Overview
The Cloudflare integration monitors your web infrastructure: zones, DNS records, firewall rules, WAF configurations, SSL certificates, access policies, workers, account members, API tokens, and audit logs. LowerPlane uses read-only access via an API Token to collect compliance evidence automatically.Prerequisites
How to Get Your API Token
Log in to Cloudflare
Log in to your Cloudflare Dashboard.
Create a token
Click Create Token. Use the Read all resources template as a starting point, which grants read-only access across your account.
Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane
- Find Cloudflare under Cloud Providers
- Enter your API Token
- Click Connect
What LowerPlane Monitors
Zones & DNS
DNS zones, records, and domain configurations.
Firewall & WAF
Firewall rules, WAF managed rules, and rate limiting configurations.
SSL Certificates
SSL/TLS certificate status, expiration, and encryption modes.
Access & Members
Access policies, account members, roles, and API token inventory.
Workers
Cloudflare Workers deployments and configurations.
Audit Logs
Account-level audit logs tracking administrative actions.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Network security and access controls are enforced |
| ISO 27001 | Infrastructure protection and monitoring are in place |
| PCI-DSS | Web application firewall and encryption controls are maintained |