← 返回周报列表
2026-W16
2026 W16 (Apr 13 - Apr 19)
外部 Blog 文章
Cloudflare推出Agent Readiness评分,帮助网站评估对AI代理的支持能力,并分享相关技术标准与Radar数据。
内部 Wiki 文档
关于托管防御产品数据表更新的RFC文档,由Trevor Lyness等多位专家进行评审。
私有网络公网到私网封闭测试的内部维基草案,作为该测试项目运行的权威参考指南。
AI安全检测API集成与自定义提示主题的技术规范,涵盖dlp-classify服务采用WAD的两项相关变更。
将dlpscanner服务接入Edge Consul的技术规范,旨在实现仅用于健康状态监控的可观测性。
2026年夏季实习生Nebil Mohammed的健康分析团队项目,致力于完成带健康差异检测功能的自动化发布系统。
设计BGP传感器网络监控CNI网络,解决CCR与Conduit间路由传播路径的检测与挑战问题。
汇总应用安全领域的相关规范、RFC及PRD文档,为安全架构设计提供标准化参考依据。
制定位置感知消费者功能规范,支持基于地理位置的服务调度与消费,关联SHIP-13470需求。
2026年Q2功能规范,针对assets_asset表进行分片设计,明确应用层代码变更方案与实施状态。
基于浏览器的RDP会话录制功能规范,通过概念验证实现浏览器内远程桌面会话的录制与回放能力。
关于邮件服务Webhooks的草案规范,目前为手写版本,计划后续使用大语言模型补充完善更多技术细节。
CNI网络服务自助订购冗余互连的功能规范,旨在通过网络冗余架构实现服务级别保证与高可用性。
BotBase机器人生命周期阶段的技术规范文档,当前处于审核状态,定义了机器人从创建到销毁的完整状态流转机制。
BotBase核心机器人记录规范RFC-002,基于RFC-001生命周期阶段定义,阐述机器人核心数据结构与元数据管理标准。
用户ID信号增强技术规范,关联SHIP-14707与RM-28565工单,旨在优化用户标识信号采集与识别准确性。
关于标准化团队实践的RFC草案,由Ashwini Nayak负责,目前处于草稿状态并待审阅。
提出多项改进措施以提高Buoy版本发布的可靠性,确保镜像在投产前具备足够可信度。
Organizations企业版测试FAQ页面已停止更新,建议用户前往The State of Orgs页面查看最新信息。
针对CacheW支持WfP及预览功能的RFC提案,作为Project CacheW的后续,解决当前zone-scoped架构问题。
CNI端点功能规范文档,支持用户自助订购冗余互连服务,确保网络服务的服务级别保障。
产品更新邮件
HIPAA, ISO 27017 & GovRAMP Docs Now Live 点击展开 ▾
Cloudflare合规包已新增HIPAA、ISO 27017及GovRAMP三项认证,分别适用于医疗健康、全球企业以及美国州政府与教育机构,可为客户提供即时的第三方安全验证。使用时需确保签署BAA协议、核实产品覆盖范围并遵守共享责任模型。
The GRC team has officially updated the Cloudflare Compliance Package.
These three additions are designed to help you bypass lengthy security
assessments and provide instant, third-party validation for your prospects.
What’s New & Where it Applies
-
HIPAA AoC (US Healthcare & Global PHI)
-
The Scope: Essential for U.S. healthcare (providers/insurers)
and international
entities processing U.S. patient data.
-
The Asset: An Attestation of Compliance (AoC) providing formal audit
evidence of our PHI protections.
-
ISO 27017 (Global Enterprise)
-
The Scope: Worldwide. Our strongest asset for enterprise deals in EMEA,
APAC, and LATAM.
-
The Asset: A specialized "cloud-first" certification that builds on
ISO 27001 by addressing specific cloud service provider risks.
-
GovRAMP Authorization (US SLED)
-
The Scope: USA Only. Built for State, Local, and Tribal governments
and Higher Ed.
-
The Asset: Standardized cybersecurity verification; the state-level
equivalent of FedRAMP.
Implementation Notes (Best Practices)
To ensure we maintain the integrity of our compliance program, please
follow these operational guidelines:
-
The BAA Process: A HIPAA AoC validates our environment, but a Business
Associate Agreement (BAA) is still the required contractual vehicle for
PHI. Ensure your account team follows the standard BAA request process.
-
Verify Product Scope: Compliance is not "blanket" coverage. These
certifications apply to specific In-Scope Services. Always verify that
the customer’s intended products are covered by checking our reports.
-
Shared Responsibility Model: Remind customers that while Cloudflare
infrastructure is compliant, they are responsible for compliant
configuration (e.g., proper encryption settings, access controls) on
their end.
-
GovRAMP vs. FedRAMP: These are distinct frameworks. GovRAMP is for SLED
(State, Local, Education). If you are working on a U.S. Federal deal,
continue to reference our FedRAMP documentation.
How to Use These to Close Deals
Use these documents to pre-empt security questionnaires. Instead of manual
entry, provide these third-party audits to build immediate trust.
-
Healthcare: Lead with the HIPAA AoC to shorten the security review.
-
Global Enterprise: Put ISO 27017 front-and-center for non-U.S. prospects.
-
Public Sector: Use GovRAMP to bypass individual state-level audits.
How to get them: Request via CSCR process.
<https://wiki.cfdata.org/spaces/INFOSEC/pages/201660642/Filing+a+CSCR+Ticket#tab-How+to+file+a+Jira+ticket> 1️⃣ Cloudflare One Weekly Update 点击展开 ▾
Cloudflare One本周业务更新显示季度收入达115万美元,管道预测超5800万美元。客户数量环比增长7.6%至5,437个,并重点介绍了与EMAAR Properties达成62.7万美元ACV的重大合作案例。
Web Version: https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1lst09vfooj?email=true&lang=en ----------------------- Revenue $1.15M Closed/Won QTD 4.5% of Target ($25.58M ACV) $58.3M in Forecasted Pipeline (Q2'26) $183M in All Open Pipeline for the Year source [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/v8qhbbd9vu2/external?email=true&lang=en&a=5&p=5927620&t=1877087 ] https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/fofhi73crum?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- Partners $0.87M Closed/Won QTD w/ Partner Attach $0.22M Closed/Won PIO https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1oycigtw9y5?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- Customers 5,437 Contract Customers (7.6 % MoM) 62% Utilization - (2.3M Seats Configured / 3.7M Seats Contracted) https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1ihyjblf122?email=true&lang=en&a=2&p=5927620&t=1877087 EMAAR Properties (L.L.C.) CF1 ACV $627K | Deal Team: AE: Arun George, PAM: Eyal Al Shami, SE: Ahmad Badawi, SSE: Abou Zaher | Partner: Emirates Business Machines Landmark new logo win with one of the Middle East’s most iconic enterprises. Cloudflare displaced legacy infrastructure and a hyperscaler by positioning as a full-platform consolidation across 80+ domains, applications, and security layers, securing a multi-product deployment including Zero Trust, App Security, and Cloudforce One. https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1ba7wzbk4hs?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- Supabase Inc. CF1 ACV $184K | AE: Billy Wong, SE: Sze Rong Tham, CSE: Smitha, Specialists: Rex Sunny Direct Strategic Zero Trust upsell expanding Cloudflare’s footprint with Supabase. Strong cross-functional execution enabled deeper integration with developer workflows, with ZTNA expertise and rapid technical support key to closing the deal. https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/gt2inepqxqz?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- Midland Independent School District CF1 ACV $37K | Deal Team AE: Jack Coughlin, Specialists: Matthew Boknevitz, Scott Harris, PAM: Marcus Charles | Partner: CDW This successful engagement, resulted in the adoption of Cloudflare One Email Security to resolve critical phishing issues and provide a flexible solution for inbound email threats. With vital evaluation support from Matthew Boknevitz and Scott Harris, the customer successfully integrated this key component of the SASE platform to protect their organization from evolving digital risks. This win highlights the effectiveness of Cloudflare’s technical mastery and collaborative GTM approach in displacing competitors and securing high-value accounts. https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/sbtn392emtn?email=true&lang=en&a=2&p=5927620&t=1877087 Cloudflare accelerates post-quantum roadmap - Global press momentum (including TIME and Techmeme trending) reinforces Cloudflare’s leadership in quantum-safe security, with strong validation of its PQC-by-default approach. Read here [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/62wr7huvro9/external?email=true&lang=en&a=5&p=5927620&t=1877087 ]. https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1t0sn02nhqn?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- CASB Webhooks now live - Enables customers to send SaaS security findings directly to tools like Slack, Jira, SIEM, and PagerDuty, making CASB more actionable and easier to integrate into existing security workflows. Learn more [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/89krbbge8fr/external?email=true&lang=en&a=5&p=5927620&t=1877087 ]. https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/16vwggs2j2i?email=true&lang=en&a=2&p=5927620&t=1877087 ----------------------------------- Coffee Shop Networking GTM updates - New SASE messaging and sales materials now available, including pitch decks, solution briefs, and enablement guides, with updated positioning and targeting guidance for Q2 campaigns. Customer-facing slides in “SASE use case pitch deck [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/1jh7bqtdstu/external?email=true&lang=en&a=5&p=5927620&t=1877087 ]” with talk track Enablement guide [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/10kaon03xnx/external?email=true&lang=en&a=5&p=5927620&t=1877087 ]: How to win these opportunities Infographic [ https://cloudflare-partnerteam-int.us.newsweaver.com/5p3pf93cmb/2njov4kv77k/external?email=true&lang=en&a=5&p=5927620&t=1877087 ] (2-pages) Solution brief [ https://cloudflare-partnerteam-int.us.newsweaver.com ... (内容已截断,原文共 13391 字符)