Zero Trust Gateway (SWG)
Cloudflare Gateway routes your organisation's outbound internet traffic through Cloudflare's edge, where it is inspected and filtered — blocking malware, phishing, ransomware command-and-control and policy violations before they reach users or data leaves the company.
Overview
Protecting the office network perimeter stopped being enough when work left the office. Employees on home Wi-Fi, laptops in cafés and cloud SaaS everywhere mean the old appliance-based web proxy either gets bypassed or becomes a latency-adding chokepoint that all remote traffic must hairpin through.
Gateway is a Secure Web Gateway (SWG) delivered from Cloudflare's edge: every user's DNS queries and web traffic are filtered at the nearest of 300+ locations, applying the same policy whether the user sits in your Prague office or a hotel abroad. It pairs naturally with Access — Gateway governs traffic going out to the internet, Access governs traffic coming in to your applications.
Key capabilities
- DNS filtering by threat intelligence categories — malware, phishing, C2, newly-registered domains — and content categories
- Full HTTP(S) inspection with TLS decryption, file-type controls and inline antivirus scanning of downloads
- Network-layer (L4) rules for arbitrary ports and protocols, not just web traffic
- Threat intelligence continuously derived from the attack traffic Cloudflare sees across its network
- Data Loss Prevention (DLP) profiles that detect credit card numbers, personal data or your own defined patterns in uploads
- Shadow-IT visibility and per-application SaaS controls (e.g. allow corporate tenant, block personal accounts)
- Per-group policies from your identity provider — different rules for finance, engineering, or guests
- Remote Browser Isolation (add-on) that renders risky sites in a disposable cloud browser
How it works
Traffic reaches Gateway in one of several ways: the WARP client on laptops and phones forwards DNS and network traffic over an encrypted tunnel; office networks can point their resolvers at Gateway's DNS endpoints or connect entire sites via tunnels; and proxy PAC files cover locked-down environments. Whichever the on-ramp, policy follows the user identity, not the network they happen to be on.
DNS filtering is the first, cheapest layer: a query for a known-malicious domain is answered with a block page before any connection is made. HTTP inspection goes deeper — with your organisation's root certificate deployed, Gateway decrypts TLS at the edge, scans downloads for malware, enforces file-type and DLP rules, and re-encrypts. Category and threat data update continuously from Cloudflare's global visibility, so newly-weaponised domains are typically blocked within minutes of first sighting.
Everything is logged centrally — every blocked download, every DLP match — and exportable to your SIEM, giving security teams the visibility that disappeared when users left the office network.
Plans & licensing
Gateway is part of the Cloudflare One / Zero Trust platform with per-user pricing. The free tier covers up to 50 users with DNS filtering and core HTTP policies. Paid plans extend log retention and quotas; features like full DLP and Remote Browser Isolation are add-ons or Enterprise-bundle components. As of 2026, subject to change — confirm current packaging with us.
Deployment with Integrity
As a certified Cloudflare partner for Central and Eastern Europe, Integrity delivers this product end to end — including a free pilot so you see results on your own traffic before committing. A typical rollout:
- Assessment. We review your device fleet, offices, identity provider, compliance requirements (e.g. NIS2) and the incidents you most need to prevent.
- Free pilot. DNS filtering goes live for a pilot group via the WARP client — visible protection in days, with no user-facing change.
- HTTPS inspection rollout. The root certificate is distributed via your device management, TLS inspection and download scanning are enabled, with documented exceptions for banking, healthcare and certificate-pinned apps.
- Policy build-out. Category policies, per-group rules, DLP profiles and SaaS tenant controls are configured to match your acceptable-use and compliance needs.
- Fleet rollout. WARP deploys to the full fleet through MDM; office networks are connected; logging flows to your SIEM.
- Handover or managed service. Your admins take over with our runbook, or Integrity operates Gateway as a managed service — start with the free pilot.
Ready to start? Contact us to arrange the free pilot.
FAQ
Does TLS inspection break applications or violate privacy?
Some applications pin certificates and must be exempted — we maintain that exception list during rollout. On privacy: inspection policy is yours to define, and sensitive categories (health, banking) are typically excluded by policy. Users see a clear block page, not silent surveillance.
Will routing everything through Cloudflare slow the internet down for our staff?
Generally no — often the opposite. Traffic enters Cloudflare at the nearest of 300+ cities and rides its backbone; for most users this matches or beats their ISP's default routing, unlike legacy proxies that hairpin traffic through one data centre.
Can Gateway alone make us NIS2-ready?
No single product makes you compliant, but Gateway directly addresses several expected controls: malware protection, web filtering, logging and data-loss controls for a hybrid workforce. We can map its capabilities to your specific NIS2 obligations during assessment.