Cloudflare has rolled out a new security feature designed to enforce positive security policies by learning the expected structure of HTTP requests. Application Profiles, currently in closed beta for Enterprise customers, allows organizations to block traffic that deviates from observed patterns without requiring predefined attack signatures. The tool extends Cloudflare’s existing Schema Learning and Validation capabilities from APIs to web applications, offering an automated approach to reducing attack surfaces amid rising concerns about AI-generated threats.
How the tool works
Application Profiles analyzes live traffic to determine the expected structure of HTTP requests, including path variables, query parameters, headers, cookies, and request bodies. The system learns data types (such as integers, strings, UUIDs, and enums) and constraints like numeric ranges, string lengths, and character classes. Once a profile is established, Cloudflare flags requests that do not conform to the learned schema, adding metadata to indicate violations. Customers can review these violations in Security Analytics before deciding whether to enforce blocking rules.
The learning process requires a minimum of 1,000 successful requests (2xx responses) over seven days to identify fields and 10,000 requests to establish data boundaries. Profiles update weekly to reflect changes in application traffic, though customers can manually export and pin schemas if needed. The tool supports JSON and form-encoded request bodies but does not currently handle multipart forms, GraphQL, or XML. Cloudflare also plans to introduce on-demand learning and the ability to exclude automated traffic from profile generation.
Background: Positive security models enforce policies based on what is known to be safe, rather than attempting to block all known malicious patterns. This approach reduces reliance on signature-based detection, which can struggle to keep pace with evolving attack techniques, particularly those generated by AI tools.
Practical applications and limitations
Application Profiles can identify a range of deviations, such as malformed UUIDs, unexpected characters in query parameters, or values outside learned ranges. For example, if a search field expects alphanumeric input, the tool can block requests containing special characters, mitigating common attack vectors like SQL injection or cross-site scripting. However, non-conforming requests are not inherently malicious—new application releases, unusual but valid requests, or changes in client behavior can also trigger violations. Cloudflare recommends starting in observation mode to assess the impact before enabling enforcement.
The tool provides granular control over enforcement. Customers can create Security Rules to block non-conforming requests at the application, path, or field level. Metadata fields indicate where violations occurred (e.g., query parameters, headers) and whether undeclared parameters were detected. This allows teams to tailor rules to specific operations or exclude certain fields from enforcement. For instance, a rule could block requests where the product_id query parameter violates the learned schema while allowing other deviations.
Operational challenges and future enhancements
Deploying positive security at scale presents operational complexities, particularly for large applications with thousands of operations and fields. Cloudflare acknowledges this challenge and is developing tools to help prioritize enforcement. Upcoming features include LLM-powered insights to contextualize learned profiles, identifying critical fields (such as those linked to authentication or account management) and recommending targeted mitigations. For example, the system could highlight fields like clientId or account_number and suggest rate-limiting rules to defend against brute-force attacks.
Cloudflare also plans to introduce metrics to rank operations by risk, such as unusual data transfer trends, reconnaissance activity, or business criticality. These metrics will help security teams focus on high-priority areas first. Additionally, the company is exploring the use of Application Profiles to learn other characteristics of expected traffic, such as autonomous system numbers (ASNs) or JA4 fingerprints, further refining the definition of "good" traffic.
Availability and next steps
Application Profiles is available now to customers with Cloudflare’s API Security offering. A closed beta is open to invited Enterprise customers without API Security, allowing them to test the feature on production web applications. Participants can provide feedback on profile accuracy, analytics, and enforcement controls. Access is by invitation only and does not guarantee future availability. Interested customers are advised to contact their account teams for details.
Companies mentioned
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 29 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 11 candidates
- Checking for duplicates — New story No prior coverage of Cloudflare's Application Profiles for positive security.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers Cloudflare's Application Profiles for positive security.
- Writing the article — Draft created article_id=622 slug=cloudflare-launches-application-profiles-for-positive-security
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states 'Application Profiles, currently in closed beta for Enterprise customers' — the source specifies it is available to customers with API Security and a closed beta for invited Enterprise customers without API Security. The phrasing in the draft could imply all Enterprise customers are in closed beta, which is not strictly accurate.
- Style compliance: The draft uses 'Application Profiles' in the headline, but the source refers to 'Application Schema Profiles' in some places. While the draft is consistent in using 'Application Profiles', the source's full name is not used, which could cause minor confusion for readers cross-referencing the source.
- No copied phrasing: The draft's 'Background' block closely paraphrases the source's explanation of positive security models but does not copy phrasing verbatim. This is acceptable, but the phrasing is very similar in structure to the source's 'What if you could learn what good requests look like...' section. Consider restructuring further to avoid echoing the source's flow.
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image reused image #16
- Linking related stories — Linked 4 relations from 323 candidates
- Linking related stories — Linked 4 relations from 324 candidates
- Publishing — Published cloudflare-launches-application-profiles-for-positive-security
- Mastodon — Posted https://mstdn.social/@hostingpaper/117354953529628328




Discussion · coming soon
Be the first to join the thread when community discussion launches.