Prove It to the Client
Every client site carries a grade you can stand behind — and a report card you can hand over. White-label it on the Agency plan and make posture part of the retainer.
"Know the grade before your client asks."
Cloudflare fleet monitoring
ZoneGrade gives every Cloudflare zone you manage an A–F report card — WAF, cache, email DNS, CAA, DNSSEC and more, audited nightly across every account. Drift gets caught at 2 AM, not in a client email.
Read-only token · no credit card · first grades in two minutes
How It Works
No agents, no DNS changes, no write access. ZoneGrade reads your Cloudflare configuration the same way you would — then never stops checking it.
Create a Cloudflare API token with read-only permissions from our checklist and paste it in. It's encrypted with AES-256-GCM before it ever touches disk — and it can't change anything, by construction.
ZoneGrade discovers every zone the token can see — across all the client accounts you manage. Pick the ones to monitor; each gets a policy that says what "good" looks like.
The nightly sweep audits every surface, grades each zone A–F, and emails you the moment something drifts — with the exact surface, the change, and the grade impact.
What We Grade
Completeness counts for half the grade, staying drift-free for a third, and security posture for the rest. Suppress what doesn't apply — the grade stays honest.
Sweep fans out across every connected account — rate-limit-aware, token by token.
Each zone's surfaces are read, snapshotted, and compared against last night.
Drift opens an alert and an email goes out — before anyone's coffee.
Who it's for
Every client site carries a grade you can stand behind — and a report card you can hand over. White-label it on the Agency plan and make posture part of the retainer.
"Know the grade before your client asks."
A deleted WAF rule or broken DMARC record becomes a 2 AM alert instead of a Monday incident. Suppressions keep intentional changes from paging you.
"Misconfigurations don't survive the night."
Dozens of zones across multiple Cloudflare accounts, one dashboard. Coverage stats show exactly what got swept, what got skipped, and which tokens need attention.
"Every zone. Every night."
Pricing
$99/mo
All paid plans start with a 14-day free trial. Month-to-month, cancel anytime.
Questions
You create the token yourself, from a checklist of read-only permissions — ZoneGrade never asks for write access and cannot change anything in your Cloudflare account. Tokens are encrypted at rest with AES-256-GCM, never leave the API, and you can revoke them in Cloudflare at any time.
Eleven surfaces per zone: WAF custom rules, config & cache rules, response headers, SPF/DMARC/TLS-RPT, MTA-STS, CAA, zone security settings, bot management, DNSSEC, robots.txt, and ESP DKIM records. Surfaces that don't apply to a zone are marked N/A and don't drag the grade.
The sweep compares every surface against its last snapshot. A change opens a drift alert with the exact surface, severity, and grade impact — and emails your alert address. Intentional changes can be suppressed per zone and surface so they never page you again.
No. ZoneGrade is an independent product by Peace Harbor, not affiliated with or endorsed by Cloudflare, Inc. It reads Cloudflare's public API with credentials you create and control.
Yes — plans are month-to-month through Stripe with self-service billing. Downgrade to free and your zones and history stay readable.