TLDR: Cloudflare has introduced ‘Application Confidence Scorecards’ as part of its Cloudflare One SASE platform, designed to help organizations evaluate the security, compliance, and reliability of third-party SaaS and generative AI applications. These scorecards aim to combat ‘Shadow AI’ by providing automated, transparent risk ratings, enabling businesses to adopt AI tools safely without compromising data privacy or security.
San Francisco, CA – September 23, 2025 – Cloudflare, Inc. (NYSE: NET), a leading connectivity cloud company, today announced the launch of its Application Confidence Scorecards, a new suite of AI Security features integrated within the Cloudflare One SASE platform. This initiative addresses the growing challenge faced by security and IT teams: the proliferation of ‘Shadow AI,’ where employees adopt AI tools without official approval, posing significant risks to compliance, data privacy, and security practices.
Traditionally, preventing Shadow AI has involved a labor-intensive manual vetting process for each AI application, a method deemed unscalable. Blanket bans on AI applications, while seemingly a solution, often drive usage underground, making it even harder to secure. Cloudflare’s new scorecards offer a scalable and automated approach to evaluating generative AI and SaaS applications.
The Cloudflare Application Confidence Scorecards provide a clear, transparent rating from one to five, reflecting an application’s safety and trustworthiness. This score is derived from an assessment of various factors, including industry-recognized certifications (such as SOC 2, GDPR, ISO 27001, and ISO 42001), data management and retention policies, third-party data sharing practices, security controls, and the overall maturity level of the vendor.
In addition to the general Application Confidence Score, a complementary ‘Generative AI Confidence Score’ specifically targets AI-centric risks. This score awards higher ratings to AI models that provide comprehensive system cards detailing testing for bias, ethics, and safety considerations, and crucially, to those that do not train on user inputs.
Illustrative examples provided by Cloudflare demonstrate the nuanced nature of these ratings. ChatGPT Enterprise, for instance, scores higher than its free or consumer counterparts due to its default setting of disabling training on user prompts and offering enhanced enterprise controls. Similarly, Anthropic PBC’s enterprise offerings achieved near-perfect confidence ratings, while consumer tiers scored lower due to fewer safeguards.
Matthew Prince, CEO and co-founder at Cloudflare, emphasized the importance of balancing innovation with safety, stating, “Employees are always looking for an edge – ways to save time, spark creativity, or boost efficiency. Using Generative AI tools gives them that edge. But there is often a missing link between rapid innovation and safety.”
Cloudflare plans to make these scores freely accessible through its dashboard’s Application Library. Future integrations will extend their utility, allowing organizations to enforce policies directly through Cloudflare Gateway and Access. This will enable actions such as blocking or warning employees about low-scoring applications, or tying Data Loss Prevention (DLP) policies directly to confidence levels, thereby preventing untrusted AI and SaaS providers from becoming conduits for sensitive information.
Also Read:
- TeKnowledge Unveils Advanced Security Suite to Fortify Generative AI Implementations
- Radware Uncovers “ShadowLeak” Zero-Click Exploit in ChatGPT Deep Research Agent, Enabling Covert Data Theft
This move further solidifies Cloudflare’s commitment to strengthening generative AI security for businesses, building upon previous safeguards and integrations with leading AI tools like ChatGPT Enterprise, Claude by Anthropic, and Google Gemini.


