If you believe you have found a security vulnerability in Cloudflare's services or infrastructure, please report it through Cloudflare's public disclosure process:
HackerOne: https://hackerone.com/cloudflare
Cloudflare's public bug bounty program is the fastest way to reach the Security team and is monitored 24/7.
This repository contains public compliance metadata only — the FedRAMP Marketplace Certification Package Overview describing our authorized service scope. There is no executable code, no cryptographic implementation, and no infrastructure surface exposed through this repository.
If you have identified an issue with the content of the listing (a service that is out of date, an incorrect Certification-class notation, a scope mismatch versus what you see in the FedRAMP Marketplace), please open a GitHub issue instead of using the security channel — the content is public and non-sensitive.
For questions about controls, boundary, or FedRAMP-scoped incident response for Cloudflare for Government, contact fedramp-team@cloudflare.com. Federal agencies with active authorizations should route incident notifications through their existing SLA channels.