← → or space to navigate
/ OS
01 / 27
PARTNER BRIEFING · PREPARED FOR ST ENGINEERING

Cloudflare
OS

An operating system for AI productivity — built by the team that built Workers, running inside Cloudflare every day, and open source so you can build your own.

SESSIONArchitecture · Security · Get Started
FORMAT90 min briefing + 30 min Q&A
AUDIENCESecurity · Cloud · Leadership
01

Cloudflare

The connectivity cloud — one network, every layer.

GLOBAL SCALE

One network,
one control plane.

210+ cities for AI inference
80% of top 50 genAI companies
215B threats blocked / day
330+
Cities
125+
Countries
13,000+
Network interconnections
<50ms to 95%
of the world's Internet users
THE COMPLETE PORTFOLIO

Connect. Protect. Build.

Cloudflare's connectivity cloud — one control plane across security, performance, and developer services.

SASE & Workspace Security
  • ZTNA (with MCP Server Portals)
  • SWG (with AI Usage Controls)
  • CASB (with AI Posture Management)
  • Email Security
  • Data Loss Prevention
  • Remote Browser Isolation
  • Digital Experience Monitoring
App Security & Perf Services
  • AI Security for Apps
  • Bot Management (with AI Crawl Control)
  • WAF with Rate Limiting
  • API Protection
  • Load Balancing
  • L7 DDoS Protection
  • CDN and DNS
  • Origin Shield
Developer Services
  • AI inference
  • AI Gateway
  • Agentic SDK and Workflows
  • Serverless compute
  • Full stack applications
  • Object & key-value storage
  • SQL database
  • Media optimization and delivery
Network Services
Network-as-a-ServiceFirewall-as-a-ServiceL3 & L4 DDoS ProtectionNetwork InterconnectSmart RoutingIDS/IPS

Cloudflare Programmable Global Network

◆ Artificial Intelligence / Machine Learning◆ Threat, Network Intelligence
WHERE YOU ALREADY ARE

You know us
for this.

WAF with Rate Limiting
Bot Management
API Protection
L7 DDoS Protection

It all runs on one platform — the same one you're about to see power an entire AI operating system.

02

Cloudflare OS

An AI productivity environment — the framework, the architecture, and a live look inside.

DEFINITION

An operating system
for AI productivity.

Originally built for internal use — now open source so any company can make it their own.

Built inside Cloudflare
Used company-wide
Apache 2.0 · Open Source
WHY NOW

Enterprise AI adoption
follows a pattern.

VISIBILITY

Shadow AI sprawl

Employees adopt dozens of tools; IT has no idea what's used or what data leaves the building.

SECURITY

Speed outpaces review

Vibe-coded apps ship to production before security ever sees them.

PRODUCTIVITY

Duplicate work

No shared direction — everyone re-solves the same problem, alone.

COST

Token spend unmanaged

Every employee, most expensive model, every task — with no budget controls.

CREDIBILITY

Cloudflare's own journey.

Dogfooded before it ever shipped.

MAY 2025

Gemini

Sanctioned LLM for writing tasks & thought partnership

JAN 2026

Opencode

Agentic workflows opened beyond R&D

MAY 2026

Cloudflare OS

Full agent harness, curated skills, built in

CORE PILLARS

Equip every team member
to do more.

One-Click Workspace

Full agent harness, seconds after login.

Context Layer

Institutional knowledge, centrally curated.

Secure System-of-Record Access

Scoped access to real data, tightly controlled.

Model Optionality

Right model, by role and task.

COST MECHANICS

Scaling productivity
without scaling cost.

Model optionality
Dynamic routing
Faster inference
Caching

Map roles and skill files to the right model — control spend without slowing anyone down.

ARCHITECTURE

Cloudflare's agentic workspace.

AI Inference

Model optionality

AI Gateway

AI Agent Workspace

Deployed or local harness

Deployed Apps & Agents

One-click environments

Content Library

Curated context + skills

Systems of Record

Salesforce · Jira · Email · Radar

loads skills + context
MCP Portal
enriched by
GOVERNANCE MODEL

A framework for where and how
team members build.

Most work starts here ↓
LAYER II

Cloudflare OS

Skills + Context
  • Ad-hoc research
  • Meeting prep
  • Document generation
Contribute improvements
LAYER III

Cloudflare OS Apps

Custom-Purpose Apps
  • Self-service forms
  • Team dashboards
  • Shared apps by URL
Alpha
LAYER IV

Centrally Managed

Rigid Business Logic
  • Deal desk tools
  • Compliance workflows
  • Canonical reporting
Team-owned + governed
LAYER V

Public Use

External Audience
  • Customer-facing tools
  • Partner demos
  • External microsites
Reviewed
FLEXIBLESTRUCTUREDREVIEWED
LAYER I

Systems of Record

Salesforce · Workday · ERP · Jira · Internal platforms
↑ MCP
CLOUDFLARE OS 2.0 · OPEN SOURCE

A real operating system,
built on Cloudflare's own stack.

Traditional OSShell
workshop-frontend React single-page app — chat, gadget canvas, connections & action-approval UI.
Cap'n Web RPC / WebSocket
Traditional OSKernel
workshop-backend · Overseer DO Owns all session state · capability-based security · Action Approval Queue for every write.
Durable Objects · SQLite
Traditional OSDevice drivers
Gatekeepers Per-vendor Workers as credential custodians — GitHub, Google, Slack, Notion, MCP & more.
Workers · DO Facets
Traditional OSProcesses
Gadgets · from Blueprints One private, sandboxed app instance per user — internet-disabled, real-time collaborative.
Dynamic Worker Facets
Traditional OSno equivalent
AI Agents · Code Mode Agents write & execute code against typed Gatekeeper + Gadget APIs — the new primitive.
Workers AI · AI Gateway
github.com/cloudflare/cloudflare-os Open source · Apache 2.0 — fork it, self-host it, make it yours.

Cloudflare OS
in Action

Two ways teams already use it, live.

BUILDERS

A comprehensive
skill library.

Every team member, one shared playbook — no more re-explaining the same task twice.

skill-repo
BUILDERS

Agents fix problems
so engineers build.

Code review and bug-fixing, automated safely — ship faster without shipping recklessly.

pull request #482
SELLERS

Solution architecture,
self-served.

Sellers build their own technical proposals, on demand.

Sound familiar? Your solutions engineers do this too.
MOMENTUM

And, we're
just getting started.

What you just saw is the current state — not the finish line.

03

AI Security

Securing agents, models, and every tool call in between.

THE FULL SUITE

Cloudflare's AI Security Suite.

One platform, four categories — spanning Zero Trust, Application Security, and the Developer Platform.

01

Protect workforce use of AI

Discover & control how employees interact with genAI tools like ChatGPT and Claude.

SASE for AI
02

Protect agentic AI access

Secure interactions between AI agents and corporate resources.

ZTNA + MCP Server Portals
03

Protect AI-powered apps

Defend chatbots and AI apps against data loss and attacks.

AI Security for Apps
04

Build securely with AI

Build AI apps and agents for internal or customer use.

AI Gateway

Highlighted: the two pillars that directly secure Cloudflare OS — next.

TECHNICAL ARCHITECTURE

Model agnostic.
Secure by default.

LLMs
ChatGPTCursorWorkers AI
User
Cloudflare OS
Codex
Reqs.SkillsRFCs
CLOUDFLARE
AI Gateway
Remote MCP servers
MCP server portals
ZTNA (Access)
Internal services
ClickHouseSnowflake
SaaS MCP Servers
Slack · Salesforce · Jira · PayPal · Shopify · GitHub
1
click the diagram to step through the four components →
PILLAR 04 · AI SECURITY / COST / PERFORMANCE

AI Gateway

One control plane between your apps and any LLM — for security, cost governance, and performance.

Guardrails & DLP — security
Caching & rate limiting — cost
Dynamic routing — performance
Full request logging — visibility
Solves: Token cost + Shadow AI visibility + model lock-in
PILLAR 04 · AI SECURITY / COST / PERFORMANCE

AI Gateway — the control plane
for every LLM call.

Apps & Agents
Skills · harness · deployed agents
Cloudflare AI Controls
Cloudflare's control plane for AI traffic
AI Gateway MCP Server Portals Zero Trust Network Access
Cloudflare Workers AI
External Inference

Cost-efficient AI usage for every employee:

Model optionality

Control model usage without lock-in risk.

Dynamic routing

Map employee roles and skill files to specific models.

Faster inference

Faster, more cost-efficient inference.

Caching

Save token spend on at-scale usage.

PILLAR 03 · PROTECT AI-POWERED APPS

AI Security for Apps

Formerly Firewall for AI — a WAF-integrated detection layer for your own AI-powered, customer-facing apps.

LLM endpoint discovery
Prompt injection score (1–99)
PII detection, 37 categories
Unsafe topic detection

Model-agnostic, runs inline at the edge — the bidirectional counterpart to AI Gateway's outbound DLP.

PILLAR 02 · PROTECT AGENTIC AI ACCESS

Remote MCP Servers

Host MCP remotely — instead of locally on developer devices.

No ambient credentials on laptops
Centrally managed & monitored
Smaller local attack surface
PILLAR 02 · PROTECT AGENTIC AI ACCESS

MCP Server Portals

A governed portal for internal services & SaaS apps — capability-based, not ambient.

Capability-based access
Human-in-the-loop approval
Full audit log

Gatekeepers approve asynchronously — agents keep working, humans review on their own time.

Solves: Dev-speed-vs-review + Shadow AI visibility
PILLAR 02 · PROTECT AGENTIC AI ACCESS

ZTNA (Access)

Enforce Zero Trust policies to authenticate and authorize every request.

The same Access product you already sell — now securing agent traffic too.
BACK TO WHERE WE STARTED

Every pain point,
accounted for.

VISIBILITY

Shadow AI sprawl

AI Gateway + MCP Portal
SECURITY

Speed outpaces review

Gatekeepers
PRODUCTIVITY

Duplicate work

Shared skill library
COST

Token spend

AI Gateway
04

Developer Platform

What Cloudflare OS is actually built on.

FULL PORTFOLIO

Every primitive,
one runtime.

Cloudflare OS uses a slice of this — the rest is available for whatever ST Engineering builds next.

COMPUTE
WorkersDynamic WorkersPagesContainersWorkers for Platforms
STATE & STORAGE
Durable ObjectsR2KVD1HyperdriveQueues
AI
AI GatewayWorkers AIVectorizeAI SearchAgents SDK
REALTIME & MEDIA
Browser RunRealtimeStreamImages
ORCHESTRATION
WorkflowsSandbox SDKSecrets StorePipelines

Verified against the cloudflare-os source repo — wrangler bindings, env.AI + AI Gateway billing code, and the README's own architecture notes.

Orange = confirmed used by Cloudflare OS today
FOUNDATION

Built on Workers,
by the Workers team.

Cloudflare OS

Workers

Every Gadget runs in a Dynamic Worker

Durable Objects

Every workspace is its own DO

Dynamic Workers

Sandboxed, spun up on demand

Facets

Gatekeepers install into each workspace

THE HARDER QUESTION

Why here, not AWS / GCP / Azure?

Agents are a different workload than websites — they chain tool calls, wait on LLMs, and need to run close to whatever they're calling.

DIMENSION
HYPERSCALERS
CLOUDFLARE
Cold start
Lambda: 100–500ms · containers: seconds+
Workers: under 5ms
Billing model
Wall-clock time — billed while waiting
CPU time only — not billed while idle
Agent-service reach
Bedrock / Foundry: a handful of regions
330+ cities, edge-native
Security model
IAM + separate WAF/CDN vendor, bolted on
Zero Trust, Access, Gateway — same network

Honest caveat: hyperscalers still lead on deep managed ML training and GPU pipelines. Cloudflare's story is serving and securing agents at the edge — not training foundation models.

ARCHITECTURE, NOT ASSEMBLY

Purpose-built,
not assembled from parts.

On traditional cloud, an agent means stitching together six services before writing any agent logic.

Compute service
Database
Message queue
Container runtime
Secrets manager
API gateway

On Cloudflare, it's one integrated framework:

Agents SDK
Durable Objects — state lives with the agent
Workflows — durable retries + human-in-the-loop
THE PRICING ARGUMENT

Pay for thinking,
not for waiting.

Agents spend most of their time waiting — on the LLM, on a human approval, on a scheduled trigger.

Traditional VM / container
alive 24 hours
24 hours
Cloudflare Durable Object
alive 24 hours, hibernates when idle
10 seconds

An agent that runs 10 seconds of actual compute but stays "alive" for 24 hours costs 10 seconds — not a day of a server.

05

Let's bring it to
market together.

Cloudflare brings the platform. You bring the customer.

WHO DOES WHAT

Cloudflare provides the toolkit;
you bring expertise & white-glove services.

Cloudflare's own
Partner augmented

Comprehensive security & cost controls

  • AI Gateway
  • Zero Trust Network Access
  • MCP server hosting + portals

Full-stack developer platform

  • Storage
  • Compute
  • AI

Starter kit of skill & context files

  • Cloudflare's own
  • Partner augmented

Services to build central context layer

  • Work with customer to document skills & context

Implementation & support

  • Develop custom frontend
  • Integrate with internal systems
  • Roll out
FOUNDATIONAL WORK

Invest in a
central context layer.

Email Alias
Magic inbox for work requests
Expert Tasks
Documented expert workflows
Triage & Audit
AI agent operators curate the work
Skill Repo
Curated skill files + context, centrally managed
AI Agent Workspace
Surfaced and ready-to-use in Cloudflare OS

Defining the jobs-to-be-done as centrally managed skill files:

1

Document workflows

Tap experts to document workflows and create skill files.

2

Open a magic inbox

An email alias where everyone else can send work.

3

Staff it with agents

AI agent operators run the inbox as a service.

4

Curate into skills

Collect the use cases and convert them to skill files.

5

Surface in Cloudflare OS

Everything is ready-to-use for the whole team.

SKILLS VS CONTEXT

Two file types,
one knowledge layer.

Skill File

Teaches an agent how to do one task — like a recipe.

When to use it — what triggers the task
Step-by-step, each step an action verb
Common mistakes to avoid + if/then logic
One page ideal · .md

Context File

Gives an agent background knowledge — like a glossary.

Overview — 2–3 sentences on the topic
Key definitions — terms, plain-language
Quick reference table — "if X, use Y"
One–two pages · .md
06

Get Started

Standing up your own instance on your NFR account.

SETUP · PART 1

From zero
to running.

1

Confirm NFR access

Not-For-Resale account, provisioned via your PSM.

2

Run it locally

pnpm run-locallocalhost:8787

3

Deploy to your NFR account

os.cloudflare.app/deploy

SETUP · PART 2

Make it
yours.

$ git clone cloudflare/cloudflare-os-starter
$ pnpm dev-server
$ pnpm dev-client
4

Customize via the starter repo

Add your own Gatekeepers and code changes.

5

Configure Gatekeepers

OAuth setup per integration — GitHub, Google, Slack, Notion, and more.

SET EXPECTATIONS

What you're
actually seeing.

EARLY ACCESS

v2 rewrite

Very capable, but still has rough edges — the team says so themselves.

Self-hosted workerd

Fully independent deployment — coming soon, not available today.

NEXT STEP

Let's build
ST Engineering OS.

The idea was never "use Cloudflare OS" — it's "make it yours," then make it theirs.

MOVE 01

For your teams

Run your own OS internally — the productivity, security, and cost controls you saw today, tuned to how ST Engineering works.

MOVE 02

For your customers

Package that same platform as a new offering — deliver a purpose-built OS to your customers and turn internal advantage into revenue.

Trial on your NFR account