Skip to content

Get started

Security Center scans your Cloudflare account configuration and identifies potential security risks, misconfigurations, and vulnerabilities across your domains. This guide covers the initial setup.

Prerequisites

  • A Cloudflare account.
  • At least one zone (domain or subdomain) added to your Cloudflare account.

Enable Security Insights and start initial scan

Security Insights scans are enabled by default. The scan reviews your Cloudflare account settings and product configurations across all your domains, then reports any issues it finds as insights — potential security risks, misconfigurations, or vulnerabilities.

Security Insights start scans by default. Security Insights will scan your Cloudflare environment and provide you with a list of detected insights. Refer to How it works to learn more about how Security Insights perform a scan.

The initial scan time depends on the number of IT assets in all the domains of your Cloudflare account. When the scan is complete, the status of the page will change from Scan in Progress to Last scan performed on: <DATE_TIME>.

You can decide to stop a scan, and restart a scan later.

To disable scans:

  1. In the Cloudflare dashboard, go to the Security Insights page.

    Go to Security insights
  2. Go to Disable Security Center scans, select Disable scans.

To restart a scan:

  1. In the Cloudflare dashboard, go to the Security Insights page.

    Go to Security insights
  2. Select Scan now.

Start a new scan

To manually start a scan:

  1. In the Cloudflare dashboard, go to the Infrastructure page.

    Go to Infrastructure
  2. Select Scan now.

Scan frequency

After you enable Security Insights, Cloudflare performs scans automatically on a recurring schedule based on your plan:

PlanScan frequencyOn-demand scans
Free, Pro, or BusinessEvery 7 daysYes
EnterpriseEvery 3 daysYes

For more details, refer to How it works.