[BidClub_]
Business Breakdowns · · 70 min

Cloudflare: Leading Cybersecurity [Business Breakdownes Ep 241]Cloudflare Final

Matt ReustleSam Eden

YouTube
TL;DR
  • Cloudflare now runs over 20% of the world's web traffic through “a single global private network,” absorbing “over 2 and a half million cyber attacks every single second,” on $2B+ of annualized revenue. Sam Eden of Square Peg's Global Tech Fund frames the whole business as one insight compounding for 15 years: intercept everything once, then layer product after product on the same commodity hardware.
  • The moat is a reinforcing loop, not a product: cheap hardware plus a generous free tier attracts the long tail, more traffic means more threat data and more peering leverage with 13,000+ networks, driving costs down and quality up. “This network gets better as it gets bigger” — and legacy players like Akamai couldn't follow because simple interception threatened their enterprise revenue, while scaling it technically was difficult.
  • The three “acts” — website services (~2/3 of revenue), zero-trust corporate security (~30%, highest incremental gross margin), and the developer platform — all run on the same boxes, diversifying capex ROI. Cloudflare won one large customer because its DDoS capacity was “over four times the two legacy competitors combined,” absorbing 30+ Tbps; 3M+ developers build on Workers, many entirely within the free tier.
  • The enterprise go-to-market rebuild is the near-term inflection: after 2023 rep-productivity declines and layoffs, ex-Palo Alto sales president Mark Anderson has large-customer revenue growth accelerating from ~30% to 40% YoY, and Q3 NRR jumped from 112% to 119%. “Pool of funds” bundling (one $130M/5-year deal) is already low double digits of ACV, RPO grows ~40% YoY, and channel-partner revenue at 30% of total vs. ~90% for Zscaler/Netskope implies a long runway.
  • Latest reporting put 80% of top AI-native companies among Cloudflare's customers, and Workers AI serves inference from GPUs across 330 cities — enabled because Cloudflare's motherboards “left an empty slot open” for an unknown future use case. But Eden flags this as the strategic divergence risk: GPU ROI is concentrated in one product rather than split across all services, and inference was pursued as a market opportunity rather than emerging from internal tooling.
  • The outage “wasn't an attack… it was a process error” — an upstream error doubled the bot-management model's features, and a corrupted file was pushed every five minutes until servers ran out of memory — and Eden argues the transparent same-day report, like CrowdStrike 2024, leaves the franchise intact. Matt Reustle's frame: like Moody's or Equifax, “if it doesn't kill them it kind of proves the moat.”
  • Valuation is the honest sticking point: ~25x NTM revenue at the start of the year means “there's effectively no margin for execution error… this is priced for pretty flawless execution.” Getting comfortable requires modeling Act 2 catching up to and perhaps surpassing incumbents and Act 3/inference becoming very large; FCF margins near 10% (capex 11–14% of revenue) are guided to 25%+, which Square Peg thinks they can exceed.
Digest · the substance, structured for research

1. The postal-service model: speed and security for anything with a URL

  • Eden's opener: Cloudflare's original product protects any public website — “your weekend hobby project” or the largest sites on earth — from DDoS floods, traffic interception, and bot scraping. His analogy: Cloudflare is a sorting factory intercepting all your mail, blocking junk and organized spam attacks, scanning packages, then extending to “local warehouses” (CDN caching) and “dedicated fast freeways” across the postal network.
  • The Shopify example, on Matt's prompt: a botnet hits a merchant storefront on Black Friday; without Cloudflare the servers overload and the store goes dark — “if your website's down, well, you're not making any revenue.” Cloudflare absorbs the attack at the edge.
  • Scale, before anything else: over 20% of world web traffic and “an average of over 2 and a half million cyber attacks every single second” absorbed and blocked. Matt's reaction: “somewhat frightening.”

2. The world before, and Project Honeypot

  • Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway. Pre-2009, legacy CDNs like Akamai split the network: customers decided what went on the CDN vs. direct, bought physical firewalls separately, and needed sales engineers for complex implementations — enterprise-only, with “no solution for the long tail of websites.”
  • Founding trio: Matthew Prince (childhood computer tinkerer, literature degree, lawyer, ducked out of taking over the family business — including a Hooters — for HBS), Michelle Zatlyn (met at HBS; “Matthew brings the vision, Michelle brings the operational rigor”), and technical co-founder Lee Holloway, later diagnosed with frontotemporal dementia — “his technical influence remains strong throughout Cloudflare today.”
  • Project Honeypot, the precursor: tracker email addresses that spammers scraped, building “effectively a do not call list for spammers.” Hundreds of thousands installed it, and the network-effect DNA was set: “the more users, the better the service because the list got bigger.”

3. The breakthrough: one proxy that intercepts everything

  • Rather than multiple reverse proxies with split rules, customers just say “my new mailing address is Cloudflare” — every service can then be toggled on without a sales engineer, making Cloudflare “the first real product-led growth company for internet services.” Matt's question — were they getting paid? — draws the recurring theme: no, the generous free tier is the moat-builder.
  • Why incumbents didn't copy it: revenue (“a classic case of the innovator's dilemma” — enterprises didn't want simple interception) and cost — intercepting all traffic at scale is difficult, solved with commodity hardware and a software-defined network “inspired by Google.”
  • Early adopters were nonprofits (high traffic, no budget) and the hacker community protecting itself — “if they could protect hackers, then they could protect a more basic website as well.”

4. Peering leverage and the reinforcing loop

  • Aggregating the long tail gave negotiating power with ISPs: “why don't I just put my server next to yours?” — the ISP escapes transfer fees, its internet speeds up, and Cloudflare often doesn't have to pay bandwidth fees. Matt asks whether the ISP is the loser; Eden insists it is win-win, since customers blame slow internet on the ISP. Today the single network connects directly to over 13,000 networks.
  • The flywheel Eden calls the most important part of the business: cheap hardware and easy product → long-tail adoption → more traffic and threat signal → better blocking and optimization → more enterprise customers → more peering leverage and lower costs → reinvestment into more products. “This network gets better as it gets bigger… an incredibly difficult system to replicate” after 15 years.

5. Three acts on one network

  • Act 1 hit a tipping point where capacity and services beat the legacy vendors: a recent large-customer win came because DDoS protection capacity was “over four times the two legacy competitors combined” — over 30 terabytes per second absorbed easily.
  • Act 2 flips the proxy: the same hardware inspects outbound corporate traffic instead of inbound website traffic. Zero trust means “just because you could access app number one doesn't mean you can access app number two” — every web request inspected every time, “which looks a lot like their original services.” Three buckets: employee-to-public-internet traffic, internal app access, and adjacencies like phishing/email security.
  • Act 3 grew from Cloudflare's internal tooling: nobody else, including AWS, could handle their scale, so they built proprietary software — then realized developers could build powerful products with the same tools. Workers serverless functions, storage, lightweight databases; 3M+ developers; free tier of 100,000 Worker queries/day and 10GB storage with zero egress fees. Canonical use case: an edge script swapping local pricing or language faster than querying a central database.

6. AI: everywhere around the market, plus one deliberate bet

  • Eden's map: adjacent tailwinds (agents reading data without egress fees), serving AI companies directly — latest reporting put 80% of top AI-native companies among Cloudflare's customers — and inference itself via Workers AI.
  • The empty-slot story is the tell on long-term strategy: when designing their motherboards, “they left an empty slot open because they didn't know what the use case would be… it turns out AI inference was that something.” GPUs plugged into servers across 330 cities, with no pre-provisioning — “you only pay for the AI inference that you use.”
  • His flagged risk: this diverges from the model where every box runs every product. GPU ROI “is just from the AI inference — a more concentrated ROI risk,” and unlike Acts 2 and 3, which emerged from what Cloudflare was already doing internally, “they just saw the importance of the market and decided to go after it.”

7. The go-to-market rebuild: Anderson, pool of funds, partners

  • The PLG-to-enterprise transition stumbled — 2023 rep productivity dropped and much of the sales team was let go — before Mark Anderson (ex-president of sales at Palo Alto Networks, CEO of Alteryx) arrived in 2024. Hiring shifted to majority-enterprise reps; large-customer revenue growth inflected “from around 30% up to 40% year-over-year.” Customers over $100K are under 1.5% of the base but ~75% of revenue, and at a $2B run-rate Cloudflare has under 200 $1M+ customers vs. Zscaler's ~500 at the same size — the runway.
  • Pool of funds fixes the three-buyer friction: multi-year commitments (one $130M five-year contract) drawable against any product, encouraging experimentation with newer Acts. Rolled out in 2024, already low double digits of total ACV, with RPO growing ~40% YoY and NRR reaccelerating from 112% to 119% in Q3.
  • Channel partners, under new hire Tom Evans (ex-Palo Alto worldwide channel lead): partner-led growth ~65% YoY for two years, incremental revenue from partners up from ~20% to over 40%. At 30% of total revenue vs. ~90% for Zscaler and Netskope, “they're just getting started.” Since larger partners often monetize implementation services rather than product cuts, that can help protect Cloudflare's margins; Act 2 is the highest-incremental-gross-margin business.

8. The model in numbers: charge for complexity, not volume

  • Freemium is doctrinal: free users get unmetered DDoS protection and free CDN bandwidth — “they're not going to punish you” for being attacked — with monetization on complexity (rules, bot management) via subscription tiers in Act 1 and usage pricing in Act 3. Eden's proof point: Square Peg built “quite sophisticated AI products” internally on Cloudflare and “our bills have been remarkably low.” Revenue splits roughly two-thirds Act 1, ~30% Act 2, with Act 3 still smaller but growing very quickly; there are 55+ revenue-generating products, and customers with 10+ products are the fastest-growing category.
  • Margins need adjustment: non-GAAP gross margin of 75–78% carries ~6% of revenue in equipment depreciation — cash-basis comparison lands at 83–85%. Capex runs 11–14% of revenue, FCF margins ~10% with management guiding to 25%+, and sales & marketing at 35% of revenue is the main opportunity for operating leverage.
  • Capital allocation discipline: “investing behind the demand curve,” commodity hardware, and — the key — every server runs every product, so each capex dollar's ROI is split across Acts 1, 2, and 3.

9. Outage, Zscaler, and a valuation with no room for error

  • On the outage: “it wasn't an attack. It wasn't a security breach… it was a process error” — an upstream error doubled the bot-management model's features, and a corrupted file was pushed every five minutes until servers ran out of memory. Eden's parallel is CrowdStrike 2024, and the transparent same-day incident report was appreciated by the engineering-focused community; an earlier Google Cloud KV-cache outage even accelerated the migration off third-party software. Matt's framing — Moody's, Equifax — “if it doesn't kill them it kind of proves the moat.”
  • Act 2 is more competitive and Cloudflare is admittedly the second mover behind Zscaler, which has an incumbent advantage with large enterprises. But the network argument bites: a request routed through Zscaler may still end at a Cloudflare-protected site — “we're processing all of this traffic anyway, why don't we process it on the way out as well?” The Canva example carries it: Southeast Asian design contractors get agentless inline access with low latency because Cloudflare has peering relationships and has improved connectivity in those markets for years, while Zscaler's direct app-peering model may work less well in certain markets.
  • Eden's intellectually honest close on valuation: ~25x NTM revenue at the start of the year, “one of the highest in the industry,” sustained ~29–30% growth, but “there's effectively no margin for execution error — this is priced for pretty flawless execution.” You must believe Act 2 can catch up to and perhaps surpass incumbents and Act 3 inference “can be a very large business.” Matt compared it with headlines implying ~100x sales for a SpaceX IPO: it “makes it look cheap.”
  • The pattern-recognition takeaways, mapped to Square Peg's theme/team/model/moat framework: founder DNA, product simplicity atop technical sophistication (Snowflake, Datadog analogies), multiple growth levers, and the contrarian one — “capex in software can be okay provided that it has that very high ROI.” The thesis in one line: “a business that gets better as it gets bigger.”
Full transcript
Matt Reustle

This is Matt Reustle, and today we are breaking down the cybersecurity giant Cloudflare.

Today, Cloudflare controls over 20% of the world's web traffic. To me, an equally notable metric is that Cloudflare absorbs 2.5 million cyberattacks per second. My guest for this episode is Sam Eden, an investor at Square Peg's Global Tech Fund.

While I could understand on the surface what Cloudflare does, Sam really helped me get into the weeds on how the digital pipes actually work. We go through the rise of Cloudflare, how they built a differentiated product, and how they evolved that over time versus incumbents and fellow upstarts in what is obviously an in-demand market.

Through this story, Sam gets into the product offerings that led to Cloudflare's leading market share, some of the new evolutions, what that might mean for growth looking forward, and how to conceptualize and break that down through the various buckets.

If you have any interest in better understanding the world of cybersecurity, you will enjoy this episode.

All right, Sam, I am excited to have you here to break down Cloudflare. It is a tech company that I think is obviously understood by tech investors. Generalists maybe have more of a high-level understanding, and I think the population at large probably has very little understanding of what's going on.

We're going to do our best to get that understanding before we get into the overall business and what it looks like today. To start, how would you describe or explain what Cloudflare does as a business and as a technology for its customers?

1. How Cloudflare Works

Sam Eden

Cloudflare has many different products, and we'll get to these throughout this conversation, but the most common one, and what they started with, is their application and website services.

Cloudflare provides speed and security for your website. Their customers are companies with a website. This could be your weekend hobby project, or it could be some of the largest companies in the world with some of the most highly trafficked websites in the world.

If you run a website, it has a public URL, so anyone can visit it. But that also means that anyone can attack it. Cloudflare provides security to prevent these spam attacks. These are known as DDoS attacks, which basically try to overload your servers. Hackers will try to intercept and manipulate internet traffic. Cloudflare protects you from that, and it prevents bots from scraping your website.

That probably sounded a little technical, so maybe an analogy for these internet services is a postal service. Let's say you run a website, which in this analogy would be a warehouse that ships out products. You'll get mail orders from all over the world. These would be your internet requests.

In this analogy, Cloudflare would be a sorting factory that intercepts all of your mail. They'll block junk mail for you. They'll block organized spam attacks that might try to clog up your mailbox. They'll scan all incoming boxes to make sure there's nothing malicious coming in. This is all their application security.

They extend this further. In this analogy, they would also help you set up local warehouses to reduce international shipping. They would create dedicated, fast freeways for postal services. They can speed up the whole postal network. They provide all these things to make your website fast and secure.

Matt Reustle

You're proving to me that I use the internet quite a bit but don't fully appreciate everything that's going on behind the scenes when I'm clicking around and ordering things and whatnot.

One of their customers is Shopify. Can you just give me a relatable example of what it would look like for Cloudflare to help Shopify? The speed portion makes a lot of sense in terms of making sure that they can run at optimized speed, but from a security perspective, what might that look like in a scenario for Shopify?

Sam Eden

They have millions of merchant storefronts. From the security point of view, let's say a massive botnet attacks a specific store. Let's say it's during Black Friday.

Without Cloudflare, that merchant's servers are just going to get overloaded. The website would go down, and they can't make any sales. But with Cloudflare, they're going to absorb that traffic at the edge. The website's protected, and it can stay online.

That's really important for these e-commerce companies because if your website's down, you're not making any revenue.

Matt Reustle

It's a time-is-money type of thing. Anytime there's an outage or things go down, it matters.

Before we get into some of the history, can you just give me a sense of how big Cloudflare is today, in terms of any numbers that would capture the size and impact they have in the market?

Sam Eden

Cloudflare is huge, and when you think about the scale of the internet, it's sometimes hard to wrap your head around. But you can think of Cloudflare as a single global private network that runs all this traffic.

Over 20% of the world's web runs through Cloudflare's servers. That's the scale we're talking about. In terms of cyberattacks, an average of over 2.5 million cyberattacks every single second is absorbed and blocked by the Cloudflare network.

Matt Reustle

2.5 million cyberattacks per second is somewhat frightening to me—that that's happening.

Let's get into the history here, because I know Cloudflare has evolved quite a bit over the years, and you don't get to that 20% without evolution. What's the founding story? Obviously, it wasn't around before the internet, but tell me a bit about the founding story, the founding team, and some of those key moments in its history.

2. The Internet Before Cloudflare

Sam Eden

It's really important to understand the history of Cloudflare because if you can understand why they were successful at the start and how they got their initial foothold in the market, all of their new products were built on top of that. If you understand the history, then you can understand all of their new products.

Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway. They now have over $2 billion in revenue.

One thing to always remember about the internet is that everything still runs on physical hardware. There are cables that actually run across the oceans. They run through mountains, and they physically connect server boxes that intercept and process all this internet traffic.

Before Cloudflare was founded, let's use an example of someone based in New York who wants to visit a website in Australia. To do that, you send a request all the way from New York to Australia. They process that and then send it all the way back through a cable across the Pacific Ocean back to the server.

That's slow, and it also costs your ISP, your internet service provider, some money because they have to pay transfer fees to work with other ISPs across the world. So this is a bit of a lose-lose situation for the ISP. They have to pay transfer fees, and it's a bad and slow customer experience.

This is still before Cloudflare. Some of the early legacy companies, let's say Akamai, provide what's called a CDN, or content delivery network. The Australian website can pay Akamai to store images or some of the other website assets on a server in New York. Anytime someone in New York visits the same Australian website, it's just pulling the data from New York, across the city, much faster.

One thing that's important to understand, because it sets up Cloudflare well, is that these legacy companies like Akamai split the network. Customers have to decide what to put on their CDN network and what to handle directly.

To set this up, you need a sales engineer. It's a complex implementation, there's a lot of ongoing maintenance, and if you buy a different service, then you have to administer that and set up a whole different network and decide what gets redirected where.

Also, this website in Australia, for example, might want to serve only valid requests. So they actually have to buy a physical firewall to intercept and check this traffic. All these services are what's called reverse proxies, which basically means they intercept incoming traffic on behalf of the website. That's part of the security piece that we talked about earlier.

So that's the lay of the land before Cloudflare. This was all very difficult. It needed those sales engineers. This was only really accessible to larger enterprises and more sophisticated websites, and these legacy vendors didn't have a solution for the long tail of websites that Cloudflare started serving.

If we want to relate this back to the postal example, this legacy setup would be if that website in Australia had to inform all of the different postal routing services all over the world. They would have to tell them their different split rules: if the mail is directed to this department, use this address; if it's directed to that department, use that address; if it's a package, use this address.

That takes maintenance because if your rules change, you have to update them. It's a lot of work.

Matt Reustle

It feels very manually intensive and a bit of a traveling-salesman problem in terms of optimizing for where things go.

3. The One Network Breakthrough

Sam Eden

So now we can get to Cloudflare. Matthew Prince, the co-founder and CEO of Cloudflare, has a very interesting background. He tinkered with computers as a child, studied literature, and became a lawyer. You can see that in his storytelling abilities.

Here's another interesting detail: he was set to take over his family business, which actually included running a Hooters. He didn't want that, so he went to HBS. Before and during that, he was working on a project called Project Honeypot, which eventually became Cloudflare.

He was working on Project Honeypot with the technical co-founder Lee Holloway, who was responsible for a lot of the early code and many of the early innovations. Unfortunately, Lee was diagnosed with frontotemporal dementia, so he's no longer with the business, but his technical influence remains strong throughout Cloudflare today.

Project Honey Pot is kind of as it sounds. It was a way to let hackers and spammers scrape email addresses from your website, but these email addresses were just trackers. You could see if someone tried to spam that email address, and they would get put on, effectively, a big list of bad addresses. It was creating a big bad list—effectively, a do-not-call list for spammers.

Hundreds of thousands of people were installing Honey Pot to help build out this list, and they were helping build out this list because they wanted to be protected from it. So the more users, the better the service, because the list got bigger.

At HBS, Matthew met Michelle Zatlyn. She's now the COO. She heard about this idea and wanted to be a part of it. They're a great pair. Matthew Prince is a real visionary, and Michelle brings a lot of the operational rigor.

Now we can get into the technical side of Cloudflare. I'll keep it high level, but they had this Honey Pot list—a list of bad actors—and it's a tricky problem to solve because it's effectively a lookup table. You see an incoming address, compare it to the list, and see whether you want to accept the request or not.

One way would be to put it on all of your customers' servers so they could do the lookup, but that would slow the entire internet down because every single request would now have to be compared. So what Cloudflare did—and this was the real innovation—was just intercept everything.

You didn't need multiple reverse proxies to do different things. You just had one reverse proxy: Cloudflare. And that does many things.

Matt Reustle

Were they getting paid to do that?

Sam Eden

No. And this is a story throughout Cloudflare. For a lot of their products, they'll turn them on, and they have a very generous free program. But this helps build out their business moat, improve their products, and create a business that's highly defensible.

Matt Reustle

Network-effect beneficiary, and getting the free service out there can lead to that.

Sam Eden

Totally. Project Honey Pot was the exact start of this. So all these customers could just redirect all of their traffic to Cloudflare, and Cloudflare would do the lookup. Now, this is really hard to do, so Lee Holloway was able to build a technical solution for this.

If we relate this back to our postal example, instead of splitting the network and all that, all you have to do now is say, “My new mailing address is Cloudflare.” No matter what the recipient is, no matter what the package type, Cloudflare will intercept it and decide what to do with it.

What this allowed, because it's intercepting everything, is for Cloudflare to easily turn another service on and off, whether it's a CDN or DDoS protection. You don't need that sales engineer that we mentioned before. Cloudflare is already in front of your traffic; you don't have to redirect anything. So that makes it simple.

This was the main breakthrough for Cloudflare. They could now serve that long tail of websites, and they were the first real product-led growth company for internet services. Anyone could sign up really quickly. They could serve all those weekend hobby projects, all the small websites, and start providing web protection services for them.

Matt Reustle

In terms of getting those users, were they just in front of the community of open-source developers, or was there anything that got their attention and helped them get that initial user base going? Was there anything that stands out?

Sam Eden

A lot of their early customers were nonprofits because they had a lot of traffic but couldn't pay much. So that was really big. They also served a lot of the hacker community because a lot of hackers get hacked as well. So hackers would sign up to Cloudflare to protect themselves.

Those were some of the big starting customers that really proved that this service could work, because if they could protect hackers, then they could protect a more basic website as well.

Matt Reustle

It's very interesting. It also meant they had to be better than the hackers because, in theory, the hackers would see what they were doing. The hacking community is fascinating to me.

4. The Reinforcing Network Effect

Sam Eden

One thing that's important to understand—and this is why their business is so hard to replicate if anyone tried—is why competitors just didn't do what they did. Why not just intercept all the traffic? The reasons would be revenue and costs.

With revenue, Cloudflare is a classic case of the innovator's dilemma. These large enterprises that I mentioned before didn't want to offer this simple interception because that's not what the large enterprises wanted. So the short-term revenue wasn't there. Cloudflare could build for this long tail on its own.

Cost is the other reason that competitors didn't do this. It's really technically difficult to build a system that scales to intercept all the traffic. They made a decision early on to just use commodity hardware. They didn't want dedicated hardware to process this.

They created a software-defined network inspired by Google, running on commodity hardware, so they could scale their network with cheaper hardware. Today, that's still the case. Today, Cloudflare is still that single global network of commodity hardware with layers of very sophisticated software on top of that.

Another really important thing is the peering relationships with the ISPs. An ISP is who you pay each month for your internet bill. If we go back to that New York-to-Australia example we mentioned earlier, let's say you visit a small website in Australia.

This small website can't afford those legacy services that only cater to enterprises. In this case, the ISP has to pay those transit fees to get the traffic to and from Australia, and the ISPs provide a slow traffic experience. So it's lose-lose. Those enterprises aren't serving those customers.

Now, because Cloudflare makes it easy, they have that product-led growth and that really generous freemium model, they can start providing those services for these small websites. One website isn't enough, but if you aggregate that whole long tail that they serve, Cloudflare has negotiating power with the ISP.

They can say, “I see you're transferring a lot of bandwidth to this region, and I know that because I see all the traffic from my customers, so why don't I just put my server next to yours? We'll have a peering relationship. That means you don't have to pay those transit fees. I'll serve the content directly.”

That ISP situation has gone from a lose-lose kind of cost and slow internet to a win-win because they don't have to pay those transit fees and their internet just sped up. So Cloudflare can negotiate this relationship and often doesn't have to pay bandwidth fees.

Matt Reustle

Is the ISP the loser in that case?

Sam Eden

I would say it's a win-win situation because without Cloudflare, they have to pay the cost of connecting to other networks. So it's a cost for the ISP. If you think about your own internet experience, if your internet's slow, you don't blame the fact that the server is on the other side of the world or anything like that; you blame your internet service provider.

By partnering with Cloudflare, they cut out those costs because they just serve it from Cloudflare, and they can speed up their internet so their customers are happier. They partner with all these ISPs across the world.

One way that I like to visualize Cloudflare is that they have this single global network that spans across the world. It's a single web, and that connects to all these sub-networks, all the ISPs. Today, their single global network connects to over 13,000 different networks directly.

These sub-networks could be ISPs, cloud providers, or corporate networks, but they connect them all together in this one connectivity layer.

Now we're ready to piece this all together. I think this is the most important part of the Cloudflare business. If you put this history together, it creates a reinforcing loop. I'll try and help you visualize it.

At the top of the cycle, we talked about their low bandwidth and low hardware costs and their easy-to-use product that enables this product-led growth motion. So they can serve that long tail of customers.

What that enables is more traffic going through their servers. So they collect more signals, they collect more data, and then they get better and better at blocking malicious actors. They get better at optimizing the network for speed and just providing better website services and better services, which is halfway around the cycle.

Now that leads to more paying customers and more enterprise customers, which again brings in more traffic. As they get more traffic, they can negotiate even more with these ISPs to reduce their bandwidth fees further and create more peering relationships that bring their costs down further.

Then they can reinvest that revenue and cost savings back into their global network, create more products, and continually build out. And the cycle continues. They attract more of that long tail, collect more data, and build out their network.

This network gets better as it gets bigger. We often look for businesses that follow this characteristic because they’ve been doing this for over 15 years. It’s an incredibly difficult system to replicate, and it’s a really important part of their moat. That’s how they can continually offer these premium services while processing over 20% of the world’s traffic. It’s just a powerful reinforcing loop that gets stronger and stronger.

Matt Reustle

In terms of controlling that volume, that puts you in a better position from a negotiating perspective. You can bring down costs in a lot of ways. But for a business like this, which is trying to detect certain things and optimize certain things, you get better in terms of what you’re offering if done right.

I’m really curious, too, just in terms of the evolutions that occurred over that period—when they hit a point of evolving into commercial operations, what that looked like, how challenging that might have been, and then some of the products that have been layered on since then, because it definitely has evolved into a full suite of things that are very complementary. How did that pace out together?

5. Cloudflare's Expanding Product Suite

Sam Eden

The Cloudflare we just described looked very different from the Cloudflare of today in terms of its product suite. The main product evolutions have been going from that product-led growth to enterprise and then using that single global network to add services. They’ve added a lot of internal cybersecurity products and then a whole developer platform on top of them. We can go through each of those.

The first one is just that transition from serving this long tail of premium customers to serving the biggest websites in the world. It follows that same loop: the more data they collected, the more they could build out the network. It reached a tipping point where their capacity and services were better than those of the legacy companies.

The capacity to absorb, say, cyberattacks or those DDoS attacks is just unmatched. A recent example they gave in one of their earnings calls is that they won over a large customer because their DDoS protection capacity was over 4 times that of the 2 legacy competitors combined. It was over 30 terabytes per second, which they easily absorbed because they’ve continually built out this network. They can serve the long tail and now these high-willingness-to-pay enterprise customers. That’s one product evolution within their original product set.

They’re able to evolve from those web security products to this whole new market of internal cybersecurity.

Matt Reustle

I’ve seen a lot of references to this in terms of a growth engine, but how would you articulate what’s going on there? I think it’s clear once it’s articulated, but describe that for the audience.

Sam Eden

If you think about the services I just explained, it’s Cloudflare intercepting outside traffic for a website. What they realized is, “We have all this hardware. Why don’t we intercept and inspect traffic that goes from a company to the outside world?” It’s basically the other way around.

This is a reverse proxy and a forward proxy, and they use the same hardware for that. If you think of a reverse proxy as protecting a website from the public internet, a forward proxy server, which is what the whole security product suite is, protects an employee from the outside internet. It protects you when you have outbound traffic.

This is the basis of the whole product suite. It’s often termed zero trust. That’s a type of approach that you can provide with these internal security products. Zero trust means there’s zero trust between any app and any user. If you contrast that with old services, maybe you log into your corporate network, gain trust once, and then you’re within your private network.

Zero trust just means that because you can access app number 1, it doesn’t mean you can access app number 2. You have zero trust between the apps. You have to get validated each time. To do that, you have to get inspected each time. All of your web requests have to get inspected each time.

That looks a lot like their original services because they’re very, very good at inspecting every single packet. They realized that they could apply their commodity hardware. They didn’t have to change anything; they just added a software layer to provide this whole new market of internal corporate cybersecurity.

Matt Reustle

If I’m thinking about that as an internal employee, would that be, if I’m logged in and I click on a link that goes to a website, it gives me an alert that this looks unsafe? Does it extend beyond that in terms of phishing emails and scams? I’m curious to know who’s doing what in the chain of constant precautions that I’m being told.

Sam Eden

Anytime you’re doing something on the internet in a work context, that’s this whole space, and Cloudflare has a solution to that. It’s a very broad market, and there are a lot of competitors in here. There are probably 3 buckets of activity that an employer will commonly take that you need to protect.

One would be that you’re on your work laptop or work network and visiting an outside public website. You want to make sure that the traffic going in and out of your work environment to the public internet is safe and secure. The second type would be that you’re working just with your internal apps. You’re checking Salesforce, you’re checking ServiceNow, things like that. You need to make sure that you’re actually approved—and this is that zero-trust approval—to view each app. Maybe there are different policies on what you can view.

The third bucket is, I guess, all the adjacent things. Email security is one, protecting against phishing attacks and things like that.

Matt Reustle

I’ve definitely experienced that when I’m on-premises, I can access certain apps, but when I’m off-premises, on mobile or on my own device, there are certain restrictions on what I can access, for good reason. I have some sense of how they’ve evolved pretty naturally from being that external third-party guard dog of sorts to also protecting from the inside. Would you point to anything else in terms of the evolution, or what they’ve rolled out that was key or monumental in terms of the development of the overall business and what they offered?

Sam Eden

This is a continual evolution that all companies are going through. Your corporate environment used to just be your on-premises network, but now everything’s cloud-based. You can work from home; you can work from anywhere. The corporate perimeter—the security perimeter—is effectively the whole internet. That’s why they can fit nicely in there and provide those services.

They realized that with their hardware system and their single global network, they could expand from web services to corporate security. The way they did that was by building a lot of the software themselves. To be able to provide these services at a global scale, they often had to build a lot of their own software. They couldn’t rely on AWS, for example. No one else could handle their scale, and they wanted to have really strong security.

What that meant is that they have this proprietary software stack, which leads to their next product evolution. They realized that if you can build Cloudflare using these internal tools that they’ve built themselves, then other developers will be able to build really powerful products with these tools as well. So they started offering these services to the developer market.

These include things like cloud storage, lightweight databases, and video services. Their flagship product in what’s called Act 3 is Cloudflare Workers. That’s a serverless function service, and they specialize in lightweight containers and lightweight functions that can be spun up and spun down really quickly to solve bite-sized tasks.

Matt Reustle

Are these developers working within corporations, where what Cloudflare is building off the shelf needs to be expanded upon and they’re incorporating it there? Or is it separate from the enterprise corporate-type clients, and are these developers building some unique product and then selling it themselves to a different audience?

Sam Eden

It’s currently quite separate. You don’t have to use these products together. You can just be a developer building a weekend hobby project and want to use the Cloudflare serverless functions. That’s a totally valid use case. They’re working to bring the products together into a more unified experience, but they don’t need to be. You can use these Cloudflare developer products on anything, really.

Matt Reustle

The developers, I assume, are then paying Cloudflare some software cost to use that?

Sam Eden

That’s right. Similar to other cloud models, say from the hyperscalers, their developer products follow a usage-based pricing model. The more you use, the more you pay. But similar to the early products, they have a very generous free tier because they really want to attract that long tail of developers and then bring that into the enterprise, which is what they’re doing at the moment.

There are over 3 million developers building with these Cloudflare developer products. A lot of them would be building quite sophisticated functions just within their free tier. To give a sense of how generous this free tier is, I think with their Workers serverless functions, you can query them up to 100,000 times a day. Their storage is 10 GB per month with zero egress fees, which is dramatically cheaper than a lot of the alternative developer products.

Matt Reustle

Can you just give an example of what a developer might build with the tools, just to give a sense of what a tangible example might be?

Sam Eden

Cloudflare Workers are best for quick functions that need to be done close to the user. One quick example would be that, if you’re loading a website, you might have a quick Worker script that changes the local pricing or changes the local language based on where that web page is loaded. That’s done at the edge, so it’s faster than querying, say, a central database to generate the page from scratch.

The way to conceptually think about these Workers is that anytime you can take a task and put it into bite-sized functions, it’s good for that because they spin up so quickly and then turn themselves off.

It is a slightly different way of thinking because you're deploying again to the single global network. If you deploy a function to AWS, you might put that on the US East servers, so it lives there. If you call that function, you have to travel there.

Whereas with Cloudflare, if, say, you're building an app in New Zealand, you deploy a function, and immediately someone in London can query that website and have that same function served from the London server at the edge. Everything gets propagated around really quickly, which is just another benefit of this single global network that they've built.

Matt Reustle

Yeah, I can speak to that example as someone who tends to find myself on UK or Japan websites. The currency switch is always beneficial. It saves me some time from doing the currency conversion.

When you think about AI, this is a business that has clearly benefited from and taken advantage of what the cloud has provided in terms of opportunities. They've been very thoughtful about that and evolved naturally into different pieces of an organization and offering more. So, two different things: riding the wave, but also being operationally thoughtful about how they're going to market.

When you think about where they fit into the AI boom and the potential to be whatever they might be in that world, how do you frame it? And then how does the management team talk about where Cloudflare fits into the AI ecosystem?

6. Cloudflare's AI Strategy

Sam Eden

I would say they fit kind of all around the AI industry, and there are probably 4 ways I'll describe this. The first way is just the adjacent tailwinds, which you mentioned. As people want to use AI, they're thinking more about their data strategy. Often, you want your AI agents, for example, to read a lot of data, and you might want to do that quickly without paying a lot of egress fees. So there are tailwinds in general for Cloudflare's approach to doing that. That's the first relationship to AI: just adjacent services.

The next 3 are the different sides of AI that they serve. The first is just serving the AI companies themselves. The latest reporting was that 80% of the top AI-native companies—the top AI companies—were Cloudflare customers. That just shows that this next generation, this next era of businesses, still look to Cloudflare first. So if they're providing other services for these AI companies, it positions them well to provide AI services as well. That's one: just serving the customers themselves.

The second direct AI involvement with Cloudflare is inference itself. They've started to offer inference at the edge through their Workers AI product. It's a slight evolution from their previous strategy, where they still have this single global network, but previously every component—every piece of that hardware—could provide every service. That's really powerful because it meant the return on investment on each of those pieces of hardware could be split across all of their products.

But now, with AI inference, the hardware starts to matter. They had to install GPUs across their servers. They have servers across 330 different cities around the world. This was done really quickly.

Cloudflare is a very long-term strategic company. When they're designing their motherboards for all of their chips, they left an empty slot open because they didn't know what it would be for or what the use case would be, but they needed it just in case something came up. It turns out AI inference was that something. So they could go to all of their boxes and simply plug in a GPU, and then AI inference would be available across the world at all of these locations.

This is serving these LLM models. You can quickly query an open-source model for text generation, image generation, or voice, or enterprise customers can deploy their own custom LLMs as well. Again, that gets propagated across their single global network.

The AI inference from Cloudflare can be done really quickly at the edge. As I mentioned before, Cloudflare Workers are really quick at spinning up and spinning down. So unlike, say, a hyperscaler, you don't have to pre-book or pre-provision capacity. You only pay for what you use. If an inference is small and you don't use it for a day, you're not going to pay anything. So you're charged directly for the AI inference that you use.

Matt Reustle

It feels like a key layer of infrastructure, so you could see them on all sides of the market. Thinking about how they transitioned, you mentioned they got to a point where their offering was on par with, and then eventually better than, what incumbents and legacy providers were offering.

Can you talk about what that looks like? I imagine they broke into the enterprise market over time—what that looked like, how they approached it, and some of the nuance to what it looks like to have an enterprise contract.

7. Selling Cloudflare To Enterprises

Sam Eden

This is an ongoing evolution; their go-to-market changes. Three things I'll call out are the general enterprise sales motion, the partner motion, which is really important to understand, and then their pool-of-funds bundling strategy.

The first go-to-market evolution was enterprise sales. This is just a typical transformation from product-led sales to enterprise sales. The product capabilities were there, but it was still a new go-to-market muscle, and across all companies this is never an easy transition, particularly as you're moving into security as well.

It's a new buyer for them. Instead of just an IT administrator who is looking over the website, you're now selling to the whole security office. It could be a multiple-month process, so they had to build this new go-to-market muscle.

In 2023, they actually saw all their rep productivity start to drop, and they had to let go of a lot of their sales team. But in 2024, they brought in a new president of revenue, Mark Anderson. He's incredibly experienced. He's formerly president of sales for Palo Alto Networks and CEO of Alteryx, so he has deep experience with enterprise sales.

They're hiring a lot more reps. They've switched from hiring a majority of mid-market reps to now hiring a majority of enterprise reps. They're still keeping this product-led growth because it's so important to their story, but now they're really increasing their sales-led growth motion.

There's still an ongoing transformation, but a quick quantitative proof that we're starting to see is that the growth of revenue from large customers has started to inflect. It was around 30%, and now it's starting to inflect up to 40% year-over-year. It's a really impressive transformation.

Matt Reustle

How big of a chunk of the business is it today?

Sam Eden

If you look at customers over $100,000 in revenue, they're less than 1.5% of the actual customer base, but they contribute about 75% of the revenue. It's very important to get this segment right.

There's a long runway in that segment as well. They're at a bit over $2 billion of annualized revenue. With that, they have a bit less than 200 customers that are over $1 million. If you compare that to Zscaler when they were at that same size—that $2 billion run rate—they had almost 500 customers with $1 million in revenue. So it highlights the runway that they have at that very large enterprise end. The go-to-market transformation is a big part of that.

Matt Reustle

How much stickiness is there, both from the perspective of keeping customers and being able to win share from some of the competition? Are there long-term contracts that are in place? Is there major friction associated with ripping out old infrastructure and implementing new? It seems like they've been able to gain market share, but how much goes into that, and what are some of the unique dynamics there?

Sam Eden

It's definitely a sticky product because if you have all your web security set up, it would take a lot to migrate from that, as well as a lot of convincing to migrate away from such a powerful network. So there is definitely stickiness involved, and one way to look at that is net revenue retention over the years. It's always been above 110%.

In the last few years, it has dipped a little, to 112% in the last few quarters. But with a lot of their other efforts—the pool of funds, a recent initiative—that's been starting to inflect, and in the latest quarter, Q3, that reaccelerated up to 119%.

Going from 112% up to 119% expansion of existing customers is a significant reacceleration. Obviously, their product is important, but some of this go-to-market contracting is really important as well.

Matt Reustle

I want to get to the partner strategy, but you mentioned the pool of funds and how that might link to that reacceleration. Can you describe that?

We've spoken about the 3 different products: web security, corporate security, and then the developer platform. We also spoke about how they can be quite separate. What that meant is you could have 3 different buyers, and you could have a company that was using each of the 3 different product groups but not necessarily talking to each other. There's a bit too much friction for what should be a smoother process for working on a single platform.

Sam Eden

That's where they introduced pool of funds. This is a bundling method, and, as it sounds, it's also a pool of funds that large customers can draw down from. What's really important with this is that you can draw it down from any product. So this really encourages experimentation and adoption of some of their newer products.

These are multiyear commitments as well. These are their top enterprise customers, and they recently signed a $130 million, 5-year contract. So these are big contracts.

But what it means is that if you plan to, say, use 80% of this pool of funds on one product, you still have a little capacity and flexibility to experiment and try out a few of these Workers products. You'll see that they work at an enterprise scale, and that just encourages adoption there.

It's still a fairly new initiative, rolled out in 2024, but it's already up to the low double digits of their total annual contract value.

A quick metric to show that this is working is that this puts a lot of focus on RPO, the remaining performance obligations, which has been growing around 40% year over year through 2025. So there's very high growth at this scale, and these pools of funds are contributing to that. I mentioned before that it's starting to accelerate net revenue retention as well. Obviously, not all of that is from the pool of funds because it's still new, but it's a contributing factor as well.

Matt Reustle

It's a really interesting strategy. You look at all these different businesses that have complementary products, but oftentimes we gloss over the fact that you have different divisions that are buying them, different customers, and what seems complementary gets bogged down in frictions associated with that. You don't get the synergistic effect that you should. I'm sure it exists elsewhere in terms of this type of approach—pooling funds—but that's quite notable.

On the partner strategy, which I skipped over but you referenced before, what does that buyer base look like? What does that strategy look like, and when did that come into play?

Sam Eden

So, the channel partner strategy is really important for their Act 2. This is their enterprise security products because the buyers often go through channel partners. These channel partners often have a preferred vendor list. So the relationships with these partners—and these could be consultants or system integrators—are really important. If you're not on their preferred vendor list, it makes the sale a lot harder.

Matt Reustle

So, would it be like WordPress might have Cloudflare?

Sam Eden

It's more like maybe a Cognizant, a CDW for security, like Tata and all these consulting and professional services groups. So they will help with the sale and then help with the implementation as well. These are whole companies on their own, so the relationships with them are really important.

Mark Anderson, the new CRO, brought in a new head of partnerships, Tom Evans, and he has a long history in these cybersecurity partnerships—a worldwide channel sales lead at Palo Alto Networks. So he has this big rolodex to pull from.

The results for that are quite impressive. Channel partner-led growth over the last few quarters has been growing around 65% year over year for the past 2 years. The percentage of incremental total revenue from partner channels has gone from about 20% to over 40% of incremental sales. So it's a really important driver of their growth, and there's a long runway too.

Just to really highlight how important this channel is for security, Cloudflare's current channel partner revenue as a percentage of total revenue is about 30%. If you contrast that with Zscaler and Netskope, they're almost at 90% of their revenue going through channel partners or channel-referred partners. So there's a long runway to go. It's a relatively new motion, so I would say they're just getting started there.

Matt Reustle

Those channels are always interesting. It's kind of like an external sales force in many ways that can do the work on your behalf. Do they give any sense of whether the margin looks materially different through the partner channel versus the other buckets? Sometimes you get lower margins associated with that because there is, in theory, a middleman involved, but do they provide any disclosure on that?

Sam Eden

They don't give too much because it is different depending on the partners, and you might have different contracts. Typically, what these partners do, though, is the large-scale resellers will basically take a cut. But for some of the larger ones, most of their revenue is actually from the professional services and implementation on top. So they're not trying to skim a product fee. They're more interested in the professional services that go on after the sale. So that just helps with the negotiation, and it can protect their margins.

Quickly on margins, these Act 2 products are the highest incremental gross-margin part of the business. It's a high-willingness-to-pay buyer of security, and you're using your existing network. So, very strong margins in that part of the business as well.

8. The Cloudflare Business Model

Matt Reustle

Maybe we can get into the financial business model and some of the spreadsheet details. I think you referenced that you're looking at over $2 billion in revenue on an annualized basis today. How is it split out between those buckets? You may have referenced it in passing, but just give a clean snapshot of that.

Sam Eden

They don't split it out exactly, but you can estimate if you split it between the Act 1, Act 2, and Act 3 products. That $2 billion is a majority of Act 1; it's their bread and butter. You could estimate maybe roughly ⅔ of their revenue is from Act 1, maybe 30% from Act 2, growing quickly, and then Act 3 is still a bit smaller but growing very quickly as well.

Matt Reustle

In terms of the customer base, I'm assuming most customers—or at least a large percentage of the revenue—are using multiple products. I think, to your point, in terms of the largest accounts being 1.5% of customers versus 75% of revenue, that kind of gets to the power of large customers. But is that the case, where the majority of customers are using multiple products—or the majority of revenue is coming from customers that are using multiple products?

Sam Eden

That's exactly the case. And they have over 55 revenue-generating products, so they have a long product suite. Customers with more than 10 products are the fastest-growing revenue category. So that's exactly the case.

Matt Reustle

Offering a freemium model seems to be ingrained in their DNA. How have they managed that over time in terms of continuing to offer a product that attracts users and potentially gets them into the funnel over time? What does that look like? We spoke a lot about the freemium model and how they got started, and they've really kept that in their DNA for Act 2 and Act 3 as well.

Sam Eden

The way they do it as well is strategically quite different from some of their competitors. On Act 1, they don't really charge for volume. Free users can actually get unmetered DDoS protection and free bandwidth for CDN. This is really generous. What they actually charge for is complexity, if you want specialized rules and special bot management setups.

But that means if you're a website that constantly gets attacked with high volume, they're not going to charge you extra. They're not going to punish you for that. That's one interesting part of the different strategy, at least for the Act 1 products. For Act 2, it's quite generous as well, up to 50 free users.

But then Act 3, their developer products as well, you can very realistically set up and build a sophisticated app without paying much at all. That's actually what we have done at Square internally. We've built some quite sophisticated AI products to ingest a lot of our research, create dashboards, and have a full AI interface built on Cloudflare. It generates an enormous amount of value, and our Cloudflare bills have been remarkably low.

Matt Reustle

Interesting that an investment firm can do that and fit into that category. Is there a way to capture what's subscription-based versus what you mentioned, like the complexity? Does that still fall under a subscription? I'm just trying to get an understanding of the contractual nature versus the usage-based nature, which I'll bucket complexity into if it should be. They're not charging based on volume necessarily, but how do you split that up?

Sam Eden

It is slightly different per product group, but for Act 1, it is a contract; it's a subscription tier. So you pick a plan—Pro tier, Business tier, or custom Enterprise tier—and you're paying that flat monthly rate for that tier. It includes a bunch of things. You would upgrade a tier when you need more enterprise features, whether it's those complexity rules, special splitting of traffic, and things like that. Not on volume, for Act 1 at least.

Act 3, those developer products, use more usage-based pricing: no egress fees, but it's usage-based pricing for how much you use their services.

Matt Reustle

Putting it all together on a margin, however you would look at this, what do margins look like for Cloudflare?

Sam Eden

They're a software business, so their non-GAAP gross margins are about 75% to 78%. This looks lower than maybe a top-performing software business that you would expect to see, but you have to keep in mind that they own and operate their own physical infrastructure, and the depreciation of this equipment is included in the reported cost of goods sold. That naturally compresses their gross margin.

If you did want to try to look at a cash-based gross margin to compare apples to apples, about 6% of their revenue is depreciation directly tied to equipment. So you could add that back in and compare gross margins in the 83% to 85% range.

Matt Reustle

As it falls to the bottom line, whether it's EBITDA margin or free cash flow margin, what does that look like? Are there any major cost buckets that eat into that?

Sam Eden

The main one to call out is the capex, which is naturally, again, a lot higher than at many software businesses. Capex has consistently been around 11% to 14% of revenue. That's going to bring your free cash flow margins down. Free cash flow margins have been around 10% in recent years. The long-term guidance, at least from management, is to expand those to over 25% as operating leverage continues to expand. They'll get the majority of that from operational costs, labor, whatever it might be.

Matt Reustle

Yeah. One big cost now is their sales and marketing cost. That's 35% of revenue, which has an opportunity to come down, and there are margin points available there as well.

Capital allocation. With that in mind, it feels like a business that has reinvestment opportunities that would take up the majority of where that cash flow would go. Has that been the policy, and how do you think about how they allocate the capital that they do have? What has their history been for capex spend and ROI on that capex?

Sam Eden

Capital allocation is a really important part of the business, and they're very strategic about how they do it so that they get a really strong ROI on their capex. We spoke earlier about just using commodity hardware, so that reduces the cost of the hardware. They often talk about investing behind the demand curve, so they see where the traffic is and what the demand is before they build.

They're not just building for no reason. What's really important to understand with their capex is that all of their servers can run all of their products and provide all of their services. That means the capex and the ROI are split across all of their product lines, across Acts 1, 2, and 3. The incremental ROI is more diversified, and it's higher. So, you're not building a separate network for each product. It's one network that can contribute to the return on each incremental capex spend.

Matt Reustle

You've alluded a lot to legacy competition. Are there new competitors in the market? It does seem like a market that will only get more important over time. How do you frame the competition? Does anybody have large, comparable market share similar to what Cloudflare has?

9. Testing The Cloudflare Moat

Sam Eden

In Act 1, they've established themselves as a leader. Some of the legacy companies specialize in certain types of networks where there's media and things like that. So, they're still important competitors, but Cloudflare has the biggest network that, as we mentioned, is very hard to catch up to. But in Act 2 and Act 3, it's much more competitive.

I think Act 2 is probably the most competitive because cybersecurity always has new players and new trends. Importantly, Cloudflare isn't leading the innovation there like they did in Act 1. They're a second mover, so Zscaler is probably the largest pure-play zero-trust Act 2 competitor, and they also have a global network that they run and manage themselves.

Matt Reustle

It's a decent time to bring up the outage, which I'm probably really burying the lead on in terms of recent activities and news, but just in terms of competition and what it could represent. Can you walk through what exactly happened? I felt like, one, the entire internet was out on me. Two, I learned just how many websites were connected to Cloudflare. So, two important things came out of that. Maybe just an explanation of what happened, and then we can get into whether there are any residual implications from it.

Sam Eden

The outage affected everyone, and I guess one of the downsides of having a single global network is that it can all go down, and that's what happened. I think what's important to understand with that outage is that it wasn't an attack. It wasn't a security breach or anything like that. It was a process error.

Basically, their bot management software that inspects all the traffic is a little machine learning model, so it has all these features. There was an upstream error that caused those features to double in size, and their servers just didn't have the memory for them. These features are updated constantly. Every 5 minutes, the model is getting updated with new threats. Every 5 minutes, a corrupted file was getting pushed out, and it broke a lot of their services. So, everything went down.

It's not dissimilar to, say, the CrowdStrike outage that happened in 2024, where it wasn't a security breach. It was a process error for something that was very much in the weeds, and it caused all these outages. Everyone similarly realized how many businesses ran on CrowdStrike. But they've come back just as strong as ever because I think people realized, "Okay, it's a process error, and they're clearly going to do something about it," which is exactly the case with Cloudflare.

I think what the customers and community really appreciate about them is just how transparent they were. They wrote a very in-depth and transparent report the day of the incident. Having quite an engineering-forward customer base, I think that was really appreciated. They've outlined process steps and updates they'll take to make sure something like that doesn't happen again.

Matt Reustle

It's a little tough when it's the machine learning. You don't have a scapegoat if it's just the machine. I guess you do, but nobody, in theory, gets fired over that. Or maybe the person behind the machine learning who codes that all up.

But, noteworthy, has it happened over history? I do think it's interesting with businesses, whether it's Moody's during the financial crisis or Equifax with security breaches, where if it doesn't kill them, it kind of proves the moat or strength of the business in many ways and to all different degrees. Have there been historical outages, maybe not as impactful as that one, and any signal as to whether they have material impacts, whether short- or long-term, on the business?

Sam Eden

There was one semi-recently. It wasn't as big as the one that happened recently, but there was an outage, and this actually encouraged some internal transformation or accelerated some internal transformations.

I mentioned earlier that Cloudflare is built on Cloudflare. They've built a lot of this proprietary software to run their systems—most of their systems, but not all of them. This could include things like acquisitions or other situations where, when they're scaling up new products, they might borrow something.

What happened in the previous outage was that there was an issue with a Google Cloud KV cache, or a small piece of the database, which flowed through some of their products and caused an outage. Again, it wasn't a security breach. It was an error that happens. But what it did was accelerate an internal project to migrate off those third-party solutions. So, I guess it was not good, but they kind of turned it into a strength to increase the robustness of their systems.

Matt Reustle

Then, I guess, based on current growth numbers or more recent growth numbers, it hasn't been too impactful on the underlying business performance. On competition, it feels like Zscaler is one that shows up in multiple categories, so I'd put them there. In Act 3, you mentioned the hyperscalers, which I think are worthy competitors for anyone to deal with.

But in terms of the competitive risks and threats, how high do you rate that on the risk spectrum? Is it something that concerns you? Sometimes, in a growing market, if you have one of the leaders, you usually feel pretty good that even if things move slightly, it's not going to be too material. I'm just thinking about the competitive threats and how fragile their position is versus being very strong and only strengthening.

Sam Eden

My view is that it's a strengthening position. With Act 2, Zscaler has that incumbent advantage and that trust with very large enterprises, but it's a huge market. Cloudflare and their other products start at the smaller end and work up to the enterprises, and they're starting to do that.

What really benefits them is having that global network across all of the products. They can use their Act 1 strength to prove their product and encourage adoption of the Act 2 products. One example of that would be, let's say you're using Zscaler for internal security. You send a request; it goes to Zscaler's machines and then to a website, but that website is likely using Cloudflare. So, it ends up going to a Cloudflare server anyway and then back.

Cloudflare is in a really strong position. It's like, "We're processing all of this traffic anyway. Why don't we process it on the way out as well as the way back in?" That will improve your latency.

Another difference would be on their peering networks. It's very hard for another company to have all these partnerships with all these ISPs around the world. Zscaler took a different approach, where they peered directly with the apps, which is great for dense cities, but in certain markets it doesn't work as well.

An example to highlight some of these differences would be Canva. Canva, the web design company, has thousands of employees around the world, and they employ a lot of contractors to help with the design templates and things like that. A lot of those contractors are based in Southeast Asia.

Canva uses Cloudflare's Act 2 products to help with access because Cloudflare uses what's called an inline service. You don't actually have to install an agent or anything onto the machine, which is really important when you're working with contractors. You can give these contractors access to all of the corporate apps that they need without having to have them install anything.

A lot of these contractors are based in markets where other competitors won't have direct peering relationships. Cloudflare can say, "Look, we've been improving the speed of this area for years. These contractors can sign on, be secure, and interact with your product with low latency that's not going to slow anyone down." That's a really strong value proposition that a lot of other companies can't speak to.

Matt Reustle

Are there any other risks that really stand out to you from a business perspective, the organization, and some of the external factors sitting around it?

Sam Eden

There are 2 risks to call out. One is that second mover in Act 2 that we were just speaking about. They are playing a bit of catch-up, but there is a long runway to go, and they're a solid contender there. So, I think the trajectory is very positive when you look at their product positioning, their channel partner growth, and all that, but it's worth just calling out because they are the second mover.

The other risk to call out is their AI inference strategy and AI in general, because it is new and it does slightly diverge from their previous strategy. So, that always adds some risk there, because I mentioned earlier that all of their other services can run on all hardware, whereas GPUs are specialized for inference.

With the ROI of their other products, it was split across all of their services, but the ROI of their GPU component is just from the AI inference. So, it's a more concentrated ROI risk.

Also, there's a slight difference in how the AI inference product came about compared with their other products. A lot of their other products emerged from what Cloudflare was doing internally. With Act 3, they had to build these services themselves. They never planned on launching a developer product, but they saw the value in that, and they released it.

Similarly with Act 2, they saw that during the day, when not many people were on websites, there were underutilized servers. So they could work with corporate security that was used during the day, and then during the night, use it for all their website security. They saw these opportunities, built for them, and leaned into them.

Whereas with AI inference, I think they just saw the importance of the market and decided to go after it. It's still that single global network, but there is a bit of a difference in strategy versus their other product launches. That's worth calling out.

Matt Reustle

Thank you for calling that out. I do want to get your general framework for valuation. I find software businesses, heaven forbid, with 75% to 80% gross margins relative to the 90% that some of these software businesses post. But how does the market approach it? How do you think about valuation? Anything that you would comment on that topic would be useful to hear.

Sam Eden

It's no secret that Cloudflare is a highly valued company. I think at the start of the year, they were at 25 times next-twelve-month revenue, which is one of the highest in the industry.

From my perspective, I love Michelle and Matthew as the operators of Cloudflare, but valuation is always a constant battle, even though it's such an impressive company. Importantly as well, it's a capital-intensive business. So free cash flow margins and earnings will start to matter more and more in, say, 5 years' time. They'll likely have lower free cash flow margins than what we've seen in best-in-class software.

But I think what gives confidence in the bull case for Cloudflare is that there are numerous growth levers that can support sustained high growth. They've sustained it in that 29% to 30% or higher range, and the markets they operate in have a lot of runway. They're continually adding products and features that support that sustained high growth rate. So that's a distinguishing factor for them.

But to get comfortable with the valuation, you have to model out 2 things. You have to model out Act 2—how quickly they can catch up to and perhaps surpass the incumbents in that space. The trajectory is very solid there. But also, you need to model out what the Act 3 scenarios could look like. How important will they be for AI inference? How big will the inference market be? We believe that it can be a very large business, and you have to believe that.

And just quickly on margin structure: sales and marketing is 35% of revenue today, so there is room for operating leverage. They've guided to 25% free cash flow margins, plus we think they can exceed that. So then you can model that out over the years and still make money on the stock. But it's important to call out that there's effectively no margin for execution error. This price is for pretty flawless execution, which they've delivered, but you just have to build confidence that it will continue.

Matt Reustle

Well, it was a very intellectually honest approach to it. At 25 times sales, I saw the SpaceX IPO headlines today, which implied, I think, 100 times sales. It's all relative in this market.

Sam Eden

Yeah. Makes it look cheap.

Matt Reustle

Yeah, exactly. And the growth number on revenue—they must be sandbagging, because it wasn't that material from the beat.

Nonetheless, this has been fascinating. I really tried to scrape out as much as I could on the technology, so thank you for keeping up with that. We like to talk about the lessons that you could take away, maybe bring it up a notch to think about frameworks and pattern recognition. What would you point to from Cloudflare that really stands out?

Sam Eden

There are a few lessons from Cloudflare that I think can be applied generally. I'll call out 4 quick ones.

Number 1, I think founder-led companies are very important. For companies to have that founder vision can be very powerful for setting that long-term strategy, setting bold visions, and sticking to the company mission. Square Peg's origins are as a VC fund and then as a global tech fund. Regardless of our listed strategy, we still look for that founder DNA, and Matthew Prince is a great example of that.

The second general lesson would just be looking for product simplicity, particularly for complicated industries. To the extent they can serve the whole long tail of the internet despite having a very sophisticated technical infrastructure, that sets them up really well and is a really positive signal.

Applying that elsewhere, I think that applies to Snowflake as well. They have a very powerful engine under the hood. It's very hard to replicate, but when you look at the product, it's a very simple query interface. It's very easy to use and adopt. Similar with Datadog: it's very easy to get started and set up, but it's powerful enough and flexible enough to work with the world's largest companies as well as the world's smallest companies. Looking for that product simplicity, yet flexibility and power, is really important.

Number 3 would just be looking for multiple levers of growth. Great companies have multiple levers of growth, and they find ways to solve more problems for more customers over time. Cloudflare is a great example of that. They've expanded their product lines, expanded the customer archetypes within each market, and have done so in markets that all have tailwinds, particularly for AI.

The fourth lesson would be that capex in software can be okay, provided that it has that very high ROI and that capex is used to build defensibility for the business. We talked a lot about that earlier with that reinforcing cycle. It creates a moat that's very hard to replicate, and because they're stacking layers on top of that hardware, you can extract a lot of ROI from each individual purchase there.

Those lessons fit very cleanly into what Square Peg looks for. We have a framework around theme, team, model, and moat. Cloudflare sits at the center of a critical theme: managing networks for speed, efficiency, and trust, particularly in the era of AI.

The team is hungry, founder-led, very focused, and able to attract and retain some of the best talent in the world. I think it's an underappreciated, high-quality business model. They can stack multiple revenue lines on top of their core capability, and all of these levers have that long duration that we look for.

And finally, moat. Cloudflare is a business that gets better as it gets bigger, and that's really important. They use their scale to enhance their differentiation and create barriers to entry as well.

Matt Reustle

Capex can be okay is a good lesson. I think AI has certainly shifted the narrative in terms of the willingness to accept high-capex companies out there in the market, assuming that they're creating barriers to entry. We can debate where that falls in line for companies and whether that's true or not.

But this has been fascinating, Sam. I appreciate you sharing all of your knowledge, getting into the nitty-gritty details here, and giving me a better appreciation of all that's happening on the internet behind the scenes. I appreciate you joining us. Thank you. This has been a lot of fun.