Skip to content

Cloudflare Access encryption, keys & secrets security checks

Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.

On Cloudflare Access, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Cloudflare Access connector needs.

Checks (3)

severity: high Service Token Without Expiry fix difficulty: medium #

Set an expiration date on the Cloudflare Access service token to limit credential exposure

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Service Auth > Service Tokens
  3. Locate the service token without an expiry date
  4. Click the token to edit it and set an expiration date (recommended: 1 year or less)
  5. Save the token and update consuming services with the new token if it was regenerated
  6. Schedule a rotation reminder before the expiry date

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8

severity: medium Stale Service Token fix difficulty: medium #

Rotate or revoke the Cloudflare Access service token that has not been rotated in over 180 days

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Service Auth > Service Tokens
  3. Locate the stale service token (last rotated over 180 days ago)
  4. Click "Refresh" to generate a new client secret for the token
  5. Update all services and automation that use this token with the new credentials
  6. Confirm the old token is no longer in use and document the rotation

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8

severity: low Expired Service Token Not Deleted fix difficulty: easy #

Delete or renew the expired Cloudflare Access service token to remove abandoned credentials

  1. Sign in to the Cloudflare Zero Trust dashboard at one.dash.cloudflare.com
  2. Navigate to Access > Service Auth > Service Tokens
  3. Locate the expired service token
  4. If the token is no longer needed, click "Delete" and confirm deletion
  5. If the token is still required, click "Refresh" and set a new expiration date, then update consuming services
  6. Verify no active services are still attempting to use the expired token

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.1 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.ii HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.8

More Cloudflare Access checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial