloudflare said it would start issuing classical certificates after completing the relevant browser root acceptance processes. Production issuance of Merkle Tree Certificates is scheduled to begin in the first quarter of 2027.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
Find jobs on Simplify and start your career today