The security model
Zero Trust applies least privilege to each request. Identity, device and context are evaluated before access instead of trusting a person merely because they reached a corporate network.
Core building blocks
Cloudflare One combines several products in one control plane.
- Access controls who can reach private or SaaS applications.
- Tunnel connects private resources through outbound-only connectors.
- Gateway filters DNS, network and HTTP traffic.
- The Cloudflare One Client connects managed devices and supplies device posture.
- DLP, CASB, Browser Isolation and Email Security add specialised data and threat controls.
A sensible starting point
Begin with one application or a small device group, define identity and recovery requirements, then expand policy after reviewing logs. The Free plan covers the first 50 active users; current paid Silurian prices are shown on the service page and in your workspace before ordering.
Not the same as website protection
Zero Trust primarily protects workforce access and outbound activity. Public website WAF, CDN and authoritative DNS belong to Web Security and Performance, although both families share Cloudflare's network.
Official sources
This Silurian guide uses the following provider documentation as its technical source. Product availability still depends on the managed account and plan.
Cloudflare DevelopersCloudflare One↗ Cloudflare DevelopersCloudflare pricing overview↗ Cloudflare DevelopersCloudflare Zero Trust plans↗