Infrastructure

Cloudflare Configuration Status

Edge security and performance posture for sitooadvisory.com on the Cloudflare Free plan.

22
Complete
0
Pending
22
Total Items
#ItemStatus
1SSL/TLS — Full (strict), TLS 1.2 min, TLS 1.3, OE, Auto HTTPS Rewrites● Done
2Edge Certificates — Always HTTPS, HSTS (6 mo)● Done
3Bot Fight Mode● Done
40-RTT Connection Resumption● Done
5Browser Cache TTL — Respect Existing Headers● Done
65 WAF Custom Rules (threat-score, empty-UA, bad-bots, admin-paths, non-GET/POST)● Done
7Rate Limiting on /api/public/* — 17 req / 10s (Free-plan max)● Done
83 Page Rules — /assets/* cache, /api/* bypass, Always HTTPS● Done
9Crawler Hints — Caching → Configuration toggle● Done
10DNSSEC — DS record auto-provisioning at registrar (Active pending DS propagation)● Done
Free-plan deviation: Rate limiting could not match the original spec (100/min, 1-hour block) — Cloudflare Free only allows period=10s and mitigation_timeout=10s. Configured as 17 req / 10s, block 10s (≈100 req/min equivalent). In-Worker per-IP throttles in /api/public/chat and /api/public/lead remain the primary defense.
DNSSEC: Enabled via Cloudflare's auto-setup flow; DS record propagation at the registrar typically completes within a few hours. Status will flip from "pending" to "Active" automatically once propagation finishes.
Last reviewed: 2026-05-19 · Zone: sitooadvisory.com · Plan: Free