Cloudflare: Leading Cybersecurity - [Business Breakdowns, EP.241]
71m 11s
Cloudflare is a cybersecurity and network infrastructure giant that handles over 20% of global web traffic and blocks millions of attacks per second. Founded in 2009, it disrupted legacy providers by intercepting all website traffic through a single reverse proxy, making security and speed services simple and accessible to everyone, from hobbyists to enterprises. This innovation created a powerful reinforcing loop: more traffic improves its data and services, reduces costs through ISP peering, and builds a formidable moat that competitors struggle to replicate.
The company has evolved into three product areas: web security (Act 1), internal corporate security using zero trust (Act 2), and a developer platform with serverless functions and AI inference (Act 3). Its AI strategy positions it across the industry, serving AI-native companies and offering edge inference, though this introduces new risks. Go-to-market efforts now include enterprise sales, channel partnerships, and "pool of funds" bundling, which have driven strong customer expansion and revenue growth.
Financially, Cloudflare generates ~$2 billion in annualized revenue with gross margins around 75-78%, though cash-based margins are higher. CapEx is significant due to its physical network, but management targets free cash flow margins above 25% over time. Competition is intense, especially in Act 2 and Act 3, but Cloudflare's integrated network and product synergies strengthen its position. Despite a high valuation requiring flawless execution, its multiple growth levers and founder-led team make it a compelling, defensible business.
This episode is brought to you by Portrait. Portrait was built by former buy-side investors.
And they understand great investing isn't just about having more information, from low-quality
sources, it's about having the right information organized the right way.
And if you listen to the show, you appreciate diligence consists of many things, diving
into the history of a business, framing the nuance competitive dynamics, tracking key
signposts around your thesis. And historically, that would take up material time that you
do not have. But Portrait is basically like adding an army of analysts to your team.
It's powered by an AI system specifically designed for investment research workflows.
So you get nuanced idea generation. Portrait assesses the same types of qualitative attributes
that we discuss on this show. And that can help identify businesses which fit your frameworks.
Portrait also customizes research report generation. And third, there's intelligent thesis
monitoring. And that's where Portrait assesses thousands of data points across value chains,
each day, extracting the insights, driving the business. Again, all this work would typically take
hours and hours and hours. Is that your fingertips now? Visit PortraitResearch.com to start your
free trial today. This is Business Breakdowns. Business Breakdowns is a series of conversations
with investors and operators diving deep into a single business. For each business, we explore
its history, its business model, its competitive advantages, and what makes it tick. We believe
every business has lessons and secrets that investors and operators can learn from.
And we are here to bring them to you. To find more episodes of Breakdowns, check out joincolossus.com.
All opinions expressed by hosts and podcast guests are solely their own opinions.
Hosts, podcast guests, their employers, or affiliates,
may maintain positions in the securities discussed in this podcast. This podcast is for informational
purposes only and should not be relied upon as a basis for investment decisions.
This is Matt Russell and today we are breaking down the Cybersecurity Giant Cloudflare.
Today, Cloudflare controls over 20% of the world's web traffic. And to me, an equally notable metric
is that Cloudflare absorbs 2.5 million cyber attacks per second.
My guest for this episode is Sam Eden Investor at Squarespace Global Tech Fund.
And while I could understand on the surface what Cloudflare does,
Sam really helped me get into the weeds on how the digital pipes actually work.
So we go through the rise of Cloudflare and how they built a differentiated product
then and evolve that over time versus incumbents and fellow upstarts in what is obviously an
in-demand market. And through this story, Sam gets into the product offerings that led to
Cloudflare's leading market share, some of the new evolutions and what that might mean for growth
looking forward and how to conceptualize that and break it down through the various buckets.
So if you have any interest in better understanding the world of cybersecurity, you will enjoy this episode.
All right, Sam. I am excited to have you here to break down Cloudflare. It is a tech company that
I think is obviously understood by tech investors. Generalists maybe have more of a high level
understanding and I think the population at large probably has very little understanding of
what's going on. We're going to do our best. Get that understanding before we get into the
overall business and what it looks like today. And just to start there, how would you describe,
explain, paint a picture of what Cloudflare does as a business and as a technology for its customers?
Cloudflare has many different products and we'll get to these throughout this conversation, but
the most common one and is what they started with is their application services and their website
services. Cloudflare provides speed and security for your website. The customers are companies with
a website. This could be your weekend hobby project or it could be some of the largest companies in
the world with some of the most traffic websites in the world. So if you run this website, it has
a public URL, so anyone can visit it, but that also means that anyone can attack it. So Cloudflare
provides security to prevent these spam attacks, isn't known as DDoS attacks, that basically try
to overload your servers. Hackers will try and intercept and manipulate internet traffic. Cloudflare
will protect you from that and it prevents bots from scraping a website. That probably sounded a
little technical, so maybe an analogy for these internet services I like to think of is a postal
service. Let's say you run a website which in this analogy would be say a warehouse that ships
out products. So you'll get in mail orders from all over the world. This would be your internet
request. In this analogy, Cloudflare would be a sorting factory that intercepts all of your mail.
They'll block junk mail for you. They'll block organized spam mail attacks that might try to
clog up your mailbox. They'll scan all incoming boxes to make sure there's nothing malicious
coming in. So this is all the application security. They extend this further. So in this analogy,
they'll also help you set up local warehouses to reduce international shipping. They would create
dedicated fast freeways for postal services. They can speed up the whole postal network. So they
provide only things to make your website fast and secure. You're proving to me that I use the
internet quite a bit but don't fully appreciate all that's going behind the scenes when I'm
clicking around and ordering things and whatnot. One of their customers is Shopify. Can you just
give a relatable example of what it would look like for Cloudflare helping out Shopify? The speed
portion makes a lot of sense in terms of making sure that they can run on optimize speed but from
a security perspective, what might that look like in a scenario? For Shopify, they have millions of
merchant storefronts from the security point. Let's say a massive botnet. They attack a specific
store. Let's say it's during Black Friday. With our Cloudflare, that merchant servers, they're just
going to get overloaded. The website would go down and they can't make any sales. But with Cloudflare,
they're going to absorb that traffic at the edge. The website is protected and it can stay online.
That's really important for these e-commerce companies because if your website's down,
will you not make any revenue? It's a time as money type thing. Anytime there's an outage or
things go down. Before we get into some of the history, can you just give me a sense of how big
Cloudflare is today just in terms of any numbers that would capture the size and impact that they have
in the market. Cloudflare is huge and when you think about the scale of the internet, it's sometimes
hard to wrap your head around. But Cloudflare, you can think of as a single global private network that
runs all this traffic and over 20% of the world's web runs through Cloudflare service. So that's the
scale that we're talking about. And in terms of cyberattacks, an average of over two and a half
million cyberattacks every single second is absorbed and blocked by the Cloudflare network.
Two and a half million cyberattacks per second is somewhat frightening to me that's happening.
Totally. Let's get into the history here because I know it has evolved quite a bit over the years
and you don't get to that 20% without evolution. What's the founding story? Obviously, it wasn't around
before the internet, but tell me a bit about founding story, founding team and some of those key
moments in the history. It's really important to understand the history of Cloudflare because if you
can understand why they were successful in the start and how they got their initial foothold in
the market, all of their new products built on top of that. So if you understand the history,
then you can understand all of their new products. Cloudflare, they'll found it in 2009,
a Matthew Prince, Michelle Zatlin, and Lee Holloway. They now have over two billion in revenue.
One thing to always remember about the internet is that everything still runs on physical hardware.
So there's cables that actually run across the oceans, run through mountains, and they physically
connect server boxes that intercept and process all this internet traffic. Before Cloudflare was
founded, let's use an example of someone based in New York. They want to visit a website in Australia.
So to do that, you send a request all the way from New York to Australia. They process that
and then send it all the way back through a cable across the Pacific Ocean back to the server.
So that's slow. And it also costs your ISP, your internet service provider, some money because
I have to pay some transfer fees to work with other ISPs across the world. So this is a bit of a
loose-lose situation for the ISP. They have to pay transfer fees and it's a bad and slow customer
experience. This is still before Cloudflare. Some of the early legacy companies, let's say Akamai,
they provide what's called a CDN content delivery network. The Australian website can pay Akamai
to store images or some of the other website assets in a server in New York.
Anytime someone in New York visits the same Australian website, it's just pulling the
data from New York across the city much faster.
One thing that's important to understand
because it sets up CloudFlair, well,
is that these legacy companies, like Akamai,
they split the network.
Customers have to decide what to put on their CDN network
and what to handle directly.
To set this up, you need a sales engineer.
It's complex implementation.
There's a lot of ongoing maintenance.
And then if you buy a different service,
then you have to administer that
instead of a whole different network
and decide what to get redirected where.
Also, this website in Australia, for example,
might want to only serve valid requests.
So they actually have to buy a physical firewall
to intercept and check this traffic.
All these services, they're worth called reverse proxies,
which basically means they just intercept incoming traffic
on behalf of the website.
And that's part of the security piece
that we talked about earlier.
So that's the lay of the land before CloudFlair.
This was all very difficult.
It needed those sales engineers.
This was only really accessible for larger enterprises
and more sophisticated websites.
And these legacy vendors didn't have a solution
for the long tail of websites that CloudFlair started serving.
If we want to just relate this back to the postal example,
this legacy setup would be if that website in Australia,
they would have to inform all of the different
postal routing services all over the world.
They would have to tell them their different split rules
if the mail is directed to this apartment,
use this address, if it's directed to this department,
use this address, if it's a package, use this address.
And that takes maintenance because if he rules change,
you have to update that and it's a lot of work.
That's a bit of a history of the pre-CloudFlair time.
Feels very manually intensive
and a bit of a traveling salesman problem
in terms of optimizing for where things go.
So now we can get to CloudFlair.
Matthew Prince, the co-founder and CEO of CloudFlair,
a very interesting background,
tinkered with computers as a child,
studied literature and became a lawyer,
and you can see that with his storytelling abilities now.
Here's an interesting background.
He was set to take over his family business,
which actually included running of hooters.
He didn't want that, so he went to HBS.
But before enduring that, he was working
on a project called Project Honeypot,
and that eventually became CloudFlair.
So he was working on Project Honeypot
with the technical co-founder Lee Holloway,
who was responsible for a lot of the early code
and a lot of the early innovations.
Unfortunately, Lee was diagnosed
with front of temporal dementia,
so he's no longer with the business,
but his technical influence
remained strong throughout CloudFlair today.
Project Honeypot, it's kind of as it sounds,
it was a way to let hackers and spammers
scrape email addresses from your website,
but these email addresses were just trackers.
You could see if someone tried to spam that email address,
they would get put on effectively a big list of bad addresses.
It was creating a big bad list.
It was effectively a do not call list for spammers.
Hundreds of thousand people were installing Honeypot
to help build out this list,
and helping build out this list
because they wanted to be protected from this list.
So the more users, the better the service
because the list got bigger.
At HBS, this is where Matthew Michelle's atlin,
she's now the COO, she heard about this idea
and wanted to be a part of it.
They're a great pair, Matthew brands the real visionary,
and Michelle brings a lot of the operational rigor.
Now we can get into the technical side of CloudFlair,
and I'll keep a high level,
but they have this Honeypot list, a list of bad actors,
but it's a tricky problem to solve
because it's effectively a lookup table, right?
You see in incoming address,
you'll compare that to the list
and see whether you want to accept the request or not.
So one way would be to put it on all of your customer's servers
and they can do the lookup,
but that would slow the entire internet down
because every single request now has to compare it.
So what CloudFlair did,
and this was the real innovation,
was that they just intercepted everything.
You didn't need multiple reverse proxies
to do different things.
You just have one reverse proxy, that's CloudFlair,
and that does many things.
Were they getting paid to do that?
No, and this is a story throughout CloudFlair,
a lot of their products they'll turn on,
and they have a very generous free program,
but this helps build out their business mode,
improve their products, and create a business
that's highly defensible.
Network effect, beneficiary,
and getting the free service out there can lead to that.
Totally, that project Honeypot was the exact start of this.
So all these customers could just redirect
all of their traffic to CloudFlair,
and they would do the lookup.
Now this is really hard to do.
So Lee Holloway was able to build a technical solution
on this.
If we relate this back to our postal example,
instead of splitting the network and all that,
all you have to do now is just say,
my new mailing address is CloudFlair.
No matter what the recipient is,
no matter what the package type,
CloudFlair will intercept it and decide what to do with it.
What this allowed is because it's intercepting everything,
if you want to add another service,
whether it's a CDN or a DDoS protection,
it doesn't matter.
You can just really easily turn that on and off.
You don't need that sales engineer
that we mentioned before.
CloudFlair is already in front of your traffic.
You don't have to redirect anything
so that makes it simple.
So this was the main breakthrough for CloudFlair.
They could now serve that long tail of websites,
and they were the first real product-led growth company
for internet services.
Anyone could sign up really quickly.
They could serve all those like weekend hobby projects,
all the small websites, and start providing
web protection services for them.
In terms of getting those users,
were they just in front of the community,
of open source developers,
or was there anything that got the attention
to where they got that initial user base going?
Was there anything that stands out?
A lot of the early customers,
they serve a lot of nonprofits
because they had a lot of traffic but couldn't pay much.
So that was really big.
And they actually served a lot of the hacker community
because a lot of hackers get hacked as well.
So hackers would sign up to CloudFlair to protect themselves.
Those are some of the big starting customers
that really proved that the service would work
because if they could protect hackers,
then they could protect a more basic website as well.
That's very interesting.
It also introduces they had to then be better
than the hackers because in theory,
the hackers would see what they're doing.
The hacking community is one that is fascinating to me.
One thing that's important to understand
and this is why their business is so hard to replicate
if anyone tried is trying to understand
why competitors just didn't do what they did.
Why not just intercept all the traffic?
The reasons would be revenue and costs.
So with revenue, CloudFlair,
it's a classic case of the innovators dilemma.
So these large enterprises that I mentioned before,
they didn't want to offer this simple interception
because that's not what the large enterprises wanted.
So the short-term revenue wasn't there.
So CloudFlair could build for this long tail on their own.
And then costs is the other reason
that competitors didn't do this.
It's really technically difficult
to build a system that scales to intercept all the traffic.
And they made a decision early on
to just use commodity hardware.
They didn't want dedicated hardware to process this.
They created the software-defined network,
which was inspired by Google running on commodity hardware.
So they could just scale their network with cheaper hardware.
And today, that's still the case.
Today, CloudFlair's still that single global network
of commodity hardware with layers
of various sophisticated software on top of that.
And another really important thing
is the peering relationships with the ISPs.
So the ISPs who pay each month for your internet bill.
If we go back to that New York Australia example
we mentioned earlier, let's say you visit a small website
in Australia, this small website,
they can't afford those legacy services
that only cater towards the enterprises.
In this case, the ISP has to pay those transfer fees
to get the traffic to and from Australia.
And the ISPs provide a slow traffic experience
so it's lose-lose.
Those enterprises aren't serving those customers.
Now, because CloudFlair makes it easy,
they have that product-led growth
and that really generous freemium model.
They can start providing those services
for these small websites.
Now, one website isn't enough,
but if you aggregate that whole long tail that they serve,
CloudFlair has negotiating power with the ISP.
They can say, I see you're transferring a lot of bandwidth
to this region and I know that
because I see all the traffic from my customers.
So why don't I just put my server next to yours
will have a peering relationship?
That means you don't have to pay those transfer fees
also the content directly.
And that ISP situation has gone from a lose-lose
cost and slow internet to a win-win
because they don't have to pay those transfer fees
and the internet to sped up.
So CloudFlair can negotiate this relationship
and often doesn't have to pay bandwidth fees.
Is the ISP the loser in that case?
I would say it's a win-win situation
because without CloudFlair,
they have to pay the cost of connecting to other networks.
So it's a cost for the ISP.
If you think about your own internet experience,
if your internet's slow,
you don't blame the fact that the server
is on the other side of the world
or anything like that.
You blame your internet service provider.
By partnering with CloudFlair,
they cut out those costs
because they just serve it from CloudFlair
and they can speed up their internet
so their customers are happier.
They partner with all these ISPs across the world.
And one way that I like to visualize CloudFlair,
is they have this single global network
that spans across the world.
It's a single web and that connects
to all these subnetworks, all the ISPs.
And today, their single global network
connects to over 13,000 different networks directly.
And these subnetworks could be ISPs,
they could be cloud providers, they could be corporate networks,
but they connect them all together
in this one connectivity layer.
Now we're ready to piece this all together.
I think this is the most important part
of the Cloudflare business.
So if you put this history together,
it creates a reinforcing loop.
So I'll try and help you visualize it
that at the top of the cycle, we talked about their load bandwidth
and low hardware costs and their easy to use products
that enables this product-led growth motion,
so they can serve that long tail of customers.
What that enables is more traffic goes through their servers.
So they collect more signals, they collect more data,
and then they get better and better
at blocking malicious actors.
They get better at optimizing the network for speed
and just providing better website services.
And better services, which is halfway around the cycle now,
that leads to more pain customers and more enterprise customers,
which again brings in more traffic.
And then as they get more traffic,
they can negotiate even more with these ISPs
to reduce their bandwidth fees further,
create more peering relationships,
that brings their costs down further.
And then they can reinvest that revenue and cost saving
back into their global network,
create more products, continually building out.
And the cycle continues, they attract more of that long tail,
collect more data, build out the network.
This network gets better as it gets bigger.
We often look for businesses that follow this characteristic.
Because they've been doing this for 15 years,
it's an incredibly difficult system to replicate.
And it's a really important part of their moat.
So that's how they can continually offer
these freemium services while processing over 20%
of the world's traffic.
And it's just a powerful reinforcing loop
that gets stronger and stronger.
In terms of controlling that volume
that puts you in a better position
from a negotiating perspective,
you can bring down costs in a lot of ways.
But for a business like this,
which is trying to detect certain things
and optimize certain things,
you get better in terms of what you're offering if done right.
On the evolutions that occurred over that period,
really curious too, just in terms of
when they hit a point of evolving
into the commercial operations,
what that looked like,
how challenging that might have been.
And then some of the products that have been layered on
since then because it definitely has evolved
into a full suite of things that are very complimentary.
But how did that piece out together?
- The Cloudflare we just described
looked very different to the Cloudflare
of today in terms of their product suite.
The main product evolutions have been going
from that product led growth to enterprise.
And then using that single global network
to add services.
So they've added a lot of internal cybersecurity products
and then a whole developer platform on them.
We can go through each of those.
The first one is just that transition
from serving this long tail only of freemium customers
to serving the biggest websites in the world.
And it follows that same loop.
The more data they collected,
the more they could build out the network.
It reached a tipping point
where now their capacity and their services
were better than the legacy companies.
The capacity to absorb, say cyber attacks
or those DDoS attacks is just unmatched.
And a recent example they gave in one of their earnings call
is they won over a large customer
because their DDoS protection capacity
was over four times the two legacy competitors combined.
It was over 30 terabytes per second
that they just easily absorbed
because they'd continually built out this network
so they conserved the long tail
and now these high willingness to pay enterprise customers.
That's one product evolution
within their original product set.
They able to evolve just from those web security products
to this whole new market of internal cybersecurity.
I've seen a lot of references to this
in terms of kind of a growth engine
but how would you articulate what's going on there?
I think it's clear once it's articulated
but describe that for the audience.
If you think about the services I just explained,
it's CloudFlare intercepting outside traffic for a website.
What they realize is that we have all this hardware.
Why don't we intercept and inspect
traffic that goes from a company to the outside world?
It's basically the other way.
This is a reverse proxy and a forward proxy
and they use the same hardware for that.
So if you think of a reverse proxy
as protecting a website from the public internet,
a forward proxy server which is the whole security products
is protecting an employee from the outside internet.
It protects you when you have outbound traffic.
This is the basis of the whole product suite.
It's often term zero trust.
That's a type of approach that you can provide
these internal security products.
Zero trust means the zero trust between any app and any user.
So if you contrast that to old services,
maybe log into your corporate network,
you gain trust once and then you're within your private network.
Zero trust just means just because you could access app number one,
doesn't mean you can access app number two.
You have zero trust between the app.
You have to get validated each time.
To do that, that means you have to get
inspected each time.
All of your web requests have to get expected each time.
And that looks a lot like their original services
because they're very, very good at inspecting every single packet.
So they realize that they could apply their commodity hardware.
They didn't have to change anything.
They just added a software layer
to provide this whole new market
of internal corporate cybersecurity.
If I'm thinking about that as an internal employee,
would that be if I'm logged in?
And I click on a link that goes to a website.
It's giving me the alert that this looks unsafe.
Does it extend beyond that in terms of fishing emails and scams?
Curious to know who's doing what?
In the chain of constant precautions that I'm being told.
Anytime you're doing something on the internet in a work context,
that's this whole space.
And Cloudflare has a solution to that.
It's a very broad market.
There's a lot of competitors in here.
There's probably three buckets of activity
that an employee will commonly take that you need to protect.
One would be you're on your work laptop or your work network
and you're visiting an outside public website.
And you want to make sure that the traffic going in and out of your work
environment to the public internet is safe and secure.
The second type would be you're working just with your internal apps.
You're checking Salesforce, you're checking service now, things like that.
So you need to make sure that you're actually approved.
And this is that zero trust.
Approved to view each app and then maybe there's different policies
on what you can view.
And then the third bucket is I guess all the adjacent things
with that, the email, security is what, protecting against phishing attacks
and things like that.
I've definitely experienced where being on-prem,
I can use certain apps even but went off-prem mobile
or on my own device.
There are certain restrictions on what I can access for good reason.
I have some sense of how they've evolved pretty naturally
from being that external third party guard dog of sorts
to also protecting from the inside.
Would you point to anything else just in terms of the evolution
or what they've rolled out that was key or monumental
in terms of the development of the overall business
and what they offered?
This is a continual evolution that all companies are going through
is your corporate environment used to just be your on-prem network.
But now everything's cloud-based, you can work from home,
you can work from anywhere.
The corporate perimeter security perimeter
is effectively the whole internet.
That's why they can fit nicely in there
and provide those services.
They realize that with their hardware system
and their single global network,
they could expand from web services to corporate security.
The way they did that was building a lot of the software themselves
to be able to provide these services at a global scale.
They often had to build a lot of their own software.
They couldn't rely on AWS, for example.
No one else could handle their scale
and they wanted to have really strong security.
What that meant is they have this proprietary software stack.
That leads to their next product devolution
where they realize that if you can build cloud flare
using these internal tools that we've built ourselves,
then other developers will be able to build really powerful products
with these tools as well.
So they started offering these services to the developer market.
So these include things like cloud storage,
lightweight databases, video services,
and their flagship product in this,
what's called act three, is the Cloudflare workers.
So that's a serverless function service.
And they specialize in lightweight functions
that can be spun up and spun down really quickly
to solve bite-sized tasks.
And are these developers working within corporations
where what cloud flares building off the shelf
needs to be maybe expanded upon
and they're incorporating it there?
Or is it separate from the enterprise corporate-type clients?
and its developers that are building some unique product
and then selling it themselves to a different audience.
It's currently quite separate.
You don't have to use these products together.
You can just be a developer building a weekend hobby project
and you want to use the Cloudflare serverless functions.
That's a totally valid use case.
They're working to bring the products together
into a more unified experience, but they don't need to be.
You can use these Cloudflare developer products on anything really.
The developers I assume are then paying Cloudflare
some software costs to use that.
That's right.
Similar to other Cloud models I say from the hyperscalers,
their developer products follow a usage-based process model.
The more you use, the more you pay.
But similar to the early products,
they have a very generous free tier
because they really want to attract that long tail of developers
and then bring that into the enterprise,
which is what they're doing at the moment.
There's over 3 million developers building
using these Cloudflare developer products.
A lot of them would be building quite sophisticated functions
just within their free tier.
To give a sense of how generous this free tier is,
I think with their workers serverless functions,
you can query that up to 100,000 times a day.
Their storage is 10 gigabytes per month with zero egress fees,
which is dramatically cheaper than a lot of the alternative developer products.
Can you just give an example of what developer might build
with the tools just to give a sense of what a tangible example might be?
Cloudflare workers are best for quick functions
that need to be done close to the user.
Maybe one quick example would be that if you're loading a website,
you might have a quick worker script
that changes the local pricing or changes the local language
based on where that web page is loaded.
That's done at the edge,
so it's faster than querying say essential database
to generate the patron scratch.
The way to conceptually think about these workers
is anytime you can take like a task
and put it into bite size functions,
it's good for that just because they spin up so quickly
and then turn themselves off.
It is a slightly different way of thinking
because you're deploying again to the single global network.
If you deploy a function to AWS,
you might put that on the US East servers,
so it lives there.
So if you call that function,
you have to travel there,
whereas with Cloudflare,
if say you're building an app in New Zealand,
you deploy a function immediately in London,
someone can query that website
and that same function is served
from that London server at the edge.
Everything gets propagated around really quickly,
which is just another benefit of this single global network
that they've built.
Yeah, I can speak to that example
as someone who tends to find myself on UK
or Japan websites,
just the currency switch is always beneficial,
saves me some time from doing the currency conversion.
When you think about AI,
this is a business that is clearly benefit
and took advantage of what the cloud has provided
in terms of opportunities.
It's been very thoughtful about that
and evolved naturally into different pieces
over an organization and offering more.
So two different things writing away,
but also being operationally thoughtful
about how they're going to market.
When you think about where they fit into the AI boom
and potential to be whatever they might be in that world,
how do you frame it and then
how does the management team talk about
where Cloudflare fits into the AI ecosystem?
I would say they fit all around the AI industry
and there's probably four ways I'll describe this.
First way is just the adjacent tailwinds,
which you mentioned as people want to use AI
then they're thinking more about the data strategy
and often you want your AI agents, for example,
to read a lot of data
and you might want to do that quickly
without paying a lot of egress fees.
So there's tailwinds in general
for Cloudflare's approach for doing that.
So that's the first relationship to AI
as just adjacent services.
The next three are the different sides of AI that they serve.
The first is just serving the AI companies themselves.
The alleged reporting was that 80%
of the top AI native companies,
the top AI companies, were Cloudflare customers.
So that just shows that this next generation
and this next era of businesses
still looked to Cloudflare first.
So if they're providing other services
for these AI companies, it positions them well
to provide AI services as well.
That's one is just serving the customers themselves.
The second direct AI involvement
with Cloudflare is inference themselves.
They've started to offer inference
at the edge through the Workers AI product.
It's a slight evolution from their previous strategy
where they still have this single global network,
but previously every component like every piece of that hardware
could provide every service,
which is really powerful
because it just meant the return and investment
on each of those pieces of hardware
could be split across all of their products.
But now with AI inference,
the hardware starts to matter.
They had to install GPUs across their servers.
Their servers cost 330 different cities across the world.
This was done really quickly.
So Cloudflare is a very long term strategic company
when they're actually designing their motherboards
for all of their chips.
They left an empty slot open
because they didn't know what would it be for,
what the use case would be,
but they needed it just in case something came up.
And it turns out AI inference was that something
so they could go to all of their boxes
and simply just plug in a GPU.
And then AI inference is available
across the world at all of these locations.
This is serving these LLM models.
You can quickly query an open source model
for text generation, image generation, voice,
or enterprise customers can deploy
their own custom LLMs as well.
And again, that gets propagated
across their single global network.
The AI inference from Cloudflare
can be done really quickly at the edge.
And as I mentioned before,
Cloudflare work is a really quick
at spinning up and spinning down.
So I'm like, so hyperscaler,
you don't have to pre-bork or pre-provision capacity.
You're only used for what you pay for.
If an inference is small and you don't use it for a day,
you're not going to pay anything.
So it only charges you directly
on the AI inference that you use.
It feels like a key layer of infrastructure.
So you could see them on all sides of the market.
Thinking about how they transition,
you mentioned they got to a point
where their offering was on par
and then eventually better
than what incumbents and legacy providers were offering.
Can you talk about what that looks like?
Because I imagine they broke into
the enterprise market over time.
What that looked like, how they approach it.
Some of the nuance to what it looks like
to have an enterprise contract.
This is an ongoing evolution.
They go to market changes.
Three things I'll call out.
One is just the general enterprise sales motion.
The partner motion, which is really important to understand.
And then they're pool of funds.
Bumbling strategy.
So the first go to market evolution was the enterprise sales.
This is just a typical transformation
from product-led sales enterprise sales.
And the product capabilities were there,
but it's still a new go-to-market muscle.
And across all companies,
this is never an easy transition.
Particularly as you're moving into security as well.
It's a new buyer for them.
Instead of just an IT administrator
that is looking over the website,
you're now selling to the whole security office.
It could be a multiple month process.
So they had to build this new go-to-market muscle out.
So in 2023,
they actually saw their rep productivity start to drop
and they had to let go a lot of their sales team.
But in 2024,
they brought in a new president of revenue, Marc Anderson.
He's incredibly experienced.
He's formerly president of sales for Palo Alto Networks,
CEO of OuterRex.
So he has this deep experience with enterprise sales.
This transformation, they're hiring a lot more reps.
They've switched from hiring majority bid market reps
to now hiring a majority of enterprise reps.
And they're still keeping this product-led growth
because it's so important to their story.
But now they're really increasing their sales-led growth motion.
They're still ongoing transformation,
but quick quantitative proof that we're starting to see
is that the growth of revenue from large customers
has started to inflate to around 30%
and now it's starting to inflate up to 40% year-over-year.
It's a really impressive transformation.
How big of a chunk of the business is it today?
If you look at customers over $100,000 in revenue,
they're less than 1.5% of the actual customer base.
But they contribute to about 75% of the revenue.
It's very important to get this segment right.
There's a long runway to that segment as well.
They're at bit of a 2 billion of annualized revenue.
With that, they have a bit less than 200 customers
that are over $1 million.
If you compare that to Z-scaler,
when they're at that same size, that 2 billion run rate,
they had almost 500 customers with that $1 million revenue.
So it highlights that runway that they have
at that very large enterprise end.
And the go-to-market transformation is a big part of that.
How much stickiness is there,
both from a perspective of keeping customers,
but also being able to win share from some of the competition?
their long-term contracts that are in place is they're a major friction associated with
ripping out old infrastructure and implementing new, seems like they may have an again market
share, but how much goes into that and what are some of the unique dynamics there?
It's definitely a sticky product because if you have oil, kind of web and security set
up, it would take a lot to migrate from that and a lot of convincing to do to migrate away
from such a powerful network.
So there is definitely a stickiness involved and one way to look at that is their net revenue
retention over the years.
It's always been above 110%.
In the last few years, it has dipped a little to 112 in the last few quarters, but with
a lot of their other efforts, which is the pool of funds, recent initiative, that's been
starting to inflect and their latest quarter, or Q3 2025, that reaccelerated up to 119%,
so going from 112% up to 119% of expansion of existing customers is a significant reacceleration
and obviously the product's important, but some of this go to market contracting is really
important as well.
I want to get to the partner strategy, but you mentioned the pool of funds and how that
might link to that reacceleration.
Can you describe that?
We've spoken about like the three different products, the web security, the corporate security,
and then the developer platform.
We also spoke that it can be quite separate.
What that meant is you could have three different buyers and you could have a company that we're
using each of the three different product groups, but not necessarily talking to each other.
There's a bit too much friction for what should be a smoother process for working on
a single platform, so that's where they introduce pool of funds.
This is a bundling method and it's also as it sounds, it's a pool of funds that large
customers can draw down from.
What's really important with this is that you can draw it down from any product, so this
really encourages experimentation and adoption of some of their newer products.
These are multiple year commitments as well, this is their top enterprise customers and
they recently signed a $130 million five-year contract, so these are big contracts.
What it means is if you plan to say use 80% of these pool of funds on to Act One, you
still have a little capacity and flexibility to experiment and try out a few of these
workers products, you'll see that they work at an enterprise scale and that just encourages
the adoption there.
It's still a fairly new initiative, it wrote down 2024, but it's already up to low
double digits of their total annual contract value.
A quick metric to show that this is working is that this puts a lot of focus on RPO, the
remaining performance obligations.
That's been growing around 40% year-over-year through 2025, so there's very high growth at
this scale and these pool of funds are contributing to that and I mentioned before that it's starting
to accelerate the net revenue retention as well, obviously not all from pool of funds
because it's still new, but it's a contributing factor as well.
It's a really interesting strategy, you look at all these different businesses that have
complimentary products, but oftentimes we glance over that you have different divisions
that are buying them, different customers and what seems complimentary gets bogged down
and friction is associated with that and you don't get the synergistic effect that you
should.
I'm sure it exists elsewhere in terms of this type of approach pooling funds, but that's
quite notable.
On the partner strategy, which I skipped over, but you referenced before, what does that
buyer base look like?
What does that strategy look like and when did that come into play?
So the channel partner strategy, it's really important for their act to, this is their internal
security products, because the buyers often go through channel partners.
These channel partners, they often have a preferred vendor list, so the relationships
with these partners and these could be consultants, system, integrators.
If you're not on their preferred vendor list, it makes the sale a lot harder.
So would it be like WordPress might have cloud flare?
It's more like a maybe a cognizant, a CDW for security like Tata and all these insulting
and professional services groups, so they will help with the sale and then help with
the implementation as well.
These are whole companies on their own, so the relationships with them are really important.
So Mark Anderson, the new CRO, brought in a new head of partnerships, Tom Evans, and
here's a long history in these cybersecurity partnerships, worldwide channel sales lead
at Palo Alto Networks, so there's this big role that they support from.
The results with that are quite impressive, the channel partner led growth, and the last
few quarters has been growing around 65% year over year for the past two years.
The percentage of incremental total revenue from partner channels has gone from about 20%
to over 40% of incremental sales, so it's a really important driver of their growth,
and there's a long runway to just to really highlight how important this channel is for
security, cloud flares, current channel partner revenue as a percentage of total revenue
is about 30%.
And if you contrast that to Z-scaler and Netscope, they're almost at 90% of the revenue going
through channel partners, or channel referred partners, so there's a long runway to go.
It's a relatively new motion, so I would say they're just getting started there.
Those channels are always interesting, it's kind of like an external sales force in many
ways that can do the work on behalf of you.
Do they give any sense of whether the margin looks materially different through the partner
channel versus the other buckets, sometimes you get lower margins associated with that
because there is a theory of middleman involved, but do they provide any disclosure on that?
They don't give too much because it is different depending on the partners and that you might
have different contracts.
Typically what these partners do though is the large-scale resellers will basically take
a cut, but some of the larger ones, most of their revenue is actually from the professional
services and implementation on top, so they're not trying to skim a product fee.
They're more interested in the professional services that go on after the sale, so that
just helps with the negotiation and it can protect their margins quickly on margins.
These act two products, they're the highest incremental gross margin part of the business.
It's a high willingness to pay by or of security and you're using your existing networks,
so very strong margins in that part of the business as well.
Maybe we can get into the financial business model in some of the spreadsheet details.
I think you referenced, you're looking at over 2 billion in revenue on an annualized
basis today.
How is it split out between those buckets?
You may have referenced it in passing, but just to give a clean snapshot of that.
They don't split it out exactly, but you can estimate if you split it between the act
one, the act two, and the act three products, that two billion dollars is majority of act
one, like it's their bread and butter, and you could estimate maybe roughly two thirds
of their revenue is from act one, maybe 30% from act two, growing quickly, and then act
three, it's still a bit smaller, but growing very quickly as well.
In terms of the customer base, I'm assuming most customers, or at least a large percentage
of the revenue are using multiple products.
Your point in terms of the large accounts being 1.5% versus 75% of Refugee kind of gets
to the power of large customers, but is that the case where the majority of customers
are using or majority of revenue is coming from customers that are using multiple products?
That's exactly the case, and they have over 55 revenue generating products, or a long
product sheet, and customers with more than 10 products is the fastest growing revenue
category.
That's exactly the case.
Offering a freemium model seems to be ingrained in their DNA.
How would they manage that over time in terms of continuing to offer a product that attracts
users and potentially gets them into the funnel over time?
What does that look like?
We spoke a lot about the freemium model for like how they got started, and they've really
kept that in their DNA for Act 2 and Act 3 as well.
The way they do it as well, it's quite strategically different to some of their competitors.
On Act 1, they don't really charge for volume.
Their free users can actually get unmeted DDoS protection, free bandwidth for CDN.
This is really generous.
What they actually charge for is complexity if you want specialized rules and special
bot management setups, but that means if you're a website that constantly gets attacked
with high volume, they're not going to charge you actually.
They're not going to punish you for that.
That's one interesting part of the different strategy, at least for the Act 1 products.
For Act 2, quite generous as well, up to 53 users, but then Act 3, their freemium product
as well, you can very realistically set up and build a sophisticated app without paying
much at all, and that's actually what we have done as SquareFeg internally.
We've built some quite sophisticated AI products to ingest a lot of our research, create
dashboards, and have a full AI interface, built on CloudFlare, and it generates an enormous
amount of value, and CloudFlare builds have been remarkably low.
The interesting investment firm can do that and fit into that category.
Is there a way to capture what's subscription-based versus that you mentioned like the complexity?
Is that still fall under a subscription?
I'm just trying to get an understanding of the contractual nature versus the usage-based
nature, which I'll bucket complexity into that if it should.
be, they're not charging based on volume necessarily, but how do you split that up?
It is slightly different for a product group, but for Act One, it is a subscription tier.
So you pick a plan, pro tier, business tier, or custom enterprise tier, and you're paying
that flat monthly rate for that tier, and it includes a bunch of things.
You would upgrade a tier when you need more enterprise features, whether it's those complexity,
rules, special splitting of traffic, and things like that.
Not on volume for Act One, at least.
Act Three, those developer products, that is more uses-based pricing, no egress fees,
but the uses-based pricing for how much you use their services.
Putting it all together on a margin, however you would look at this, what do margins look
like for Cloudflare?
They're a software business, so they non-gat gross margins are about 75% to 78%.
This looks lower than maybe a top-of-performing software business that you would expect to see,
but you have to keep in mind that they own and operate their own physical infrastructure,
and the depreciation of their equipment is included in the reported cost of goods sold,
that naturally compresses their gross margin.
If you did want to try to look at a cash-based gross margin to compare apples to apples, about
6% of their revenue is depreciation directly tied to equipment, so if you want, you could
add that back in and compare gross margins on an 83%, 85% range.
As it falls to the bottom line, whether it's EBITDA margin for cash-low margin, what does
that look like?
Are there any major cost buckets that eat into that?
The main one to call out is the CapEx, which is naturally, again, a lot higher than a lot
of software businesses.
The CapEx has consistently been around 11 to 14% of revenue.
That's going to bring your free cash-low margins down, and the free cash-low margins have
been around 10% in recent years.
The long-term guidance, at least from management, is to expand those to over 25% as operating
leverage continues to expand.
They'll get the majority of that off of the operational cost, labor, whatever it might
be.
One big cost now is their sales and marketing cost.
That's 35% of revenue.
That has opportunity to come down, and there's margin points available there as well.
Capital allocation, with that in mind, it feels like a business that has reinvestment
opportunities that would take up the majority of where that cash-low would go.
Has that been kind of the policy, and how do you think about how they allocate the capital
that they do have and their history for CapEx spend in ROI in that CapEx?
The capital allocation, it's a really important part of the business, and the very strategic
about how they do it, such that they get a really strong ROI on their CapEx.
We spoke earlier about just using commodity hardware, so that reduces the cost of the
hardware.
They often talk about investing behind the demand curve, so they see whether traffic
is and what the demand is before they build.
They're not just building for no reason.
What's really important to understand with their CapEx is that all of their servers can
run all of their products and provide all of their services.
That means the CapEx and the ROI is split across all of their product lines across Act
1, 2, and 3.
The incremental ROI is more diversified and it's higher.
You're not building a separate network for each product.
It's one network that can contribute to the return on each incremental CapEx spend.
You alluded a lot to legacy competition.
Are there new competitors that are in the market?
It does seem like a market that will only get more important over time.
How do you frame the competition and does anybody have large, comparable market share similar
to what Cloudflare has?
In Act 1, they've established themselves as a leader.
Some of the legacy companies specialize in certain types of networks where there's media
and things like that, so they're still important competitors, but Cloudflare has the biggest
network that, as we mentioned, is very hard to catch up to.
But in Act 2 and Act 3, it's much more competitive there.
I think Act 2 is probably the most competitive because cybersecurity, there's always new players,
there's always new trends, and importantly, Cloudflare isn't leading the innovation there
like they did in Act 1, like they're a second mover.
ZScaler is probably the largest pure play, zero trust, Act 2 competitor, and they also have
a global network that they run and manage themselves.
It's a decent time to bring up the outage, which I probably, like, really burying the lead
in terms of recent activities and news, but just in terms of competition and what it could
represent, can you walk through what exactly happened where I felt like one, the entire
internet was out on me, two, I learned just how many websites were connected to Cloudflare,
so two important things came out of that, but maybe just an explanation of what happened,
and then we can get into if there's any residual implications from it.
The outage affected everyone, and it's one of the downsides of having a single global
network is that it can all go down, and that's what happened.
I think what's important to understand with that outage is that it wasn't an attack,
it wasn't a security breach or anything like that.
It was a process error, basically, their bot management software that inspects all the
traffic, it's a little machine learning model, so it has all these features.
There was an upstream error that caused those features to double in size, and their service
just didn't have the memory for them.
These features, they updated constantly, every five minutes, the model's getting updated
with new threats, every five minutes, a corrupted file is getting pushed out, and it broke
a lot of their services, so everything went down.
It's not just similar to say the CrowdStrike outage that happened in 2024, where it wasn't
a security breach, it was a process error for something that was very in the weeds, it
caused all these outages, everyone realized, similarly, how many businesses ran on CrowdStrike,
but they've come back just as strong as ever, because I think people realized, okay, as
a process error, and they're clearly going to do something about it, which is exactly
the case with CloudFlare.
I think what the customers and community really appreciate with them is just how transparent
they were, they wrote a very in-depth and transparent report day of the incident, and having
quite like an engineering-forward customer base, I think that was just really appreciated.
They've outlined process steps and updates they'll take to make sure something like that
doesn't happen again.
It's a little tough when it's the machine learning, you don't have a scapegoat if it's
just the machine, I guess you do, but nobody in theory gets fired over that, or maybe the
person behind the machine learning who codes that all up, but noteworthy, and as it happened
over history, I do think it's interesting with businesses, whether it's moodies during
the financial crisis, Equifax, with security breaches, where if it doesn't kill them, it
kind of proves the moat or strength of the business in many ways, and to all different
degrees.
But have there been historical outages, maybe not as impactful as that one, and any signal
to whether they have material impacts, whether it's shorter or long-term in the business?
There was one, semi-recently, it wasn't as big as the one that happened recently, but
there was an outage, and this actually encouraged some internal transformation or accelerated some
internal transformations.
So I mentioned earlier that CloudFlares built on CloudFlares, they built a lot of this proprietary
software to run their systems for most of their systems, but not all of them, and this
could include things like acquisitions or other things when they're scaling up new products
they might borrow something.
And what happened in the previous outage was there was an issue with like a Google Cloud
KV cache or like a small piece of the database, which flowed through some of their products
and course and outage.
Again, wasn't the security breaches an error that happens, but what it did was they had
an internal project to migrate off those third party solutions, and that just accelerated
that.
It was not good, but they kind of turned it into a strength to increase the robustness
of their systems.
Then I guess based on current growth numbers or more recent growth numbers hasn't been
too impactful on the underlying business performance.
On competition, it feels like Z-scaler is one that shows up in multiple categories.
So I put them there.
In Act 3, you mentioned the hyperscalers, which I think are worthy competitors for anyone
to deal with.
But in terms of the competitive risks and threats, how high do you rate that on the risk spectrum?
Like is it something that concerns you sometimes in a growing market?
If you have one of the leaders, you usually feel pretty good that even if things move slightly,
it's not going to be too material, just thinking about the competitive threats and how fragile
their position is versus being very strong and only strengthening.
My view is that it's a strengthening position.
Say with Act 2, Z-scaler has that incumbent advantage and that trust with very large enterprises.
But it's a huge market and Cloudflake and like there are other products, start up the
smaller end and work up to the enterprises.
and it's starting to do that. What really benefits them is having that global network of all the
products, they can use their Act 1 strength to prove their product, encourage adoption of the
Act 2 products. One example of that would be, let's say you're using Zscaler for internal security,
you send a request, it goes to Zscaler's machines, and then to a website. But that website is
going to be likely using Cloudflare. So it ends up going to a Cloudflare server anyway. And then
back. And then so Cloudflare is in a really strong position. It's like we're processing all of
this traffic anyway. Why don't we process it on the way out as well as the way back in,
and that will improve your latency. Another difference would be just on the appearing networks. So
it's very hard for another company to have all these partnerships with all these ISPs around the
world. Zscaler took a different approach where they appeared directly with the apps, which is great
for dense cities, but in certain markets, it doesn't work as well. And maybe an example,
just to highlight some of these differences would be Canva. So thousands of employees around the
world, Canva, the web design company, they employ a lot of contractors to help out with the design
templates and things like that. And a lot of those contractors are based in Southeast Asia. Canva
uses their Cloudflare Act 2 products to help with the access because Cloudflare uses what's called
like an inline service. So you don't actually have to install agents or anything onto the machine,
which is really important when you're working with contractors. You can give these contractors
access to all of the corporate apps that they need without having to have them install anything.
Because say a lot of these contractors are based in markets where other competitors
won't have direct-pearing relationships. Cloudflare can say, look, we've been improving the speed
of this area for years. These contractors can sign on, be secure, and interact with your product
with low latency. That's not going to slow anyone down. And that's a really strong value proposition
that a lot of other companies can't speak to. Are there any other risks that really stand out to
you just from a business perspective and the organization and some of the external factors
sitting around it? Two risks to call out. One is that second move in the Act 2 that we were just
speaking about. They are playing a bit of a catch-up, but there is a long runway to go and they're
a solid contender there. So I think all the trajectory is very positive when you look at their product
positioning, the channel partner growth, and all that. But it's worth just calling out just because
they are the second to move. The other risk to call out is just their AI inference strategy
and AI in general, because it is new and it does slightly diverge a little from their previous
strategy. So that always adds some risk there. Because I mentioned earlier that all of their other
services can run at all hardware, whereas GPUs are specialized for inference. With the ROI of
their other products, it was split across all of their services. By the ROI of their GPU component,
that's just from the AI inference. So it's a more concentrated ROI risk. Also, there's a slight
difference in how the AI inference product came about from their other products. A lot of their
other products, they kind of emerged from what Cloudflare was doing internally. With the Act 3,
they had to build these services themselves. They never planned on launching a developer product,
but they saw the value on that and they released it. Similar with Act 2, they saw that during the day,
not many people on websites, they were underutilized servers, so they could work with corporate
security that was used during the day and then during the night, they saw their website security.
So they kind of saw these opportunities and built for them and went into them. Whereas AI
inference, I think they just saw the importance of the market and decided to go after it. It's still
that single global network, but there is a bit of top spin of difference and strategy versus
there are other product launches. That's worth calling out. Thank you for calling that out.
I do want to get your general framework for valuation. I find software businesses, heaven for
bid 75 to 80% gross margins relative to the 90 that some of these software businesses post. But
how does the market approach it? How do you think about valuation and just anything that you would
comment on that topic would be useful to you? It's no secret that CloudFlare's a highly
valued company. I think at the start of the year, there were 25 times the next 12 month revenue,
which is one of the highest in the industry. From my perspective, I love Michelle and Matt as the
operators of CloudFlare. But valuation, it's always a constant battle, even though it's such an
impressive company. And importantly, as well, it's a capital intensive business, so the free cashflow
margins and earnings will start to matter more and more in say five years time. And they'll likely
have lower pre-cashflow margins than what we've seen in best-in-class software. But I think what
gives confidence, the ball case for CloudFlare is that there's numerous growth levers that can support
sustained high growth. And they've sustained it in that 29, 30% or higher range. And the markets that
they operate in have a lot of runway and the continually adding products and features that support
that sustained high growth rate. So that's a distinguishing factor for them. But to get comfort with
the valuation, you have to model out two things. You have to model out the act two. How quickly
they can catch up and perhaps surpass the incumbents in that space. And the trajectory is very solid
there, but also you need to model out what the act three scenarios could look like. Like how important
will they be for AI inference? How big will the inference market be? We believe that it can be a very
large business, and you have to believe that. And just quickly on margin structure, sales and
marketing, 35% of revenue today, there is room for operating leverage. They've guided to 25%
free cash and might as plus. We think they can exceed that. So then you can model that out over
the years and still make money on the stock. But it's important to call out that there's effectively
no margin for execution error. There's price for pretty flawless execution, which they've done,
but you just have to build confidence that will continue. Well, I was very intellectually honest
approach to it. A 25 time sales. I saw the SpaceX IPO headlines today, which implied I think 100
time sales. That's all relative in this market. It makes it look cheap. Yeah, exactly. And the
growth number on revenue, they must be sandbagging because it wasn't that material from your year.
Nonetheless, this has been fascinating. I really tried to scrape out as much on the technology. So
thank you for keeping up with that. We like to talk about the lessons that you can take away. Maybe
bring it up a notch to think about frameworks and pattern recognition. What would you point to
from Cloudflare that really stands out? There's a few lessons from Cloudflare that I think can
be applied generally. I'll call out four quick ones. So number one, I think Fountallade companies
is very important for companies to have that Fountallade vision. It can be a very powerful
for setting that long-term strategy and setting bold visions and sticking to the company mission.
SquarePeg's origins are as a VC fund. And then the global tech fund listed strategy, we still look
for that founder DNA. And Matthew Prince is a great example of that. The second general lesson would
just be looking for product simplicity, particularly for complicated industries. To the extent they
can serve the whole long tail of the internet, despite having a very sophisticated technical
infrastructure, that sets them up really well and so really positive signal applying that elsewhere.
I think that applies to Snowflake as well. They have a very powerful engine under the hood.
It's very hard to replicate. But when you look at the product, it's a very simple query interface.
It's very easy to use and adopt and similar with Datadog. Very easy to get started and set up.
But it's powerful enough and flexible enough to work with the world's largest companies as well
as the world's smallest companies. So that looking for that product simplicity, yet flexibility and
power is really important. Number three would just be looking for multiple levers of growth. So great
companies, their multiple levers of growth, and they find ways to solve more problems for more
customers over time. Cloudflare, great example of that. They've expanded their product lines,
expanded the customer archetypes within each market. And I've done so in markets that all have
tailwinds, particularly for AI. Fourth lesson would be that CapEx in software can be okay. Provided
that it has that very high ROI, that CapEx is used to build that defensibility for their business.
Talked a lot about that earlier with that reinforcing cycle. It creates a
mode that's very hard to replicate. And because they're stacking layers on top of that hardware,
you can extract a lot of ROI from each individual purchase there. Those lessons they've fit very
cleanly into what SquarePag looks for. We have a framework around theme, team, model, and mode.
And Cloudflare, they sit at the center of a critical theme in managing networks for speed,
efficiency, and trust, particularly in the era of AI. The team, the hungry, founder led,
very focused, and they can attract and retain some of the best talent in the world. I think it's
an underappreciated high quality business model. So it's
they can stack multiple revenue lines on top of their core capability, and all of these
levers have that long duration that we look for.
And finally, moat.
Cloudflare, it's a business that gets better as it gets bigger, and that's really important.
They use their scale to enhance their differentiation and create barriers to entry as well.
CapEx can be okay.
It's a good lesson.
I think AI certainly has shifted the narrative in terms of the willingness to accept high
CapEx companies out there in the market, assuming that they're creating barriers to entry,
we can debate where that falls in line for companies and whether that's true or not.
But this has been fascinating.
Sam, I appreciate you sharing all of the knowledge, getting into the nitty gritty details
here.
Give me a better appreciation of all that's happening on the internet behind the scenes.
So I appreciate you joining us.
Thank you.
This has been a lot of fun.
[Music]
Podcast Summary
Key Points:
Cloudflare controls over 20% of global web traffic and absorbs 2.5 million cyberattacks per second, positioning it as a dominant cybersecurity and network infrastructure provider.
Founded in 2009 by Matthew Prince, Michelle Zatlyn, and Lee Holloway, Cloudflare innovated by intercepting all website traffic with a single reverse proxy, enabling simple, product-led growth for the long tail of websites.
Its business model benefits from a reinforcing loop
Product evolution spans three "acts"
AI strategy includes serving AI-native companies, offering edge inference with GPUs, and leveraging network advantages, though this introduces new strategic risks.
Go-to-market transformation includes enterprise sales, channel partnerships (growing 65% YoY), and "pool of funds" bundling, which boosted net revenue retention to 119%.
Financials show ~75-78% gross margins (higher on a cash basis), ~10% free cash flow margins, with CapEx at 11-14% of revenue, and long-term margin expansion targets above 25%.
Competition is strongest in Act 2 (e.g., Zscaler) and Act 3 (hyperscalers), but Cloudflare's network and product integration provide a strengthening position.
Recent outages were process errors, not security breaches, and were handled transparently, with minimal lasting business impact.
1
Valuation is high (~25x next-12-month revenue), requiring flawless execution, but multiple growth levers support sustained high growth.
Summary:
Cloudflare is a cybersecurity and network infrastructure giant that handles over 20% of global web traffic and blocks millions of attacks per second. Founded in 2009, it disrupted legacy providers by intercepting all website traffic through a single reverse proxy, making security and speed services simple and accessible to everyone, from hobbyists to enterprises. This innovation created a powerful reinforcing loop: more traffic improves its data and services, reduces costs through ISP peering, and builds a formidable moat that competitors struggle to replicate.
The company has evolved into three product areas: web security (Act 1), internal corporate security using zero trust (Act 2), and a developer platform with serverless functions and AI inference (Act 3). Its AI strategy positions it across the industry, serving AI-native companies and offering edge inference, though this introduces new risks. Go-to-market efforts now include enterprise sales, channel partnerships, and "pool of funds" bundling, which have driven strong customer expansion and revenue growth.
Financially, Cloudflare generates ~$2 billion in annualized revenue with gross margins around 75-78%, though cash-based margins are higher. CapEx is significant due to its physical network, but management targets free cash flow margins above 25% over time. Competition is intense, especially in Act 2 and Act 3, but Cloudflare's integrated network and product synergies strengthen its position. Despite a high valuation requiring flawless execution, its multiple growth levers and founder-led team make it a compelling, defensible business.
FAQs
Cloudflare provides speed and security for websites, protecting them from attacks like DDoS and bots while optimizing performance. It serves both small hobby projects and large enterprises.
Cloudflare was founded in 2009 by Matthew Prince, Michelle Zatlin, and Lee Holloway, evolving from a project called Project Honeypot that tracked spammers. They innovated by intercepting all web traffic with a single reverse proxy, making security services easy to use.
Cloudflare's moat is its reinforcing loop: more traffic leads to better data and services, which attracts more customers and enables cost-saving peering relationships with ISPs. This network effect, built over 15 years with commodity hardware, is very difficult to replicate.
Cloudflare has three main product groups: Act One (web security and performance), Act Two (internal corporate cybersecurity like zero trust), and Act Three (developer platform including serverless functions like Workers). They all run on the same global network.
Cloudflare offers generous free tiers across all product groups, not charging for volume on Act One but for complexity. This attracts a long tail of users and developers, which feeds into enterprise adoption and revenue growth.
The outage was a process error, not a security breach. A corrupted file in their bot management software's machine learning model caused memory issues, breaking services. Cloudflare responded transparently and outlined steps to prevent recurrence.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.