The lock and HTTPS were invented for one reason: so that nobody between you and the site could read what you send. Your ISP, cafe Wi-Fi, a state on the wire - all see only ciphertext. Browsers spent years teaching you: no lock - do not enter a password.
Cloudflare is a proxy that sits between you and the site; Amazon CloudFront, Azure Front Door, Akamai and Fastly work the same way. To «mitigate attacks», the middlebox needs to see traffic in the clear. So your connection ends on its server: there the request is decrypted, checked against its rules, and only then sent to the site over a separate connection. Cloudflare's own docs call this TLS termination - «the point where HTTPS traffic is decrypted so Cloudflare can inspect it». Amazon, Azure and Akamai use the same name for the same point in their docs.
Technically this is a classic man in the middle. The only difference from an attack: the site owner signed up for it when they put the site behind the middlebox. Plan or settings do not remove this: while the site is behind a middlebox, encryption ends at the middlebox - on the free plan and on Enterprise alike. Nobody asked you, and the lock will not tell you.
No judgments. Only Cloudflare's own documentation, its own incident reports and public write-ups - with dates, so every line can be checked.

Per HTTP Archive 2025, 71% of the thousand most visited sites in the world serve even the HTML document through a middlebox; among the top 10,000 - 70%, among the top 100,000 - 62%. Who those middleboxes are: Cloudflare - 58% of such sites, then Amazon CloudFront (7%), Fastly (5%), Akamai (2%) and cloud load balancers. Counting all sites in the world, every third is behind a middlebox; Cloudflare alone - 26% of all sites and 85% of the reverse-proxy market.

Cloudflare rules «inspect the body of each incoming request», and the field http.request.body.raw in their rules language is «the unaltered HTTP request body». A login form is a request body. The login and password in it are plaintext.

From 22 September 2016 to 18 February 2017 a bug in Cloudflare's parser mixed chunks of memory from one site into responses of another: headers, pieces of POST requests with passwords, cookies, API keys and tokens. Cloudflare counted 1.2 million hits; leaks landed in search caches - more than 80,000 pages cleaned. Press coverage named Uber, OkCupid, Fitbit.

From 14 to 24 November 2023 attackers - Cloudflare calls them «nation-state» - with credentials stolen in the Okta breach worked inside Cloudflare's systems: Confluence wiki, Jira tracker, Bitbucket repos, 76 repositories downloaded. After that Cloudflare rotated more than 5,000 credentials and reviewed 4,893 systems.

2 July 2019 - 27 minutes, one regex in the WAF, traffic dropped 82%. 21 June 2022 - 75 minutes, 19 data centers. 18 November 2025 - almost six hours, «worst outage since 2019»: X, ChatGPT, Spotify, Shopify, Coinbase went down. 5 December 2025 - another 25 minutes. 20 February 2026 - six hours, a BGP error. None of the outages was an attack.

The site owner ticks a box - and access is decided not by them, but by Cloudflare's filter. Their docs admit a «challenge loop, when the challenge appears again and again», including because of VPNs and proxies. Since 2016 Cloudflare treats Tor as a separate «country» and claims 94% of requests from there are malicious; Tor Project answered about an «endless loop of CAPTCHAs» and a block of at least 80% of Tor addresses.

In October 2024 Cloudflare enabled ECH encryption by default on free plans. On 6 November 2024 sites behind Cloudflare with ECH stopped opening for Russian ISPs; on 7 November CMU SSOP (a Roskomnadzor unit) called ECH a «means of bypassing restrictions» and recommended that owners disable it «or, better, use domestic CDNs». Since 9 June 2025 the four largest Russian operators cut Cloudflare traffic to the first 16 KB of any file. Traffic from Russia fell about 30%; more than 40% of Russian-web sites - about 300,000 - sit behind Cloudflare. On 2 June 2026 the FSB announced that foreign intelligence services had been collecting data from Russian officials' phones «using the technical capabilities» of Cloudflare and Fastly, and opened cases under Criminal Code articles 272 and 273 - it showed no technical evidence, and the companies did not reply. The same Cloudflare has since 2022 covered UK Ministry of Defence sites under a government contract - Army, Royal Navy, RAF and the Defence Gateway portal for 330,000 users: £425k for 2022-2025 and £105k for 2025-2026.

Any proxy or cloud load balancer that terminates TLS on itself works the same way: Amazon CloudFront and ALB, Azure Front Door and Application Gateway, Akamai, Fastly, Imperva. Each has its own WAF that reads the request body, its own cache and its own outages. Cloudflare is simply the largest and the most open in its documentation. Ordinary hosting with a certificate on the origin server is different: there only the site reads the traffic.



You do not have to believe us or them. The middlebox leaves traces in every response, and anyone can see them.
We did not guess and did not read other people's reviews: we made ordinary requests to the sites, looked at response headers and certificates. The result is below, as-is.
A middlebox company: the site sends all its traffic through their servers, and they «protect» it. To «protect», they decrypt your connection on their side. That is how a quarter of all sites in the world work.
Yes. The connection ends on its server, and filtering rules per the docs read the body of every request - a login form with username and password is exactly that request body. Whether it stores that and for how long is governed by its policies, which you cannot verify.
That is not the site, that is Cloudflare. The owner turned on the check, and the middlebox filter decides: VPN, Tor, a «suspicious» region, an old browser - and you fall into a challenge loop. Cloudflare itself admits such loops in its documentation.
When a country fights with a middlebox, users get VPN - or a site without a middlebox. Site owners have one real fix: remove Cloudflare from between themselves and their users. The Russia case in Fact 07 shows how fast «the site is down» becomes «the middlebox fell out with the ISP».
No. Any middlebox that terminates TLS on itself works this way: Amazon CloudFront and AWS load balancers, Azure Front Door, Akamai, Fastly, Imperva. Among the thousand largest sites in the world, 71% sit behind a middlebox: Cloudflare - 58% of them, Amazon - 7%, Fastly - 5%, Akamai - 2%. Ordinary hosting is different: there the traffic and the certificate belong to the site itself.
Decide which matters more: «protection from attacks» or the fact that your users' passwords do not pass through someone else's code. Plan and settings do not change this - on any plan the cipher ends at the middlebox. There is a compromise - a proxy that does not decrypt TLS and only forwards the stream by server name. That is how our front server works: protection from excess traffic stays, a plaintext middlebox does not.