Key Findings
- Digital: Cloudflare operates listed network locations in Tel Aviv and Haifa; its 2022 deployment update reported local delivery for practically all requests from one unnamed large Israeli ISP’s subscribers.1, 2
- Economic: Cloudflare acquired Delaware-incorporated Zaraz in 2021; the acquired group included Israeli-incorporated Sweeps Ltd., which Cloudflare’s 2023 filing described as holding de minimis assets and conducting no operations.3
- Political: Continuing direct network operations in Tel Aviv and Haifa govern the political assessment as sustained commercial normalization. Historical website-service and DAWN DNS allegations remain qualified alternatives; the 2024 U.S. sanctions designations were revoked in January 2025.1, 4, 5, 6, 2
- Not found: No public evidence identified of a direct Cloudflare contract with the Israeli Ministry of Defense, IDF, Israeli intelligence agencies, or settlement operations.7
Target Profile
| Field | Detail |
|---|---|
| Company Name | Cloudflare, Inc. |
| Jurisdiction | Delaware, United States.8 |
| Headquarters | Principal executive office in San Francisco, California.8 |
| Sector | Commercial cloud infrastructure, internet-security, routing, caching, content-delivery, and application-delivery services.8 |
| Ownership | NYSE-listed as NET; co-founders Matthew Prince and Michelle Zatlyn held substantial aggregate voting power through Class B holdings. Disclosed institutional holders include Capital World Investors, Baillie Gifford & Co., Morgan Stanley, and BlackRock.9 |
| Key Executives / Governance | Matthew Prince (CEO/Co-Chair); Michelle Zatlyn (President/Co-Chair); board members disclosed in the reviewed proxy materials include Stacey Cunningham, John Graham-Cumming, Mark Hawkins, Karim Lakhani, Carl Ledbetter, Scott Sandell, and Katrin Suder.9 |
| Israeli-Nexus Summary | Documented nexus consists principally of network locations in Tel Aviv and Haifa, a 2021 acquisition whose group included an inactive Israeli subsidiary, and limited, qualified reporting concerning DNS/service use by Israeli political or government-linked websites.1, 3, 4 |
Key Facts:
- Cloudflare is not an Israeli-origin company and is not documented as Israeli state-owned or Israeli-controlled.8
- No public evidence identified of a Cloudflare-branded Israeli office, staffed Israeli R&D centre, Israel-specific workforce, tax registration, or Israel-specific revenue disclosure.3
- No public evidence identified that Cloudflare appears in the reviewed OHCHR settlement-business database, Who Profits, or AFSC Investigate materials.10
Executive Summary
Cloudflare is a U.S.-domiciled internet-infrastructure and cybersecurity company. Its documented Israel nexus is primarily commercial network presence: it announced Tel Aviv as its 135th data-center city in March 2018, and current company network materials list both Tel Aviv and Haifa. In 2022, Cloudflare reported deployments with an unnamed large Israeli ISP that served practically all requests from that ISP’s subscribers locally. The record does not disclose the Israeli ISP’s identity, traffic volume, capacity, facility address, colocation provider, local staffing, or the proportion of Israeli traffic served by each location.1, 6, 2
A second documented nexus is the October 2021 acquisition of Zaraz Inc., a Delaware corporation. The acquired group included Sweeps Ltd., an Israeli-incorporated subsidiary of Zaraz. Cloudflare’s March 2023 filing described Sweeps as holding de minimis assets and conducting no operations. Cloudflare’s acquisition announcement said the Zaraz team would join its Portugal office and continue product development there. Zaraz remains an active Cloudflare product, but the reviewed evidence does not establish ongoing Israeli development, a continuing Israeli R&D office, or a current Israel-based Zaraz workforce.3, 11, 12
The principal scrutiny in the record concerns Cloudflare’s neutral-infrastructure model and services associated with contentious websites. DAWN reported that four domains associated with Benzion Gopstein, Lehava, Jewish Power, or Meir Kahane-related material used Cloudflare DNS services in 2024, when Gopstein was under U.S. sanctions. Treasury announced in January 2025 that Executive Order 14115 had been revoked and its designations removed.5 A September 2026 DNS query identified Cloudflare nameservers for one domain, rabbikahane.co.il; this is limited evidence of DNS delegation, not proof of Cloudflare hosting, proxy/CDN service, payment processing, ownership, endorsement, or operation in a settlement.4, 13
The audit record does not support allegations of direct Israeli military, intelligence, weapons, settlement, or sovereign-cloud contracting. Historical reporting that the IDF used Cloudflare during Operation Pillar of Defense in 2012 describes ad hoc use of a commercially available service, not a documented procurement contract; the current status is unknown. No public evidence identified of direct contracts with the Ministry of Defense, IDF, intelligence agencies, Israeli defense primes, Project Nimbus, TAFNIT, or settlement entities.7
Under the fixed, human-vetted V6.5 assessment, Cloudflare receives a BRS of 526, placing it in Tier C (Substantial Complicity). The result is driven by documented digital-network operations and economic presence, together with the audited political/service-governance record; it does not rest on a finding of military contracting or weapons involvement.
Timeline of Relevant Events
| Date | Event |
|---|---|
| 2012 | The IDF reportedly moved its website onto Cloudflare services during Operation Pillar of Defense to withstand cyberattacks; the audit treats this as reported ad hoc use of a general commercial service, not a documented procurement contract.14 |
| 2014 | Reporting stated that Benjamin Netanyahu’s personal website used Cloudflare protection and described Cloudflare’s stated neutral-service approach to Israeli and Hamas-affiliated sites.14 |
| 15 March 2018 | Cloudflare announced Tel Aviv as its 135th data-center city.15 |
| 2019 IPO filings | Cloudflare disclosed voluntary reports concerning possible use of its services by or for certain OFAC-listed parties and separate export-filing errors; the disclosure did not identify an Israel-specific nexus.16 |
| 15 October 2021 | Cloudflare completed its acquisition of Zaraz Inc.; the acquired group included Israeli-incorporated Sweeps Ltd.3 |
| 8 December 2021 | Cloudflare stated that the Zaraz team would join its Portugal office and continue leading product development there.11 |
| March 2022 | Cloudflare reported Tel Aviv and Haifa deployments with an unnamed large Israeli ISP, serving practically all requests from that ISP’s subscribers locally.1 |
| September 2024 | DAWN reported that four Gopstein/Lehava/Jewish Power/Kahane-associated domains used Cloudflare DNS services and submitted material to U.S. authorities requesting seizure under E.O. 14115.4 |
| 24 January 2025 | U.S. Treasury announced revocation of E.O. 14115 and removal of all designations made under it.5 |
| 8 September 2026 | Cloudflare’s status materials listed Tel Aviv as operational; a DNS query found Cloudflare nameservers for rabbikahane.co.il, while the other three DAWN-identified domains used different nameservers.6, 13 |
Corporate Overview
Cloudflare provides internet infrastructure and security services, including routing, caching, CDN, DDoS mitigation, DNS, Zero Trust, and application-security functions. Its FY2025 reporting describes a network using third-party colocation and ISP-partner facilities, with Cloudflare having electronic and more limited physical access to components and infrastructure while not controlling facility operations.8
The confirmed Israeli-connected corporate record is narrow. Cloudflare acquired all outstanding shares of Delaware-incorporated Zaraz Inc. in October 2021. Sweeps Ltd., an Israeli company, was a Zaraz subsidiary, but was described in a 2023 Cloudflare SEC application as inactive, holding de minimis assets, and conducting no operations. Secondary startup-registry material listing a Tel Aviv address does not independently establish a headquarters, lease, workforce, R&D expenditure, or present operating status.3
Cloudflare’s network materials establish locations in Tel Aviv and Haifa. They do not publicly identify the buildings, landlords, colocation providers, equipment ownership, local operations contractors, or the unnamed ISP involved in the 2022 deployments. No public evidence identified of a registered Israeli office or named legal entity operating these network locations, or of a Cloudflare-branded Israeli sales, support, warehouse, or R&D facility.1, 8
Domain Summaries
Military: Military
Mechanism of Involvement
No public evidence identified of a Cloudflare contract, tender, or memorandum of understanding with the Israeli Ministry of Defense, IDF, Israel Prison Service, Israel Border Police, or Israeli intelligence agencies. No public evidence identified of a supply relationship with Elbit Systems, Israel Aerospace Industries, Rafael, or IMI/Elbit Land; of tactical or military-specific product variants; or of any Cloudflare role in weapons systems, munitions, strategic platforms, targeting, or military logistics.7
The record includes a reported 2012 instance in which the IDF used Cloudflare to protect a website during Operation Pillar of Defense. The audit classifies this as use of commercially available reverse-proxy/CDN infrastructure, not evidence of a defense procurement contract, and does not establish any continuing relationship. Reporting also stated that Netanyahu’s personal website used Cloudflare in 2014; this was government-related rather than defense-specific, and its current status is unknown.14
Counter-Arguments and Evidence Limits
Cloudflare’s products are general-purpose civilian internet-infrastructure services. The audit found no evidence of purpose-built kinetic, targeting, or tactical functionality, export licensing for Israeli defense end-users, or military end-use arrangements. Cloudflare’s own defense-focused materials describe U.S. Department of Defense work, including SHIELD, but do not identify Israeli defense contracting.17
Cloudflare’s strongest stated defense is service neutrality. In 2014, CEO Matthew Prince said that serving parties on both sides did not constitute material support and that Cloudflare was not providing money or arms. This is a corporate position, not independent proof regarding any particular customer relationship.14
Named Entities and Evidence Map
- IDF / Israeli Ministry of Defense / intelligence agencies: No public evidence identified of direct procurement contracts; the separately described historical website-service use remains attributed reporting.7, 14
- Israeli defense primes: No public evidence identified of supply-chain, joint-development, or technology-transfer arrangements.7
- CYBERcom: An Israeli IT/cybersecurity integrator announced a general Cloudflare partner relationship; no defense-prime nexus was identified.18
- PFLP litigation: A November 2024 private U.S. civil lawsuit alleged Cloudflare knowingly aided the PFLP by providing general cybersecurity/CDN services to a website. The audit located no independent confirmation of outcome or current docket status; it is not evidence of Israeli defense contracting.19
Digital: Digital
Mechanism of Involvement
Cloudflare operates network locations listed in Tel Aviv and Haifa. Its March 2022 update stated that deployments with an unnamed large Israeli ISP allowed practically all requests from that ISP’s subscribers to be served locally. Before deployment, the requests had been served through Frankfurt, London, and Amsterdam; afterward, Cloudflare reported lower response times. This establishes local delivery for that unnamed ISP’s subscribers, not a quantified Israeli customer base, Tel Aviv-specific capacity, staffing, or traffic volume.1
Cloudflare’s privacy and product materials describe network-wide processing capabilities involving end-user interactions, IP addresses, traffic-routing information, DNS queries, encrypted web traffic, DDoS traffic, API-security analytics, cached content, and related logs. The materials do not identify which of these functions occur at Tel Aviv or Haifa, whether traffic is decrypted locally, what data are stored there, retention periods, or local access arrangements.20, 21, 22
The adjudicated digital score applies the rubric’s routing/processing limb to the documented local delivery and identifiable end-user IP/routing information. It treats this as moderate data exploitability, with a 0.5 Impact increase for continued post-July-2024 operation. It does not infer a specific locally decrypted content pool, Israeli access to retained logs, state surveillance use, or a state contract.1, 6, 20, 2
No public evidence identified that Israel is a selectable Cloudflare metadata-boundary region, that Tel Aviv logs are stored in Israel, or that Israeli state bodies, local employees, ISP partners, or colocation providers can access customer content, encryption keys, or telemetry. Cloudflare states company-wide that it has never turned over encryption or authentication keys and has never installed law-enforcement software or equipment anywhere on its network; this is not Tel Aviv-specific.23, 21, 22
Counter-Arguments and Evidence Limits
Network presence is not equivalent to sovereign-cloud participation, surveillance assistance, or a government-security contract. No public evidence identified of Cloudflare participation in Project Nimbus, TAFNIT, or another identified Israeli government-cloud procurement; nor of a documented offensive-cyber, AI, surveillance, or data-access contract with Israeli state, military, or intelligence bodies. The attributed historical website-service use is distinct from those unverified contractual relationships.7, 14
The evidence documents Cloudflare infrastructure operating in Israel but leaves material operational questions unresolved, including capacity, data classes, local storage, facility ownership, and customer identity. Those evidence limits preclude treating general network capability as proof of a specific surveillance or state-security function.1, 20
Named Entities and Evidence Map
- Tel Aviv and Haifa: Listed Cloudflare network locations; Tel Aviv was operational in the cited status material.6
- Unnamed large Israeli ISP: Cloudflare documented local delivery for practically all of that ISP’s subscribers’ requests; it did not name the ISP.1
- SentinelOne and Wiz: Reviewed materials describe integrations and reference architectures, not evidence that their software is embedded in Cloudflare’s core edge infrastructure or supplied to Israeli state bodies through Cloudflare.24
- Israeli state/military/intelligence bodies: No public evidence identified of direct contracts or sovereign-cloud participation.7
Economic: Economic
Mechanism of Involvement
The material economic nexus is Cloudflare’s Israeli network footprint and its acquisition of Zaraz, whose group included Sweeps Ltd. Cloudflare announced Tel Aviv in 2018 and later reported Tel Aviv and Haifa deployments. Its public record does not disclose investment value, capital expenditure, facility ownership, local workforce, tax contribution, Israel-specific revenue, or profit flows attributable to these locations.1, 2
Cloudflare acquired Zaraz for reported total consideration of $7.2 million under purchase accounting.25 Its filings describe the acquisition through slightly different securities-law and accounting presentations rather than conflicting values. Although secondary sources characterized Zaraz as Israeli, the primary record establishes that the acquired parent was Delaware-incorporated. The Israeli subsidiary Sweeps was disclosed as inactive in 2023, while Cloudflare’s acquisition announcement located the Zaraz team’s product-development integration in Portugal.3, 11
No public evidence identified of Cloudflare underwriting Israeli sovereign debt or Israel Bonds; holding disclosed Israeli securities; importing or sourcing Israeli or settlement goods; operating in settlements; or having settlement-service contracts, franchise activity, or supply-chain relationships with settlement-linked exporters.10, 26
Counter-Arguments and Evidence Limits
Cloudflare does not manufacture or sell physical goods, making conventional origin-labelling, customs, and settlement-goods sourcing categories inapplicable. Its Tel Aviv and Haifa presence is documented as network infrastructure, not as a separately disclosed Israel-based revenue operation.2
The Zaraz acquisition should not be represented as proof of an ongoing Israeli R&D centre. Sweeps was reported inactive, the Zaraz parent was Delaware-incorporated, and the integration plan named Portugal. No public evidence identified of a current Israel-based Zaraz workforce, continued Israeli development, or Israeli R&D budget.3, 11
Named Entities and Evidence Map
- Zaraz Inc.: Delaware-incorporated company acquired by Cloudflare in 2021; Zaraz remains an active Cloudflare product.3, 12
- Sweeps Ltd.: Israeli-incorporated Zaraz subsidiary; reported in 2023 as holding de minimis assets and conducting no operations.3
- Tel Aviv / Haifa: Cloudflare network locations; no public disclosure establishes their investment value or local economic contribution.1, 2
- Settlement-business databases: No public evidence identified of Cloudflare in the reviewed OHCHR, Who Profits, or AFSC material.10
Political: Political
Mechanism of Involvement
The governing political act is Cloudflare’s continuing direct network operation in Tel Aviv and Haifa, treated under the supplied rubric as sustained Business-as-Usual normalization. The final I=3.9 includes post-July-2024 continuation; M=7.0 and P=9.1 reflect sustained corporate association and direct operation. This does not establish ideological advocacy, military welfare, or a state partnership.1, 6, 2
Cloudflare has articulated a neutral-infrastructure approach to conflict-related customers. In reporting on Israeli and Hamas-affiliated website protection, Prince said both sides had a right to tell their story and that Cloudflare was not providing material support. The company spokesperson cited in that reporting stated that, as Cloudflare was not a host, terminating a customer would not remove content from the internet.14
DAWN’s 2024 report alleged that Cloudflare nameservers provided DNS service to four websites associated with Benzion Gopstein, Lehava, Jewish Power, or Kahane-related material, and requested U.S. seizure action. The audit treats this as an attributed civil-society claim, not a Cloudflare admission. Treasury’s 2025 revocation of E.O. 14115 means the report’s referenced 2024 sanctions status is historical. The later DNS check for one named domain establishes DNS delegation only.4, 5
Cloudflare is a federally registered U.S. lobbying client, with OpenSecrets reporting $40,000 in year-to-date lobbying spend on the cited summary page. No public evidence identified in the retrieved summaries of lobbying specifically itemized as Israel-Palestine policy, anti-boycott legislation, or trade-restriction advocacy. No public evidence identified of corporate donations to listed Israeli military-welfare, settlement, or pro-Israel/anti-BDS organisations.27
Counter-Arguments and Evidence Limits
No public evidence identified of a named corporate statement explicitly supporting either Israeli or Palestinian civilians comparable to Cloudflare’s named Russia-Ukraine policy commentary. Its Israel/Palestine public communications reviewed here are principally technical traffic, attack, and connectivity reporting rather than declared political advocacy.28
No public evidence identified of employee discipline over pro-Palestinian activism, Israel-specific content-moderation criteria, Israeli state honors, state partnerships, or a named BDS-focused boycott/divestment campaign against Cloudflare. The audit also found no public evidence linking named executives or board members to listed Israeli military-welfare, settlement, or anti-BDS advocacy organisations; this is a bounded-record result and does not establish the absence of undisclosed personal activity.9, 29
Named Entities and Evidence Map
- Benzion Gopstein / Lehava / Jewish Power / Kahane-related domains: Subject of DAWN’s attributed DNS/sanctions-screening report; later DNS evidence is limited to one domain’s nameserver delegation.4
- Shurat HaDin: Pressured Cloudflare in 2017 to end service to a Hamas-linked site. Cloudflare said it was aware of and compliant with U.S. legal obligations; no outcome was confirmed.30
- Project Galileo: Cloudflare describes the program as protecting vulnerable civil-society organisations, including both Israeli and Palestinian organisations after October 2023; the reviewed material does not identify support directed specifically to the Israeli state or IDF.31
- OpenSecrets lobbying record: Shows federal lobbying registration and reported spending, without an identified Israel-Palestine-specific item in the retrieved summaries.27
BDS-1000 Score
Method: V6.5.
| Domain | I | M | P | V-Domain Score |
|---|---|---|---|---|
| Military | 0.00 | 0.00 | 0.00 | 0.00 |
| Digital | 6.00 | 6.10 | 9.10 | 5.23 |
| Economic | 5.70 | 7.00 | 9.10 | 5.70 |
| Political | 3.90 | 7.00 | 9.10 | 3.90 |
- V_MAX: 5.70 Avg_OTHERS: 3.04
- BRS Score: 526 Tier: C (Substantial Complicity)
The highest domain score is Economic at 5.70, governed by the continuing direct network footprint. The historic Zaraz/Sweeps acquisition is a separate, lower-valued frame and is not added to that score. Digital applies the data-routing principle to the local service footprint with the stated sensitivity and access limits; Political reflects sustained current commercial normalization. Each nonzero domain incorporates the examiner’s 0.5 Impact adjustment for continued post-July-2024 operation. Military is zero because the reviewed record did not establish defense contracting, weapons involvement, or military-specific supply. The scale-free, evidence-only, human-vetted method scores documented activity type, scale, and directness rather than allegations alone.
Methodology Note
- This dossier compiles only the supplied four domain audits and their cited documentary record; it does not treat activist allegations, reporting, or DNS observations as self-proving.
- The assessment is evidence-only and scale-free: I concerns activity type, M its documented scale, and P its directness.
- The temporal rule applies mitigation where operations were exited, divested, or shown inactive. Accordingly, Sweeps Ltd.’s disclosed inactive status and the Portugal integration plan qualify claims about ongoing Israeli R&D.3, 11
- Entity attribution is limited to Cloudflare and documented subsidiaries, operations, contracts, or services. There is no transitive attribution from customers, domains, resellers, or ecosystem partners to unproven state or settlement conduct.
- A settlement operation, if documented, would bear on both Economic and Political; no public evidence identified of such an operation in the reviewed record.10
- “No public evidence identified” records the outcome of the audits’ stated checks. It does not establish that undisclosed conduct is impossible, nor does it convert unresolved claims into findings.
Footnotes
-
https://blog.cloudflare.com/mid-2022-new-cities/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13
-
https://d18rn0p25nwr6d.cloudfront.net/CIK-0001477333/af98834c-0096-428e-b7d8-0de71e9cd155.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
https://dawnmena.org/u-s-seize-jewish-power-and-other-extremist-websites-promoting-violence-against-palestinians/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
https://content.govdelivery.com/accounts/USTREAS/bulletins/3ce946f ↩ ↩2 ↩3 ↩4
-
https://www.sec.gov/Archives/edgar/data/1477333/000147733326000016/cloud-20251231.htm ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
https://www.sec.gov/Archives/edgar/data/1477333/000147733326000016/cloud-20251231.htm ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
https://www.sec.gov/Archives/edgar/data/1477333/000119312526263809/d160227ddef14a.htm ↩ ↩2 ↩3
-
https://www.ohchr.org/en/press-releases/2025/09/un-human-rights-office-updates-database-businesses-involved-israeli ↩ ↩2 ↩3 ↩4
-
https://blog.cloudflare.com/cloudflare-acquires-zaraz-to-enable-cloud-loading-of-third-party-tools/ ↩ ↩2 ↩3 ↩4 ↩5
-
https://dns.google/resolve?name=rabbikahane.co.il&type=NS ↩ ↩2
-
https://www.timesofisrael.com/us-firm-helps-hamas-netanyahu-keep-hackers-at-bay/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
https://www.sec.gov/Archives/edgar/data/1477333/000119312519222176/d735023ds1.htm ↩
-
https://www.linkedin.com/posts/cybercom-il_doingmore-cybercom-cloudflare-activity-7371438471774756865-V2NI ↩
-
https://www.motleyrice.com/anti-terrorism/hamas-terrorist-attack-lawsuit ↩
-
https://developers.cloudflare.com/data-localization/metadata-boundary/faq/ ↩ ↩2
-
https://www.sentinelone.com/press/sentinelone-and-cloudflare-expand-partnership-to-deliver-real-time-threat-detection-and-automated-response-for-enterprises/ ↩
-
https://cloudflare.net/files/doc_financials/2021/q4/98f467d0-9cc2-452a-817d-17e94bdcb2b9.pdf ↩
-
https://www.banktrack.org/news/seven_underwriters_of_war_bonds_instrumental_in_enabling_israel_s_assault_on_gaza_new_research_finds ↩
-
https://www.opensecrets.org/federal-lobbying/clients/summary?id=D000071785 ↩ ↩2
-
https://blog.cloudflare.com/internet-traffic-patterns-in-israel-and-palestine-following-the-october-2023-attacks/ ↩
-
https://blog.cloudflare.com/applying-human-rights-frameworks-to-our-approach-to-abuse/ ↩
-
https://www.washingtontimes.com/news/2017/aug/30/cloudflare-pressued-to-cut-ties-with-hamas-linked-/ ↩
-
https://www.cloudflare.com/press/press-releases/2024/cloudflares-project-galileo-turns-10-marks-one-decade-of-protecting-vulnerable-groups/ ↩











