Cloudflare:领先的网络安全 [Business Breakdownes 第241期]Cloudflare Final
- Cloudflare 现在通过“一张全球私有网络”承载全球超过20%的网络流量,每秒吸收“超过250万次网络攻击”,年化收入超过20亿美元。 Square Peg 全球科技基金的 Sam Eden 将这项业务概括为一个持续复利了15年的洞见:先把所有流量拦截一次,再在同一套通用硬件上不断叠加产品。
- Cloudflare 的护城河不是某个产品,而是一套自我强化的循环:廉价硬件加慷慨的免费层吸引长尾客户,更多流量带来更多威胁数据和与13,000多个网络的更强对等互联议价权,进而同时降低成本、提升质量。 “网络越大,网络越好”(“This network gets better as it gets bigger”);Akamai 等传统厂商无法跟进,一方面是简单拦截会威胁企业收入,另一方面是大规模技术实现本身就很困难。
- 三条业务主线——网站服务(约占收入2/3)、零信任企业安全(约30%,增量毛利率最高)和开发者平台——都运行在同一套服务器上,从而分摊资本开支回报。 Cloudflare 曾赢下一家大客户,原因是其 DDoS 防护容量“超过两家传统竞争对手合计容量的4倍”,可轻松承接30+ Tbps;Workers 上已有超过300万名开发者,许多业务完全运行在免费层内。
- 企业市场重建是近期拐点:2023年销售代表人效下滑并裁员后,前 Palo Alto 销售总裁 Mark Anderson 推动大客户收入增速从约30%同比提速至40%,Q3 NRR 也从112%跃升至119%。 “资金池”式打包销售——一笔1.3亿美元、5年的合同——目前已占总 ACV 的低两位数百分比;RPO 同比增长约40%,而渠道合作伙伴收入占比为30%,对比 Zscaler/Netskope 约90%,说明增长空间仍大。
- 最新披露显示,头部 AI 原生公司中有80%是 Cloudflare 客户,Workers AI 则利用部署在330座城市的 GPU 提供推理服务;这一能力之所以成为可能,是因为 Cloudflare 的主板“预留了一个空插槽”,等待未知的未来用途。 但 Eden 认为,这也是战略分化的风险所在:GPU 的回报集中于单一产品,而不是由所有服务共同分摊;推理业务来自对市场机会的主动押注,而非内部工具自然演化。
- 这次宕机“不是攻击……而是流程错误”:上游错误让机器人管理模型的特征数量翻倍,一份损坏文件每5分钟推送一次,最终耗尽服务器内存;Eden 认为,像 CrowdStrike 2024年那样在当天透明披露报告,足以让这项业务的基本盘保持完整。 Matt Reustle 的框架是:像 Moody's 或 Equifax 一样,“如果这都杀不死它,反而有点证明了护城河”。
- 估值是唯一无法回避的障碍:年初约25倍 NTM 收入意味着“实际上没有执行失误的容错空间……市场定价对应的是近乎完美的执行”。 要建立足够信心,必须相信 Act 2 能追上、甚至超越传统龙头,Act 3/推理业务也能成长为非常大的业务;公司当前 FCF 利润率接近10%(资本开支占收入11–14%),管理层指引为25%以上,Square Peg 认为实际水平可以更高。
1. 邮政服务模式:为一切带 URL 的业务提速并保驾护航
- Eden 开场介绍,Cloudflare 最初的产品可以保护任何公开网站——无论是“周末做着玩的个人项目”,还是全球最大的网站——免受 DDoS 洪泛、流量拦截和机器人抓取。他的比喻是:Cloudflare 像一家拦截所有邮件的分拣工厂,挡住垃圾邮件和有组织的垃圾攻击、扫描包裹,然后进一步建设“本地仓库”(CDN 缓存)以及遍布邮政网络的“专用高速公路”。
- Matt 追问 Shopify 案例:黑色星期五期间,僵尸网络攻击一家商户的店面;没有 Cloudflare 时,服务器会过载,商店直接宕机——“网站一旦停摆,就不会再产生任何收入”。Cloudflare 则在网络边缘吸收这场攻击。
- 首先看规模:Cloudflare 承载全球超过20%的网络流量,平均每秒吸收并拦截“超过250万次网络攻击”。Matt 的反应是:“多少有点吓人。”
2. 旧世界与 Project Honeypot
- Cloudflare 于2009年由 Matthew Prince、Michelle Zatlyn 和 Lee Holloway 创立。2009年以前,Akamai 等传统 CDN 会把网络拆开:客户自行决定哪些内容放在 CDN、哪些直接传输,另行购买实体防火墙,还需要销售工程师完成复杂部署;这是一套只服务企业客户的体系,“长尾网站没有解决方案”。
- 3位创始人各有分工:Matthew Prince 从小喜欢摆弄电脑,大学读文学,后来成为律师;他没有接手包括一家 Hooters 在内的家族生意,而是选择进入 HBS。Michelle Zatlyn 在 HBS 与他相识——“Matthew 带来愿景,Michelle 带来运营上的严谨”;技术联合创始人 Lee Holloway 后来被诊断出额颞叶痴呆,但“他的技术影响力至今仍深植于 Cloudflare”。
- Project Honeypot 是 Cloudflare 的前身:设置诱捕邮箱地址,让垃圾邮件发送者主动抓取,最终建立起“实际上是给垃圾邮件发送者准备的拒接名单”。数十万人安装了这套系统,网络效应的基因就此形成:“用户越多,服务越好,因为名单变得更大。”
3. 突破:用一个代理拦截一切
- Cloudflare 没有采用多个反向代理和分拆规则,而是让客户只需说:“我的新邮寄地址是 Cloudflare。”之后所有服务都可以直接切换开启,不需要销售工程师参与,这使 Cloudflare 成为“互联网服务领域第一家真正的产品驱动增长公司”。Matt 问他们当时是否已经从中收费,答案引出全篇反复出现的主题:没有,慷慨的免费层才是构建护城河的工具。
- 传统厂商没有复制这套模式,既有收入层面的原因——这是“创新者困境”的经典案例,企业客户并不希望简单地拦截全部流量——也有成本原因:大规模拦截所有流量本身极其困难,Cloudflare 最终用通用硬件和一套“受 Google 启发”的软件定义网络解决了问题。
- 最早采用 Cloudflare 的是非营利组织和黑客社区:前者流量很大但没有预算,后者则是在保护自己。其逻辑是:“如果他们能保护黑客,那当然也能保护更普通的网站。”
4. 对等互联议价权与自我强化循环
- 聚合长尾客户后,Cloudflare 获得了与 ISP 谈判的筹码:“我为什么不把服务器直接放在你的服务器旁边?”ISP 可以免去流量传输费,网络速度也会提升,而 Cloudflare 往往连带宽费都无需支付。Matt 问 ISP 是否反而成了输家,Eden 坚持认为这是双赢,因为用户遇到网速慢时,通常会把责任归咎于 ISP。如今,这张单一网络已直接连接超过13,000个网络。
- Eden 认为,飞轮是这项业务最重要的部分:廉价硬件和易用产品带来长尾客户,长尾客户带来更多流量和威胁信号,推动拦截和优化能力提升,进而吸引更多企业客户,带来更强的对等互联议价权和更低的成本,再把节省下来的资源投入更多产品。“网络越大,网络越好……这是一个运营15年后仍极难复制的系统。”
5. 一张网络上的3幕业务
- Act 1 已经跨过临界点,容量和服务能力开始胜过传统厂商:Cloudflare 最近赢下一家大客户,就是因为其 DDoS 防护容量“超过两家传统竞争对手合计容量的4倍”,可轻松吸收超过30 Tbps 的攻击流量。
- Act 2 则把代理方向翻转:同一套硬件不再只检查进入网站的流量,也检查企业向外发出的流量。零信任的含义是,“你能访问应用1,并不意味着你也能访问应用2”;每一次 Web 请求都要被重新检查,这与 Cloudflare 最初的服务“看起来非常相似”。业务大致分为3类:员工访问公共互联网的流量、访问内部应用的流量,以及钓鱼防护和邮件安全等相邻领域。
- Act 3 源于 Cloudflare 内部工具:包括 AWS 在内,没有其他平台能够承受 Cloudflare 自身的规模,因此公司开发了专有软件,随后意识到开发者也能用同样的工具构建强大的产品。Workers 提供无服务器函数、存储和轻量级数据库,已有超过300万名开发者;免费层每天提供10万次 Worker 查询和10GB 存储,且不收取出口流量费。一个典型用例是:通过边缘脚本替换本地价格或语言,比查询中央数据库更快。
6. AI:围绕市场的全面受益,以及一笔主动押注
- Eden 对 AI 的判断分为几层:相邻的顺风包括让智能体读取数据且无需支付出口流量费,直接服务 AI 公司——最新披露显示,头部 AI 原生公司中有80%是 Cloudflare 客户——以及通过 Workers AI 直接提供推理服务。
- 空插槽的故事揭示了 Cloudflare 的长期战略:设计主板时,公司“预留了一个空插槽,因为当时不知道未来会有什么用途……结果 AI 推理就是那个用途”。GPU 被插入部署在330座城市的服务器,而且无需预先配置资源——“你只为实际使用的 AI 推理付费”。
- Eden 指出的风险是,这一业务偏离了“每台服务器运行所有产品”的原有模式。GPU 的回报“只来自 AI 推理,因此回报风险更加集中”;与从 Cloudflare 内部既有实践中自然演化出的 Act 2 和 Act 3 不同,“公司只是看到了这个市场的重要性,然后决定主动进入”。
7. 企业市场重建:Anderson、资金池与渠道伙伴
- Cloudflare 从 PLG 转向企业销售的过程一度受挫:2023年销售代表人效下滑,大部分销售团队被裁撤;随后,曾任 Palo Alto Networks 销售总裁、Alteryx CEO 的 Mark Anderson 于2024年加入。招聘重心转向以企业销售代表为主,大客户收入增速由“约30%提升至40%同比增长”。收入超过10万美元的客户占客户总数不到1.5%,却贡献约75%的收入;在20亿美元年化收入规模下,Cloudflare 的100万美元以上客户不到200家,而同等规模的 Zscaler 约有500家,这意味着增长空间仍然很大。
- “资金池”模式解决了3类产品分别面对3类买家的摩擦:客户先作出多年期承诺——其中一笔合同规模为1.3亿美元、期限5年——再将资金提取用于任意产品,从而鼓励客户尝试较新的业务主线。该模式于2024年推出,目前已占总 ACV 的低两位数百分比;RPO 同比增长约40%,NRR 也在 Q3 从112%重新加速至119%。
- 在新聘的 Tom Evans——前 Palo Alto 全球渠道负责人——带领下,合作伙伴主导的业务连续2年同比增长约65%,来自合作伙伴的增量收入占比从约20%升至超过40%。目前渠道收入占总收入30%,而 Zscaler 和 Netskope 约为90%,“他们其实才刚刚起步”。大型合作伙伴往往靠实施服务而非产品分成赚钱,这有助于保护 Cloudflare 的利润率;Act 2 是增量毛利率最高的业务。
8. 数字化模型:为复杂度收费,而不是为流量收费
- 免费增值是 Cloudflare 的基本教义:免费用户可以无限量使用 DDoS 防护和 CDN 带宽——“不会因为你遭到攻击就惩罚你”;Act 1 通过订阅层级对规则、机器人管理等复杂度收费,Act 3 则采用按使用量计费。Eden 的验证是,Square Peg 曾在 Cloudflare 上内部搭建“相当复杂的 AI 产品”,但“我们的账单一直低得惊人”。收入约2/3来自 Act 1,约30%来自 Act 2,Act 3 目前规模较小但增速很快;公司已有55+个创收产品,使用10个以上产品的客户是增长最快的类别。
- 毛利率需要调整口径:GAAP 口径下的毛利率为75–78%,其中约6%的收入对应设备折旧;按现金口径比较,毛利率实际为83–85%。资本开支占收入11–14%,FCF 利润率约10%,管理层指引为25%以上;销售与营销费用占收入35%,是经营杠杆释放的主要机会。
- 资本配置保持克制:公司“跟着需求曲线投资”,采用通用硬件,更关键的是每台服务器运行所有产品,因此每1美元资本开支的回报都能在 Act 1、Act 2 和 Act 3 之间分摊。
9. 宕机、Zscaler 与没有犯错空间的估值
- 关于宕机,Eden 的结论是:“这不是攻击,也不是安全漏洞……而是流程错误。”上游错误让机器人管理模型的特征数量翻倍,一份损坏文件每5分钟推送一次,直到服务器内存耗尽。Eden 将其与 CrowdStrike 2024年事件相提并论;工程师主导的社区认可 Cloudflare 当天发布的透明事故报告。更早发生的一次 Google Cloud KV cache 故障,甚至加速了 Cloudflare 从第三方软件迁出的进程。Matt 的框架是 Moody's 或 Equifax:“如果这都杀不死它,反而有点证明了护城河。”
- Act 2 的竞争更加激烈,Cloudflare 也承认自己是落后于 Zscaler 的第二进入者,后者在大型企业中拥有先发优势。但网络效应仍然成立:经由 Zscaler 路由的请求,最终可能仍会落到由 Cloudflare 保护的网站上——“反正这些流量我们都在处理,为什么不顺便处理它们发出去的路径?”Canva 案例说明了这一点:东南亚的设计外包人员可以低延迟、无代理地获得内联访问,因为 Cloudflare 拥有对等互联关系,并且多年来持续改善这些市场的连接质量;Zscaler 直接与应用建立对等连接的模式,在部分市场可能效果较差。
- Eden 对估值的收尾非常坦率:年初约25倍 NTM 收入,“是行业内最高的估值之一”,同时维持约29–30%的增长,但“实际上没有执行失误的容错空间——市场定价对应的是近乎完美的执行”。投资者必须相信 Act 2 能追上、甚至超越传统龙头,Act 3 的推理业务也“可以成长为一项非常大的业务”。Matt 将其与暗示 SpaceX IPO 可能达到销售额约100倍的新闻标题相比,后者“反而让 Cloudflare 看起来很便宜”。
- 按 Square Peg 的主题/团队/模式/护城河框架,最终提炼出的模式包括:创始人基因,建立在技术复杂度之上的产品简洁性(类似 Snowflake、Datadog),多条增长杠杆,以及一个逆向判断——“只要资本开支能带来非常高的回报,软件公司的资本开支也可以是合理的”。一句话概括这项投资逻辑:“一家越做越强的公司”(“a business that gets better as it gets bigger”)。
完整逐字稿
This is Matt Reustle, and today we are breaking down the cybersecurity giant Cloudflare.
Today, Cloudflare controls over 20% of the world's web traffic. To me, an equally notable metric is that Cloudflare absorbs 2.5 million cyberattacks per second. My guest for this episode is Sam Eden, an investor at Square Peg's Global Tech Fund.
While I could understand on the surface what Cloudflare does, Sam really helped me get into the weeds on how the digital pipes actually work. We go through the rise of Cloudflare, how they built a differentiated product, and how they evolved that over time versus incumbents and fellow upstarts in what is obviously an in-demand market.
Through this story, Sam gets into the product offerings that led to Cloudflare's leading market share, some of the new evolutions, what that might mean for growth looking forward, and how to conceptualize and break that down through the various buckets.
If you have any interest in better understanding the world of cybersecurity, you will enjoy this episode.
All right, Sam, I am excited to have you here to break down Cloudflare. It is a tech company that I think is obviously understood by tech investors. Generalists maybe have more of a high-level understanding, and I think the population at large probably has very little understanding of what's going on.
We're going to do our best to get that understanding before we get into the overall business and what it looks like today. To start, how would you describe or explain what Cloudflare does as a business and as a technology for its customers?
1. How Cloudflare Works
Cloudflare has many different products, and we'll get to these throughout this conversation, but the most common one, and what they started with, is their application and website services.
Cloudflare provides speed and security for your website. Their customers are companies with a website. This could be your weekend hobby project, or it could be some of the largest companies in the world with some of the most highly trafficked websites in the world.
If you run a website, it has a public URL, so anyone can visit it. But that also means that anyone can attack it. Cloudflare provides security to prevent these spam attacks. These are known as DDoS attacks, which basically try to overload your servers. Hackers will try to intercept and manipulate internet traffic. Cloudflare protects you from that, and it prevents bots from scraping your website.
That probably sounded a little technical, so maybe an analogy for these internet services is a postal service. Let's say you run a website, which in this analogy would be a warehouse that ships out products. You'll get mail orders from all over the world. These would be your internet requests.
In this analogy, Cloudflare would be a sorting factory that intercepts all of your mail. They'll block junk mail for you. They'll block organized spam attacks that might try to clog up your mailbox. They'll scan all incoming boxes to make sure there's nothing malicious coming in. This is all their application security.
They extend this further. In this analogy, they would also help you set up local warehouses to reduce international shipping. They would create dedicated, fast freeways for postal services. They can speed up the whole postal network. They provide all these things to make your website fast and secure.
You're proving to me that I use the internet quite a bit but don't fully appreciate everything that's going on behind the scenes when I'm clicking around and ordering things and whatnot.
One of their customers is Shopify. Can you just give me a relatable example of what it would look like for Cloudflare to help Shopify? The speed portion makes a lot of sense in terms of making sure that they can run at optimized speed, but from a security perspective, what might that look like in a scenario for Shopify?
They have millions of merchant storefronts. From the security point of view, let's say a massive botnet attacks a specific store. Let's say it's during Black Friday.
Without Cloudflare, that merchant's servers are just going to get overloaded. The website would go down, and they can't make any sales. But with Cloudflare, they're going to absorb that traffic at the edge. The website's protected, and it can stay online.
That's really important for these e-commerce companies because if your website's down, you're not making any revenue.
It's a time-is-money type of thing. Anytime there's an outage or things go down, it matters.
Before we get into some of the history, can you just give me a sense of how big Cloudflare is today, in terms of any numbers that would capture the size and impact they have in the market?
Cloudflare is huge, and when you think about the scale of the internet, it's sometimes hard to wrap your head around. But you can think of Cloudflare as a single global private network that runs all this traffic.
Over 20% of the world's web runs through Cloudflare's servers. That's the scale we're talking about. In terms of cyberattacks, an average of over 2.5 million cyberattacks every single second is absorbed and blocked by the Cloudflare network.
2.5 million cyberattacks per second is somewhat frightening to me—that that's happening.
Let's get into the history here, because I know Cloudflare has evolved quite a bit over the years, and you don't get to that 20% without evolution. What's the founding story? Obviously, it wasn't around before the internet, but tell me a bit about the founding story, the founding team, and some of those key moments in its history.
2. The Internet Before Cloudflare
It's really important to understand the history of Cloudflare because if you can understand why they were successful at the start and how they got their initial foothold in the market, all of their new products were built on top of that. If you understand the history, then you can understand all of their new products.
Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway. They now have over $2 billion in revenue.
One thing to always remember about the internet is that everything still runs on physical hardware. There are cables that actually run across the oceans. They run through mountains, and they physically connect server boxes that intercept and process all this internet traffic.
Before Cloudflare was founded, let's use an example of someone based in New York who wants to visit a website in Australia. To do that, you send a request all the way from New York to Australia. They process that and then send it all the way back through a cable across the Pacific Ocean back to the server.
That's slow, and it also costs your ISP, your internet service provider, some money because they have to pay transfer fees to work with other ISPs across the world. So this is a bit of a lose-lose situation for the ISP. They have to pay transfer fees, and it's a bad and slow customer experience.
This is still before Cloudflare. Some of the early legacy companies, let's say Akamai, provide what's called a CDN, or content delivery network. The Australian website can pay Akamai to store images or some of the other website assets on a server in New York. Anytime someone in New York visits the same Australian website, it's just pulling the data from New York, across the city, much faster.
One thing that's important to understand, because it sets up Cloudflare well, is that these legacy companies like Akamai split the network. Customers have to decide what to put on their CDN network and what to handle directly.
To set this up, you need a sales engineer. It's a complex implementation, there's a lot of ongoing maintenance, and if you buy a different service, then you have to administer that and set up a whole different network and decide what gets redirected where.
Also, this website in Australia, for example, might want to serve only valid requests. So they actually have to buy a physical firewall to intercept and check this traffic. All these services are what's called reverse proxies, which basically means they intercept incoming traffic on behalf of the website. That's part of the security piece that we talked about earlier.
So that's the lay of the land before Cloudflare. This was all very difficult. It needed those sales engineers. This was only really accessible to larger enterprises and more sophisticated websites, and these legacy vendors didn't have a solution for the long tail of websites that Cloudflare started serving.
If we want to relate this back to the postal example, this legacy setup would be if that website in Australia had to inform all of the different postal routing services all over the world. They would have to tell them their different split rules: if the mail is directed to this department, use this address; if it's directed to that department, use that address; if it's a package, use this address.
That takes maintenance because if your rules change, you have to update them. It's a lot of work.
It feels very manually intensive and a bit of a traveling-salesman problem in terms of optimizing for where things go.
3. The One Network Breakthrough
So now we can get to Cloudflare. Matthew Prince, the co-founder and CEO of Cloudflare, has a very interesting background. He tinkered with computers as a child, studied literature, and became a lawyer. You can see that in his storytelling abilities.
Here's another interesting detail: he was set to take over his family business, which actually included running a Hooters. He didn't want that, so he went to HBS. Before and during that, he was working on a project called Project Honeypot, which eventually became Cloudflare.
He was working on Project Honeypot with the technical co-founder Lee Holloway, who was responsible for a lot of the early code and many of the early innovations. Unfortunately, Lee was diagnosed with frontotemporal dementia, so he's no longer with the business, but his technical influence remains strong throughout Cloudflare today.
Project Honey Pot is kind of as it sounds. It was a way to let hackers and spammers scrape email addresses from your website, but these email addresses were just trackers. You could see if someone tried to spam that email address, and they would get put on, effectively, a big list of bad addresses. It was creating a big bad list—effectively, a do-not-call list for spammers.
Hundreds of thousands of people were installing Honey Pot to help build out this list, and they were helping build out this list because they wanted to be protected from it. So the more users, the better the service, because the list got bigger.
At HBS, Matthew met Michelle Zatlyn. She's now the COO. She heard about this idea and wanted to be a part of it. They're a great pair. Matthew Prince is a real visionary, and Michelle brings a lot of the operational rigor.
Now we can get into the technical side of Cloudflare. I'll keep it high level, but they had this Honey Pot list—a list of bad actors—and it's a tricky problem to solve because it's effectively a lookup table. You see an incoming address, compare it to the list, and see whether you want to accept the request or not.
One way would be to put it on all of your customers' servers so they could do the lookup, but that would slow the entire internet down because every single request would now have to be compared. So what Cloudflare did—and this was the real innovation—was just intercept everything.
You didn't need multiple reverse proxies to do different things. You just had one reverse proxy: Cloudflare. And that does many things.
Were they getting paid to do that?
No. And this is a story throughout Cloudflare. For a lot of their products, they'll turn them on, and they have a very generous free program. But this helps build out their business moat, improve their products, and create a business that's highly defensible.
Network-effect beneficiary, and getting the free service out there can lead to that.
Totally. Project Honey Pot was the exact start of this. So all these customers could just redirect all of their traffic to Cloudflare, and Cloudflare would do the lookup. Now, this is really hard to do, so Lee Holloway was able to build a technical solution for this.
If we relate this back to our postal example, instead of splitting the network and all that, all you have to do now is say, “My new mailing address is Cloudflare.” No matter what the recipient is, no matter what the package type, Cloudflare will intercept it and decide what to do with it.
What this allowed, because it's intercepting everything, is for Cloudflare to easily turn another service on and off, whether it's a CDN or DDoS protection. You don't need that sales engineer that we mentioned before. Cloudflare is already in front of your traffic; you don't have to redirect anything. So that makes it simple.
This was the main breakthrough for Cloudflare. They could now serve that long tail of websites, and they were the first real product-led growth company for internet services. Anyone could sign up really quickly. They could serve all those weekend hobby projects, all the small websites, and start providing web protection services for them.
In terms of getting those users, were they just in front of the community of open-source developers, or was there anything that got their attention and helped them get that initial user base going? Was there anything that stands out?
A lot of their early customers were nonprofits because they had a lot of traffic but couldn't pay much. So that was really big. They also served a lot of the hacker community because a lot of hackers get hacked as well. So hackers would sign up to Cloudflare to protect themselves.
Those were some of the big starting customers that really proved that this service could work, because if they could protect hackers, then they could protect a more basic website as well.
It's very interesting. It also meant they had to be better than the hackers because, in theory, the hackers would see what they were doing. The hacking community is fascinating to me.
4. The Reinforcing Network Effect
One thing that's important to understand—and this is why their business is so hard to replicate if anyone tried—is why competitors just didn't do what they did. Why not just intercept all the traffic? The reasons would be revenue and costs.
With revenue, Cloudflare is a classic case of the innovator's dilemma. These large enterprises that I mentioned before didn't want to offer this simple interception because that's not what the large enterprises wanted. So the short-term revenue wasn't there. Cloudflare could build for this long tail on its own.
Cost is the other reason that competitors didn't do this. It's really technically difficult to build a system that scales to intercept all the traffic. They made a decision early on to just use commodity hardware. They didn't want dedicated hardware to process this.
They created a software-defined network inspired by Google, running on commodity hardware, so they could scale their network with cheaper hardware. Today, that's still the case. Today, Cloudflare is still that single global network of commodity hardware with layers of very sophisticated software on top of that.
Another really important thing is the peering relationships with the ISPs. An ISP is who you pay each month for your internet bill. If we go back to that New York-to-Australia example we mentioned earlier, let's say you visit a small website in Australia.
This small website can't afford those legacy services that only cater to enterprises. In this case, the ISP has to pay those transit fees to get the traffic to and from Australia, and the ISPs provide a slow traffic experience. So it's lose-lose. Those enterprises aren't serving those customers.
Now, because Cloudflare makes it easy, they have that product-led growth and that really generous freemium model, they can start providing those services for these small websites. One website isn't enough, but if you aggregate that whole long tail that they serve, Cloudflare has negotiating power with the ISP.
They can say, “I see you're transferring a lot of bandwidth to this region, and I know that because I see all the traffic from my customers, so why don't I just put my server next to yours? We'll have a peering relationship. That means you don't have to pay those transit fees. I'll serve the content directly.”
That ISP situation has gone from a lose-lose kind of cost and slow internet to a win-win because they don't have to pay those transit fees and their internet just sped up. So Cloudflare can negotiate this relationship and often doesn't have to pay bandwidth fees.
Is the ISP the loser in that case?
I would say it's a win-win situation because without Cloudflare, they have to pay the cost of connecting to other networks. So it's a cost for the ISP. If you think about your own internet experience, if your internet's slow, you don't blame the fact that the server is on the other side of the world or anything like that; you blame your internet service provider.
By partnering with Cloudflare, they cut out those costs because they just serve it from Cloudflare, and they can speed up their internet so their customers are happier. They partner with all these ISPs across the world.
One way that I like to visualize Cloudflare is that they have this single global network that spans across the world. It's a single web, and that connects to all these sub-networks, all the ISPs. Today, their single global network connects to over 13,000 different networks directly.
These sub-networks could be ISPs, cloud providers, or corporate networks, but they connect them all together in this one connectivity layer.
Now we're ready to piece this all together. I think this is the most important part of the Cloudflare business. If you put this history together, it creates a reinforcing loop. I'll try and help you visualize it.
At the top of the cycle, we talked about their low bandwidth and low hardware costs and their easy-to-use product that enables this product-led growth motion. So they can serve that long tail of customers.
What that enables is more traffic going through their servers. So they collect more signals, they collect more data, and then they get better and better at blocking malicious actors. They get better at optimizing the network for speed and just providing better website services and better services, which is halfway around the cycle.
Now that leads to more paying customers and more enterprise customers, which again brings in more traffic. As they get more traffic, they can negotiate even more with these ISPs to reduce their bandwidth fees further and create more peering relationships that bring their costs down further.
Then they can reinvest that revenue and cost savings back into their global network, create more products, and continually build out. And the cycle continues. They attract more of that long tail, collect more data, and build out their network.
This network gets better as it gets bigger. We often look for businesses that follow this characteristic because they’ve been doing this for over 15 years. It’s an incredibly difficult system to replicate, and it’s a really important part of their moat. That’s how they can continually offer these premium services while processing over 20% of the world’s traffic. It’s just a powerful reinforcing loop that gets stronger and stronger.
In terms of controlling that volume, that puts you in a better position from a negotiating perspective. You can bring down costs in a lot of ways. But for a business like this, which is trying to detect certain things and optimize certain things, you get better in terms of what you’re offering if done right.
I’m really curious, too, just in terms of the evolutions that occurred over that period—when they hit a point of evolving into commercial operations, what that looked like, how challenging that might have been, and then some of the products that have been layered on since then, because it definitely has evolved into a full suite of things that are very complementary. How did that pace out together?
5. Cloudflare's Expanding Product Suite
The Cloudflare we just described looked very different from the Cloudflare of today in terms of its product suite. The main product evolutions have been going from that product-led growth to enterprise and then using that single global network to add services. They’ve added a lot of internal cybersecurity products and then a whole developer platform on top of them. We can go through each of those.
The first one is just that transition from serving this long tail of premium customers to serving the biggest websites in the world. It follows that same loop: the more data they collected, the more they could build out the network. It reached a tipping point where their capacity and services were better than those of the legacy companies.
The capacity to absorb, say, cyberattacks or those DDoS attacks is just unmatched. A recent example they gave in one of their earnings calls is that they won over a large customer because their DDoS protection capacity was over 4 times that of the 2 legacy competitors combined. It was over 30 terabytes per second, which they easily absorbed because they’ve continually built out this network. They can serve the long tail and now these high-willingness-to-pay enterprise customers. That’s one product evolution within their original product set.
They’re able to evolve from those web security products to this whole new market of internal cybersecurity.
I’ve seen a lot of references to this in terms of a growth engine, but how would you articulate what’s going on there? I think it’s clear once it’s articulated, but describe that for the audience.
If you think about the services I just explained, it’s Cloudflare intercepting outside traffic for a website. What they realized is, “We have all this hardware. Why don’t we intercept and inspect traffic that goes from a company to the outside world?” It’s basically the other way around.
This is a reverse proxy and a forward proxy, and they use the same hardware for that. If you think of a reverse proxy as protecting a website from the public internet, a forward proxy server, which is what the whole security product suite is, protects an employee from the outside internet. It protects you when you have outbound traffic.
This is the basis of the whole product suite. It’s often termed zero trust. That’s a type of approach that you can provide with these internal security products. Zero trust means there’s zero trust between any app and any user. If you contrast that with old services, maybe you log into your corporate network, gain trust once, and then you’re within your private network.
Zero trust just means that because you can access app number 1, it doesn’t mean you can access app number 2. You have zero trust between the apps. You have to get validated each time. To do that, you have to get inspected each time. All of your web requests have to get inspected each time.
That looks a lot like their original services because they’re very, very good at inspecting every single packet. They realized that they could apply their commodity hardware. They didn’t have to change anything; they just added a software layer to provide this whole new market of internal corporate cybersecurity.
If I’m thinking about that as an internal employee, would that be, if I’m logged in and I click on a link that goes to a website, it gives me an alert that this looks unsafe? Does it extend beyond that in terms of phishing emails and scams? I’m curious to know who’s doing what in the chain of constant precautions that I’m being told.
Anytime you’re doing something on the internet in a work context, that’s this whole space, and Cloudflare has a solution to that. It’s a very broad market, and there are a lot of competitors in here. There are probably 3 buckets of activity that an employer will commonly take that you need to protect.
One would be that you’re on your work laptop or work network and visiting an outside public website. You want to make sure that the traffic going in and out of your work environment to the public internet is safe and secure. The second type would be that you’re working just with your internal apps. You’re checking Salesforce, you’re checking ServiceNow, things like that. You need to make sure that you’re actually approved—and this is that zero-trust approval—to view each app. Maybe there are different policies on what you can view.
The third bucket is, I guess, all the adjacent things. Email security is one, protecting against phishing attacks and things like that.
I’ve definitely experienced that when I’m on-premises, I can access certain apps, but when I’m off-premises, on mobile or on my own device, there are certain restrictions on what I can access, for good reason. I have some sense of how they’ve evolved pretty naturally from being that external third-party guard dog of sorts to also protecting from the inside. Would you point to anything else in terms of the evolution, or what they’ve rolled out that was key or monumental in terms of the development of the overall business and what they offered?
This is a continual evolution that all companies are going through. Your corporate environment used to just be your on-premises network, but now everything’s cloud-based. You can work from home; you can work from anywhere. The corporate perimeter—the security perimeter—is effectively the whole internet. That’s why they can fit nicely in there and provide those services.
They realized that with their hardware system and their single global network, they could expand from web services to corporate security. The way they did that was by building a lot of the software themselves. To be able to provide these services at a global scale, they often had to build a lot of their own software. They couldn’t rely on AWS, for example. No one else could handle their scale, and they wanted to have really strong security.
What that meant is that they have this proprietary software stack, which leads to their next product evolution. They realized that if you can build Cloudflare using these internal tools that they’ve built themselves, then other developers will be able to build really powerful products with these tools as well. So they started offering these services to the developer market.
These include things like cloud storage, lightweight databases, and video services. Their flagship product in what’s called Act 3 is Cloudflare Workers. That’s a serverless function service, and they specialize in lightweight containers and lightweight functions that can be spun up and spun down really quickly to solve bite-sized tasks.
Are these developers working within corporations, where what Cloudflare is building off the shelf needs to be expanded upon and they’re incorporating it there? Or is it separate from the enterprise corporate-type clients, and are these developers building some unique product and then selling it themselves to a different audience?
It’s currently quite separate. You don’t have to use these products together. You can just be a developer building a weekend hobby project and want to use the Cloudflare serverless functions. That’s a totally valid use case. They’re working to bring the products together into a more unified experience, but they don’t need to be. You can use these Cloudflare developer products on anything, really.
The developers, I assume, are then paying Cloudflare some software cost to use that?
That’s right. Similar to other cloud models, say from the hyperscalers, their developer products follow a usage-based pricing model. The more you use, the more you pay. But similar to the early products, they have a very generous free tier because they really want to attract that long tail of developers and then bring that into the enterprise, which is what they’re doing at the moment.
There are over 3 million developers building with these Cloudflare developer products. A lot of them would be building quite sophisticated functions just within their free tier. To give a sense of how generous this free tier is, I think with their Workers serverless functions, you can query them up to 100,000 times a day. Their storage is 10 GB per month with zero egress fees, which is dramatically cheaper than a lot of the alternative developer products.
Can you just give an example of what a developer might build with the tools, just to give a sense of what a tangible example might be?
Cloudflare Workers are best for quick functions that need to be done close to the user. One quick example would be that, if you’re loading a website, you might have a quick Worker script that changes the local pricing or changes the local language based on where that web page is loaded. That’s done at the edge, so it’s faster than querying, say, a central database to generate the page from scratch.
The way to conceptually think about these Workers is that anytime you can take a task and put it into bite-sized functions, it’s good for that because they spin up so quickly and then turn themselves off.
It is a slightly different way of thinking because you're deploying again to the single global network. If you deploy a function to AWS, you might put that on the US East servers, so it lives there. If you call that function, you have to travel there.
Whereas with Cloudflare, if, say, you're building an app in New Zealand, you deploy a function, and immediately someone in London can query that website and have that same function served from the London server at the edge. Everything gets propagated around really quickly, which is just another benefit of this single global network that they've built.
Yeah, I can speak to that example as someone who tends to find myself on UK or Japan websites. The currency switch is always beneficial. It saves me some time from doing the currency conversion.
When you think about AI, this is a business that has clearly benefited from and taken advantage of what the cloud has provided in terms of opportunities. They've been very thoughtful about that and evolved naturally into different pieces of an organization and offering more. So, two different things: riding the wave, but also being operationally thoughtful about how they're going to market.
When you think about where they fit into the AI boom and the potential to be whatever they might be in that world, how do you frame it? And then how does the management team talk about where Cloudflare fits into the AI ecosystem?
6. Cloudflare's AI Strategy
I would say they fit kind of all around the AI industry, and there are probably 4 ways I'll describe this. The first way is just the adjacent tailwinds, which you mentioned. As people want to use AI, they're thinking more about their data strategy. Often, you want your AI agents, for example, to read a lot of data, and you might want to do that quickly without paying a lot of egress fees. So there are tailwinds in general for Cloudflare's approach to doing that. That's the first relationship to AI: just adjacent services.
The next 3 are the different sides of AI that they serve. The first is just serving the AI companies themselves. The latest reporting was that 80% of the top AI-native companies—the top AI companies—were Cloudflare customers. That just shows that this next generation, this next era of businesses, still look to Cloudflare first. So if they're providing other services for these AI companies, it positions them well to provide AI services as well. That's one: just serving the customers themselves.
The second direct AI involvement with Cloudflare is inference itself. They've started to offer inference at the edge through their Workers AI product. It's a slight evolution from their previous strategy, where they still have this single global network, but previously every component—every piece of that hardware—could provide every service. That's really powerful because it meant the return on investment on each of those pieces of hardware could be split across all of their products.
But now, with AI inference, the hardware starts to matter. They had to install GPUs across their servers. They have servers across 330 different cities around the world. This was done really quickly.
Cloudflare is a very long-term strategic company. When they're designing their motherboards for all of their chips, they left an empty slot open because they didn't know what it would be for or what the use case would be, but they needed it just in case something came up. It turns out AI inference was that something. So they could go to all of their boxes and simply plug in a GPU, and then AI inference would be available across the world at all of these locations.
This is serving these LLM models. You can quickly query an open-source model for text generation, image generation, or voice, or enterprise customers can deploy their own custom LLMs as well. Again, that gets propagated across their single global network.
The AI inference from Cloudflare can be done really quickly at the edge. As I mentioned before, Cloudflare Workers are really quick at spinning up and spinning down. So unlike, say, a hyperscaler, you don't have to pre-book or pre-provision capacity. You only pay for what you use. If an inference is small and you don't use it for a day, you're not going to pay anything. So you're charged directly for the AI inference that you use.
It feels like a key layer of infrastructure, so you could see them on all sides of the market. Thinking about how they transitioned, you mentioned they got to a point where their offering was on par with, and then eventually better than, what incumbents and legacy providers were offering.
Can you talk about what that looks like? I imagine they broke into the enterprise market over time—what that looked like, how they approached it, and some of the nuance to what it looks like to have an enterprise contract.
7. Selling Cloudflare To Enterprises
This is an ongoing evolution; their go-to-market changes. Three things I'll call out are the general enterprise sales motion, the partner motion, which is really important to understand, and then their pool-of-funds bundling strategy.
The first go-to-market evolution was enterprise sales. This is just a typical transformation from product-led sales to enterprise sales. The product capabilities were there, but it was still a new go-to-market muscle, and across all companies this is never an easy transition, particularly as you're moving into security as well.
It's a new buyer for them. Instead of just an IT administrator who is looking over the website, you're now selling to the whole security office. It could be a multiple-month process, so they had to build this new go-to-market muscle.
In 2023, they actually saw all their rep productivity start to drop, and they had to let go of a lot of their sales team. But in 2024, they brought in a new president of revenue, Mark Anderson. He's incredibly experienced. He's formerly president of sales for Palo Alto Networks and CEO of Alteryx, so he has deep experience with enterprise sales.
They're hiring a lot more reps. They've switched from hiring a majority of mid-market reps to now hiring a majority of enterprise reps. They're still keeping this product-led growth because it's so important to their story, but now they're really increasing their sales-led growth motion.
There's still an ongoing transformation, but a quick quantitative proof that we're starting to see is that the growth of revenue from large customers has started to inflect. It was around 30%, and now it's starting to inflect up to 40% year-over-year. It's a really impressive transformation.
How big of a chunk of the business is it today?
If you look at customers over $100,000 in revenue, they're less than 1.5% of the actual customer base, but they contribute about 75% of the revenue. It's very important to get this segment right.
There's a long runway in that segment as well. They're at a bit over $2 billion of annualized revenue. With that, they have a bit less than 200 customers that are over $1 million. If you compare that to Zscaler when they were at that same size—that $2 billion run rate—they had almost 500 customers with $1 million in revenue. So it highlights the runway that they have at that very large enterprise end. The go-to-market transformation is a big part of that.
How much stickiness is there, both from the perspective of keeping customers and being able to win share from some of the competition? Are there long-term contracts that are in place? Is there major friction associated with ripping out old infrastructure and implementing new? It seems like they've been able to gain market share, but how much goes into that, and what are some of the unique dynamics there?
It's definitely a sticky product because if you have all your web security set up, it would take a lot to migrate from that, as well as a lot of convincing to migrate away from such a powerful network. So there is definitely stickiness involved, and one way to look at that is net revenue retention over the years. It's always been above 110%.
In the last few years, it has dipped a little, to 112% in the last few quarters. But with a lot of their other efforts—the pool of funds, a recent initiative—that's been starting to inflect, and in the latest quarter, Q3, that reaccelerated up to 119%.
Going from 112% up to 119% expansion of existing customers is a significant reacceleration. Obviously, their product is important, but some of this go-to-market contracting is really important as well.
I want to get to the partner strategy, but you mentioned the pool of funds and how that might link to that reacceleration. Can you describe that?
We've spoken about the 3 different products: web security, corporate security, and then the developer platform. We also spoke about how they can be quite separate. What that meant is you could have 3 different buyers, and you could have a company that was using each of the 3 different product groups but not necessarily talking to each other. There's a bit too much friction for what should be a smoother process for working on a single platform.
That's where they introduced pool of funds. This is a bundling method, and, as it sounds, it's also a pool of funds that large customers can draw down from. What's really important with this is that you can draw it down from any product. So this really encourages experimentation and adoption of some of their newer products.
These are multiyear commitments as well. These are their top enterprise customers, and they recently signed a $130 million, 5-year contract. So these are big contracts.
But what it means is that if you plan to, say, use 80% of this pool of funds on one product, you still have a little capacity and flexibility to experiment and try out a few of these Workers products. You'll see that they work at an enterprise scale, and that just encourages adoption there.
It's still a fairly new initiative, rolled out in 2024, but it's already up to the low double digits of their total annual contract value.
A quick metric to show that this is working is that this puts a lot of focus on RPO, the remaining performance obligations, which has been growing around 40% year over year through 2025. So there's very high growth at this scale, and these pools of funds are contributing to that. I mentioned before that it's starting to accelerate net revenue retention as well. Obviously, not all of that is from the pool of funds because it's still new, but it's a contributing factor as well.
It's a really interesting strategy. You look at all these different businesses that have complementary products, but oftentimes we gloss over the fact that you have different divisions that are buying them, different customers, and what seems complementary gets bogged down in frictions associated with that. You don't get the synergistic effect that you should. I'm sure it exists elsewhere in terms of this type of approach—pooling funds—but that's quite notable.
On the partner strategy, which I skipped over but you referenced before, what does that buyer base look like? What does that strategy look like, and when did that come into play?
So, the channel partner strategy is really important for their Act 2. This is their enterprise security products because the buyers often go through channel partners. These channel partners often have a preferred vendor list. So the relationships with these partners—and these could be consultants or system integrators—are really important. If you're not on their preferred vendor list, it makes the sale a lot harder.
So, would it be like WordPress might have Cloudflare?
It's more like maybe a Cognizant, a CDW for security, like Tata and all these consulting and professional services groups. So they will help with the sale and then help with the implementation as well. These are whole companies on their own, so the relationships with them are really important.
Mark Anderson, the new CRO, brought in a new head of partnerships, Tom Evans, and he has a long history in these cybersecurity partnerships—a worldwide channel sales lead at Palo Alto Networks. So he has this big rolodex to pull from.
The results for that are quite impressive. Channel partner-led growth over the last few quarters has been growing around 65% year over year for the past 2 years. The percentage of incremental total revenue from partner channels has gone from about 20% to over 40% of incremental sales. So it's a really important driver of their growth, and there's a long runway too.
Just to really highlight how important this channel is for security, Cloudflare's current channel partner revenue as a percentage of total revenue is about 30%. If you contrast that with Zscaler and Netskope, they're almost at 90% of their revenue going through channel partners or channel-referred partners. So there's a long runway to go. It's a relatively new motion, so I would say they're just getting started there.
Those channels are always interesting. It's kind of like an external sales force in many ways that can do the work on your behalf. Do they give any sense of whether the margin looks materially different through the partner channel versus the other buckets? Sometimes you get lower margins associated with that because there is, in theory, a middleman involved, but do they provide any disclosure on that?
They don't give too much because it is different depending on the partners, and you might have different contracts. Typically, what these partners do, though, is the large-scale resellers will basically take a cut. But for some of the larger ones, most of their revenue is actually from the professional services and implementation on top. So they're not trying to skim a product fee. They're more interested in the professional services that go on after the sale. So that just helps with the negotiation, and it can protect their margins.
Quickly on margins, these Act 2 products are the highest incremental gross-margin part of the business. It's a high-willingness-to-pay buyer of security, and you're using your existing network. So, very strong margins in that part of the business as well.
8. The Cloudflare Business Model
Maybe we can get into the financial business model and some of the spreadsheet details. I think you referenced that you're looking at over $2 billion in revenue on an annualized basis today. How is it split out between those buckets? You may have referenced it in passing, but just give a clean snapshot of that.
They don't split it out exactly, but you can estimate if you split it between the Act 1, Act 2, and Act 3 products. That $2 billion is a majority of Act 1; it's their bread and butter. You could estimate maybe roughly ⅔ of their revenue is from Act 1, maybe 30% from Act 2, growing quickly, and then Act 3 is still a bit smaller but growing very quickly as well.
In terms of the customer base, I'm assuming most customers—or at least a large percentage of the revenue—are using multiple products. I think, to your point, in terms of the largest accounts being 1.5% of customers versus 75% of revenue, that kind of gets to the power of large customers. But is that the case, where the majority of customers are using multiple products—or the majority of revenue is coming from customers that are using multiple products?
That's exactly the case. And they have over 55 revenue-generating products, so they have a long product suite. Customers with more than 10 products are the fastest-growing revenue category. So that's exactly the case.
Offering a freemium model seems to be ingrained in their DNA. How have they managed that over time in terms of continuing to offer a product that attracts users and potentially gets them into the funnel over time? What does that look like? We spoke a lot about the freemium model and how they got started, and they've really kept that in their DNA for Act 2 and Act 3 as well.
The way they do it as well is strategically quite different from some of their competitors. On Act 1, they don't really charge for volume. Free users can actually get unmetered DDoS protection and free bandwidth for CDN. This is really generous. What they actually charge for is complexity, if you want specialized rules and special bot management setups.
But that means if you're a website that constantly gets attacked with high volume, they're not going to charge you extra. They're not going to punish you for that. That's one interesting part of the different strategy, at least for the Act 1 products. For Act 2, it's quite generous as well, up to 50 free users.
But then Act 3, their developer products as well, you can very realistically set up and build a sophisticated app without paying much at all. That's actually what we have done at Square internally. We've built some quite sophisticated AI products to ingest a lot of our research, create dashboards, and have a full AI interface built on Cloudflare. It generates an enormous amount of value, and our Cloudflare bills have been remarkably low.
Interesting that an investment firm can do that and fit into that category. Is there a way to capture what's subscription-based versus what you mentioned, like the complexity? Does that still fall under a subscription? I'm just trying to get an understanding of the contractual nature versus the usage-based nature, which I'll bucket complexity into if it should be. They're not charging based on volume necessarily, but how do you split that up?
It is slightly different per product group, but for Act 1, it is a contract; it's a subscription tier. So you pick a plan—Pro tier, Business tier, or custom Enterprise tier—and you're paying that flat monthly rate for that tier. It includes a bunch of things. You would upgrade a tier when you need more enterprise features, whether it's those complexity rules, special splitting of traffic, and things like that. Not on volume, for Act 1 at least.
Act 3, those developer products, use more usage-based pricing: no egress fees, but it's usage-based pricing for how much you use their services.
Putting it all together on a margin, however you would look at this, what do margins look like for Cloudflare?
They're a software business, so their non-GAAP gross margins are about 75% to 78%. This looks lower than maybe a top-performing software business that you would expect to see, but you have to keep in mind that they own and operate their own physical infrastructure, and the depreciation of this equipment is included in the reported cost of goods sold. That naturally compresses their gross margin.
If you did want to try to look at a cash-based gross margin to compare apples to apples, about 6% of their revenue is depreciation directly tied to equipment. So you could add that back in and compare gross margins in the 83% to 85% range.
As it falls to the bottom line, whether it's EBITDA margin or free cash flow margin, what does that look like? Are there any major cost buckets that eat into that?
The main one to call out is the capex, which is naturally, again, a lot higher than at many software businesses. Capex has consistently been around 11% to 14% of revenue. That's going to bring your free cash flow margins down. Free cash flow margins have been around 10% in recent years. The long-term guidance, at least from management, is to expand those to over 25% as operating leverage continues to expand. They'll get the majority of that from operational costs, labor, whatever it might be.
Yeah. One big cost now is their sales and marketing cost. That's 35% of revenue, which has an opportunity to come down, and there are margin points available there as well.
Capital allocation. With that in mind, it feels like a business that has reinvestment opportunities that would take up the majority of where that cash flow would go. Has that been the policy, and how do you think about how they allocate the capital that they do have? What has their history been for capex spend and ROI on that capex?
Capital allocation is a really important part of the business, and they're very strategic about how they do it so that they get a really strong ROI on their capex. We spoke earlier about just using commodity hardware, so that reduces the cost of the hardware. They often talk about investing behind the demand curve, so they see where the traffic is and what the demand is before they build.
They're not just building for no reason. What's really important to understand with their capex is that all of their servers can run all of their products and provide all of their services. That means the capex and the ROI are split across all of their product lines, across Acts 1, 2, and 3. The incremental ROI is more diversified, and it's higher. So, you're not building a separate network for each product. It's one network that can contribute to the return on each incremental capex spend.
You've alluded a lot to legacy competition. Are there new competitors in the market? It does seem like a market that will only get more important over time. How do you frame the competition? Does anybody have large, comparable market share similar to what Cloudflare has?
9. Testing The Cloudflare Moat
In Act 1, they've established themselves as a leader. Some of the legacy companies specialize in certain types of networks where there's media and things like that. So, they're still important competitors, but Cloudflare has the biggest network that, as we mentioned, is very hard to catch up to. But in Act 2 and Act 3, it's much more competitive.
I think Act 2 is probably the most competitive because cybersecurity always has new players and new trends. Importantly, Cloudflare isn't leading the innovation there like they did in Act 1. They're a second mover, so Zscaler is probably the largest pure-play zero-trust Act 2 competitor, and they also have a global network that they run and manage themselves.
It's a decent time to bring up the outage, which I'm probably really burying the lead on in terms of recent activities and news, but just in terms of competition and what it could represent. Can you walk through what exactly happened? I felt like, one, the entire internet was out on me. Two, I learned just how many websites were connected to Cloudflare. So, two important things came out of that. Maybe just an explanation of what happened, and then we can get into whether there are any residual implications from it.
The outage affected everyone, and I guess one of the downsides of having a single global network is that it can all go down, and that's what happened. I think what's important to understand with that outage is that it wasn't an attack. It wasn't a security breach or anything like that. It was a process error.
Basically, their bot management software that inspects all the traffic is a little machine learning model, so it has all these features. There was an upstream error that caused those features to double in size, and their servers just didn't have the memory for them. These features are updated constantly. Every 5 minutes, the model is getting updated with new threats. Every 5 minutes, a corrupted file was getting pushed out, and it broke a lot of their services. So, everything went down.
It's not dissimilar to, say, the CrowdStrike outage that happened in 2024, where it wasn't a security breach. It was a process error for something that was very much in the weeds, and it caused all these outages. Everyone similarly realized how many businesses ran on CrowdStrike. But they've come back just as strong as ever because I think people realized, "Okay, it's a process error, and they're clearly going to do something about it," which is exactly the case with Cloudflare.
I think what the customers and community really appreciate about them is just how transparent they were. They wrote a very in-depth and transparent report the day of the incident. Having quite an engineering-forward customer base, I think that was really appreciated. They've outlined process steps and updates they'll take to make sure something like that doesn't happen again.
It's a little tough when it's the machine learning. You don't have a scapegoat if it's just the machine. I guess you do, but nobody, in theory, gets fired over that. Or maybe the person behind the machine learning who codes that all up.
But, noteworthy, has it happened over history? I do think it's interesting with businesses, whether it's Moody's during the financial crisis or Equifax with security breaches, where if it doesn't kill them, it kind of proves the moat or strength of the business in many ways and to all different degrees. Have there been historical outages, maybe not as impactful as that one, and any signal as to whether they have material impacts, whether short- or long-term, on the business?
There was one semi-recently. It wasn't as big as the one that happened recently, but there was an outage, and this actually encouraged some internal transformation or accelerated some internal transformations.
I mentioned earlier that Cloudflare is built on Cloudflare. They've built a lot of this proprietary software to run their systems—most of their systems, but not all of them. This could include things like acquisitions or other situations where, when they're scaling up new products, they might borrow something.
What happened in the previous outage was that there was an issue with a Google Cloud KV cache, or a small piece of the database, which flowed through some of their products and caused an outage. Again, it wasn't a security breach. It was an error that happens. But what it did was accelerate an internal project to migrate off those third-party solutions. So, I guess it was not good, but they kind of turned it into a strength to increase the robustness of their systems.
Then, I guess, based on current growth numbers or more recent growth numbers, it hasn't been too impactful on the underlying business performance. On competition, it feels like Zscaler is one that shows up in multiple categories, so I'd put them there. In Act 3, you mentioned the hyperscalers, which I think are worthy competitors for anyone to deal with.
But in terms of the competitive risks and threats, how high do you rate that on the risk spectrum? Is it something that concerns you? Sometimes, in a growing market, if you have one of the leaders, you usually feel pretty good that even if things move slightly, it's not going to be too material. I'm just thinking about the competitive threats and how fragile their position is versus being very strong and only strengthening.
My view is that it's a strengthening position. With Act 2, Zscaler has that incumbent advantage and that trust with very large enterprises, but it's a huge market. Cloudflare and their other products start at the smaller end and work up to the enterprises, and they're starting to do that.
What really benefits them is having that global network across all of the products. They can use their Act 1 strength to prove their product and encourage adoption of the Act 2 products. One example of that would be, let's say you're using Zscaler for internal security. You send a request; it goes to Zscaler's machines and then to a website, but that website is likely using Cloudflare. So, it ends up going to a Cloudflare server anyway and then back.
Cloudflare is in a really strong position. It's like, "We're processing all of this traffic anyway. Why don't we process it on the way out as well as the way back in?" That will improve your latency.
Another difference would be on their peering networks. It's very hard for another company to have all these partnerships with all these ISPs around the world. Zscaler took a different approach, where they peered directly with the apps, which is great for dense cities, but in certain markets it doesn't work as well.
An example to highlight some of these differences would be Canva. Canva, the web design company, has thousands of employees around the world, and they employ a lot of contractors to help with the design templates and things like that. A lot of those contractors are based in Southeast Asia.
Canva uses Cloudflare's Act 2 products to help with access because Cloudflare uses what's called an inline service. You don't actually have to install an agent or anything onto the machine, which is really important when you're working with contractors. You can give these contractors access to all of the corporate apps that they need without having to have them install anything.
A lot of these contractors are based in markets where other competitors won't have direct peering relationships. Cloudflare can say, "Look, we've been improving the speed of this area for years. These contractors can sign on, be secure, and interact with your product with low latency that's not going to slow anyone down." That's a really strong value proposition that a lot of other companies can't speak to.
Are there any other risks that really stand out to you from a business perspective, the organization, and some of the external factors sitting around it?
There are 2 risks to call out. One is that second mover in Act 2 that we were just speaking about. They are playing a bit of catch-up, but there is a long runway to go, and they're a solid contender there. So, I think the trajectory is very positive when you look at their product positioning, their channel partner growth, and all that, but it's worth just calling out because they are the second mover.
The other risk to call out is their AI inference strategy and AI in general, because it is new and it does slightly diverge from their previous strategy. So, that always adds some risk there, because I mentioned earlier that all of their other services can run on all hardware, whereas GPUs are specialized for inference.
With the ROI of their other products, it was split across all of their services, but the ROI of their GPU component is just from the AI inference. So, it's a more concentrated ROI risk.
Also, there's a slight difference in how the AI inference product came about compared with their other products. A lot of their other products emerged from what Cloudflare was doing internally. With Act 3, they had to build these services themselves. They never planned on launching a developer product, but they saw the value in that, and they released it.
Similarly with Act 2, they saw that during the day, when not many people were on websites, there were underutilized servers. So they could work with corporate security that was used during the day, and then during the night, use it for all their website security. They saw these opportunities, built for them, and leaned into them.
Whereas with AI inference, I think they just saw the importance of the market and decided to go after it. It's still that single global network, but there is a bit of a difference in strategy versus their other product launches. That's worth calling out.
Thank you for calling that out. I do want to get your general framework for valuation. I find software businesses, heaven forbid, with 75% to 80% gross margins relative to the 90% that some of these software businesses post. But how does the market approach it? How do you think about valuation? Anything that you would comment on that topic would be useful to hear.
It's no secret that Cloudflare is a highly valued company. I think at the start of the year, they were at 25 times next-twelve-month revenue, which is one of the highest in the industry.
From my perspective, I love Michelle and Matthew as the operators of Cloudflare, but valuation is always a constant battle, even though it's such an impressive company. Importantly as well, it's a capital-intensive business. So free cash flow margins and earnings will start to matter more and more in, say, 5 years' time. They'll likely have lower free cash flow margins than what we've seen in best-in-class software.
But I think what gives confidence in the bull case for Cloudflare is that there are numerous growth levers that can support sustained high growth. They've sustained it in that 29% to 30% or higher range, and the markets they operate in have a lot of runway. They're continually adding products and features that support that sustained high growth rate. So that's a distinguishing factor for them.
But to get comfortable with the valuation, you have to model out 2 things. You have to model out Act 2—how quickly they can catch up to and perhaps surpass the incumbents in that space. The trajectory is very solid there. But also, you need to model out what the Act 3 scenarios could look like. How important will they be for AI inference? How big will the inference market be? We believe that it can be a very large business, and you have to believe that.
And just quickly on margin structure: sales and marketing is 35% of revenue today, so there is room for operating leverage. They've guided to 25% free cash flow margins, plus we think they can exceed that. So then you can model that out over the years and still make money on the stock. But it's important to call out that there's effectively no margin for execution error. This price is for pretty flawless execution, which they've delivered, but you just have to build confidence that it will continue.
Well, it was a very intellectually honest approach to it. At 25 times sales, I saw the SpaceX IPO headlines today, which implied, I think, 100 times sales. It's all relative in this market.
Yeah. Makes it look cheap.
Yeah, exactly. And the growth number on revenue—they must be sandbagging, because it wasn't that material from the beat.
Nonetheless, this has been fascinating. I really tried to scrape out as much as I could on the technology, so thank you for keeping up with that. We like to talk about the lessons that you could take away, maybe bring it up a notch to think about frameworks and pattern recognition. What would you point to from Cloudflare that really stands out?
There are a few lessons from Cloudflare that I think can be applied generally. I'll call out 4 quick ones.
Number 1, I think founder-led companies are very important. For companies to have that founder vision can be very powerful for setting that long-term strategy, setting bold visions, and sticking to the company mission. Square Peg's origins are as a VC fund and then as a global tech fund. Regardless of our listed strategy, we still look for that founder DNA, and Matthew Prince is a great example of that.
The second general lesson would just be looking for product simplicity, particularly for complicated industries. To the extent they can serve the whole long tail of the internet despite having a very sophisticated technical infrastructure, that sets them up really well and is a really positive signal.
Applying that elsewhere, I think that applies to Snowflake as well. They have a very powerful engine under the hood. It's very hard to replicate, but when you look at the product, it's a very simple query interface. It's very easy to use and adopt. Similar with Datadog: it's very easy to get started and set up, but it's powerful enough and flexible enough to work with the world's largest companies as well as the world's smallest companies. Looking for that product simplicity, yet flexibility and power, is really important.
Number 3 would just be looking for multiple levers of growth. Great companies have multiple levers of growth, and they find ways to solve more problems for more customers over time. Cloudflare is a great example of that. They've expanded their product lines, expanded the customer archetypes within each market, and have done so in markets that all have tailwinds, particularly for AI.
The fourth lesson would be that capex in software can be okay, provided that it has that very high ROI and that capex is used to build defensibility for the business. We talked a lot about that earlier with that reinforcing cycle. It creates a moat that's very hard to replicate, and because they're stacking layers on top of that hardware, you can extract a lot of ROI from each individual purchase there.
Those lessons fit very cleanly into what Square Peg looks for. We have a framework around theme, team, model, and moat. Cloudflare sits at the center of a critical theme: managing networks for speed, efficiency, and trust, particularly in the era of AI.
The team is hungry, founder-led, very focused, and able to attract and retain some of the best talent in the world. I think it's an underappreciated, high-quality business model. They can stack multiple revenue lines on top of their core capability, and all of these levers have that long duration that we look for.
And finally, moat. Cloudflare is a business that gets better as it gets bigger, and that's really important. They use their scale to enhance their differentiation and create barriers to entry as well.
Capex can be okay is a good lesson. I think AI has certainly shifted the narrative in terms of the willingness to accept high-capex companies out there in the market, assuming that they're creating barriers to entry. We can debate where that falls in line for companies and whether that's true or not.
But this has been fascinating, Sam. I appreciate you sharing all of your knowledge, getting into the nitty-gritty details here, and giving me a better appreciation of all that's happening on the internet behind the scenes. I appreciate you joining us. Thank you. This has been a lot of fun.