Just wrapped up a Cloudflare One trial. Our setup: ~200 people, almost everything in AWS (EC2, S3, RDS). We were drowning in VPN chaos.
Zero Trust Network Access is the clear win. Got rid of the VPN gateway for good. The magic was Cloudflare Tunnel to our private subnets. No egress data charges back to a central firewall is huge for AWS spend. The DNS filtering and posture checks are solid, but the real value is making our AWS instances feel like internal apps without the network headache.
Senior cloud architect at a 300-person fintech, managing a hybrid AWS/GCP environment with a global team. We migrated off traditional firewalls to a full SASE model two years ago and now run Palo Alto Prisma Access for our main workforce and Zscaler Zero Trust Exchange for contractor/third-party access.
* **Cost structure for AWS-heavy use**: Cloudflare One's lack of egress fees for traffic to your AWS VPCs is its killer feature, saving you 2-4 cents per GB. For a 200-user startup, that can be $1-3k/month saved versus competitors who charge per inspected gigabyte. Their $7/user/month Zero Trust seat is straightforward, but you must monitor usage to stay under the included 1 TB/month data allowance.
* **Deployment complexity for private apps**: Cloudflare Tunnel (argo) is phenomenally simple. A single cloudflared daemon in your VPC and you're done, no route tables or VPC attachments. The trade-off is you lose Layer 4 control; it's a proxy for HTTP/HTTPS/TCP. For SSH or raw database protocols on non-standard ports, you're back to a bastion host.
* **Operational maturity gap**: Their admin console and API lag behind. Automated user lifecycle management is basic compared to Zscaler's SCIM depth. Reporting is fine for high-level trends but insufficient for forensic audits. Support is adequate, but you'll wait longer for engineering-tier escalation than with Cisco or Palo Alto.
* **Performance outside the Cloudflare network**: Their 270+ PoPs are excellent if your users are near them. We saw sub-20ms latency for most. However, for a team in, say, São Paulo accessing us-east-1, the direct AWS backbone from a provider like Cato Networks or Zscaler's private backplane provided 30% better performance because they peer directly with AWS Transit Gateway.
Given your description, Cloudflare One is likely the correct choice for a 200-user startup now. The cost advantage and operational simplicity outweigh the maturity gaps. I'd recommend it unless you have a hard requirement for granular Layer 3 firewall policies or need to support legacy non-web protocols without a jump box. To be sure, confirm if your team needs SSH/RDP access to instances directly and what your average monthly data transfer to AWS is.
That sounds like a huge relief. I've been hearing a lot about Zero Trust but always got stuck on the "replacing the VPN" part. How did your team handle the initial switch? Was there a period where people were confused about not having a VPN icon to connect to anymore?