CYBERRIPPER EDGEWANCOMING SOON

Autonomous edge security. Cloud-scale enforcement. NIGHTFALL intelligence.

A planned multi-tenant cloud security platform that combines Cloudflare’s global edge with NIGHTFALL evidence, correlation, policy and fleet intelligence.

NO PROOF = NO GREEN.A rule being deployed is not enough. EdgeWAN is designed to preserve decision, provider readback, effect and rollback evidence.
EDGEWAN CONTROL PLANEARCHITECTURE PREVIEW
InternetCloudflareEdge ShieldNIGHTFALL Cloud BrainOrigin
DATA PLANECloudflare
SECURITY BRAINNIGHTFALL
EVIDENCETruth-first
STATUSRoadmap
Control Plane Preview

A first look at the EdgeWAN security operations console.

A non-operational UI preview of the planned multi-tenant WAF, evidence, policy and fleet experience. All values below are demo-only.

SECURITY OPERATIONSEdgeWAN Overview
DEMO UICOMING SOON
Protected hostnames03demo tenants
Edge protectionREADYarchitecture state
Cloud BrainPREVIEWnot operational
Proof stateTRUTH FIRSTno synthetic green
LIVE PATH CONCEPTRequest Processing Fabric
SIMULATED
01InternetTenant traffic
02Cloudflare EdgeDDoS + network edge
03Edge ShieldWAF + rate + API
04NIGHTFALL BrainEvidence + correlation
05OriginProtected service
Normal trafficFast path → origin
Suspicious evidenceDeep analysis → bounded policy
Provider readbackEffect → evidence → rollback
INCIDENT QUEUEEvidence Timeline
DEMO
Credential abuse pattern/auth/login · tenant-03
CHALLENGE
SQL injection signature/api/search · tenant-01
BLOCK
Bot burst anomaly/checkout · tenant-02
RATE LIMIT
Proof chainrequest → decision → provider → readback → effectConceptual UI only
POLICY SURFACESEdge Shield Controls
PLANNED
Managed WAFBaseline web protection
PREVIEW
Rate LimitingEndpoint-aware quotas
PREVIEW
Bot & AbuseChallenge and bounded mitigation
PREVIEW
API ProtectionMethod, path and schema policy
PREVIEW
Fleet CorrelationEndpoint + server evidence bridge
COMING
Provider PortabilityCloudflare first, adapters later
COMING
Coming soon — architecture preview.This console is a visual product concept only. It does not claim that the public WAF service, tenant onboarding or Cloud Brain are live today.
Architecture

Cloudflare is the muscle. NIGHTFALL becomes the security brain.

All web traffic receives fast baseline edge protection; only suspicious evidence is promoted into deeper correlation and adaptive policy decisions.

00Tenant trafficEvery customer hostname enters through the edge.
01Native edge shieldDDoS, WAF, rate limits, bot and API controls.
02Suspicion signalOnly meaningful events are promoted for deeper analysis.
03Cloud BrainCorrelation, intelligence and bounded decision logic.
04Provider actionChallenge, rate-limit or block with TTL and readback.
Security Fabric

One control plane, five independent responsibilities.

The product stays portable by keeping the NIGHTFALL decision and evidence model separate from the first enforcement provider.

Edge Shield

Always-on WAF, DDoS, rate and API baseline at the edge.

Cloud Brain

Evidence normalization, correlation, confidence and bounded decisions.

Edge Evidence

Decision IDs, provider rule IDs, readback, observed effect and rollback history.

Edge Control

Tenant policy, onboarding, automation, TTL and provider abstraction.

Edge Fleet

Optional correlation with NIGHTFALL endpoints, servers, DNS and appliances.

Truth Model

A provider rule is not proof by itself.

EdgeWAN is intended to keep the same NIGHTFALL doctrine in the cloud: distinguish detection, decision, enforcement and actual observed effect.

requestEvidenceIdpolicyDecisionIdproviderRuleIdproviderReadbackeffectObservedrollbackId
Roadmap

Build the cloud brain after the contracts freeze — not after all 63 engines move to cloud.

EdgeWAN is a separate cloud codebase sharing a small set of stable NIGHTFALL contracts. Packet drivers and endpoint engines stay on endpoint/appliance products.

01

Freeze shared contracts

Evidence envelope, causal identity, decision, policy/effect and truthful health states.

02

Cloud provider adapter

Cloudflare hostname onboarding, Rulesets/WAF orchestration and provider readback.

03

Multi-tenant control plane

Tenant identity, isolation, policy, audit, TTL, rollback and secure secrets.

04

Evidence + correlation

Normalize edge events, connect threat intelligence and correlate only meaningful suspicious signals.

05

Fleet bridge

Optional evidence exchange with NIGHTFALL endpoint/server/appliance without moving native engines into Workers.

06

Controlled public trial

Staging, abuse tests, quotas, billing boundaries, observability, fail-safe defaults and rollback proof.

Current statusArchitecture preview only. No public protection service is being claimed as live yet.