Cloudflare's Reference Architecture Secures Enterprise MCP Deployments
Cloudflare details its best practices for securely, efficiently, and cost-effectively deploying the Model Context Protocol (MCP) across its enterprise.

Cloudflare has aggressively adopted the Model Context Protocol (MCP) as a core component of its artificial intelligence strategy. This shift extends beyond engineering, with employees across product, sales, marketing, and finance teams now using "agentic" workflows to boost daily efficiency. "Agentic" workflows allow AI agents to autonomously pursue goals and take actions. However, adopting agentic workflows with MCP introduces significant security risks. These include authorization sprawl, prompt injection, and supply chain vulnerabilities. To secure this broad company-wide adoption, Cloudflare integrated a suite of security controls from both its Cloudflare One (SASE) platform and its Cloudflare Developer platform. This approach allows the company to govern AI usage with MCP without slowing down its workforce.
Cloudflare is sharing its best practices for securing MCP workflows by combining different platform components into a unified security architecture for the autonomous AI era. The Model Context Protocol is an open standard enabling developers to build a two-way connection between AI applications and necessary data sources. In this architecture, the MCP client serves as the integration point with the large language model (LLM) or other AI agent. The MCP server sits between the MCP client and the corporate resources.
This separation between MCP clients and MCP servers allows agents to autonomously pursue goals and take actions. It also maintains a clear boundary between the AI (integrated at the MCP client) and the credentials and APIs of the corporate resource (integrated at the MCP server). Cloudflare's workforce constantly uses MCP servers to access information within various internal resources. These include project management platforms, the internal wiki, documentation, and code management platforms, among others.
The separation between MCP clients and MCP servers allows agents to autonomously pursue goals and take actions.
Cloudflare quickly realized that locally-hosted MCP servers posed a significant security liability. Local MCP server deployments might rely on unvetted software sources and versions, increasing the risk of supply chain or tool injection attacks. Furthermore, they prevent IT and security administrators from managing these servers. This leaves individual employees and developers responsible for choosing and updating their MCP servers, which is an unsustainable strategy.
Instead, Cloudflare established a centralized team to manage its remote MCP servers. This centralized approach provides significantly better visibility and control over the entire MCP infrastructure. Centralized management ensures all servers are consistently updated and adhere to strict security standards. This mitigates the risks associated with decentralized deployments, creating a more secure environment for the entire organization.
To further support enterprise MCP deployments, Cloudflare is introducing two new concepts. First, they are launching Code Mode with MCP server portals, designed to drastically reduce token costs associated with MCP usage. Second, they describe how to use Cloudflare Gateway for Shadow MCP detection, a crucial tool for discovering unauthorized remote MCP servers within the network. These innovations, alongside Cloudflare products like Cloudflare Access and AI Gateway, form a proactive and unified security architecture.
Article topics
Related articles

Windows Drops NTLM: Microsoft Boosts Security with Kerberos
Microsoft is taking a crucial step to bolster security in Windows 11, announcing the deprecation of NTLM, its oldest authentication protocol, in favor of Kerberos.

Google Launches Gemma 4 12B: Local AI for Your Laptop with 16GB RAM
Google's new artificial intelligence model aims to democratize access to generative AI, allowing it to run on average consumer computers.

Nvidia Challenges Intel and AMD with RTX Spark Superchip for PCs
Nvidia introduced RTX Spark, a processor promising to bring advanced artificial intelligence directly to your PC, without cloud dependence, and boost gaming to unprecedented levels on conventional machines.
Latest news
View all
Stuntman Hollywood: Returns After 19 Years to PS5, Xbox Series, and PC
The iconic action and vehicular stunt franchise makes its comeback courtesy of Saber Interactive, promising a dose of nostalgia and adrenaline for the new generation.

NASA's Maven Mars Orbiter Declared Out of Service After Six Months of Silence
Following an anomaly that disrupted its orbit and depleted its batteries, the Maven spacecraft, vital for understanding Mars' atmosphere, has ended its active mission. Its scientific data remains an invaluable legacy.

NASA Reveals New Path for Earth's Essential Life Elements
A recent study, published in Science Advances, uncovers how early Earth may have received phosphorus and nitrogen, highlighting Jupiter's critical role.
Comments (0)
No comments yet. Be the first!
Leave a comment