Overview

The Cloudflare integration monitors your web infrastructure: zones, DNS records, firewall rules, WAF configurations, SSL certificates, access policies, workers, account members, API tokens, and audit logs. LowerPlane uses read-only access via an API Token to collect compliance evidence automatically.

Prerequisites

You need Cloudflare Account Admin or Super Administrator permissions to create an API token with the required access.

How to Get Your API Token

1

Log in to Cloudflare

Log in to your Cloudflare Dashboard.
2

Navigate to API Tokens

Click your profile icon, then go to My Profile > API Tokens.
3

Create a token

Click Create Token. Use the Read all resources template as a starting point, which grants read-only access across your account.
4

Copy the token

Copy the generated token. This is shown only once.

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find Cloudflare under Cloud Providers
  3. Enter your API Token
  4. Click Connect

What LowerPlane Monitors

Zones & DNS

DNS zones, records, and domain configurations.

Firewall & WAF

Firewall rules, WAF managed rules, and rate limiting configurations.

SSL Certificates

SSL/TLS certificate status, expiration, and encryption modes.

Access & Members

Access policies, account members, roles, and API token inventory.

Workers

Cloudflare Workers deployments and configurations.

Audit Logs

Account-level audit logs tracking administrative actions.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Network security and access controls are enforced
ISO 27001Infrastructure protection and monitoring are in place
PCI-DSSWeb application firewall and encryption controls are maintained