CORE MODULE

How Cloudflare Protects Your Published Forms

What you'll learn in this guide

Learn how Cloudflare helps protect your published forms in CX Platform by supporting secure hosting, threat protection and reliable access for users.

Overview

Every form published through CX Platform is delivered via Cloudflare, a global security and performance network that sits between your forms and the internet. This happens automatically — there's nothing to configure, and it applies to all published forms across your tenant.

For your team, this means the security and availability groundwork is already done. For the people filling in your forms, it means a faster, safer experience — wherever they are.

‍

DDoS protection

Cloudflare monitors incoming traffic to your forms in real time and automatically absorbs distributed denial-of-service (DDoS) attacks — attempts to overwhelm the form with a flood of requests and take it offline. Because Cloudflare handles this at the network level, your forms stay available even during large-scale attacks, with no action required from your team.

‍

Bot management

Not all form traffic is human. Bots can submit spam, scrape content, or attempt credential stuffing attacks against authenticated forms. Cloudflare's bot management layer identifies and blocks malicious automated traffic before it reaches your form, while letting legitimate users through without friction.

This works alongside CX Platform's own rate limiting — the Max requests per minute per IP setting in Edit settings — to provide layered protection against automated misuse.

‍

Web Application Firewall

Cloudflare's Web Application Firewall (WAF) inspects requests to your forms and blocks known attack patterns — things like SQL injection attempts, cross-site scripting (XSS), and other common web exploits. The WAF ruleset is continuously updated by Cloudflare as new threats emerge, so your forms benefit from up-to-date protection without any maintenance overhead on your side.

‍

TLS encryption in transit

All traffic between users and your published forms is encrypted using Transport Layer Security (TLS). This means that data entered into a form — names, addresses, account details, or any other personal information — is protected from interception as it travels across the network. Users will see the padlock in their browser, confirming the connection is secure.

‍

Global content delivery

Cloudflare operates a globally distributed network of data centres. Static form assets — such as scripts and stylesheets — are cached and served from the location closest to the user, reducing load times regardless of where your users are based. For forms that need to reach a geographically dispersed audience, this makes a real difference to the experience.

‍

What this means in practice

  • Your forms stay online — attack traffic is absorbed before it affects availability.
  • Submissions are clean — bot-driven spam and automated abuse is blocked at the edge.
  • Data in transit is protected — TLS encryption applies to every form, every submission.
  • No configuration required — Cloudflare protection is on by default for all published forms across your tenant.

‍

‍Legitimate users getting blocked? In rare cases, Cloudflare's security rules may challenge or block a user it has flagged as suspicious — for example, someone on a shared IP that has been associated with malicious activity. If users report unexpected challenges or access issues, contact your Chandler support team to review the relevant Cloudflare settings for your tenant.

‍

Cloudflare protection runs quietly in the background on every published form. Your team doesn't need to manage it — it's part of the platform infrastructure so you can focus on building forms, not securing them.

‍