Cloudflare says it replaced most third-party security tools with in-house software
Cloudflare’s security chief says more than 200 internal agents now support its security work, but warns most companies should not copy the model.
By Renata Fuchs · Policy Reporter
· 3 min read
Cloudflare says it has replaced almost all of its third party security tools with internally built applications, some developed with AI assistance. Chief Security Officer Grant Bourzikas said the company runs more than 200 autonomous agents for its own security work, while cautioning that its build-versus-buy decision is not a general prescription for banks or other enterprises.
Bourzikas described the approach during a press lunch in Sydney, Australia, according to The Register. The company’s claimed experience is a pointed counterweight to the broad argument that AI will push every enterprise to replace SaaS products with bespoke systems. Cloudflare’s own security-software expertise and its particular operating demands are central to its calculation, Bourzikas said.
Why did Cloudflare replace third-party security tools?
Cloudflare has not set out a public vendor-by-vendor account of the change in the material cited by The Register. Bourzikas said its internal agents and home-grown applications had allowed the company to remove nearly all external security tools, but he also said Cloudflare is unusually equipped to make and operate security software.
He explicitly rejected the idea that every large organization should respond by building all of its own systems. For companies weighing internal development against a purchased product, the lesson is narrower: a bounded workflow, internal technical capability and operating economics can justify custom software in some cases. They do not establish that a wholesale move away from security SaaS will work elsewhere.
Cloudflare itself has published limited detail on one part of that work. In a June post, the company described a multi-stage vulnerability-discovery harness and an automated triage loop, including controls over system state, adversarial review intended to reduce false positives, and methods to work around LLM context limits. That post provides context for its automation efforts, but does not independently verify the broader claim that nearly all third-party tools have been retired.
What does Cloudflare’s AI bug-bounty triage system do?
The clearest example Bourzikas gave was Cloudflare’s intake process for bug-bounty reports. The company previously handled incoming reports manually, he said. It now uses Anthropic’s Claude Sonnet to screen submissions, identify apparent duplicates and estimate whether a report should receive human attention.
Bourzikas told The Register that this use of Sonnet costs about $58 a month. He estimated that using Anthropic’s security-focused Mythos model for the same task would cost roughly $200,000 a month. Those figures are Cloudflare’s reported, use-case-specific estimates, not independently audited operating results.
The comparison also cuts against the assumption that a specialized model is automatically the best production choice. For this particular intake workflow, Cloudflare said a lower-cost general model was adequate to sort work before human review. The Register’s report did not name retired vendors, remaining external tools, or provide independent measures of security outcomes from the shift.
Cloudflare has separately argued that third-party applications and integrations can create security and privacy exposure, recommending due diligence on vendors, configurations and permissions. That is general guidance from the company, not evidence that third-party risk was the reason for each internal replacement. The more specific claim here is operational: Cloudflare says its own capabilities and security requirements made bespoke tooling viable, while its CSO says others should be careful about drawing a broader conclusion.
This story draws on original reporting from The Register.