× Cloudflare
Talk to Cloudflare →
Executive Brief · AI Identity Security & Developer Platform

Put Cloudflare inside the identity control plane Delinea sells.

Delinea's marketing site already rides Cloudflare's edge through HubSpot. The bigger opportunity is upstream of that: Cloudflare's developer platform, API security and Zero Trust network built directly into the Delinea Platform — the product authorizing 1M+ identities a day and 2.1M AI agent sessions a week.

1M+identities secured daily by the Delinea Platform
2.1MAI agent sessions authorized every week
60%of identities in a typical org are non-human
150+customers already securing AI agents with Delinea

Racing to secure the agentic AI era — in public, right now

Delinea isn't waiting on AI identity — it's shipping. In the last few weeks alone it announced runtime authorization for AI agents, joined Anthropic's Project Glasswing (securing the Model Context Protocol ecosystem), shipped a Delinea MCP Server, and won FedRAMP High authorization for Secret Server — while being named an overall leader in the 2026 KuppingerCole Leadership Compass for PAM and a growth & innovation leader in the 2026 Frost Radar for PAM. Every one of those moves needs a network underneath it.

Five identities Delinea protects. One network to run them on.

Delinea's own platform is built around five identity categories — IT admins, workforce, machine, AI agents and developers. Every one of them crosses a network before Delinea ever makes an authorization decision.
5 identities → 1 network
IT adminsprivileged accounts
Workforceemployees & contractors
Machinesecrets, certs, service accts
AI agentsruntime authorization
DevelopersJIT, zero standing privilege
Cloudflare network · API security · developer platform
Goal: make Delinea's own runtime authorization faster & harder to attack

Five strategic plays: Cloudflare inside the Delinea Platform

Not a vendor swap — a platform play. Each maps to a product Delinea already ships or just announced.
01

AI Gateway + Enterprise MCP — govern Iris AI and the Delinea MCP Server

Fits: Iris AI · Delinea MCP Server · Project Glasswing

Delinea's Iris AI engine makes real-time authorization calls at machine speed, and Delinea just joined Anthropic's Project Glasswing to help secure the MCP ecosystem. AI Gateway puts a governed, logged front door on every outbound LLM call Iris AI makes — caching, rate limits, spend caps, full audit trail. Enterprise MCP adds governance and access control around the Delinea MCP Server itself, so joint customers get policy enforcement on both sides of the AI-agent connection.

  • One pane of glass + logs across any model provider behind Iris AI
  • Cache & rate-limit to control token spend at 2.1M sessions/week scale
  • Enterprise MCP wraps the Delinea MCP Server with Zero Trust access control
  • Complements Project Glasswing's mission to make MCP safe by default
02

API Shield — protect the APIs that ARE the product

Fits: Cloud Suite/PAS API · Secret Server · DevOps Secrets Vault

Delinea's own documentation markets "advanced automation: tap into CLI and REST API" as a core feature of DevOps Secrets Vault, and publishes a public Cloud Suite/PAS API reference at developer.delinea.com. For a PAM vendor, the API is the crown jewel — a credential-vault endpoint being scraped, abused or missing a schema check is an existential risk. API Shield discovers every endpoint, enforces schema and mTLS/JWT validation, and stops credential stuffing or volumetric abuse before it reaches the vault.

  • Automatic discovery across Secret Server, DSV & Cloud Suite/PAS APIs
  • Schema validation stops malformed or unauthorized calls at the edge
  • mTLS client certs for CI/CD callers — no static API keys in pipelines
  • Negative-security defaults align with Delinea's own "zero standing privilege" ethos
03

Workers + Durable Objects — run runtime authorization at the edge

Fits: "authorize every action before it executes"

Delinea's flagship claim is that it authorizes every tool call, query and command before it runs — not just at the gate. That's a latency-sensitive, globally-distributed problem. Workers (0ms cold start, 330+ cities) is a natural home for edge-hosted policy evaluation close to wherever an agent, pipeline or admin session originates, and Durable Objects give each session a strongly-consistent, stateful coordination point — ideal for tracking "has this credential already been used for this task."

  • Push policy decisions physically closer to agents & CI/CD runners worldwide
  • Durable Objects model per-session state for just-in-time credential injection
  • Workflows can orchestrate multi-step provisioning/deprovisioning safely
  • Same platform Cloudflare uses to run its own zero-cold-start products
04

Zero Trust Access for Infrastructure — extend PRA & Secure Developer Access

Fits: Privileged Remote Access · Secure Developer Access · FedRAMP High

Delinea's Privileged Remote Access and Secure Developer Access solutions broker human and agent connections into SSH hosts, Kubernetes and cloud consoles without exposing credentials. Cloudflare Access for Infrastructure and WARP provide the Zero Trust network transport those brokered sessions can ride on — device posture, mTLS and short-lived certs at the network layer, mirroring Delinea's "zero standing privilege" at the identity layer. It also lines up with Secret Server's new FedRAMP High authorization for public-sector deals.

  • Network-layer Zero Trust to match Delinea's identity-layer Zero Standing Privilege
  • Short-lived, mTLS-based connections for SSH/RDP/K8s — no standing VPN
  • Device posture checks add a second signal before Delinea grants access
  • Supports the FedRAMP High / public-sector push announced Sept 2026
05

R2 + Vectorize + Workers AI — fuel Iris AI's identity graph at zero-egress cost

Fits: Continuous Identity Discovery · Identity Posture & Threat Analysis · Iris AI

Iris AI has to ingest and risk-score telemetry from 1M+ identities a day and 2.1M AI sessions a week to power Continuous Identity Discovery and Identity Posture & Threat Analysis. That's an object-storage, vector-search and inference bill that grows with every new customer Delinea signs. R2 (egress-free) is a natural audit-log and session-recording data lake; Vectorize can hold the identity-relationship and anomaly embeddings Iris AI scores against; Workers AI offers pay-as-you-go inference for lighter-weight risk-scoring workloads — improving the unit economics behind Delinea's own AI differentiation.

  • R2: $0 egress vs. typical hyperscaler egress fees on growing audit-log volume
  • Vectorize: purpose-built vector DB for identity-risk embeddings & RAG
  • Workers AI: pay-per-neuron inference vs. dedicated GPU clusters
  • Directly strengthens the "AI-native by design" story Delinea sells today

Integration roadmap

A staged path — prove value on the highest-leverage surfaces first (the public APIs and the new AI-agent workloads), then move deeper into the platform's runtime and data layer.
First 6 months

Prove it on the edges

  • API Shield discovery + schema on the Cloud Suite/PAS & Secret Server APIs
  • AI Gateway pilot in front of Iris AI's outbound LLM calls
  • Stand up R2 for audit-log / session-recording storage (egress-free)
  • Technical workshop mapping Delinea's runtime-authorization latency budget
By 12 months

Move into the runtime

  • Workers + Durable Objects proof-of-concept for edge-hosted policy decisions
  • Access for Infrastructure pilot alongside Privileged Remote Access
  • Vectorize pilot for Iris AI identity-risk embeddings
  • Enterprise MCP governance layered on the Delinea MCP Server
Within 24 months

Make it the reference architecture

  • Cloudflare referenced in Delinea solution briefs & joint GTM (Cyera-style integration)
  • FedRAMP High Zero Trust paired with Secret Server's FedRAMP High authorization
  • Workers AI + Vectorize embedded in Iris AI's production risk-scoring path
  • Joint story for Project Glasswing / MCP ecosystem security

Snapshot

Product facts are sourced from Delinea's own site and newsroom; the last row is informational context, not a displacement target — see methodology.
FunctionDelinea todayHow it was identifiedCloudflare fit
Public API surface Cloud Suite/PAS, Secret Server & DSV REST/CLI APIs identified developer.delinea.com (ReadMe); product pages tout "REST API" API Shield
AI agent runtime authorization Iris AI + new "Runtime Authorization for AI Agents" identified delinea.com/news press release; /solutions/ai-solutions AI Gateway + Workers
MCP security Delinea MCP Server; joined Anthropic's Project Glasswing identified delinea.com/news; delinea.com/blog/unlocking-ai-agents-mcp Enterprise MCP
Identity telemetry & analytics 1M+ identities/day, 2.1M AI sessions/week (Iris AI) identified delinea.com/about; /solutions/ai-solutions R2 + Vectorize + Workers AI
Privileged remote & developer access Privileged Remote Access, Secure Developer Access identified delinea.com/products/privileged-remote-access; /solutions/developer-solutions Access for Infrastructure
Public-sector push Secret Server just achieved FedRAMP High identified delinea.com/news, Sept 2026 Cloudflare for Government (FedRAMP High)
Marketing & docs stack HubSpot CMS, ReadMe, AWS CloudFront, Atlassian Statuspage, Salesforce Community context only CNAME sweep + CSP, delinea.com — Sept 17, 2026 Not a displacement target — noted for completeness

How we know — observed on delinea.com

No assumptions: every item below was identified from public DNS, HTTP headers, the live delinea.com Content-Security-Policy, or Delinea's own published product/news pages, as of the recon date below.
Cloudflare fronts the marketing site (via HubSpot's edge — server: cloudflare, cf-ray observed) HubSpot www.delinea.com CNAME → hubspot.net ReadMe developer.delinea.com → ssl.readmessl.com AWS CloudFront docs.delinea.com Atlassian Statuspage status.delinea.com Salesforce support.delinea.com → siteforce.com Microsoft 365 MX → delinea-com.mail.protection.outlook.com AWS Route 53 nameservers (awsdns-*)
LIVE Checking the Cloudflare edge serving this page…