
Cloudflare
Access
Cloud Provider
Mycroft checks Cloudflare zone configuration, including TLS enforcement, certificate validity, WAF rules and DNSSEC.
Cloudflare usually terminates TLS for everything a customer can reach, which makes its configuration the evidence for transmission security. Certificate expiry is tested continuously rather than discovered by a customer, and account administrators appear in access reviews.
How Mycroft connects to Cloudflare
- How it connects
- You create a read-only API token in your Cloudflare dashboard and give it to Mycroft. It can be revoked from the same place at any time.
- What Mycroft can access
- Read-only. Mycroft reads zone and account configuration through the token, and does not write back.
Which controls Cloudflare evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Cloudflare to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Cloudflare |
|---|---|---|---|
| SOC 2 | CC6.6 | Logical access measures protect against threats from outside the system boundary. | WAF managed ruleset enablement, DDoS protection state, rate-limiting rules and bot management configuration per zone. |
| SOC 2 | CC6.7 | Transmission of information is restricted and protected. | SSL/TLS encryption mode, minimum TLS version, Always Use HTTPS and HSTS settings, with certificate issuer and expiry per zone. |
| SOC 2 | CC6.2 | Credentials are issued only to authorized users and reviewed. | Cloudflare account member roster with roles, two-factor authentication status and pending invitations. |
| SOC 2 | CC7.2 | System components are monitored for anomalies. | Audit log availability and retention, plus security event and firewall analytics configuration on the account. |
| ISO 27001 | A.8.20 | Networks are secured and managed. | Zone-level firewall and WAF rule inventory, DNSSEC status and DNS record configuration for each domain. |
| ISO 27001 | A.8.24 | Cryptography is used effectively. | TLS version enforcement, cipher configuration and certificate validity windows across all managed zones. |
| HIPAA | §164.312(e)(1) | Technical measures guard ePHI transmitted over networks. | Proof of enforced HTTPS with a current TLS minimum version and valid certificates on every zone serving regulated traffic. |
What Mycroft collects automatically
Gathered from Cloudflare on a schedule, dated and stored against the controls above.
- TLS mode, minimum TLS version, HSTS and Always Use HTTPS per zone
- Certificate inventory with issuer, validity window and days to expiry
- WAF managed ruleset and custom firewall rule configuration
- DDoS protection and rate-limiting rules in force
- DNSSEC status and DNS record inventory per domain
- Account member roster with roles and two-factor authentication state
- Audit log availability and retention settings
Manual work this removes
The tasks that disappear from someone's quarter once Cloudflare is connected.
- Tracking certificate expiry dates manually
- Screenshotting zone SSL settings one domain at a time
- Compiling the list of who holds Cloudflare account admin
- Confirming WAF rules are still enabled after configuration changes
Cloudflare and Mycroft: frequently asked questions
Why does an auditor care about Cloudflare?
What API token permissions are needed?
Does Mycroft see traffic passing through Cloudflare?
Will Mycroft alert us before a certificate expires?
We turn the compliance nightmare into a dream
Talk to us


