Integration · Cloud

HailBytes + Cloudflare

Discover what's behind the edge — including the origins that shouldn't be reachable at all.

What you get

  • Asset discovery via REST API v4. DNS records, Workers routes, and R2 buckets. This matters because edge-resident apps often don't resolve on the public internet without a Cloudflare hostname — without the connector they're invisible to external scanning entirely.
  • Origin-bypass detection. Certificate search combined with origin confirmation identifies non-Cloudflare IPs serving the same content, raised as exposed-origin-ip findings.
  • Findings feed the standard pipeline. Discovered assets back-link to the scan-target model, so the rest of the pipeline — SIEM forwarding, ticketing, exposure graph, compliance reports — runs unchanged.

Why origin exposure is worth checking

A correctly configured Cloudflare deployment means traffic reaches your application only through the edge, where WAF rules, rate limiting, and DDoS protection apply. An origin IP that answers directly bypasses all of it — the protection is bought and configured but silently not in the path.

It's a common misconfiguration and an easy one to miss, because everything appears to work. HailBytes ASM checks for it on every scan cycle rather than at onboarding only, so a later infrastructure change that re-exposes an origin surfaces as a new finding.

Bring your own API token, scoped read-only. Usage stays on your existing Cloudflare plan.

All cloud integrations → API reference → Talk to us →