Application Security / Performance
Cloudflare: CDN · WAF · DDoS · Bot Mgmt · API Shield · Page Shield · Auth DNS · Cloudflare for SaaS · Load BalancingThe headline: there is no Akamai, Fastly, Imperva, or F5 to rip out. Your competitor in this category is AWS bundling plus internal platform engineering. That is a harder fight than a vendor displacement — the objection is "we already have this in AWS," not "we already bought someone else."
AWS
CloudFront · WAF · Shield · R53 · ALB
via: 1.1 …cloudfront.net + x-amz-cf-pop: ATL59-P2 on care-app-cdn. CSP allows d2vqbi7vtsc2p9.cloudfront.net. NS = ns-*.awsdns-*. fasv2 → k8s-istiosys-*.us-east-1.elb.amazonaws.com.
How we win
- All services, all locations. No regions to reason about. AWS is region-bound by design.
- Inspect once. Composable architecture applies every policy in one pass; AWS chains services and adds latency at each hop.
- We protect apps wherever they live. AWS only secures what's hosted in AWS.
- Unmetered DDoS. AWS bills you for attack traffic.
- Predictable spend. We use data caps and share overage risk; the AWS meter simply keeps running.
- Security is a compliance checkbox in AWS's business model — their product reflects that.
Akamai
CDN · App & API Protector
x-akamai-*, no akamaighost, no *.edgekey.net / *.akadns.net in DNS.
If they appear in an RFP
- 31 acquisitions → a zoo of admin UIs and overlapping tech. Professional Services is effectively a mandatory line item; we onboard in days.
- Manual DDoS scrubbing. A share of traffic is diverted to scrubbing centers, degrading app performance. We block at every data center closest to the source — no security/performance tradeoff.
- Add-on and location premiums. Every Cloudflare service ships from every edge at no extra cost. We are #1 on authoritative DNS performance.
Fastly
CDN · Next-Gen WAF (Signal Sciences)
x-served-by / x-fastly-* / Varnish headers on any tested host.
If they appear in an RFP
- VCL tax. Advanced config requires programmers. A single app with zero customization already emits ~400 lines of VCL — which makes delegating to a security team painful.
- 80 locations, no private backbone, no China presence. We run 330 locations plus Argo Smart Routing.
- Still two systems in 2026. Fastly's CDN and WAF remain separate; R&D has been flat since 2022.
- They will steer to purge speed (claiming 150 ms) — we shipped instant purge in 2024.
Imperva
Cloud WAF · DDoS · Bot · API Sec
incap_ses / visid_incap cookies, no x-iinfo header, no Incapsula DNS delegation.
If they appear in an RFP
- Thales owns them ($3.6B). Integration work is an internal distraction we can exploit.
- On-demand scrubbing only — which adds latency to legitimate requests too. Ours is always-on in every location.
- Two deployment modes that don't talk. Imperva on-prem and Imperva cloud have unequal capabilities and separate management.
F5
BIG-IP · Distributed Cloud (DCS)
BIGipServer* cookies, no x-cnection quirk, no F5 DCS edge. They are 100% AWS-hosted — there is no appliance fleet here.
If they appear in an RFP
- Truly cloud-native. F5 papered over a late cloud entry with acquisitions; BIG-IP → DCS is a steep relearn. Skip straight to cloud-delivered.
- ~11× larger footprint than F5 DCS, with a 10-year head start. All services from all locations; F5 has specialized ones.
- Say goodbye to the box — no hardware refresh cycles, firmware upgrades, or EOL notices.
| Highest-value gap | What the evidence shows | Cloudflare product |
|---|---|---|
| app + api | server: istio-envoy fronting the PHI-bearing member app and API, with no WAF, no bot management, and no API discovery detectable in front of it. | WAF, Bot Management, API Shield, DDoS — highest-severity finding in the account |
| per-tenant hosts | wex-mcd-fas, pnc-penske-fas, fasv2 — customer-branded hostnames for WEX/McDonald's and PNC/Penske, on hand-managed Sectigo certs. | Cloudflare for SaaS — quantifiable ops pain, zero vendor to displace |
| client-side | Marketing CSP is effectively absent: default-src * with 'unsafe-inline' 'unsafe-eval', while Amplitude, Mixpanel, DoubleClick, and Qualtrics all load client-side. | Page Shield, Zaraz |
| auth DNS | Route 53 is authoritative. Without Cloudflare DNS there is no Cloudflare data plane — this is the anchor for everything above. | Authoritative DNS |
Developer Platform
Cloudflare: R2 · Realtime (SFU/TURN) · Containers · Workers · Durable Objects · Queues · AI GatewayWhy this category matters most right now: docs.agent-platform.includedhealth.com and docs.dot-chat.includedhealth.com are live, and they have verified Anthropic and Cursor domains. They are building AI agents today — which lines up exactly with the open AI Gateway opp closing 10/13.
AWS S3
vs. Cloudflare R2
server: AmazonS3 and x-amz-bucket-region: us-east-1 on practitioner-cdn.includedhealth.com, served through CloudFront.
How we win
- $0 egress vs $0.09/GB. 10 TB/month out of S3 is $900/mo in egress alone. From R2 it is $0. This is the single most disruptive pricing decision in cloud storage.
- 35% cheaper storage — $0.015/GB-mo vs $0.023.
- Operations are orders of magnitude cheaper. Class A: $4.50/M vs S3's $5.00 per thousand. Class B: $0.36/M vs $0.40 per thousand.
- No hyperscaler can match zero egress without cannibalizing their own core revenue.
practitioner-cdn and imaging workloads here.WebRTC
vs. Cloudflare Realtime — SFU · TURN
wss://*.sendbird.com in the app CSP confirms Sendbird for chat. Video-visit vendor is not externally identifiable — but Doctor on Demand heritage means real-time video is core to the product.
Who we displace
- Twilio — mature SDKs, PSTN/cellular gateways. $0.004/participant/min.
- Agora — low/no-code SDKs, extensions marketplace. $0.00399/min.
- LiveKit — self-hosted, open-source foundations.
- Daily.co / 100ms — DX-led challengers.
- Self-hosted TURN — in practice the #1 competitor, not another vendor.
How we win
- ~50% cheaper — RealtimeKit at $0.002/min video is roughly half of Agora and Twilio.
- At SFU level ($0.05/GB) the gap widens: internal estimates show ~60% savings vs Agora and ~72% vs LiveKit Cloud.
- TURN is $0.05/GB with a 1,000 GB free tier; STUN is free and unlimited; TURN↔SFU and TURN↔Stream traffic is never billed.
Containers
vs. AWS EKS · Fargate · ECS
server: istio-envoy across app, api, looker.data; k8s-istiosys-servicef-*.elb.amazonaws.com; a dedicated observability-cn1ts.production cluster.
How we win
- No cluster to run. They are maintaining EKS, Istio, Envoy, service meshes, and their own gateway tier. Containers removes that operational surface entirely.
- $0.000020/vCPU-s + $0.0000025/GiB-s, billed per 10 ms of active runtime — no idle cost.
- Custom instance types GA (Jan 2026) and resource limits raised 15× (Feb 2026) — the historic "too small" objection is gone.
- Pairs with Workers for the agent workloads they are already building.
| Also in play | Incumbent / competitor | Signal at Included Health |
|---|---|---|
| AI Gateway | Self-built LLM proxy, LiteLLM, Portkey, Helicone, Langfuse, AWS Bedrock | Open opp, closing 10/13. docs.agent-platform + docs.dot-chat live; Anthropic and Cursor domains verified |
| Workers | AWS Lambda / EKS | Workers at $0.30/M requests is 50% cheaper than Lambda@Edge and Vercel Functions at $0.60/M; ~0 ms cold start vs 100–500 ms |
| D1 / Hyperdrive | AWS Aurora / RDS / DynamoDB | Known weakness. D1 is SQLite — 10 GB cap, no stored procedures. Do not take this into an enterprise relational bake-off |
| Vectorize | Pinecone, Weaviate, pgvector on RDS, OpenSearch | Unknown — pair with the AI Gateway discovery |
| Images / Stream | Cloudinary, imgix, Mux | No fingerprint found. Ambra Health (*.dicomgrid.com) handles medical imaging |
Zero Trust
Cloudflare One: Access (ZTNA) · Gateway (SWG/DNS) · CASB · DLP · Browser Isolation · DEXWe are 0-for-2 here — Closed Lost in 2022 and again in 2024 on "DNS/WAF + ZT Suite, DLP" — and there is no external evidence of either vendor below. vpn.includedhealth.com resolves only to the *.includedhealth.com wildcard, which proves nothing. Do not re-pitch until you know what they actually bought in 2024. Note also that Gartner lists Healthcare as a primary target industry for both Zscaler and Prisma Access — assume both are calling on this account.
Zscaler
ZIA · ZPA · ZDX
*.zscaler*.net delegation, no ZPA connector footprint. $2.6B revenue FY25 (+23% YoY), 9,600 customers, ~7,900 employees. ZIA alone is 50–60% of revenue.
How we win
- Every Zscaler product has its own cloud, delivered from a subset of locations. Their rigid purpose-built architecture slows innovation and produces inconsistent service delivery.
- 600+ data centers across 300+ locations vs 160 for Zscaler — and only ~80 per tenant, so 4× more Cloudflare locations in practice.
- One UI that is actually one UI. "Zscaler Experience" is a unified front end over policies that remain separate underneath.
- 100% cloud-delivered, no on-prem requirement.
- Gartner cautions: complex price list, periodic licensing changes, and latency complaints relative to peers.
Palo Alto Networks
Prisma Access · GlobalProtect · Prisma SD-WAN
How we win
- 300+ locations vs ~40 compute locations. Prisma must haul traffic from 100+ on-ramps to a compute location before any processing happens.
- Data sovereignty. Some Prisma services only run in certain locations. Every Cloudflare One service runs in every location.
- No anycast — customers manually pick a termination location for each IPsec tunnel. Permanent ops tax, weak failover.
- Two consoles: Panorama for legacy firewall customers, Strata Cloud Manager for greenfield. We have one.
- They resell Google's cloud. Prisma Access runs 100% on hyperscalers — mostly GCP. PANW stacks its margin on top of Google's. Ours runs on our own network.
- Gartner cautions: complex licensing, inflated pricing mid-motion, and it "appeals primarily to existing customers."
Email Security
Cloudflare: Email Security (Area 1) · Outbound MTA · DMARC ManagementCleanest gap in the account. MX is Google-only and SPF contains no security gateway: v=spf1 mx include:_spf.salesforce.com include:_spf.google.com include:sendgrid.net include:…hubspotemail.net include:spf.virtrugateway.com include:docebosaas.com ~all. A HIPAA covered entity handling PHI is running Google Workspace native plus Virtru encryption and nothing else inline. DMARC is at p=reject via dmarcian — so they already care about email trust, which is your opening.
Abnormal AI
API-deployed · no MTA
How we win
- They have no MTA. No outbound relay, no deliverability management, no enterprise-scale mail processing, no comprehensive compliance logging. A specialized point solution, not a platform.
- Genuinely strong at behavioral AI detection of BEC, vendor email compromise, and account takeover — concede that and compete on platform scope.
- Strong Microsoft partnership and Azure Marketplace presence.
Mimecast
Legacy cloud SEG
aspmx.l.google.com only; SPF has no Mimecast include. Reliably ruled out.
How we win
- Full relay dependency — all outbound mail routes through their infrastructure.
- Broad suite (threat, DLP, encryption) marketed on a single unified console.
- Detection is a hybrid of traditional techniques and newer AI/ML — not AI-native.
- Powerful but rigid, unforgiving policy engine — the most common source of admin friction.
Proofpoint
Legacy cloud SEG on Sendmail
pphosted.com MX, no Proofpoint SPF include. Reliably ruled out.
How we win
- Built on the Sendmail MTA — genuinely deep, granular routing and policy control. Respect it in complex enterprise environments.
- But detection leans on signatures and reputation analysis, which makes it slow to react to zero-day exploits and malware-less threats like BEC.
- DLP and encryption are robust but notoriously complex add-on modules.
| Adjacent | What's there today | Cloudflare angle |
|---|---|---|
| Virtru | SPF include:spf.virtrugateway.com + virtru-site-verify TXT. Solves encryption, not inline threat detection or DLP. | Not a competitor to displace — a gap indicator. Nothing inline is inspecting mail |
| dmarcian | DMARC at p=reject, reporting to ag.us.dmarcian.com. | DMARC Management — a low-friction consolidation wedge and a proof point that email trust already has an internal owner |
| Outbound senders | SendGrid (Twilio), Salesforce Marketing Cloud (cloud./click./view./image.e), HubSpot, Docebo — four separate sending paths. | Outbound MTA — sprawl to consolidate; also a brand-impersonation surface |
| Sublime Security | Not detected. Developer-focused, custom MQL detection rules. | Pure detection and response — no MTA for sending, routing, or deliverability |