Cloudflare swaps third-party tools for AI-driven bug bounty automation
Cloudflare now uses Anthropic’s Claude Sonnet model to triage bug bounty reports at a cost of $58 a month, abandoning costly third-party security solutions.
At a press lunch in Sydney, Cloudflare’s chief security officer revealed the firm now relies on Anthropic’s Claude Sonnet to automate its bug bounty intake, paying just $58 per month. The model evaluates reports, removes duplicates and judges the merit of each submission, dramatically reducing manual triage. In contrast, Anthropic’s security-focused Mythos model would have cost about $200,000 monthly for the same task.
The shift is part of a broader strategy that has seen Cloudflare develop more than 200 autonomous agents and retire nearly all third-party security products in favor of internally built, AI-enhanced tools. The chief security officer cautioned that this buy-versus-build calculus only works for Cloudflare’s specific security challenges. Chief strategy officer added that AI will reshape vendor-client relationships, leading to fewer packaged software sales and more on-site engineering support, a change reflected in recent AI-driven layoffs.
Why it matters
It shows how a major internet firm is using low-cost AI to overhaul security operations, signaling a shift for the industry.
In this story
Related stories
2 in this thread