Cloudflare opens Threat Signals to every account
Cloudflare is giving away the threat-intelligence platform it built for its own analysts, and turning open-source security reporting into something a web application firewall can act on.

Cloudflare has opened the threat-intelligence platform that its own Cloudforce One analysts use to every Cloudflare account, and it is not charging for the entry tier. Threat Signals launched on 29 September, during the company's Birthday Week, and turns open-source security reporting into structured, tagged intelligence that can be pushed straight into a firewall policy.
The company also made its Threat Events Platform free for all accounts, expanding an offering that was previously reserved for enterprise customers. Cloudforce One, Cloudflare's threat research arm, described the change as a way to let organisations scale threat-intelligence expertise the way they already scale infrastructure.
What the free tier actually includes
A free account gets API and dashboard access to Threat Signals, the ability to point it at one RSS feed, and a private dataset built from that feed and stored for up to 30 days. API and dashboard access to the Threat Events Platform comes with it, so a defender can investigate the events, indicators and tags that land in that dataset.
Essentials, Advantage and Elite customers can extend the setup with more RSS feeds, access to Cloudforce One's proprietary datasets, custom agentic skills, more storage for the derived reporting, and the ability to build custom WAF rules from both open-source and proprietary threat events.
Why unstructured reporting is the hard part
Automated threat feeds have been part of security stacks for years. The awkward part has always been everything that is not structured: a research post that explains a campaign has to be read, summarised, stripped of its indicators, normalised, tagged against an internal taxonomy, pushed into a threat-intelligence platform and then shared with the rest of the team. Almost every step is human judgement, and context is usually lost on the way, which is how a domain ends up on a blocklist weeks later with nobody able to say why.
Threat Signals uses agentic skills — detailed instruction sets that capture how an experienced analyst handles one part of the job — to run that process the same way on every report. Feeds can be added as RSS 2.0, Atom or RSS 1.0, and each one is polled on a schedule. The article text is fetched and cleaned into markdown, passed through an indicator-of-compromise extractor and Cloudforce One's default skills, and returned as a summary with key points, tags and indicators that stay linked to the original report. The result becomes a threat event inside the account's own private dataset, ready to be applied in a WAF policy.
Our opinion
Free threat intelligence is not a new idea, and most of what gets given away is a feed with a logo on it. The interesting part here is where Cloudflare drew its lines. It will not let the model invent tags, restricting automatic tagging to the vocabulary an account already uses, and it records whether each tag came from an agent or an analyst. Those are the decisions of a team that expects security people to argue with the output rather than swallow it, and they are a better signal of intent than the price tag.
The 30-day retention on the free tier is the honest catch. Open-source reporting is published once and then quietly rots, so a month of history is enough to prove the workflow and not much else, and the companies most likely to need contextualised intelligence are often the ones least able to afford the tiers above it. Cloudflare has made a genuinely useful thing free; it has also made sure the version worth relying on is the one you pay for.