Vendor lineage
Cloudflare
Began as a project asking where spam came from, and became infrastructure after users asked it to stop the spam instead.
In 2004 Matthew Prince and Lee Holloway built Project Honey Pot to answer a narrow question: where does email spam actually come from? Anyone with a website could participate, and thousands in more than 185 countries did. The users kept making the same request - do not just track them, stop them - and five years later that request became a company.
Prince met Michelle Zatlyn at Harvard Business School during a sabbatical, described the project, and the two of them plus Holloway founded Cloudflare in July 2009. It won the school's business plan competition that April and closed a $2.1M Series A in November from Venrock and Pelion.
The product was a reverse proxy you joined by changing your DNS, which is a genuinely low barrier: no hardware, no software, no contract, and a free tier from the beginning. That freemium decision was strategic rather than generous. Every free site sends traffic through the network, and every attack against a free site is an attack the network learns to recognise for everyone else.
That is the same argument this timeline shows three times before. IronPort made it about email sender reputation in 2002. Zscaler made it about web traffic in 2007. CrowdStrike made it about endpoint behaviour in 2013. Cloudflare made it about the web itself, and got its initial threat data from a spam-tracking project - which is where IronPort had started too.
Public launch was at TechCrunch Disrupt in September 2010, and traffic went from roughly 50 million page views a month to over 5 billion within the first year.
The company has since become something harder to categorise: DDoS mitigation, WAF, DNS, zero-trust access, and a serverless compute platform that runs code in the same points of presence that serve the cache - which turns a content network into somewhere applications actually execute. It went public in 2019, and its network now spans more than 300 cities.
It also occupies an awkward position it did not entirely choose. A company that will serve almost anyone, at scale, for free, ends up making decisions about who may remain online - and has been criticised both for acting and for declining to.
Founding stories
Project Honey Pot
Five years before the company existed, Prince and Holloway built a distributed system that let any website owner watch how spammers harvested email addresses. It worked, and it produced a community of webmasters with a question the project could not answer: knowing who was attacking them did nothing to stop it. That gap between observation and defence is what the company was eventually built to close.
Cloudflare
Prince was on sabbatical taking an MBA at Harvard Business School when he described Project Honey Pot to a classmate, Michelle Zatlyn. She saw the commercial shape of it immediately: not tracking threats but blocking them. The first business plan was called Project Web Wall and convinced nobody. A friend of Prince's described what they were building as a firewall in the cloud, and the name that came out of that stuck. Holloway wrote the prototype over the summer. The company was incorporated on 26 July 2009 and its first office was above a nail salon.
Founding date and founder list per Cloudflare's own account and Wikipedia; the naming sequence and the Project Web Wall working title come from the company's Our Story page.
The timeline
- Project Honey Pot
A distributed spam-tracking network run by Prince and Holloway under Unspam Technologies, and the source of both the threat data and the founding question.
- Incorporated, and a business plan competition won
Founded 26 July in Palo Alto after winning the Harvard Business School business plan competition earlier that year. A $2.1M Series A followed in November from Pelion Venture Partners and Venrock.
- Public launch at TechCrunch Disrupt
Launched 27 September. Traffic through the network went from roughly 50 million page views a month to more than five billion within the first year, on a freemium model that gave the free tier away and learned from its traffic.
- Lee Holloway steps down
The co-founder who wrote the original prototype and led the early engineering team, including its Anycast work, withdrew after a diagnosis of frontotemporal dementia. The company's 2019 flotation was codenamed Project Holloway.
Recounted publicly by Prince and Zatlyn on Cloudflare TV. Included because the company tells it themselves and because the engineering it credits is load-bearing.
- 1.1.1.1
A public DNS resolver launched with a privacy commitment and independent audits, on an address short enough to be memorable and previously used as a dumping ground for misconfigured equipment.
- New York Stock Exchange listing
Listed as NET, ten years after incorporation.
- Scale, and the cost of it
Revenue of $2.168B against an operating loss of $207M, with 5,156 employees. Building a global network and giving a large part of it away is expensive at every scale.
Figures from Wikipedia's summary of the 2025 financial statements.
Flagship products and solutions
- Reverse-proxy CDN and WAFThe original service: traffic is pointed at Cloudflare by DNS, cached and inspected at the edge, and forwarded to the origin. Everything else was built on this path.
- DDoS mitigationAbsorbing volumetric attacks in a network large enough that an attack sized to overwhelm one customer is not sized to overwhelm the network carrying them.
- WorkersCode that runs at the edge rather than in a region, on an isolate model that starts fast enough to sit in the request path without adding a cold start to it.
- R2Object storage sold without egress fees, which is a pricing decision aimed squarely at the charge that makes leaving a cloud provider expensive.
- Cloudflare One and Zero TrustAccess, gateway and tunnel services that put the same edge in front of internal applications, competing with the secure service edge vendors elsewhere on this timeline.
- 1.1.1.1A public recursive resolver, offered free, which also gives the company a view of DNS behaviour at a scale very few organisations have.
Key innovations
- Free tier as an instrument, not a discountThe free plan was not customer acquisition alone. A network carrying millions of small sites sees attacks earlier and more often than one carrying a few large ones, and the data improves the defence sold to everybody. The giveaway is how the product learns.
- Anycast as the architecture rather than a featureThe same address announced from every location, so traffic lands at the nearest point of presence and an attack is divided across the network instead of concentrated. It is why capacity and defence are the same asset here.
- Edge compute without cold startsWorkers use V8 isolates rather than containers, trading isolation strength and language freedom for start times low enough to run per-request. That trade is the whole product decision, and it is the reason the model suits request handling rather than long jobs.
- Egress pricing as a competitive weaponCharging nothing to take data out attacks the specific fee that makes migration between clouds expensive. It is a pricing argument aimed at a structural one.
Main markets
Two very different customers on one platform: millions of small sites on the free and low-cost tiers, and enterprises buying performance, security and increasingly network services. The company reports over 100,000 paying customers against tens of millions of properties, which is the freemium shape stated plainly.
Its network reaches 300 or more cities across 100 or more countries, and its position competes on different fronts at once - content delivery against Akamai, security against the firewall and secure service edge vendors, and developer platform against the large cloud providers whose egress fees it undercuts.
Analyst standing
- Named in analyst coverage across several distinct categories rather than one, which reflects a portfolio assembled around a single network rather than a single product line.
- The financial picture is worth reading alongside the growth: revenue above $2B in 2025 with an operating loss, which is what building global infrastructure and giving a substantial part of it away looks like on a balance sheet.
- Cloudflare's own account - Project Honey Pot in 2004, the users asking them to stop the attacks, meeting at HBS, the November 2009 Series A with Venrock and Pelion
- Company history: founded July 2009, the April 2009 HBS competition win, TechCrunch Disrupt launch, 50M to 5B page views in the first year