Cloudflare logo

Cloudflare

Access
Cloud Provider

Mycroft checks Cloudflare zone configuration, including TLS enforcement, certificate validity, WAF rules and DNSSEC.

Cloudflare usually terminates TLS for everything a customer can reach, which makes its configuration the evidence for transmission security. Certificate expiry is tested continuously rather than discovered by a customer, and account administrators appear in access reviews.

How Mycroft connects to Cloudflare

How it connects
You create a read-only API token in your Cloudflare dashboard and give it to Mycroft. It can be revoked from the same place at any time.
What Mycroft can access
Read-only. Mycroft reads zone and account configuration through the token, and does not write back.

Which controls Cloudflare evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Cloudflare to satisfy it. Collection runs on a schedule and every result is timestamped.

Cloudflare compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Cloudflare
SOC 2CC6.6Logical access measures protect against threats from outside the system boundary.WAF managed ruleset enablement, DDoS protection state, rate-limiting rules and bot management configuration per zone.
SOC 2CC6.7Transmission of information is restricted and protected.SSL/TLS encryption mode, minimum TLS version, Always Use HTTPS and HSTS settings, with certificate issuer and expiry per zone.
SOC 2CC6.2Credentials are issued only to authorized users and reviewed.Cloudflare account member roster with roles, two-factor authentication status and pending invitations.
SOC 2CC7.2System components are monitored for anomalies.Audit log availability and retention, plus security event and firewall analytics configuration on the account.
ISO 27001A.8.20Networks are secured and managed.Zone-level firewall and WAF rule inventory, DNSSEC status and DNS record configuration for each domain.
ISO 27001A.8.24Cryptography is used effectively.TLS version enforcement, cipher configuration and certificate validity windows across all managed zones.
HIPAA§164.312(e)(1)Technical measures guard ePHI transmitted over networks.Proof of enforced HTTPS with a current TLS minimum version and valid certificates on every zone serving regulated traffic.

What Mycroft collects automatically

Gathered from Cloudflare on a schedule, dated and stored against the controls above.

  • TLS mode, minimum TLS version, HSTS and Always Use HTTPS per zone
  • Certificate inventory with issuer, validity window and days to expiry
  • WAF managed ruleset and custom firewall rule configuration
  • DDoS protection and rate-limiting rules in force
  • DNSSEC status and DNS record inventory per domain
  • Account member roster with roles and two-factor authentication state
  • Audit log availability and retention settings

Manual work this removes

The tasks that disappear from someone's quarter once Cloudflare is connected.

  • Tracking certificate expiry dates manually
  • Screenshotting zone SSL settings one domain at a time
  • Compiling the list of who holds Cloudflare account admin
  • Confirming WAF rules are still enabled after configuration changes

Cloudflare and Mycroft: frequently asked questions

Because it is where transmission security is actually enforced. SOC 2 CC6.7 and HIPAA §164.312(e)(1) ask you to protect information in transit; if Cloudflare terminates TLS for your application, its configuration is the evidence. Its WAF and DDoS settings also evidence the boundary protection expected under CC6.6.
A read-only Cloudflare API token that you create and can revoke from your dashboard at any time. Mycroft reads zone and account configuration through it and does not write back. The token can be scoped to specific zones.
No. The integration reads configuration and account metadata only. Request logs, proxied payloads and customer traffic are not accessed or stored.
Yes. Certificate validity is a continuously tested control, so an approaching expiry raises a finding, and if Slack is connected it lands in the channel you nominate rather than sitting in a dashboard.

We turn the compliance nightmare into a dream

Talk to us