AI Briefing
Sign in

Cloudflare Launches Application Profiles to Enforce Positive Security via Schema Validation

·2026.09.29 22:00

Key point

Cloudflare has launched Application Profiles, a new feature that extends Schema Learning and Validation to web applications, allowing customers to enforce positive security policies by blocking traffic that deviates from learned request structures.

Details

Cloudflare's new Application Profiles feature enables positive security enforcement for web applications by analyzing HTTP request structures and identifying non-conforming traffic. Building on existing Schema Learning and Validation for APIs, the system learns expected request patterns—including path variables, query parameters, and body structures—by observing traffic. Operations require at least 1,000 successful requests to begin learning, with data boundaries refined after 10,000 requests. The validation results are exposed via the cf.schema_validation.learned.violated field, allowing customers to create Security Rules that block requests violating learned schemas, such as those with invalid UUIDs or unexpected characters. A new Profile Analysis tab in Security Analytics helps customers review violations and distinguish between malicious activity and legitimate application changes. The feature is currently available to customers with API Security, while a closed beta is open to invited Enterprise customers without it. Future updates will include LLM-driven contextual insights to help prioritize critical fields.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.