Cloudflare · Internal Competitive One-Pager

Included Health/Competitive Landscape

Who we compete with, by product category — mapped against Included Health's actual observed stack. Every incumbent claim below is backed by a live HTTP header, DNS record, or CSP directive. Nothing is assumed.

Prepared 2026-08-06
Owner A. Geiser
Evidence public recon + SFDC
Positioning wiki/CI Hub
Account status
Prospect — not a customer2 duplicate SFDC records; merge before building pipeline
Industry
Hospital & Health CareVirtual care / navigation; HIPAA covered entity
Open opportunities
3Zero Trust (10/18) · AI Gateway (10/13) · CF1 pre-pipeline (10/19)
Closed lost
32022 ZT · 2022 · 2024 "DNS/WAF + ZT Suite, DLP"
Hosting posture
100% AWS us-east-1EKS + Istio/Envoy + ALB; Route 53 authoritative DNS
Status key Confirmed incumbent — displacement target Not externally detectable — discovery required No footprint found — greenfield or non-competitive
01

Application Security / Performance

Cloudflare: CDN · WAF · DDoS · Bot Mgmt · API Shield · Page Shield · Auth DNS · Cloudflare for SaaS · Load Balancing

The headline: there is no Akamai, Fastly, Imperva, or F5 to rip out. Your competitor in this category is AWS bundling plus internal platform engineering. That is a harder fight than a vendor displacement — the objection is "we already have this in AWS," not "we already bought someone else."

AWS

CloudFront · WAF · Shield · R53 · ALB

Incumbent
Evidence via: 1.1 …cloudfront.net + x-amz-cf-pop: ATL59-P2 on care-app-cdn. CSP allows d2vqbi7vtsc2p9.cloudfront.net. NS = ns-*.awsdns-*. fasv2k8s-istiosys-*.us-east-1.elb.amazonaws.com.

How we win

  • All services, all locations. No regions to reason about. AWS is region-bound by design.
  • Inspect once. Composable architecture applies every policy in one pass; AWS chains services and adds latency at each hop.
  • We protect apps wherever they live. AWS only secures what's hosted in AWS.
  • Unmetered DDoS. AWS bills you for attack traffic.
  • Predictable spend. We use data caps and share overage risk; the AWS meter simply keeps running.
  • Security is a compliance checkbox in AWS's business model — their product reflects that.

Akamai

CDN · App & API Protector

Not found
Evidence No Akamai headers on any tested host — no x-akamai-*, no akamaighost, no *.edgekey.net / *.akadns.net in DNS.

If they appear in an RFP

  • 31 acquisitions → a zoo of admin UIs and overlapping tech. Professional Services is effectively a mandatory line item; we onboard in days.
  • Manual DDoS scrubbing. A share of traffic is diverted to scrubbing centers, degrading app performance. We block at every data center closest to the source — no security/performance tradeoff.
  • Add-on and location premiums. Every Cloudflare service ships from every edge at no extra cost. We are #1 on authoritative DNS performance.
Live play: Akamai Pricing Takeout campaign is running for renewals Q3'26–Q3'27 (5K accounts).

Fastly

CDN · Next-Gen WAF (Signal Sciences)

Not found
Evidence No x-served-by / x-fastly-* / Varnish headers on any tested host.

If they appear in an RFP

  • VCL tax. Advanced config requires programmers. A single app with zero customization already emits ~400 lines of VCL — which makes delegating to a security team painful.
  • 80 locations, no private backbone, no China presence. We run 330 locations plus Argo Smart Routing.
  • Still two systems in 2026. Fastly's CDN and WAF remain separate; R&D has been flat since 2022.
  • They will steer to purge speed (claiming 150 ms) — we shipped instant purge in 2024.

Imperva

Cloud WAF · DDoS · Bot · API Sec

Not found
Evidence No incap_ses / visid_incap cookies, no x-iinfo header, no Incapsula DNS delegation.

If they appear in an RFP

  • Thales owns them ($3.6B). Integration work is an internal distraction we can exploit.
  • On-demand scrubbing only — which adds latency to legitimate requests too. Ours is always-on in every location.
  • Two deployment modes that don't talk. Imperva on-prem and Imperva cloud have unequal capabilities and separate management.
Coming: Imperva Takeout campaign, Q2 FY26. WAF, App Services, Magic Transit, and API Shield comparison decks all refreshed Aug–Sep 2025.

F5

BIG-IP · Distributed Cloud (DCS)

Not found
Evidence No BIGipServer* cookies, no x-cnection quirk, no F5 DCS edge. They are 100% AWS-hosted — there is no appliance fleet here.

If they appear in an RFP

  • Truly cloud-native. F5 papered over a late cloud entry with acquisitions; BIG-IP → DCS is a steep relearn. Skip straight to cloud-delivered.
  • ~11× larger footprint than F5 DCS, with a 10-year head start. All services from all locations; F5 has specialized ones.
  • Say goodbye to the box — no hardware refresh cycles, firmware upgrades, or EOL notices.
Note: the real F5 analogue at Included Health is their self-managed Istio/Envoy ingress — a DIY BIG-IP. Sell against the operational burden, not against F5.
Highest-value gapWhat the evidence showsCloudflare product
app + apiserver: istio-envoy fronting the PHI-bearing member app and API, with no WAF, no bot management, and no API discovery detectable in front of it.WAF, Bot Management, API Shield, DDoS — highest-severity finding in the account
per-tenant hostswex-mcd-fas, pnc-penske-fas, fasv2 — customer-branded hostnames for WEX/McDonald's and PNC/Penske, on hand-managed Sectigo certs.Cloudflare for SaaS — quantifiable ops pain, zero vendor to displace
client-sideMarketing CSP is effectively absent: default-src * with 'unsafe-inline' 'unsafe-eval', while Amplitude, Mixpanel, DoubleClick, and Qualtrics all load client-side.Page Shield, Zaraz
auth DNSRoute 53 is authoritative. Without Cloudflare DNS there is no Cloudflare data plane — this is the anchor for everything above.Authoritative DNS
02

Developer Platform

Cloudflare: R2 · Realtime (SFU/TURN) · Containers · Workers · Durable Objects · Queues · AI Gateway

Why this category matters most right now: docs.agent-platform.includedhealth.com and docs.dot-chat.includedhealth.com are live, and they have verified Anthropic and Cursor domains. They are building AI agents today — which lines up exactly with the open AI Gateway opp closing 10/13.

AWS S3

vs. Cloudflare R2

Incumbent
Evidence server: AmazonS3 and x-amz-bucket-region: us-east-1 on practitioner-cdn.includedhealth.com, served through CloudFront.

How we win

  • $0 egress vs $0.09/GB. 10 TB/month out of S3 is $900/mo in egress alone. From R2 it is $0. This is the single most disruptive pricing decision in cloud storage.
  • 35% cheaper storage — $0.015/GB-mo vs $0.023.
  • Operations are orders of magnitude cheaper. Class A: $4.50/M vs S3's $5.00 per thousand. Class B: $0.36/M vs $0.40 per thousand.
  • No hyperscaler can match zero egress without cannibalizing their own core revenue.
Do not overstate this. R2 egress is free, but enterprise CDN data transfer still bills per their CDN contract. Never tell an enterprise buyer that serving R2 assets to end users is free. The zero-egress story is strongest for API/backend access patterns — exactly the practitioner-cdn and imaging workloads here.

WebRTC

vs. Cloudflare Realtime — SFU · TURN

Discovery
Evidence wss://*.sendbird.com in the app CSP confirms Sendbird for chat. Video-visit vendor is not externally identifiable — but Doctor on Demand heritage means real-time video is core to the product.

Who we displace

  • Twilio — mature SDKs, PSTN/cellular gateways. $0.004/participant/min.
  • Agora — low/no-code SDKs, extensions marketplace. $0.00399/min.
  • LiveKit — self-hosted, open-source foundations.
  • Daily.co / 100ms — DX-led challengers.
  • Self-hosted TURN — in practice the #1 competitor, not another vendor.

How we win

  • ~50% cheaper — RealtimeKit at $0.002/min video is roughly half of Agora and Twilio.
  • At SFU level ($0.05/GB) the gap widens: internal estimates show ~60% savings vs Agora and ~72% vs LiveKit Cloud.
  • TURN is $0.05/GB with a 1,000 GB free tier; STUN is free and unlimited; TURN↔SFU and TURN↔Stream traffic is never billed.
HIPAA gate: BAA and compliance scope for Realtime must be confirmed through the enterprise account team before this is positioned for any PHI-bearing video visit.

Containers

vs. AWS EKS · Fargate · ECS

Incumbent
Evidence AWS EKS confirmed. server: istio-envoy across app, api, looker.data; k8s-istiosys-servicef-*.elb.amazonaws.com; a dedicated observability-cn1ts.production cluster.

How we win

  • No cluster to run. They are maintaining EKS, Istio, Envoy, service meshes, and their own gateway tier. Containers removes that operational surface entirely.
  • $0.000020/vCPU-s + $0.0000025/GiB-s, billed per 10 ms of active runtime — no idle cost.
  • Custom instance types GA (Jan 2026) and resource limits raised 15× (Feb 2026) — the historic "too small" objection is gone.
  • Pairs with Workers for the agent workloads they are already building.
Be honest: Containers are not edge-deployed, and Workers has a 128 MB memory ceiling with no native container support. Lambda does 10 GB and any runtime. Lead with operational burden and the agent platform, not raw compute specs.
Also in playIncumbent / competitorSignal at Included Health
AI GatewaySelf-built LLM proxy, LiteLLM, Portkey, Helicone, Langfuse, AWS BedrockOpen opp, closing 10/13. docs.agent-platform + docs.dot-chat live; Anthropic and Cursor domains verified
WorkersAWS Lambda / EKSWorkers at $0.30/M requests is 50% cheaper than Lambda@Edge and Vercel Functions at $0.60/M; ~0 ms cold start vs 100–500 ms
D1 / HyperdriveAWS Aurora / RDS / DynamoDBKnown weakness. D1 is SQLite — 10 GB cap, no stored procedures. Do not take this into an enterprise relational bake-off
VectorizePinecone, Weaviate, pgvector on RDS, OpenSearchUnknown — pair with the AI Gateway discovery
Images / StreamCloudinary, imgix, MuxNo fingerprint found. Ambra Health (*.dicomgrid.com) handles medical imaging
03

Zero Trust

Cloudflare One: Access (ZTNA) · Gateway (SWG/DNS) · CASB · DLP · Browser Isolation · DEX

We are 0-for-2 here — Closed Lost in 2022 and again in 2024 on "DNS/WAF + ZT Suite, DLP" — and there is no external evidence of either vendor below. vpn.includedhealth.com resolves only to the *.includedhealth.com wildcard, which proves nothing. Do not re-pitch until you know what they actually bought in 2024. Note also that Gartner lists Healthcare as a primary target industry for both Zscaler and Prisma Access — assume both are calling on this account.

Zscaler

ZIA · ZPA · ZDX

Discovery
Evidence No Zscaler CNAMEs, no *.zscaler*.net delegation, no ZPA connector footprint. $2.6B revenue FY25 (+23% YoY), 9,600 customers, ~7,900 employees. ZIA alone is 50–60% of revenue.

How we win

  • Every Zscaler product has its own cloud, delivered from a subset of locations. Their rigid purpose-built architecture slows innovation and produces inconsistent service delivery.
  • 600+ data centers across 300+ locations vs 160 for Zscaler — and only ~80 per tenant, so 4× more Cloudflare locations in practice.
  • One UI that is actually one UI. "Zscaler Experience" is a unified front end over policies that remain separate underneath.
  • 100% cloud-delivered, no on-prem requirement.
  • Gartner cautions: complex price list, periodic licensing changes, and latency complaints relative to peers.
Assume they've already been here. CI guidance is explicit: always assume Zscaler has talked to your SASE prospect. Their motion is early-career reps running a highly templatized prospecting process. Run the "coexist" campaign, not a rip-and-replace — lower the barrier, land remote access, expand later.

Palo Alto Networks

Prisma Access · GlobalProtect · Prisma SD-WAN

Discovery
Evidence No Prisma Access or GlobalProtect portal fingerprint. $9.2B revenue (2025), ~16,000 employees, ~100,000 customers — mostly NGFW. Prisma Access is the one product we actually compete with.

How we win

  • 300+ locations vs ~40 compute locations. Prisma must haul traffic from 100+ on-ramps to a compute location before any processing happens.
  • Data sovereignty. Some Prisma services only run in certain locations. Every Cloudflare One service runs in every location.
  • No anycast — customers manually pick a termination location for each IPsec tunnel. Permanent ops tax, weak failover.
  • Two consoles: Panorama for legacy firewall customers, Strata Cloud Manager for greenfield. We have one.
  • They resell Google's cloud. Prisma Access runs 100% on hyperscalers — mostly GCP. PANW stacks its margin on top of Google's. Ours runs on our own network.
  • Gartner cautions: complex licensing, inflated pricing mid-motion, and it "appeals primarily to existing customers."
Best wedge = GlobalProtect, not Prisma. GlobalProtect is an NGFW add-on subscription, so a large installed base is stuck on legacy VPN while PANW pushes an expensive Prisma migration. Land ZTNA against the VPN first. Do not open on CASB or DLP — our own CI concedes Prisma SaaS is more mature there, and the DLP closed-lost register is full of inline-only losses.
04

Email Security

Cloudflare: Email Security (Area 1) · Outbound MTA · DMARC Management

Cleanest gap in the account. MX is Google-only and SPF contains no security gateway: v=spf1 mx include:_spf.salesforce.com include:_spf.google.com include:sendgrid.net include:…hubspotemail.net include:spf.virtrugateway.com include:docebosaas.com ~all. A HIPAA covered entity handling PHI is running Google Workspace native plus Virtru encryption and nothing else inline. DMARC is at p=reject via dmarcian — so they already care about email trust, which is your opening.

Abnormal AI

API-deployed · no MTA

Cannot rule out
Evidence Critical caveat: Abnormal deploys via Graph API, not via MX or SPF. Its absence from DNS is not evidence of absence. This one must be asked directly.

How we win

  • They have no MTA. No outbound relay, no deliverability management, no enterprise-scale mail processing, no comprehensive compliance logging. A specialized point solution, not a platform.
  • Genuinely strong at behavioral AI detection of BEC, vendor email compromise, and account takeover — concede that and compete on platform scope.
  • Strong Microsoft partnership and Azure Marketplace presence.
POC integrity warning. Abnormal is known to curate POC results — restricting access for the first 1–2 weeks and sending out-of-band reports. The architectural asymmetry is real: we use journal/BCC of external mail only, while their Graph API deployment scans all inbound and internal mail, can look back at already-delivered messages, and can tune a detection in after delivery. Set POC terms up front — follow the CES Abnormal POC process.

Mimecast

Legacy cloud SEG

Not present
Evidence A SEG must appear in MX or the outbound relay path. MX is aspmx.l.google.com only; SPF has no Mimecast include. Reliably ruled out.

How we win

  • Full relay dependency — all outbound mail routes through their infrastructure.
  • Broad suite (threat, DLP, encryption) marketed on a single unified console.
  • Detection is a hybrid of traditional techniques and newer AI/ML — not AI-native.
  • Powerful but rigid, unforgiving policy engine — the most common source of admin friction.

Proofpoint

Legacy cloud SEG on Sendmail

Not present
Evidence No pphosted.com MX, no Proofpoint SPF include. Reliably ruled out.

How we win

  • Built on the Sendmail MTA — genuinely deep, granular routing and policy control. Respect it in complex enterprise environments.
  • But detection leans on signatures and reputation analysis, which makes it slow to react to zero-day exploits and malware-less threats like BEC.
  • DLP and encryption are robust but notoriously complex add-on modules.
AdjacentWhat's there todayCloudflare angle
VirtruSPF include:spf.virtrugateway.com + virtru-site-verify TXT. Solves encryption, not inline threat detection or DLP.Not a competitor to displace — a gap indicator. Nothing inline is inspecting mail
dmarcianDMARC at p=reject, reporting to ag.us.dmarcian.com.DMARC Management — a low-friction consolidation wedge and a proof point that email trust already has an internal owner
Outbound sendersSendGrid (Twilio), Salesforce Marketing Cloud (cloud./click./view./image.e), HubSpot, Docebo — four separate sending paths.Outbound MTA — sprawl to consolidate; also a brand-impersonation surface
Sublime SecurityNot detected. Developer-focused, custom MQL detection rules.Pure detection and response — no MTA for sending, routing, or deliverability