An orange and yellow background with a stylized white cloud design in the center. The word Upwind is at the top left corner in white text.

Seamlessly Integrate with Cloudflare Through the Upwind Platform

Denise Ashur January 31, 2025

We are thrilled to announce a new integration with Cloudflare, bringing seamless and enhanced API security for Upwind users who leverage Cloudflare.

Why Integrate with Cloudflare

Cloudflare is an internet infrastructure and security company that helps organizations monitor and manage their API endpoints, providing additional security, monitoring and API traffic optimization. Its robust capabilities include enhanced security, comprehensive monitoring, and optimized traffic Flow. Acting as a secure API gateway, Cloudflare provides:

  • API Discovery and schema validation
  • Rate limiting to manage API traffic
  • DDos mitigation to shield APIs from malicious attacks

Upwind’s integration with Cloudflare enhances this ecosystem by offering a seamless API security experience. With this integration, Upwind users can easily discover, manage, and protect APIs, leveraging the strength of both platforms.

How Does the Integration Work?

The Upwind integration with Cloudflare functions as a dedicated Cloudflare worker, giving Upwind users the ability to monitor their API traffic at the Cloudflare level – before it even reaches your application. 

Diagram showing a network flow with icons for AWS, Azure, GCP, CloudFlare, and CloudFront. Arrows depict connections between these services, with Cloud Egress and Internet Egress nodes. The interface is from an inventory management system.

While many API security tools have integrations with Cloudflare, they often come with significant trade-offs. A common drawback is that these tools require customers to send their sensitive data outside of Cloudflare to their tool’s backend systems. This approach exposes sensitive data, leaving it vulnerable, and presenting unnecessary security risks.

Flowchart showing data movement: Customer Application sends data to Cloudflare, which then sends customers sensitive data to Other API Solution SaaS. Upwind logo is in the top right corner.

Upwind takes a unique approach to solve this challenge

  • Auto-classification of sensitive data types: Using pattern recognition, Upwind identifies sensitive data types (e.g., PII, PCI, PHI) directly at the Cloudflare worker level.
  • Data never leaves your environment: Unlike traditional tools, Upwind does not read or store sensitive data. Instead, only reports – such as API catalogs and sensitive data type classifications – are sent to the Upwind SaaS platform.
  • Comprehensive security with zero data exposure: This design ensures you can achieve full API discovery and protection without compromising sensitive information.
A diagram showing data flow. A cloud icon labeled Cloudflare connects to an Upwind SaaS icon, captioned Customer’s API catalog and sensitive data type. Both connect to a Customer Application with stacked layers. Upwind logo in top right.

How to Start Using Upwind’s Cloudflare Integration

Integrating Cloudflare through the Upwind Platform is simple:

  1. Navigate to the Integrations page in the Upwind dashboard.
  2. Click “Connect” under the Cloudflare integration.
  3. Follow the brief implementation instructions provided.

Once set up, you’ll enjoy a seamless API security experience with unified functionality across Upwind and Cloudflare.

A screen showing the Cloudflare API integration option. It provides a description of the Upwind Cloudflare Integration for controlling public-facing APIs via a deployable Cloudflare Worker. There is a Connect button.

Experience the power of Upwind’s Cloudflare integration –  streamlining proactive API discovery, management, protection and sensitive data tracking, all in one centralized location. To learn more about  Upwind’s comprehensive API security offering, schedule a demo today.

Contents

Further Reading

behind-the-curtain-part-02

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part II

Recap In Part I, we explored the AgentCore Runtime microVM from the inside and discovered we weren't alone - four platform binaries were running alongside our code, and one of them was quietly shipping logs to an AWS-internal S3 bucket. We left off with a question: what can we learn from these internal components, and…
behind-the-curtain-part-01

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part I

Introduction When you deploy an AI agent to AWS Bedrock AgentCore Runtime, your code runs inside a Firecracker microVM - but it doesn't run alone. In this three-part series, we tear down the platform internals, document what we found, and assess how well the isolation holds up. Setting the Stage AWS Bedrock AgentCore Runtime is…
upwind-code

Upwind Code Expands Enterprise Coverage to Azure DevOps and Bitbucket Cloud

Modern development organizations rarely keep all their code in one place. Teams may use different version control platforms because of acquisitions, business-unit preferences, regional requirements, or existing development workflows. But when code is spread across multiple providers, application security coverage can become fragmented too. Today, Upwind Code adds support for Azure DevOps and Bitbucket Cloud.…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS