Cloudflare Zero Trust,
deployed by TruPoint.
Cloudflare is the backbone of TruWorkspace Zero Trust. We deploy, configure, and manage ZTNA, Secure Web Gateway, CASB, and Data Loss Prevention as one Zero Trust fabric — built to your policy.
The Zero Trust fabric, four ways.
Cloudflare Zero Trust is not one product — it's a coordinated set of services that replace legacy VPN, web filtering, and SaaS visibility tools.
Zero Trust Network Access
Per-app access policy keyed to user, device posture, and identity claims. Replaces always-on VPN with conditional, audited access to internal apps.
Secure Web Gateway
DNS and HTTP filtering on every endpoint. Blocks phishing, malware C2, and unauthorized SaaS — with logs you can hand to your auditor.
Cloud Access Security Broker
Visibility and policy across Microsoft 365, Google Workspace, and 200+ SaaS apps. Detect risky shares, third-party OAuth grants, and shadow IT.
Data Loss Prevention
Inline content inspection on uploads, downloads, and email. Pre-built detectors for PII, PHI, payment data, and Canadian-specific identifiers.
From licensing to live policy in four phases.
A repeatable rollout pattern we've run across 80+ TruWorkspace deployments — each one tuned to your environment.
Discover
Inventory users, devices, apps, and existing VPN. Map identity sources to Entra. Define risk tiers.
Design
Per-app policy matrix. Device-posture signals via Intune. SWG categories, DLP rule set, CASB SaaS allowlist.
Deploy
WARP client to managed endpoints via Intune. Tunnel to internal apps. Pilot with low-risk cohort, then phased rollout.
Operate
SOC monitors blocks, anomalies, and data events. Quarterly policy review. Annual pen test against the access surface.
Enterprise-grade Zero Trust at SMB scale.
Cloudflare's pricing model and TruPoint's MSP delivery make ZTNA economically realistic for 25–250 user companies — the segment most exposed to ransomware and most often denied cyber insurance.
- Replaces VPN — no more split-tunnel failures
- Cuts the lateral-movement blast radius
- Audit trail your insurer will actually accept
- Survives a stolen credential — device + posture required
- Scales without hardware refresh cycles
"Cloudflare gave us VPN-replacement we could explain to the board, and an audit log our cyber insurer signed off on the same week.
Where Cloudflare fits in the TruPoint stack.
TruWorkspace Zero Trust™
The flagship service. Cloudflare ZTNA + Entra + Intune + ESET, delivered as one architecture.
TruCompliance™
Cloudflare logs feed our ISMS evidence library — proof for SOC II, ISO 27001, and cyber insurance audits.
Finance & Insurance
Cloudflare DLP detectors tuned for PIPEDA, PCI, and Canadian financial identifiers.
A 30-min Cloudflare Zero Trust walkthrough.
We'll show you the policy console, a live block, and the audit log your insurer cares about.