Make the origin disappear
Cloudflare-native architecture
Tunnel, WAF, Turnstile, Zero Trust, and cache rules configured as one defensive edge, with no inbound origin ports left open.
From
EUR 3,200 per project
Typical lead time
1-2 weeks
A firewall rule that allows Cloudflare IP ranges is not the same as having no open ports. The first is a list to maintain and eventually get wrong; the second removes the attack surface.
We deploy behind a tunnel, verify from outside that the origin does not answer, and hand you the runbook.
What is included
- Cloudflare Tunnel: the origin makes outbound connections only
- Zero Trust access on admin and staging, with one-time-PIN or SSO
- WAF rules and bot management tuned to your traffic, not left on defaults
- Turnstile on every public form
- Cache rules that actually cache, with a correct purge strategy
- Origin firewall closed and verified from outside
What you get
- The full configuration, documented
- An external scan showing the origin is unreachable
- A runbook for adding hostnames and rotating credentials
See it working