Technical audit · 2026-08-16

www.cloudflare.com

Infrastructure and cloud company Cloudflare

The infrastructure company Cloudflare — 803 requests, 9 nodes, an 88-second recording, seven of the nodes being Cloudflare's own infrastructure. Beyond it, no data goes out in this recording: there are no requests to Google Analytics or advertising recipients. The consent mechanism — OneTrust — is present and self-hosted on the first party. The only third-party node, Google Tag Manager, loads in health-check mode and pulls in no tags. Security headers are set in a full set. No violations were recorded.

Timeline of the leak

+0 ms · loading the home page
The recording begins on cloudflare.com, with a redirect to www.cloudflare.com. Served through Cloudflare (cf-ray, server: cloudflare). A full set of security headers is set: strict transport with subdomain inclusion, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban, the referrer policy strict-origin-when-cross-origin, a permissions policy banning geolocation, camera and microphone, and a content-security-policy. The browser was sending the DNT: 1 header.
+643…+1369 ms · consent platform from the markup
From the page markup, OneTrust starts, self-hosted on the first party: ot.www.cloudflare.com delivers the SDK stub, the consent settings and the banner SDK. The domain is served by Cloudflare's infrastructure; the consent-configuration data does not go to a third-party domain.
+692 ms · own measurement
static.cloudflareinsights.com — Cloudflare's own performance measurement.
+2173 ms · Google Tag Manager loader
www.googletagmanager.com/gtm.js?id=GTM-NDGPDFZ with the marker gtg_health=1 — the container loader in health-check mode. Throughout the recording the container pulled in not a single tag: no requests to Google Analytics, advertising or other third-party recipients initiated by it were recorded.
+23957…+76675 ms · navigation across sections
Navigation across the plans, contact-enterprise-sales, sase and policies/privacy pages. On the contact-form page Cloudflare Turnstile (challenges.cloudflare.com) fires — an own check in place of a CAPTCHA. OneTrust re-initialises on each page, with still no third-party transmissions.

Declared versus actual

Controller — Cloudflare, Inc.; cookie policy, last updated 19 October 2023 — заявлен
Four categories of cookies: strictly necessary, functional, performance, targeting; strictly necessary cannot be turned off — заявлен
Choice management — the 'Cookie Preferences' link (in the United States, 'Your Privacy Choices') in the site footer — заявлен
Google Analytics and Google Tag Manager are named directly, with the purpose of tracking behaviour and opt-out links — заявлен
Bizible and Demandbase are also named, with descriptions and links — заявлен
The own Zaraz product is described: loading third-party tools on the Cloudflare-network side, not in the user's browser — заявлен
Opt-out mechanisms are provided for each analytics and targeting technology — заявлен

Transfer timings

+643 ms ot.www.cloudflare.com

OneTrust self-hosted on Cloudflare's infrastructure, 26 requests.

+692 ms static.cloudflareinsights.com

Cloudflare's own performance measurement.

+2173 ms www.googletagmanager.com

Container GTM-NDGPDFZ in health-check mode gtg_health=1; pulled in no tags.

+5779 ms privacyportal.onetrust.com

Recording of consent by the OneTrust platform.

+37838 ms challenges.cloudflare.com

Cloudflare Turnstile, fires on submission of the contact form.

Detected trackers

Context

www.cloudflare.com is the site of Cloudflare, Inc., a provider of content-delivery, security and cloud infrastructure. The controller in the policy is Cloudflare, Inc. The site is served through Cloudflare’s own infrastructure (cf-ray, server: cloudflare).

The recording: 803 requests, 9 nodes, a recording length of 88.2 seconds, taken on 16 August 2026. Of the nine nodes, seven belong to Cloudflare’s own infrastructure: the main domain, the subdomain of the self-hosted consent platform ot.www.cloudflare.com, challenges.cloudflare.com and brunhild.challenges.cloudflare.com (Turnstile), static.cloudflareinsights.com, cdn.cookielaw.org (OneTrust resources). There are two third-party nodes: Google Tag Manager and privacyportal.onetrust.com — the OneTrust consent-recording endpoint. The session runs across the plans, contact-enterprise-sales, sase pages and the privacy-policy page.

The processing of the site side is described by Cloudflare’s cookie policy, last updated 19 October 2023.

Who receives data directly

Beyond Cloudflare’s infrastructure — only Google Tag Manager (a loader, without tags) and the OneTrust consent-recording endpoint.

Declared versus actual

The policy discloses analytics and advertising technologies. Unlike the typical discrepancy, here the document names the recipients directly. The cookie policy lists four categories and describes Google Analytics and Google Tag Manager by name, with the purpose “tracks user behaviour”, provides Bizible and Demandbase, and for each technology gives an opt-out link. Separately it describes the own Zaraz product, which loads third-party tools on the Cloudflare-network side rather than in the user’s browser.

The actual composition of requests is narrower than what is declared. In this recording, of the analytics and advertising technologies named in the policy only the Google Tag Manager loader fired, and that in health-check mode (gtg_health=1), and it pulled in not a single tag. No requests to Google Analytics, to advertising or other third-party recipients were recorded across 803 requests. That is, the site’s actual behaviour at the moment of the recording is more modest than what the policy permits.

The consent mechanism is present and self-hosted. OneTrust is loaded from the markup in the first seconds, delivering the banner SDK and the consent settings from the subdomain ot.www.cloudflare.com, that is, from the first party rather than from an external OneTrust domain. The consent record goes to privacyportal.onetrust.com at +5779 ms. Choice management is placed in the site footer via the “Cookie Preferences” link (in the United States, “Your Privacy Choices”), as declared in the policy.

Security headers are set in a full set. The site sets strict transport with subdomain inclusion, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban, the referrer policy strict-origin-when-cross-origin, a permissions policy banning geolocation, camera and microphone, and a content-security-policy. This is the fullest set among the sites analysed.

The form check is on the own infrastructure. On submission of the contact form, Cloudflare Turnstile (challenges.cloudflare.com) fires — an own check in place of a third-party CAPTCHA, so the check data does not go to an external provider.

Proven: the consent mechanism is present and works on the first party. The OneTrust requests are read from the recording: the SDK stub, the consent settings, the banner SDK — all from ot.www.cloudflare.com. The consent record goes to the OneTrust endpoint at +5779 ms.

Proven: there are no third-party analytics or advertising transmissions in the recording. Across 803 requests not a single request to Google Analytics or advertising recipients was recorded. The only third-party loader, Google Tag Manager, works in health-check mode and pulls in no tags.

Noted: the Google Tag Manager loader precedes the consent record. The request to googletagmanager.com goes out at +2173 ms, the consent record at +5779 ms. The loader, however, carries the health-check marker gtg_health=1 and transmits no analytics data. As a standalone violation this is not recorded, since no data transmission followed the loader; it is noted as the only place where a third-party script is initiated before consent is recorded.

Not proven and not asserted: the behaviour of the tags with consent given. Which tags the Google Tag Manager container would have loaded with active consent to analytics or targeting cookies is not established from this recording — at the moment of capture it did not load them. The policy permits Google Analytics and other technologies, but the recording contains no actual firing of them.

Not proven and not asserted: the state of cookies on the device. Cookie headers and response bodies were removed from the published file during sanitisation.

Separately: the browser was sending the DNT: 1 header during capture. This had no effect on the composition and addressing of the requests.

Boundaries of observation

The recording covers several pages of the site, including the contact form and the privacy-policy page. The observation records the browser’s behaviour, not the services’ internal workings: server-side processing, contractual relationships with recipients and settings on their side are not verified by a browser recording.

Two levels should be distinguished separately. This analysis concerns the behaviour of the site www.cloudflare.com as the operator of its own web resource. Cloudflare’s role as an infrastructure provider for other sites — the content-delivery network, the _cf_bm and _cfuvid cookies, the serving of third-party content — is a separate level of processing in the capacity of a processor for third-party operators, and it is not assessed by this recording of the own site.

The file is published sanitised of personal data: cookie headers in requests, response bodies and the body of the OneTrust consent record were removed. The conclusion about the absence of third-party transmissions rests on the network level — the composition, addresses and initiators of all 803 requests are read from the recording, and among them there are no requests to analytics or advertising recipients beyond Cloudflare’s infrastructure.

The identification of services rests on domains and address patterns: OneTrust — by onetrust.com, cookielaw.org and the paths ot/scripttemplates, consentreceipts; Google Tag Manager — by googletagmanager.com and the gtg_health marker; Cloudflare Insights — by cloudflareinsights.com; Turnstile — by challenges.cloudflare.com; the serving provider — by the cf-ray and server: cloudflare headers.

Conclusion

On Cloudflare’s own site, at the moment of the recording, no data goes beyond the company’s infrastructure: there are no requests to Google Analytics or advertising recipients, and the only third-party loader — Google Tag Manager — works in health-check mode and pulls in not a single tag. The OneTrust consent mechanism is present, self-hosted on the first party, and records consent. The cookie policy discloses the analytics and advertising technologies by name, with opt-out mechanisms. Security headers are set in a full set, and the form check runs on the own Turnstile.

The only point worth attention is the Google Tag Manager loader, which is initiated before consent is recorded; however, it carries the health-check marker and transmits no data, so it is not recorded as a violation. On the results of the recording, no violations were recorded.

The analysis concerns the behaviour of the Cloudflare site as the operator of its own resource and does not assess Cloudflare’s role as an infrastructure provider for other sites — that is a separate level of processing requiring separate consideration.

Evidence
Original (audit)
HAR file: global/cloudflare-com-2026-08-16.har
SHA-256: 977d3a3a26d37110c68338ba714ac9bff2b494c91a535862c5371c5e7eac4313
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.