Private beta · 20 seats Cloudflare fleet operations Est. 2026
For agencies running more zones than people

A steward for your Cloudflare fleet.

Ask a question in plain language. See the answer across every zone you manage. Approve the fix, and let the server prove it landed. Nothing writes without you.

Apply for beta How it works Free during beta. Bring your own keys.
Live This page, right now, through Zonesteward updating…

157 points of presence ·

Bright points are colos that served this zone; the arcs are the requests that missed cache and reached the origin. Load this page and the colo that served you lights up — the globe gets busier the more people are looking at it. Intensity is relative to the busiest colo in the window, never a raw request count.

The model can
Propose only
Every change
Verified by read-back
Per customer
Its own database
Every change
Revertable
The problem

Cloudflare's dashboard assumes one zone and one expert.

You have neither. You have forty zones across six clients and a support queue.

01

No single view

One dashboard per zone. To learn who is under attack you open forty tabs, or you don't look at all.

02

Answers take an afternoon

"Why is this site slow in Europe?" has a GraphQL query behind it that nobody on the team is going to write.

03

Changes are frightening

A WAF rule on a client's production site, typed at five o'clock, with no preview of what it blocks and no way back.

Plate II Proposed, approved, verified, revertable rocket55dev.com
Proposed · rocket55dev.com impact · medium

Create IP access rule

Challenge 34.165.86.164 — attacker: secrets & config scan

Verified ✓ Revert Reject Approve
The gate

Structurally unable to touch your zones.

Not a policy, not a system prompt. Every function that can change Cloudflare is reachable from the execution core alone, so a prompt injected through a request path or a user agent cannot cause a write.

  1. Impact classified before you see it

    Low, medium or high. A site-wide lockdown or an apex DNS deletion needs an explicit acknowledgement, not a click.

  2. Blast radius against real traffic

    The proposed rule is evaluated against your last 24 hours before it exists, so you know what it would have blocked.

  3. Read back from Cloudflare

    "Applied" means the server asked Cloudflare what the setting is now and received the answer it expected.

  4. Reversible, with the payload stored

    Every change lands in the audit trail together with the instructions to undo it.

The ask

Ask the question you'd actually ask.

Who is attacking us right now?

Nine attack categories, a composite severity score, and a classifier tuned hard against false positives, so a theme fetching its own assets is never called a CMS probe.

79 34.165.86.164 US · AS396982 not mitigated

Scanning for exposed credential and config files — 39 distinct paths — 100% rejected.

/.env /.git/config /wp-config.php.bak +36 more
Plate III. One ranked source, with evidenceSecurity
Rates

Priced per workspace, by zones.

Every tier includes everything. No security feature is held back for a higher plan.

PlanFrom general availabilityIncluded
Studioup to 25 zones $49/mo 3 members. Chat, globe, investigation, approvals, audit, alerts.
Agencyup to 100 zones $149/mo 10 members. Everything in Studio, plus client share links.
Fleet100+ zones Talk to us Unlimited members. Everything, plus priority support.

Free during the beta, then 50% off your first year, locked. You bring your own Cloudflare token and Anthropic key, so model usage is billed to you by Anthropic at cost. We do not mark it up.

Private beta

Twenty seats. Yours if it fits.

Free for the whole beta, then half price for your first year. You bring your own Cloudflare token and Anthropic key, so model usage is billed to you at cost and we never see your keys in the middle.

  • You run more than a handful of zones, for other people
  • You'll tell us when it's wrong, not just when it's good
  • You're comfortable being early — this is pre-1.0

How many Cloudflare zones do you manage?

We read every one. No newsletter, no drip.