Enterprise Technology Stack & Vendor Relationships
Cloudflare, Inc. is a Delaware corporation whose FY2025 financial statements consolidate its wholly owned subsidiaries; its principal executive office is in San Francisco.1 Cloudflare’s 2019 subsidiary exhibit lists no “significant subsidiaries” but expressly permits omission of non-significant subsidiaries, so it neither establishes that Cloudflare has no subsidiaries nor identifies or excludes an Israeli subsidiary.2 A Cloudflare SEC application dated 3 March 2023 identifies Sweeps Ltd. as Israeli-incorporated and a subsidiary of Zaraz Inc.; it describes Sweeps as holding de minimis assets and conducting no operations at that time.3 No public evidence identified of a registered Israeli office or a named legal entity operating the Tel Aviv or Haifa network locations.1, 4, 3
As of 31 March 2026, co-founders Matthew Prince and Michelle Zatlyn held 39.2% and 11.4% of Cloudflare’s aggregate voting power respectively, while executive officers and directors as a group held 51.4%.4 The disclosed holders of more than 5% of Class A shares were Capital World Investors, Baillie Gifford & Co., Morgan Stanley, and BlackRock.4 Prince’s Schedule 13G records interests partly held through named Prince-family trusts.5 The reviewed corporate biographies do not disclose an Israeli surveillance, cyber, AI, SIGINT, or military-technology investment or board role by the identified directors or executive officers; this is a bounded-record finding, not a comprehensive finding about private investments.4
Cloudflare maintains an active technology partnership with SentinelOne combining Cloudflare Logpush telemetry with SentinelOne Singularity AI SIEM, alongside a joint SASE/Zero Trust reference architecture.6, 7 Reporting in April 2026 described a Cloudflare–Wiz integration combining Cloudflare AI Security for Apps with Wiz Security Graph; contemporaneous reporting described Google’s completion of its acquisition of Wiz.8, 9, 10 The reviewed materials describe these as integrations and solution architectures, rather than evidence that either vendor’s software is embedded in Cloudflare’s core edge infrastructure.6, 7, 8
No public evidence identified of a direct Cloudflare licensing or integration relationship with Check Point, CyberArk, NICE, Verint, Claroty, or Palo Alto Networks in the reviewed record.1, 4 no public evidence identified that Israeli channel or deployment partners use Israeli-origin products for Cloudflare as part of a documented major Cloudflare programme.1, 4
Surveillance, Biometrics & Retail Technology
No public evidence identified of Cloudflare using or integrating Israeli-origin facial recognition, biometric identification, gait analysis, predictive policing, sentiment analysis, social-media monitoring, or workforce-surveillance systems, directly or through bundled third-party platforms.1, 4 Cloudflare’s documented services concern Internet infrastructure, security, routing, caching, and application-delivery functions rather than retail or physical-surveillance operations.1, 11
Cloud Infrastructure, Data Residency & Sovereign Cloud Participation
Cloudflare announced Tel Aviv as its 135th data-center city on 15 March 2018.12 The reduction in median response time from approximately 86 ms to 29 ms was reported separately in March 2022 for subscribers of one Israeli ISP following the Tel Aviv and Haifa deployments.13 Its current network page lists Tel Aviv and Haifa among 19 Middle East locations and states that every Cloudflare service runs in every data center; its status page listed Tel Aviv as operational on 8 September 2026.14, 15 The current network representation therefore supports continued Tel Aviv operation and an Israeli footprint including at least two listed cities, rather than the Tel Aviv-only footprint described in 2018.12, 14, 15
Cloudflare’s March 2022 update reports deployments with an unnamed large Israeli ISP in Tel Aviv and Haifa that served “practically all requests” from that ISP’s subscribers locally within Israel.13 Before those deployments, Cloudflare reported that these requests were served through Frankfurt, London, and Amsterdam; afterward, 66% were served in under 50 ms and 85% in under 100 ms.13 This is evidence of local delivery for one unnamed ISP’s subscribers, not evidence of Tel Aviv-specific traffic volume, subscriber count, rack count, capacity, throughput, or the proportion of traffic handled by Tel Aviv rather than Haifa.13
Cloudflare’s global privacy policy says that its services process end-user interactions with customer domains, websites, APIs, applications, devices, endpoints, and networks, including IP addresses, traffic-routing data, system-configuration information, and other traffic information.16 The policy further states that Cloudflare acts as processor for customer logs and for customer or end-user content that transits - and in some cases is stored on - its network.16 Its product disclosures describe network-wide handling of DNS queries, encrypted web traffic, DDoS traffic at layers 3, 4, and 7, API-security analytics, CDN-cached content, and geo-based load-balancing traffic.1 Documentation on Customer Metadata Boundary describes structured logs that can include timestamps, URLs, feature use, customer account or zone identifiers, and end-user IP addresses.17
Those sources establish network-wide capabilities and local delivery, but not the functions exercised at Tel Aviv. No public evidence identified that itemizes actual Tel Aviv traffic classes, payload categories, decryption configuration, content inspection, cache contents, customer logs, stored data, retention periods, or logging volumes.14, 15, 13, 16, 1
Cloudflare’s Data Localization Suite permits eligible customers to select where HTTPS traffic is decrypted and processed, where encryption keys are held, and where traffic metadata and logs are stored.18 Customer Metadata Boundary documentation supports EU and U.S. metadata regions, with a global default under which Customer Logs may be stored in Cloudflare core data centers globally; the documentation distinguishes distributed edge sites from centralized core data centers.19, 20 These materials do not identify Israel as a selectable metadata-boundary region or state that logs from Tel Aviv are stored in Israel.18, 19, 20
Cloudflare’s FY2025 filing states generally that its network uses third-party colocation and ISP-partner facilities, over which it has electronic and, to a lesser extent, physical access to components and infrastructure but does not control the facilities’ operations.1 The company has not publicly identified the Tel Aviv building, landlord, colocation provider, equipment owner, local operations contractor, or the unnamed ISP in the 2022 Tel Aviv/Haifa deployments.14, 15, 13, 1 Cloudflare’s DPA states that it logs and tracks system-administrator access to personal data, while its Security Exhibit describes controlled data-center access and encryption of customer data in transit and at rest.21, 22 no public evidence identified that Israel-based employees, the unnamed ISP, a colocation provider, or Israeli state bodies can access Cloudflare customer content, metadata, keys, or telemetry.21, 22, 1
No public evidence identified of Cloudflare participation in Project Nimbus, TAFNIT, or another identified Israeli government-cloud procurement, or of Cloudflare marketing or contracting sovereign-cloud or data-residency services specifically to Israeli state or military bodies.19, 23 The Israeli government health-sector cloud-security guidance addresses provider access and foreign-court-order risks generally, rather than establishing a Cloudflare-specific obligation.24 The TAFNIT tender contains data-processing and legal-process terms for tender vendors, but does not identify Cloudflare as a bidder, vendor, subcontractor, or winner.23
No public evidence identified of an Israeli legal instrument, regulator determination, court order, interception request, disclosure request, retention requirement, or cybersecurity direction publicly shown to apply to Cloudflare’s Tel Aviv infrastructure.24, 25, 23, 26 The Knesset’s January 2026 announcement concerned extension of a temporary regime addressing serious cyberattacks against defined digital-service and hosting providers through 31 January 2027, but does not identify Cloudflare or establish that its facilities are covered.26 U.S. law separately requires covered providers to comply with preservation and disclosure duties for data within their possession, custody, or control regardless of location; this is not an Israeli legal-access rule.27 Cloudflare’s transparency page states company-wide that it has never turned over encryption or authentication keys and has never installed law-enforcement software or equipment anywhere on its network; that statement is not Tel Aviv-specific.28
No public evidence identified of a further material expansion or contraction of Tel Aviv-specific capacity after the 2022 Tel Aviv/Haifa deployments.14, 15, 13
Defence, Intelligence & Security Sector Technology Relationships
No public evidence identified of a direct Cloudflare contract with the Israeli Ministry of Defence, the IDF, or Israeli intelligence agencies.1, 4 no public evidence identified of Cloudflare developing, selling, licensing, or maintaining offensive cyber capabilities for Israeli state actors.1, 4
A 2014 report described Cloudflare’s neutral-provision policy as protecting both IDF websites and the Al-Quds Brigades, the armed wing of Palestinian Islamic Jihad; the current status of the reported relationships is unconfirmed.29 Reporting from 2017 to 2019 concerned Cloudflare protection for websites associated with designated groups, including Hamas, al-Shabab, and the Popular Front for the Liberation of Palestine, and subsequent reporting indicated that Hamas-, PFLP-, and Taliban-affiliated sites no longer used Cloudflare by February 2019.30, 31, 32, 33
DAWN reported in September 2024, updated 3 February 2025, that domains associated with Benzion Gopstein - including Otzma Yehudit, Lehava, and Kahanist-related domains - used Cloudflare DNS services and remained active on Cloudflare after Gopstein’s 2024 U.S. designation; this remains an attributed civil-society claim rather than a Cloudflare admission.34, 35 The U.S. Treasury announced on 24 January 2025 that Executive Order 14115 had been revoked and all designations made under it removed, so the 2024 sanctions status is historical rather than a current U.S. prohibition.36 A DNS check on 8 September 2026 found Cloudflare nameservers for rabbikahane.co.il, while the other three identified domains used different nameservers; DNS delegation alone does not establish current ownership, proxy or CDN service, payment processing, hosting, or endorsement.37
Cloudflare’s 2019 IPO filing disclosed voluntary self-reports concerning possible use of its services by persons or entities on OFAC sanctions lists and a separate Census Bureau disclosure concerning export-control filing errors; the disclosure is general, predates the settler-sanctions programme, and does not establish a direct link to the Gopstein-domain matter.38, 39
AI, Algorithmic & Autonomous Systems
No public evidence identified of Cloudflare providing AI or ML systems, computer vision, autonomous decision support, model-training access, autonomous targeting, threat-detection, or tracking systems directly to Israeli state, military, or security bodies.1, 4 no public evidence identified that Cloudflare’s AI products or platforms have been trained on, or given access to, civilian population data, intercepted communications, or surveillance-derived datasets originating from Israel or the occupied Palestinian territories.16, 1
Technology Ecosystem & R&D Footprint
Cloudflare acquired Zaraz on 15 October 2021 for $7.2 million, according to its 2021 annual report.40, 41 The reviewed primary materials describe Zaraz as remote-first, while its Y Combinator profile lists San Francisco as its location.41, 42 The acquired group included Israeli-incorporated Sweeps Ltd., described as inactive in the 3 March 2023 SEC application.3 Cloudflare’s 8 December 2021 announcement stated that the Zaraz team would join its Portugal office and continue leading product development there; it did not identify the location of every employee.40 These primary records do not establish that Zaraz was Tel Aviv-headquartered or that Cloudflare operates a continuing Israeli R&D office through Zaraz.40, 41, 42, 3
No public evidence identified of other Israeli-company acquisitions, strategic investments in Israeli venture funds or startups, or significant patent, licensing, or co-development arrangements with the Technion, Hebrew University, or the Weizmann Institute.1, 4
Civil Society Scrutiny & Regulatory History
Cloudflare’s FY2023 Form 10-K listed the Hamas–Israel conflict as a geopolitical risk that could materially affect customers, vendors, and partners; this was a general risk disclosure rather than an operational admission.43 Cloudflare’s blog and Radar have published traffic-pattern analysis regarding the October 2023 Israel–Gaza escalation and the April 2024 Iran–Israel attack, and Access Now cited Cloudflare data in its report on Gaza Internet disruption.44, 45, 46 Cloudflare’s Project Galileo provides free protective services to at-risk civil-society organisations globally.47, 48
The reviewed document set found no Cloudflare mention in the specified editions of the UN Special Rapporteur’s A/HRC/59/23 report, reviewed OHCHR settlement-business database materials, or listed civil-society reports; this is a document-scoped result and does not establish absence from all current databases or future editions.49, 50 no public evidence identified of Cloudflare appearing in the reviewed Who Profits or AFSC Investigate material.49, 50
The most substantive identified civil-society scrutiny concerns the historical reporting on Cloudflare services for designated-group websites and DAWN’s attributed 2024–2025 reporting on Gopstein-linked domains.30, 31, 32, 33, 34 no public evidence identified of an organised boycott or divestment campaign specifically directed at Cloudflare for Israel-related technology provision, or of an OFAC penalty, DOJ action, export-control fine, or other formal enforcement outcome imposed on Cloudflare in connection with its 2019 voluntary disclosures or the DAWN-described domains.38, 39
Footnotes
-
https://www.sec.gov/Archives/edgar/data/1477333/000147733326000016/cloud-20251231.htm ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16
-
https://www.sec.gov/Archives/edgar/data/1477333/000119312519222176/d735023dex211.htm ↩
-
https://d18rn0p25nwr6d.cloudfront.net/CIK-0001477333/af98834c-0096-428e-b7d8-0de71e9cd155.pdf ↩ ↩2 ↩3 ↩4
-
https://www.sec.gov/Archives/edgar/data/1477333/000147733326000026/cloud-20251231.htm ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
https://www.sec.gov/Archives/edgar/data/1477333/000110465926015261/xslSCHEDULE_13G_X01/primary_doc.xml ↩
-
https://www.sentinelone.com/press/sentinelone-and-cloudflare-expand-partnership-to-deliver-real-time-threat-detection-and-automated-response-for-enterprises/ ↩ ↩2
-
https://developers.cloudflare.com/reference-architecture/architectures/cloudflare-sase-with-sentinelone/ ↩ ↩2
-
https://futurumgroup.com/insights/can-cloudflare-and-wiz-close-the-ai-security-visibility-gap/ ↩ ↩2
-
https://www.timesofisrael.com/in-biggest-exit-in-israeli-history-google-completes-32-billion-deal-to-buy-wiz/ ↩
-
https://blog.cloudflare.com/mid-2022-new-cities/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
https://blog.cloudflare.com/introducing-the-customer-metadata-boundary/ ↩
-
https://developers.cloudflare.com/data-localization/metadata-boundary/ ↩ ↩2 ↩3
-
https://developers.cloudflare.com/data-localization/metadata-boundary/faq/ ↩ ↩2
-
https://www.cloudflare.com/en-gb/cloudflare-customer-dpa/ ↩ ↩2
-
https://www.gov.il/BlobFolder/reports/pdns_280124/en/pdns_22_2_2024.pdf ↩ ↩2 ↩3
-
https://www.gov.il/BlobFolder/policy/mk02-2021/en/files_circulars_mk_mk02_2021-en.pdf ↩ ↩2
-
https://main.knesset.gov.il/APPS/legislation/main/laws/2000234 ↩
-
https://main.knesset.gov.il/News/PressReleases/Pages/press20012026x.aspx ↩ ↩2
-
https://uscode.house.gov/view.xhtml?edition=prelim&num=0&req=granuleid:USC-prelim-title18-section2713 ↩
-
https://www.timesofisrael.com/us-firm-helps-hamas-netanyahu-keep-hackers-at-bay/ ↩
-
https://worldisraelnews.com/israel-law-center-cloudflare-stop-supporting-terror-linked-sites/ ↩ ↩2
-
https://www.washingtontimes.com/news/2017/aug/30/cloudflare-pressued-to-cut-ties-with-hamas-linked-/ ↩ ↩2
-
https://www.haaretz.com/israel-news/2017-08-31/ty-article/.premium/cloudflare-now-being-pressed-to-stop-working-with-hamas/0000017f-dbaf-d3ff-a7ff-fbaf5c960000 ↩ ↩2
-
https://gizmodo.com/cloudflare-under-fire-for-allegedly-providing-ddos-prot-1831107649 ↩ ↩2
-
https://dawnmena.org/u-s-seize-jewish-power-and-other-extremist-websites-promoting-violence-against-palestinians/ ↩ ↩2
-
https://2021-2025.state.gov/designation-of-individuals-and-entities-contributing-to-violence-and-instability-in-the-west-bank/ ↩
-
https://content.govdelivery.com/accounts/USTREAS/bulletins/3ce946f ↩
-
https://cyberscoop.com/cloudflare-ipo-terrorism-narcotics/ ↩ ↩2
-
https://www.sec.gov/Archives/edgar/data/1477333/000119312519222176/d735023ds1.htm ↩ ↩2
-
https://blog.cloudflare.com/cloudflare-acquires-zaraz-to-enable-cloud-loading-of-third-party-tools/ ↩ ↩2 ↩3
-
https://cloudflare.net/files/doc_financials/2021/q4/98f467d0-9cc2-452a-817d-17e94bdcb2b9.pdf ↩ ↩2 ↩3
-
https://www.sec.gov/Archives/edgar/data/1477333/000147733324000040/fy202310k_ars.pdf ↩
-
https://blog.cloudflare.com/internet-traffic-analysis-iran-israel-april-attack/ ↩
-
https://blog.cloudflare.com/internet-traffic-patterns-in-israel-and-palestine-following-the-october-2023-attacks/ ↩
-
https://www.accessnow.org/publication/palestine-unplugged/ ↩
-
https://www.cxoinsightme.com/news/cloudflares-project-galileo-marks-one-decade-of-protecting-at-risk-organisations-online/ ↩
-
https://blog.cloudflare.com/galileo10anniversaryradardashboard/ ↩
-
https://www.ohchr.org/sites/default/files/documents/hrbodies/hrcouncil/sessions-regular/session59/advance-version/a-hrc-59-23-aev.pdf ↩ ↩2
-
https://www.ohchr.org/en/press-releases/2025/09/un-human-rights-office-updates-database-businesses-involved-israeli ↩ ↩2