Autonomous edge security. Cloud-scale enforcement. NIGHTFALL intelligence.
A planned multi-tenant cloud security platform that combines Cloudflare’s global edge with NIGHTFALL evidence, correlation, policy and fleet intelligence.
A first look at the EdgeWAN security operations console.
A non-operational UI preview of the planned multi-tenant WAF, evidence, policy and fleet experience. All values below are demo-only.
request → decision → provider → readback → effectConceptual UI onlyCloudflare is the muscle. NIGHTFALL becomes the security brain.
All web traffic receives fast baseline edge protection; only suspicious evidence is promoted into deeper correlation and adaptive policy decisions.
One control plane, five independent responsibilities.
The product stays portable by keeping the NIGHTFALL decision and evidence model separate from the first enforcement provider.
Edge Shield
Always-on WAF, DDoS, rate and API baseline at the edge.
Cloud Brain
Evidence normalization, correlation, confidence and bounded decisions.
Edge Evidence
Decision IDs, provider rule IDs, readback, observed effect and rollback history.
Edge Control
Tenant policy, onboarding, automation, TTL and provider abstraction.
Edge Fleet
Optional correlation with NIGHTFALL endpoints, servers, DNS and appliances.
A provider rule is not proof by itself.
EdgeWAN is intended to keep the same NIGHTFALL doctrine in the cloud: distinguish detection, decision, enforcement and actual observed effect.
Build the cloud brain after the contracts freeze — not after all 63 engines move to cloud.
EdgeWAN is a separate cloud codebase sharing a small set of stable NIGHTFALL contracts. Packet drivers and endpoint engines stay on endpoint/appliance products.
Freeze shared contracts
Evidence envelope, causal identity, decision, policy/effect and truthful health states.
Cloud provider adapter
Cloudflare hostname onboarding, Rulesets/WAF orchestration and provider readback.
Multi-tenant control plane
Tenant identity, isolation, policy, audit, TTL, rollback and secure secrets.
Evidence + correlation
Normalize edge events, connect threat intelligence and correlate only meaningful suspicious signals.
Fleet bridge
Optional evidence exchange with NIGHTFALL endpoint/server/appliance without moving native engines into Workers.
Controlled public trial
Staging, abuse tests, quotas, billing boundaries, observability, fail-safe defaults and rollback proof.