Go back

Cloudflare: Leading Cybersecurity - [Business Breakdowns, EP.241]

71m 11s

Cloudflare: Leading Cybersecurity - [Business Breakdowns, EP.241]

Cloudflare is a cybersecurity and network infrastructure giant that handles over 20% of global web traffic and blocks millions of attacks per second. Founded in 2009, it disrupted legacy providers by intercepting all website traffic through a single reverse proxy, making security and speed services simple and accessible to everyone, from hobbyists to enterprises. This innovation created a powerful reinforcing loop: more traffic improves its data and services, reduces costs through ISP peering, and builds a formidable moat that competitors struggle to replicate. The company has evolved into three product areas: web security (Act 1), internal corporate security using zero trust (Act 2), and a developer platform with serverless functions and AI inference (Act 3). Its AI strategy positions it across the industry, serving AI-native companies and offering edge inference, though this introduces new risks. Go-to-market efforts now include enterprise sales, channel partnerships, and "pool of funds" bundling, which have driven strong customer expansion and revenue growth. Financially, Cloudflare generates ~$2 billion in annualized revenue with gross margins around 75-78%, though cash-based margins are higher. CapEx is significant due to its physical network, but management targets free cash flow margins above 25% over time. Competition is intense, especially in Act 2 and Act 3, but Cloudflare's integrated network and product synergies strengthen its position. Despite a high valuation requiring flawless execution, its multiple growth levers and founder-led team make it a compelling, defensible business.

Transcription

11917 Words, 69234 Characters

English
This episode is brought to you by Portrait. Portrait was built by former buy-side investors. And they understand great investing isn't just about having more information, from low-quality sources, it's about having the right information organized the right way. And if you listen to the show, you appreciate diligence consists of many things, diving into the history of a business, framing the nuance competitive dynamics, tracking key signposts around your thesis. And historically, that would take up material time that you do not have. But Portrait is basically like adding an army of analysts to your team. It's powered by an AI system specifically designed for investment research workflows. So you get nuanced idea generation. Portrait assesses the same types of qualitative attributes that we discuss on this show. And that can help identify businesses which fit your frameworks. Portrait also customizes research report generation. And third, there's intelligent thesis monitoring. And that's where Portrait assesses thousands of data points across value chains, each day, extracting the insights, driving the business. Again, all this work would typically take hours and hours and hours. Is that your fingertips now? Visit PortraitResearch.com to start your free trial today. This is Business Breakdowns. Business Breakdowns is a series of conversations with investors and operators diving deep into a single business. For each business, we explore its history, its business model, its competitive advantages, and what makes it tick. We believe every business has lessons and secrets that investors and operators can learn from. And we are here to bring them to you. To find more episodes of Breakdowns, check out joincolossus.com. All opinions expressed by hosts and podcast guests are solely their own opinions. Hosts, podcast guests, their employers, or affiliates, may maintain positions in the securities discussed in this podcast. This podcast is for informational purposes only and should not be relied upon as a basis for investment decisions. This is Matt Russell and today we are breaking down the Cybersecurity Giant Cloudflare. Today, Cloudflare controls over 20% of the world's web traffic. And to me, an equally notable metric is that Cloudflare absorbs 2.5 million cyber attacks per second. My guest for this episode is Sam Eden Investor at Squarespace Global Tech Fund. And while I could understand on the surface what Cloudflare does, Sam really helped me get into the weeds on how the digital pipes actually work. So we go through the rise of Cloudflare and how they built a differentiated product then and evolve that over time versus incumbents and fellow upstarts in what is obviously an in-demand market. And through this story, Sam gets into the product offerings that led to Cloudflare's leading market share, some of the new evolutions and what that might mean for growth looking forward and how to conceptualize that and break it down through the various buckets. So if you have any interest in better understanding the world of cybersecurity, you will enjoy this episode. All right, Sam. I am excited to have you here to break down Cloudflare. It is a tech company that I think is obviously understood by tech investors. Generalists maybe have more of a high level understanding and I think the population at large probably has very little understanding of what's going on. We're going to do our best. Get that understanding before we get into the overall business and what it looks like today. And just to start there, how would you describe, explain, paint a picture of what Cloudflare does as a business and as a technology for its customers? Cloudflare has many different products and we'll get to these throughout this conversation, but the most common one and is what they started with is their application services and their website services. Cloudflare provides speed and security for your website. The customers are companies with a website. This could be your weekend hobby project or it could be some of the largest companies in the world with some of the most traffic websites in the world. So if you run this website, it has a public URL, so anyone can visit it, but that also means that anyone can attack it. So Cloudflare provides security to prevent these spam attacks, isn't known as DDoS attacks, that basically try to overload your servers. Hackers will try and intercept and manipulate internet traffic. Cloudflare will protect you from that and it prevents bots from scraping a website. That probably sounded a little technical, so maybe an analogy for these internet services I like to think of is a postal service. Let's say you run a website which in this analogy would be say a warehouse that ships out products. So you'll get in mail orders from all over the world. This would be your internet request. In this analogy, Cloudflare would be a sorting factory that intercepts all of your mail. They'll block junk mail for you. They'll block organized spam mail attacks that might try to clog up your mailbox. They'll scan all incoming boxes to make sure there's nothing malicious coming in. So this is all the application security. They extend this further. So in this analogy, they'll also help you set up local warehouses to reduce international shipping. They would create dedicated fast freeways for postal services. They can speed up the whole postal network. So they provide only things to make your website fast and secure. You're proving to me that I use the internet quite a bit but don't fully appreciate all that's going behind the scenes when I'm clicking around and ordering things and whatnot. One of their customers is Shopify. Can you just give a relatable example of what it would look like for Cloudflare helping out Shopify? The speed portion makes a lot of sense in terms of making sure that they can run on optimize speed but from a security perspective, what might that look like in a scenario? For Shopify, they have millions of merchant storefronts from the security point. Let's say a massive botnet. They attack a specific store. Let's say it's during Black Friday. With our Cloudflare, that merchant servers, they're just going to get overloaded. The website would go down and they can't make any sales. But with Cloudflare, they're going to absorb that traffic at the edge. The website is protected and it can stay online. That's really important for these e-commerce companies because if your website's down, will you not make any revenue? It's a time as money type thing. Anytime there's an outage or things go down. Before we get into some of the history, can you just give me a sense of how big Cloudflare is today just in terms of any numbers that would capture the size and impact that they have in the market. Cloudflare is huge and when you think about the scale of the internet, it's sometimes hard to wrap your head around. But Cloudflare, you can think of as a single global private network that runs all this traffic and over 20% of the world's web runs through Cloudflare service. So that's the scale that we're talking about. And in terms of cyberattacks, an average of over two and a half million cyberattacks every single second is absorbed and blocked by the Cloudflare network. Two and a half million cyberattacks per second is somewhat frightening to me that's happening. Totally. Let's get into the history here because I know it has evolved quite a bit over the years and you don't get to that 20% without evolution. What's the founding story? Obviously, it wasn't around before the internet, but tell me a bit about founding story, founding team and some of those key moments in the history. It's really important to understand the history of Cloudflare because if you can understand why they were successful in the start and how they got their initial foothold in the market, all of their new products built on top of that. So if you understand the history, then you can understand all of their new products. Cloudflare, they'll found it in 2009, a Matthew Prince, Michelle Zatlin, and Lee Holloway. They now have over two billion in revenue. One thing to always remember about the internet is that everything still runs on physical hardware. So there's cables that actually run across the oceans, run through mountains, and they physically connect server boxes that intercept and process all this internet traffic. Before Cloudflare was founded, let's use an example of someone based in New York. They want to visit a website in Australia. So to do that, you send a request all the way from New York to Australia. They process that and then send it all the way back through a cable across the Pacific Ocean back to the server. So that's slow. And it also costs your ISP, your internet service provider, some money because I have to pay some transfer fees to work with other ISPs across the world. So this is a bit of a loose-lose situation for the ISP. They have to pay transfer fees and it's a bad and slow customer experience. This is still before Cloudflare. Some of the early legacy companies, let's say Akamai, they provide what's called a CDN content delivery network. The Australian website can pay Akamai to store images or some of the other website assets in a server in New York. Anytime someone in New York visits the same Australian website, it's just pulling the data from New York across the city much faster. One thing that's important to understand because it sets up CloudFlair, well, is that these legacy companies, like Akamai, they split the network. Customers have to decide what to put on their CDN network and what to handle directly. To set this up, you need a sales engineer. It's complex implementation. There's a lot of ongoing maintenance. And then if you buy a different service, then you have to administer that instead of a whole different network and decide what to get redirected where. Also, this website in Australia, for example, might want to only serve valid requests. So they actually have to buy a physical firewall to intercept and check this traffic. All these services, they're worth called reverse proxies, which basically means they just intercept incoming traffic on behalf of the website. And that's part of the security piece that we talked about earlier. So that's the lay of the land before CloudFlair. This was all very difficult. It needed those sales engineers. This was only really accessible for larger enterprises and more sophisticated websites. And these legacy vendors didn't have a solution for the long tail of websites that CloudFlair started serving. If we want to just relate this back to the postal example, this legacy setup would be if that website in Australia, they would have to inform all of the different postal routing services all over the world. They would have to tell them their different split rules if the mail is directed to this apartment, use this address, if it's directed to this department, use this address, if it's a package, use this address. And that takes maintenance because if he rules change, you have to update that and it's a lot of work. That's a bit of a history of the pre-CloudFlair time. Feels very manually intensive and a bit of a traveling salesman problem in terms of optimizing for where things go. So now we can get to CloudFlair. Matthew Prince, the co-founder and CEO of CloudFlair, a very interesting background, tinkered with computers as a child, studied literature and became a lawyer, and you can see that with his storytelling abilities now. Here's an interesting background. He was set to take over his family business, which actually included running of hooters. He didn't want that, so he went to HBS. But before enduring that, he was working on a project called Project Honeypot, and that eventually became CloudFlair. So he was working on Project Honeypot with the technical co-founder Lee Holloway, who was responsible for a lot of the early code and a lot of the early innovations. Unfortunately, Lee was diagnosed with front of temporal dementia, so he's no longer with the business, but his technical influence remained strong throughout CloudFlair today. Project Honeypot, it's kind of as it sounds, it was a way to let hackers and spammers scrape email addresses from your website, but these email addresses were just trackers. You could see if someone tried to spam that email address, they would get put on effectively a big list of bad addresses. It was creating a big bad list. It was effectively a do not call list for spammers. Hundreds of thousand people were installing Honeypot to help build out this list, and helping build out this list because they wanted to be protected from this list. So the more users, the better the service because the list got bigger. At HBS, this is where Matthew Michelle's atlin, she's now the COO, she heard about this idea and wanted to be a part of it. They're a great pair, Matthew brands the real visionary, and Michelle brings a lot of the operational rigor. Now we can get into the technical side of CloudFlair, and I'll keep a high level, but they have this Honeypot list, a list of bad actors, but it's a tricky problem to solve because it's effectively a lookup table, right? You see in incoming address, you'll compare that to the list and see whether you want to accept the request or not. So one way would be to put it on all of your customer's servers and they can do the lookup, but that would slow the entire internet down because every single request now has to compare it. So what CloudFlair did, and this was the real innovation, was that they just intercepted everything. You didn't need multiple reverse proxies to do different things. You just have one reverse proxy, that's CloudFlair, and that does many things. Were they getting paid to do that? No, and this is a story throughout CloudFlair, a lot of their products they'll turn on, and they have a very generous free program, but this helps build out their business mode, improve their products, and create a business that's highly defensible. Network effect, beneficiary, and getting the free service out there can lead to that. Totally, that project Honeypot was the exact start of this. So all these customers could just redirect all of their traffic to CloudFlair, and they would do the lookup. Now this is really hard to do. So Lee Holloway was able to build a technical solution on this. If we relate this back to our postal example, instead of splitting the network and all that, all you have to do now is just say, my new mailing address is CloudFlair. No matter what the recipient is, no matter what the package type, CloudFlair will intercept it and decide what to do with it. What this allowed is because it's intercepting everything, if you want to add another service, whether it's a CDN or a DDoS protection, it doesn't matter. You can just really easily turn that on and off. You don't need that sales engineer that we mentioned before. CloudFlair is already in front of your traffic. You don't have to redirect anything so that makes it simple. So this was the main breakthrough for CloudFlair. They could now serve that long tail of websites, and they were the first real product-led growth company for internet services. Anyone could sign up really quickly. They could serve all those like weekend hobby projects, all the small websites, and start providing web protection services for them. In terms of getting those users, were they just in front of the community, of open source developers, or was there anything that got the attention to where they got that initial user base going? Was there anything that stands out? A lot of the early customers, they serve a lot of nonprofits because they had a lot of traffic but couldn't pay much. So that was really big. And they actually served a lot of the hacker community because a lot of hackers get hacked as well. So hackers would sign up to CloudFlair to protect themselves. Those are some of the big starting customers that really proved that the service would work because if they could protect hackers, then they could protect a more basic website as well. That's very interesting. It also introduces they had to then be better than the hackers because in theory, the hackers would see what they're doing. The hacking community is one that is fascinating to me. One thing that's important to understand and this is why their business is so hard to replicate if anyone tried is trying to understand why competitors just didn't do what they did. Why not just intercept all the traffic? The reasons would be revenue and costs. So with revenue, CloudFlair, it's a classic case of the innovators dilemma. So these large enterprises that I mentioned before, they didn't want to offer this simple interception because that's not what the large enterprises wanted. So the short-term revenue wasn't there. So CloudFlair could build for this long tail on their own. And then costs is the other reason that competitors didn't do this. It's really technically difficult to build a system that scales to intercept all the traffic. And they made a decision early on to just use commodity hardware. They didn't want dedicated hardware to process this. They created the software-defined network, which was inspired by Google running on commodity hardware. So they could just scale their network with cheaper hardware. And today, that's still the case. Today, CloudFlair's still that single global network of commodity hardware with layers of various sophisticated software on top of that. And another really important thing is the peering relationships with the ISPs. So the ISPs who pay each month for your internet bill. If we go back to that New York Australia example we mentioned earlier, let's say you visit a small website in Australia, this small website, they can't afford those legacy services that only cater towards the enterprises. In this case, the ISP has to pay those transfer fees to get the traffic to and from Australia. And the ISPs provide a slow traffic experience so it's lose-lose. Those enterprises aren't serving those customers. Now, because CloudFlair makes it easy, they have that product-led growth and that really generous freemium model. They can start providing those services for these small websites. Now, one website isn't enough, but if you aggregate that whole long tail that they serve, CloudFlair has negotiating power with the ISP. They can say, I see you're transferring a lot of bandwidth to this region and I know that because I see all the traffic from my customers. So why don't I just put my server next to yours will have a peering relationship? That means you don't have to pay those transfer fees also the content directly. And that ISP situation has gone from a lose-lose cost and slow internet to a win-win because they don't have to pay those transfer fees and the internet to sped up. So CloudFlair can negotiate this relationship and often doesn't have to pay bandwidth fees. Is the ISP the loser in that case? I would say it's a win-win situation because without CloudFlair, they have to pay the cost of connecting to other networks. So it's a cost for the ISP. If you think about your own internet experience, if your internet's slow, you don't blame the fact that the server is on the other side of the world or anything like that. You blame your internet service provider. By partnering with CloudFlair, they cut out those costs because they just serve it from CloudFlair and they can speed up their internet so their customers are happier. They partner with all these ISPs across the world. And one way that I like to visualize CloudFlair, is they have this single global network that spans across the world. It's a single web and that connects to all these subnetworks, all the ISPs. And today, their single global network connects to over 13,000 different networks directly. And these subnetworks could be ISPs, they could be cloud providers, they could be corporate networks, but they connect them all together in this one connectivity layer. Now we're ready to piece this all together. I think this is the most important part of the Cloudflare business. So if you put this history together, it creates a reinforcing loop. So I'll try and help you visualize it that at the top of the cycle, we talked about their load bandwidth and low hardware costs and their easy to use products that enables this product-led growth motion, so they can serve that long tail of customers. What that enables is more traffic goes through their servers. So they collect more signals, they collect more data, and then they get better and better at blocking malicious actors. They get better at optimizing the network for speed and just providing better website services. And better services, which is halfway around the cycle now, that leads to more pain customers and more enterprise customers, which again brings in more traffic. And then as they get more traffic, they can negotiate even more with these ISPs to reduce their bandwidth fees further, create more peering relationships, that brings their costs down further. And then they can reinvest that revenue and cost saving back into their global network, create more products, continually building out. And the cycle continues, they attract more of that long tail, collect more data, build out the network. This network gets better as it gets bigger. We often look for businesses that follow this characteristic. Because they've been doing this for 15 years, it's an incredibly difficult system to replicate. And it's a really important part of their moat. So that's how they can continually offer these freemium services while processing over 20% of the world's traffic. And it's just a powerful reinforcing loop that gets stronger and stronger. In terms of controlling that volume that puts you in a better position from a negotiating perspective, you can bring down costs in a lot of ways. But for a business like this, which is trying to detect certain things and optimize certain things, you get better in terms of what you're offering if done right. On the evolutions that occurred over that period, really curious too, just in terms of when they hit a point of evolving into the commercial operations, what that looked like, how challenging that might have been. And then some of the products that have been layered on since then because it definitely has evolved into a full suite of things that are very complimentary. But how did that piece out together? - The Cloudflare we just described looked very different to the Cloudflare of today in terms of their product suite. The main product evolutions have been going from that product led growth to enterprise. And then using that single global network to add services. So they've added a lot of internal cybersecurity products and then a whole developer platform on them. We can go through each of those. The first one is just that transition from serving this long tail only of freemium customers to serving the biggest websites in the world. And it follows that same loop. The more data they collected, the more they could build out the network. It reached a tipping point where now their capacity and their services were better than the legacy companies. The capacity to absorb, say cyber attacks or those DDoS attacks is just unmatched. And a recent example they gave in one of their earnings call is they won over a large customer because their DDoS protection capacity was over four times the two legacy competitors combined. It was over 30 terabytes per second that they just easily absorbed because they'd continually built out this network so they conserved the long tail and now these high willingness to pay enterprise customers. That's one product evolution within their original product set. They able to evolve just from those web security products to this whole new market of internal cybersecurity. I've seen a lot of references to this in terms of kind of a growth engine but how would you articulate what's going on there? I think it's clear once it's articulated but describe that for the audience. If you think about the services I just explained, it's CloudFlare intercepting outside traffic for a website. What they realize is that we have all this hardware. Why don't we intercept and inspect traffic that goes from a company to the outside world? It's basically the other way. This is a reverse proxy and a forward proxy and they use the same hardware for that. So if you think of a reverse proxy as protecting a website from the public internet, a forward proxy server which is the whole security products is protecting an employee from the outside internet. It protects you when you have outbound traffic. This is the basis of the whole product suite. It's often term zero trust. That's a type of approach that you can provide these internal security products. Zero trust means the zero trust between any app and any user. So if you contrast that to old services, maybe log into your corporate network, you gain trust once and then you're within your private network. Zero trust just means just because you could access app number one, doesn't mean you can access app number two. You have zero trust between the app. You have to get validated each time. To do that, that means you have to get inspected each time. All of your web requests have to get expected each time. And that looks a lot like their original services because they're very, very good at inspecting every single packet. So they realize that they could apply their commodity hardware. They didn't have to change anything. They just added a software layer to provide this whole new market of internal corporate cybersecurity. If I'm thinking about that as an internal employee, would that be if I'm logged in? And I click on a link that goes to a website. It's giving me the alert that this looks unsafe. Does it extend beyond that in terms of fishing emails and scams? Curious to know who's doing what? In the chain of constant precautions that I'm being told. Anytime you're doing something on the internet in a work context, that's this whole space. And Cloudflare has a solution to that. It's a very broad market. There's a lot of competitors in here. There's probably three buckets of activity that an employee will commonly take that you need to protect. One would be you're on your work laptop or your work network and you're visiting an outside public website. And you want to make sure that the traffic going in and out of your work environment to the public internet is safe and secure. The second type would be you're working just with your internal apps. You're checking Salesforce, you're checking service now, things like that. So you need to make sure that you're actually approved. And this is that zero trust. Approved to view each app and then maybe there's different policies on what you can view. And then the third bucket is I guess all the adjacent things with that, the email, security is what, protecting against phishing attacks and things like that. I've definitely experienced where being on-prem, I can use certain apps even but went off-prem mobile or on my own device. There are certain restrictions on what I can access for good reason. I have some sense of how they've evolved pretty naturally from being that external third party guard dog of sorts to also protecting from the inside. Would you point to anything else just in terms of the evolution or what they've rolled out that was key or monumental in terms of the development of the overall business and what they offered? This is a continual evolution that all companies are going through is your corporate environment used to just be your on-prem network. But now everything's cloud-based, you can work from home, you can work from anywhere. The corporate perimeter security perimeter is effectively the whole internet. That's why they can fit nicely in there and provide those services. They realize that with their hardware system and their single global network, they could expand from web services to corporate security. The way they did that was building a lot of the software themselves to be able to provide these services at a global scale. They often had to build a lot of their own software. They couldn't rely on AWS, for example. No one else could handle their scale and they wanted to have really strong security. What that meant is they have this proprietary software stack. That leads to their next product devolution where they realize that if you can build cloud flare using these internal tools that we've built ourselves, then other developers will be able to build really powerful products with these tools as well. So they started offering these services to the developer market. So these include things like cloud storage, lightweight databases, video services, and their flagship product in this, what's called act three, is the Cloudflare workers. So that's a serverless function service. And they specialize in lightweight functions that can be spun up and spun down really quickly to solve bite-sized tasks. And are these developers working within corporations where what cloud flares building off the shelf needs to be maybe expanded upon and they're incorporating it there? Or is it separate from the enterprise corporate-type clients? and its developers that are building some unique product and then selling it themselves to a different audience. It's currently quite separate. You don't have to use these products together. You can just be a developer building a weekend hobby project and you want to use the Cloudflare serverless functions. That's a totally valid use case. They're working to bring the products together into a more unified experience, but they don't need to be. You can use these Cloudflare developer products on anything really. The developers I assume are then paying Cloudflare some software costs to use that. That's right. Similar to other Cloud models I say from the hyperscalers, their developer products follow a usage-based process model. The more you use, the more you pay. But similar to the early products, they have a very generous free tier because they really want to attract that long tail of developers and then bring that into the enterprise, which is what they're doing at the moment. There's over 3 million developers building using these Cloudflare developer products. A lot of them would be building quite sophisticated functions just within their free tier. To give a sense of how generous this free tier is, I think with their workers serverless functions, you can query that up to 100,000 times a day. Their storage is 10 gigabytes per month with zero egress fees, which is dramatically cheaper than a lot of the alternative developer products. Can you just give an example of what developer might build with the tools just to give a sense of what a tangible example might be? Cloudflare workers are best for quick functions that need to be done close to the user. Maybe one quick example would be that if you're loading a website, you might have a quick worker script that changes the local pricing or changes the local language based on where that web page is loaded. That's done at the edge, so it's faster than querying say essential database to generate the patron scratch. The way to conceptually think about these workers is anytime you can take like a task and put it into bite size functions, it's good for that just because they spin up so quickly and then turn themselves off. It is a slightly different way of thinking because you're deploying again to the single global network. If you deploy a function to AWS, you might put that on the US East servers, so it lives there. So if you call that function, you have to travel there, whereas with Cloudflare, if say you're building an app in New Zealand, you deploy a function immediately in London, someone can query that website and that same function is served from that London server at the edge. Everything gets propagated around really quickly, which is just another benefit of this single global network that they've built. Yeah, I can speak to that example as someone who tends to find myself on UK or Japan websites, just the currency switch is always beneficial, saves me some time from doing the currency conversion. When you think about AI, this is a business that is clearly benefit and took advantage of what the cloud has provided in terms of opportunities. It's been very thoughtful about that and evolved naturally into different pieces over an organization and offering more. So two different things writing away, but also being operationally thoughtful about how they're going to market. When you think about where they fit into the AI boom and potential to be whatever they might be in that world, how do you frame it and then how does the management team talk about where Cloudflare fits into the AI ecosystem? I would say they fit all around the AI industry and there's probably four ways I'll describe this. First way is just the adjacent tailwinds, which you mentioned as people want to use AI then they're thinking more about the data strategy and often you want your AI agents, for example, to read a lot of data and you might want to do that quickly without paying a lot of egress fees. So there's tailwinds in general for Cloudflare's approach for doing that. So that's the first relationship to AI as just adjacent services. The next three are the different sides of AI that they serve. The first is just serving the AI companies themselves. The alleged reporting was that 80% of the top AI native companies, the top AI companies, were Cloudflare customers. So that just shows that this next generation and this next era of businesses still looked to Cloudflare first. So if they're providing other services for these AI companies, it positions them well to provide AI services as well. That's one is just serving the customers themselves. The second direct AI involvement with Cloudflare is inference themselves. They've started to offer inference at the edge through the Workers AI product. It's a slight evolution from their previous strategy where they still have this single global network, but previously every component like every piece of that hardware could provide every service, which is really powerful because it just meant the return and investment on each of those pieces of hardware could be split across all of their products. But now with AI inference, the hardware starts to matter. They had to install GPUs across their servers. Their servers cost 330 different cities across the world. This was done really quickly. So Cloudflare is a very long term strategic company when they're actually designing their motherboards for all of their chips. They left an empty slot open because they didn't know what would it be for, what the use case would be, but they needed it just in case something came up. And it turns out AI inference was that something so they could go to all of their boxes and simply just plug in a GPU. And then AI inference is available across the world at all of these locations. This is serving these LLM models. You can quickly query an open source model for text generation, image generation, voice, or enterprise customers can deploy their own custom LLMs as well. And again, that gets propagated across their single global network. The AI inference from Cloudflare can be done really quickly at the edge. And as I mentioned before, Cloudflare work is a really quick at spinning up and spinning down. So I'm like, so hyperscaler, you don't have to pre-bork or pre-provision capacity. You're only used for what you pay for. If an inference is small and you don't use it for a day, you're not going to pay anything. So it only charges you directly on the AI inference that you use. It feels like a key layer of infrastructure. So you could see them on all sides of the market. Thinking about how they transition, you mentioned they got to a point where their offering was on par and then eventually better than what incumbents and legacy providers were offering. Can you talk about what that looks like? Because I imagine they broke into the enterprise market over time. What that looked like, how they approach it. Some of the nuance to what it looks like to have an enterprise contract. This is an ongoing evolution. They go to market changes. Three things I'll call out. One is just the general enterprise sales motion. The partner motion, which is really important to understand. And then they're pool of funds. Bumbling strategy. So the first go to market evolution was the enterprise sales. This is just a typical transformation from product-led sales enterprise sales. And the product capabilities were there, but it's still a new go-to-market muscle. And across all companies, this is never an easy transition. Particularly as you're moving into security as well. It's a new buyer for them. Instead of just an IT administrator that is looking over the website, you're now selling to the whole security office. It could be a multiple month process. So they had to build this new go-to-market muscle out. So in 2023, they actually saw their rep productivity start to drop and they had to let go a lot of their sales team. But in 2024, they brought in a new president of revenue, Marc Anderson. He's incredibly experienced. He's formerly president of sales for Palo Alto Networks, CEO of OuterRex. So he has this deep experience with enterprise sales. This transformation, they're hiring a lot more reps. They've switched from hiring majority bid market reps to now hiring a majority of enterprise reps. And they're still keeping this product-led growth because it's so important to their story. But now they're really increasing their sales-led growth motion. They're still ongoing transformation, but quick quantitative proof that we're starting to see is that the growth of revenue from large customers has started to inflate to around 30% and now it's starting to inflate up to 40% year-over-year. It's a really impressive transformation. How big of a chunk of the business is it today? If you look at customers over $100,000 in revenue, they're less than 1.5% of the actual customer base. But they contribute to about 75% of the revenue. It's very important to get this segment right. There's a long runway to that segment as well. They're at bit of a 2 billion of annualized revenue. With that, they have a bit less than 200 customers that are over $1 million. If you compare that to Z-scaler, when they're at that same size, that 2 billion run rate, they had almost 500 customers with that $1 million revenue. So it highlights that runway that they have at that very large enterprise end. And the go-to-market transformation is a big part of that. How much stickiness is there, both from a perspective of keeping customers, but also being able to win share from some of the competition? their long-term contracts that are in place is they're a major friction associated with ripping out old infrastructure and implementing new, seems like they may have an again market share, but how much goes into that and what are some of the unique dynamics there? It's definitely a sticky product because if you have oil, kind of web and security set up, it would take a lot to migrate from that and a lot of convincing to do to migrate away from such a powerful network. So there is definitely a stickiness involved and one way to look at that is their net revenue retention over the years. It's always been above 110%. In the last few years, it has dipped a little to 112 in the last few quarters, but with a lot of their other efforts, which is the pool of funds, recent initiative, that's been starting to inflect and their latest quarter, or Q3 2025, that reaccelerated up to 119%, so going from 112% up to 119% of expansion of existing customers is a significant reacceleration and obviously the product's important, but some of this go to market contracting is really important as well. I want to get to the partner strategy, but you mentioned the pool of funds and how that might link to that reacceleration. Can you describe that? We've spoken about like the three different products, the web security, the corporate security, and then the developer platform. We also spoke that it can be quite separate. What that meant is you could have three different buyers and you could have a company that we're using each of the three different product groups, but not necessarily talking to each other. There's a bit too much friction for what should be a smoother process for working on a single platform, so that's where they introduce pool of funds. This is a bundling method and it's also as it sounds, it's a pool of funds that large customers can draw down from. What's really important with this is that you can draw it down from any product, so this really encourages experimentation and adoption of some of their newer products. These are multiple year commitments as well, this is their top enterprise customers and they recently signed a $130 million five-year contract, so these are big contracts. What it means is if you plan to say use 80% of these pool of funds on to Act One, you still have a little capacity and flexibility to experiment and try out a few of these workers products, you'll see that they work at an enterprise scale and that just encourages the adoption there. It's still a fairly new initiative, it wrote down 2024, but it's already up to low double digits of their total annual contract value. A quick metric to show that this is working is that this puts a lot of focus on RPO, the remaining performance obligations. That's been growing around 40% year-over-year through 2025, so there's very high growth at this scale and these pool of funds are contributing to that and I mentioned before that it's starting to accelerate the net revenue retention as well, obviously not all from pool of funds because it's still new, but it's a contributing factor as well. It's a really interesting strategy, you look at all these different businesses that have complimentary products, but oftentimes we glance over that you have different divisions that are buying them, different customers and what seems complimentary gets bogged down and friction is associated with that and you don't get the synergistic effect that you should. I'm sure it exists elsewhere in terms of this type of approach pooling funds, but that's quite notable. On the partner strategy, which I skipped over, but you referenced before, what does that buyer base look like? What does that strategy look like and when did that come into play? So the channel partner strategy, it's really important for their act to, this is their internal security products, because the buyers often go through channel partners. These channel partners, they often have a preferred vendor list, so the relationships with these partners and these could be consultants, system, integrators. If you're not on their preferred vendor list, it makes the sale a lot harder. So would it be like WordPress might have cloud flare? It's more like a maybe a cognizant, a CDW for security like Tata and all these insulting and professional services groups, so they will help with the sale and then help with the implementation as well. These are whole companies on their own, so the relationships with them are really important. So Mark Anderson, the new CRO, brought in a new head of partnerships, Tom Evans, and here's a long history in these cybersecurity partnerships, worldwide channel sales lead at Palo Alto Networks, so there's this big role that they support from. The results with that are quite impressive, the channel partner led growth, and the last few quarters has been growing around 65% year over year for the past two years. The percentage of incremental total revenue from partner channels has gone from about 20% to over 40% of incremental sales, so it's a really important driver of their growth, and there's a long runway to just to really highlight how important this channel is for security, cloud flares, current channel partner revenue as a percentage of total revenue is about 30%. And if you contrast that to Z-scaler and Netscope, they're almost at 90% of the revenue going through channel partners, or channel referred partners, so there's a long runway to go. It's a relatively new motion, so I would say they're just getting started there. Those channels are always interesting, it's kind of like an external sales force in many ways that can do the work on behalf of you. Do they give any sense of whether the margin looks materially different through the partner channel versus the other buckets, sometimes you get lower margins associated with that because there is a theory of middleman involved, but do they provide any disclosure on that? They don't give too much because it is different depending on the partners and that you might have different contracts. Typically what these partners do though is the large-scale resellers will basically take a cut, but some of the larger ones, most of their revenue is actually from the professional services and implementation on top, so they're not trying to skim a product fee. They're more interested in the professional services that go on after the sale, so that just helps with the negotiation and it can protect their margins quickly on margins. These act two products, they're the highest incremental gross margin part of the business. It's a high willingness to pay by or of security and you're using your existing networks, so very strong margins in that part of the business as well. Maybe we can get into the financial business model in some of the spreadsheet details. I think you referenced, you're looking at over 2 billion in revenue on an annualized basis today. How is it split out between those buckets? You may have referenced it in passing, but just to give a clean snapshot of that. They don't split it out exactly, but you can estimate if you split it between the act one, the act two, and the act three products, that two billion dollars is majority of act one, like it's their bread and butter, and you could estimate maybe roughly two thirds of their revenue is from act one, maybe 30% from act two, growing quickly, and then act three, it's still a bit smaller, but growing very quickly as well. In terms of the customer base, I'm assuming most customers, or at least a large percentage of the revenue are using multiple products. Your point in terms of the large accounts being 1.5% versus 75% of Refugee kind of gets to the power of large customers, but is that the case where the majority of customers are using or majority of revenue is coming from customers that are using multiple products? That's exactly the case, and they have over 55 revenue generating products, or a long product sheet, and customers with more than 10 products is the fastest growing revenue category. That's exactly the case. Offering a freemium model seems to be ingrained in their DNA. How would they manage that over time in terms of continuing to offer a product that attracts users and potentially gets them into the funnel over time? What does that look like? We spoke a lot about the freemium model for like how they got started, and they've really kept that in their DNA for Act 2 and Act 3 as well. The way they do it as well, it's quite strategically different to some of their competitors. On Act 1, they don't really charge for volume. Their free users can actually get unmeted DDoS protection, free bandwidth for CDN. This is really generous. What they actually charge for is complexity if you want specialized rules and special bot management setups, but that means if you're a website that constantly gets attacked with high volume, they're not going to charge you actually. They're not going to punish you for that. That's one interesting part of the different strategy, at least for the Act 1 products. For Act 2, quite generous as well, up to 53 users, but then Act 3, their freemium product as well, you can very realistically set up and build a sophisticated app without paying much at all, and that's actually what we have done as SquareFeg internally. We've built some quite sophisticated AI products to ingest a lot of our research, create dashboards, and have a full AI interface, built on CloudFlare, and it generates an enormous amount of value, and CloudFlare builds have been remarkably low. The interesting investment firm can do that and fit into that category. Is there a way to capture what's subscription-based versus that you mentioned like the complexity? Is that still fall under a subscription? I'm just trying to get an understanding of the contractual nature versus the usage-based nature, which I'll bucket complexity into that if it should. be, they're not charging based on volume necessarily, but how do you split that up? It is slightly different for a product group, but for Act One, it is a subscription tier. So you pick a plan, pro tier, business tier, or custom enterprise tier, and you're paying that flat monthly rate for that tier, and it includes a bunch of things. You would upgrade a tier when you need more enterprise features, whether it's those complexity, rules, special splitting of traffic, and things like that. Not on volume for Act One, at least. Act Three, those developer products, that is more uses-based pricing, no egress fees, but the uses-based pricing for how much you use their services. Putting it all together on a margin, however you would look at this, what do margins look like for Cloudflare? They're a software business, so they non-gat gross margins are about 75% to 78%. This looks lower than maybe a top-of-performing software business that you would expect to see, but you have to keep in mind that they own and operate their own physical infrastructure, and the depreciation of their equipment is included in the reported cost of goods sold, that naturally compresses their gross margin. If you did want to try to look at a cash-based gross margin to compare apples to apples, about 6% of their revenue is depreciation directly tied to equipment, so if you want, you could add that back in and compare gross margins on an 83%, 85% range. As it falls to the bottom line, whether it's EBITDA margin for cash-low margin, what does that look like? Are there any major cost buckets that eat into that? The main one to call out is the CapEx, which is naturally, again, a lot higher than a lot of software businesses. The CapEx has consistently been around 11 to 14% of revenue. That's going to bring your free cash-low margins down, and the free cash-low margins have been around 10% in recent years. The long-term guidance, at least from management, is to expand those to over 25% as operating leverage continues to expand. They'll get the majority of that off of the operational cost, labor, whatever it might be. One big cost now is their sales and marketing cost. That's 35% of revenue. That has opportunity to come down, and there's margin points available there as well. Capital allocation, with that in mind, it feels like a business that has reinvestment opportunities that would take up the majority of where that cash-low would go. Has that been kind of the policy, and how do you think about how they allocate the capital that they do have and their history for CapEx spend in ROI in that CapEx? The capital allocation, it's a really important part of the business, and the very strategic about how they do it, such that they get a really strong ROI on their CapEx. We spoke earlier about just using commodity hardware, so that reduces the cost of the hardware. They often talk about investing behind the demand curve, so they see whether traffic is and what the demand is before they build. They're not just building for no reason. What's really important to understand with their CapEx is that all of their servers can run all of their products and provide all of their services. That means the CapEx and the ROI is split across all of their product lines across Act 1, 2, and 3. The incremental ROI is more diversified and it's higher. You're not building a separate network for each product. It's one network that can contribute to the return on each incremental CapEx spend. You alluded a lot to legacy competition. Are there new competitors that are in the market? It does seem like a market that will only get more important over time. How do you frame the competition and does anybody have large, comparable market share similar to what Cloudflare has? In Act 1, they've established themselves as a leader. Some of the legacy companies specialize in certain types of networks where there's media and things like that, so they're still important competitors, but Cloudflare has the biggest network that, as we mentioned, is very hard to catch up to. But in Act 2 and Act 3, it's much more competitive there. I think Act 2 is probably the most competitive because cybersecurity, there's always new players, there's always new trends, and importantly, Cloudflare isn't leading the innovation there like they did in Act 1, like they're a second mover. ZScaler is probably the largest pure play, zero trust, Act 2 competitor, and they also have a global network that they run and manage themselves. It's a decent time to bring up the outage, which I probably, like, really burying the lead in terms of recent activities and news, but just in terms of competition and what it could represent, can you walk through what exactly happened where I felt like one, the entire internet was out on me, two, I learned just how many websites were connected to Cloudflare, so two important things came out of that, but maybe just an explanation of what happened, and then we can get into if there's any residual implications from it. The outage affected everyone, and it's one of the downsides of having a single global network is that it can all go down, and that's what happened. I think what's important to understand with that outage is that it wasn't an attack, it wasn't a security breach or anything like that. It was a process error, basically, their bot management software that inspects all the traffic, it's a little machine learning model, so it has all these features. There was an upstream error that caused those features to double in size, and their service just didn't have the memory for them. These features, they updated constantly, every five minutes, the model's getting updated with new threats, every five minutes, a corrupted file is getting pushed out, and it broke a lot of their services, so everything went down. It's not just similar to say the CrowdStrike outage that happened in 2024, where it wasn't a security breach, it was a process error for something that was very in the weeds, it caused all these outages, everyone realized, similarly, how many businesses ran on CrowdStrike, but they've come back just as strong as ever, because I think people realized, okay, as a process error, and they're clearly going to do something about it, which is exactly the case with CloudFlare. I think what the customers and community really appreciate with them is just how transparent they were, they wrote a very in-depth and transparent report day of the incident, and having quite like an engineering-forward customer base, I think that was just really appreciated. They've outlined process steps and updates they'll take to make sure something like that doesn't happen again. It's a little tough when it's the machine learning, you don't have a scapegoat if it's just the machine, I guess you do, but nobody in theory gets fired over that, or maybe the person behind the machine learning who codes that all up, but noteworthy, and as it happened over history, I do think it's interesting with businesses, whether it's moodies during the financial crisis, Equifax, with security breaches, where if it doesn't kill them, it kind of proves the moat or strength of the business in many ways, and to all different degrees. But have there been historical outages, maybe not as impactful as that one, and any signal to whether they have material impacts, whether it's shorter or long-term in the business? There was one, semi-recently, it wasn't as big as the one that happened recently, but there was an outage, and this actually encouraged some internal transformation or accelerated some internal transformations. So I mentioned earlier that CloudFlares built on CloudFlares, they built a lot of this proprietary software to run their systems for most of their systems, but not all of them, and this could include things like acquisitions or other things when they're scaling up new products they might borrow something. And what happened in the previous outage was there was an issue with like a Google Cloud KV cache or like a small piece of the database, which flowed through some of their products and course and outage. Again, wasn't the security breaches an error that happens, but what it did was they had an internal project to migrate off those third party solutions, and that just accelerated that. It was not good, but they kind of turned it into a strength to increase the robustness of their systems. Then I guess based on current growth numbers or more recent growth numbers hasn't been too impactful on the underlying business performance. On competition, it feels like Z-scaler is one that shows up in multiple categories. So I put them there. In Act 3, you mentioned the hyperscalers, which I think are worthy competitors for anyone to deal with. But in terms of the competitive risks and threats, how high do you rate that on the risk spectrum? Like is it something that concerns you sometimes in a growing market? If you have one of the leaders, you usually feel pretty good that even if things move slightly, it's not going to be too material, just thinking about the competitive threats and how fragile their position is versus being very strong and only strengthening. My view is that it's a strengthening position. Say with Act 2, Z-scaler has that incumbent advantage and that trust with very large enterprises. But it's a huge market and Cloudflake and like there are other products, start up the smaller end and work up to the enterprises. and it's starting to do that. What really benefits them is having that global network of all the products, they can use their Act 1 strength to prove their product, encourage adoption of the Act 2 products. One example of that would be, let's say you're using Zscaler for internal security, you send a request, it goes to Zscaler's machines, and then to a website. But that website is going to be likely using Cloudflare. So it ends up going to a Cloudflare server anyway. And then back. And then so Cloudflare is in a really strong position. It's like we're processing all of this traffic anyway. Why don't we process it on the way out as well as the way back in, and that will improve your latency. Another difference would be just on the appearing networks. So it's very hard for another company to have all these partnerships with all these ISPs around the world. Zscaler took a different approach where they appeared directly with the apps, which is great for dense cities, but in certain markets, it doesn't work as well. And maybe an example, just to highlight some of these differences would be Canva. So thousands of employees around the world, Canva, the web design company, they employ a lot of contractors to help out with the design templates and things like that. And a lot of those contractors are based in Southeast Asia. Canva uses their Cloudflare Act 2 products to help with the access because Cloudflare uses what's called like an inline service. So you don't actually have to install agents or anything onto the machine, which is really important when you're working with contractors. You can give these contractors access to all of the corporate apps that they need without having to have them install anything. Because say a lot of these contractors are based in markets where other competitors won't have direct-pearing relationships. Cloudflare can say, look, we've been improving the speed of this area for years. These contractors can sign on, be secure, and interact with your product with low latency. That's not going to slow anyone down. And that's a really strong value proposition that a lot of other companies can't speak to. Are there any other risks that really stand out to you just from a business perspective and the organization and some of the external factors sitting around it? Two risks to call out. One is that second move in the Act 2 that we were just speaking about. They are playing a bit of a catch-up, but there is a long runway to go and they're a solid contender there. So I think all the trajectory is very positive when you look at their product positioning, the channel partner growth, and all that. But it's worth just calling out just because they are the second to move. The other risk to call out is just their AI inference strategy and AI in general, because it is new and it does slightly diverge a little from their previous strategy. So that always adds some risk there. Because I mentioned earlier that all of their other services can run at all hardware, whereas GPUs are specialized for inference. With the ROI of their other products, it was split across all of their services. By the ROI of their GPU component, that's just from the AI inference. So it's a more concentrated ROI risk. Also, there's a slight difference in how the AI inference product came about from their other products. A lot of their other products, they kind of emerged from what Cloudflare was doing internally. With the Act 3, they had to build these services themselves. They never planned on launching a developer product, but they saw the value on that and they released it. Similar with Act 2, they saw that during the day, not many people on websites, they were underutilized servers, so they could work with corporate security that was used during the day and then during the night, they saw their website security. So they kind of saw these opportunities and built for them and went into them. Whereas AI inference, I think they just saw the importance of the market and decided to go after it. It's still that single global network, but there is a bit of top spin of difference and strategy versus there are other product launches. That's worth calling out. Thank you for calling that out. I do want to get your general framework for valuation. I find software businesses, heaven for bid 75 to 80% gross margins relative to the 90 that some of these software businesses post. But how does the market approach it? How do you think about valuation and just anything that you would comment on that topic would be useful to you? It's no secret that CloudFlare's a highly valued company. I think at the start of the year, there were 25 times the next 12 month revenue, which is one of the highest in the industry. From my perspective, I love Michelle and Matt as the operators of CloudFlare. But valuation, it's always a constant battle, even though it's such an impressive company. And importantly, as well, it's a capital intensive business, so the free cashflow margins and earnings will start to matter more and more in say five years time. And they'll likely have lower pre-cashflow margins than what we've seen in best-in-class software. But I think what gives confidence, the ball case for CloudFlare is that there's numerous growth levers that can support sustained high growth. And they've sustained it in that 29, 30% or higher range. And the markets that they operate in have a lot of runway and the continually adding products and features that support that sustained high growth rate. So that's a distinguishing factor for them. But to get comfort with the valuation, you have to model out two things. You have to model out the act two. How quickly they can catch up and perhaps surpass the incumbents in that space. And the trajectory is very solid there, but also you need to model out what the act three scenarios could look like. Like how important will they be for AI inference? How big will the inference market be? We believe that it can be a very large business, and you have to believe that. And just quickly on margin structure, sales and marketing, 35% of revenue today, there is room for operating leverage. They've guided to 25% free cash and might as plus. We think they can exceed that. So then you can model that out over the years and still make money on the stock. But it's important to call out that there's effectively no margin for execution error. There's price for pretty flawless execution, which they've done, but you just have to build confidence that will continue. Well, I was very intellectually honest approach to it. A 25 time sales. I saw the SpaceX IPO headlines today, which implied I think 100 time sales. That's all relative in this market. It makes it look cheap. Yeah, exactly. And the growth number on revenue, they must be sandbagging because it wasn't that material from your year. Nonetheless, this has been fascinating. I really tried to scrape out as much on the technology. So thank you for keeping up with that. We like to talk about the lessons that you can take away. Maybe bring it up a notch to think about frameworks and pattern recognition. What would you point to from Cloudflare that really stands out? There's a few lessons from Cloudflare that I think can be applied generally. I'll call out four quick ones. So number one, I think Fountallade companies is very important for companies to have that Fountallade vision. It can be a very powerful for setting that long-term strategy and setting bold visions and sticking to the company mission. SquarePeg's origins are as a VC fund. And then the global tech fund listed strategy, we still look for that founder DNA. And Matthew Prince is a great example of that. The second general lesson would just be looking for product simplicity, particularly for complicated industries. To the extent they can serve the whole long tail of the internet, despite having a very sophisticated technical infrastructure, that sets them up really well and so really positive signal applying that elsewhere. I think that applies to Snowflake as well. They have a very powerful engine under the hood. It's very hard to replicate. But when you look at the product, it's a very simple query interface. It's very easy to use and adopt and similar with Datadog. Very easy to get started and set up. But it's powerful enough and flexible enough to work with the world's largest companies as well as the world's smallest companies. So that looking for that product simplicity, yet flexibility and power is really important. Number three would just be looking for multiple levers of growth. So great companies, their multiple levers of growth, and they find ways to solve more problems for more customers over time. Cloudflare, great example of that. They've expanded their product lines, expanded the customer archetypes within each market. And I've done so in markets that all have tailwinds, particularly for AI. Fourth lesson would be that CapEx in software can be okay. Provided that it has that very high ROI, that CapEx is used to build that defensibility for their business. Talked a lot about that earlier with that reinforcing cycle. It creates a mode that's very hard to replicate. And because they're stacking layers on top of that hardware, you can extract a lot of ROI from each individual purchase there. Those lessons they've fit very cleanly into what SquarePag looks for. We have a framework around theme, team, model, and mode. And Cloudflare, they sit at the center of a critical theme in managing networks for speed, efficiency, and trust, particularly in the era of AI. The team, the hungry, founder led, very focused, and they can attract and retain some of the best talent in the world. I think it's an underappreciated high quality business model. So it's they can stack multiple revenue lines on top of their core capability, and all of these levers have that long duration that we look for. And finally, moat. Cloudflare, it's a business that gets better as it gets bigger, and that's really important. They use their scale to enhance their differentiation and create barriers to entry as well. CapEx can be okay. It's a good lesson. I think AI certainly has shifted the narrative in terms of the willingness to accept high CapEx companies out there in the market, assuming that they're creating barriers to entry, we can debate where that falls in line for companies and whether that's true or not. But this has been fascinating. Sam, I appreciate you sharing all of the knowledge, getting into the nitty gritty details here. Give me a better appreciation of all that's happening on the internet behind the scenes. So I appreciate you joining us. Thank you. This has been a lot of fun. [Music]

Podcast Summary

Key Points:

  1. Cloudflare controls over 20% of global web traffic and absorbs 2.5 million cyberattacks per second, positioning it as a dominant cybersecurity and network infrastructure provider.
  2. Founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway, Cloudflare innovated by intercepting all website traffic with a single reverse proxy, enabling simple, product-led growth for the long tail of websites.
  3. Its business model benefits from a reinforcing loop
  4. Product evolution spans three "acts"
  5. AI strategy includes serving AI-native companies, offering edge inference with GPUs, and leveraging network advantages, though this introduces new strategic risks.
  6. Go-to-market transformation includes enterprise sales, channel partnerships (growing 65% YoY), and "pool of funds" bundling, which boosted net revenue retention to 119%.
  7. Financials show ~75-78% gross margins (higher on a cash basis), ~10% free cash flow margins, with CapEx at 11-14% of revenue, and long-term margin expansion targets above 25%.
  8. Competition is strongest in Act 2 (e.g., Zscaler) and Act 3 (hyperscalers), but Cloudflare's network and product integration provide a strengthening position.
  9. Recent outages were process errors, not security breaches, and were handled transparently, with minimal lasting business impact. 1
  10. Valuation is high (~25x next-12-month revenue), requiring flawless execution, but multiple growth levers support sustained high growth.

Summary:

Cloudflare is a cybersecurity and network infrastructure giant that handles over 20% of global web traffic and blocks millions of attacks per second. Founded in 2009, it disrupted legacy providers by intercepting all website traffic through a single reverse proxy, making security and speed services simple and accessible to everyone, from hobbyists to enterprises. This innovation created a powerful reinforcing loop: more traffic improves its data and services, reduces costs through ISP peering, and builds a formidable moat that competitors struggle to replicate.

The company has evolved into three product areas: web security (Act 1), internal corporate security using zero trust (Act 2), and a developer platform with serverless functions and AI inference (Act 3). Its AI strategy positions it across the industry, serving AI-native companies and offering edge inference, though this introduces new risks. Go-to-market efforts now include enterprise sales, channel partnerships, and "pool of funds" bundling, which have driven strong customer expansion and revenue growth.

Financially, Cloudflare generates ~$2 billion in annualized revenue with gross margins around 75-78%, though cash-based margins are higher. CapEx is significant due to its physical network, but management targets free cash flow margins above 25% over time. Competition is intense, especially in Act 2 and Act 3, but Cloudflare's integrated network and product synergies strengthen its position. Despite a high valuation requiring flawless execution, its multiple growth levers and founder-led team make it a compelling, defensible business.

FAQs

Cloudflare provides speed and security for websites, protecting them from attacks like DDoS and bots while optimizing performance. It serves both small hobby projects and large enterprises.

Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlin, and Lee Holloway, evolving from a project called Project Honeypot that tracked spammers. They innovated by intercepting all web traffic with a single reverse proxy, making security services easy to use.

Cloudflare's moat is its reinforcing loop: more traffic leads to better data and services, which attracts more customers and enables cost-saving peering relationships with ISPs. This network effect, built over 15 years with commodity hardware, is very difficult to replicate.

Cloudflare has three main product groups: Act One (web security and performance), Act Two (internal corporate cybersecurity like zero trust), and Act Three (developer platform including serverless functions like Workers). They all run on the same global network.

Cloudflare offers generous free tiers across all product groups, not charging for volume on Act One but for complexity. This attracts a long tail of users and developers, which feeds into enterprise adoption and revenue growth.

The outage was a process error, not a security breach. A corrupted file in their bot management software's machine learning model caused memory issues, breaking services. Cloudflare responded transparently and outlined steps to prevent recurrence.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.