Skip to content

Product compatibility

The table below provides a summary of the Data Localization Suite product’s behavior with Cloudflare products. Refer to the table legend for guidance on interpreting the table.

✅ Product works with no caveats
🚧 Product can be used with some caveats
✘ Product cannot be used
⚫️ Not applicable

Application Performance

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Caching/CDN✅✅✅
Cache Reserve⚫️🚧✅ 1
DNS⚫️🚧 2🚧 3
HTTP/3 (with QUIC)⚫️✘⚫️
Image Resizing✅✘🚧 4
Load Balancing✅✅🚧 4
Onion Routing✘✘✘
Orange-to-Orange (O2O)✘✘✘
Stream Delivery✅✅✅
Tiered Caching✅🚧 5🚧 6
Trace✘✘✘
Waiting Room⚫️✅✅
Zaraz✅✅✅

Application Security

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Advanced Certificate Manager⚫️⚫️⚫️
Advanced DDoS Protection✅✅🚧 7
API Shield✅✅✘ 8
Bot Management✅✅🚧 9
DNS Firewall⚫️⚫️🚧 4
Page Shield✅✅✅
Rate Limiting✅✅🚧 4
SSL✅✅✅
Cloudflare for SaaS✘✅✅
Turnstile⚫️✘✅
WAF/L7 Firewall✅✅✅
DMARC Management⚫️⚫️✅

Developer Platform

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Cloudflare Images⚫️✘✘
Cloudflare Pages✘✅ 10🚧 4
Durable Objects⚫️✅ 11🚧 4
Email Routing⚫️⚫️✅
R2✅ 12✅ 13✅ 14
Stream⚫️✘✘
Workers (deployed on a Zone)✅✅🚧 4
Workers KV⚫️✘✘
Workers.dev✘✘✘

Network Services

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Argo Smart Routing✅✘ 15✘ 16
Static IP/BYOIP⚫️✅ 17⚫️
Magic Firewall⚫️⚫️✅
Magic Transit⚫️⚫️🚧 4
Magic WAN⚫️⚫️✅
Spectrum✅✅✅

Platform

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Logpull⚫️⚫️🚧 18
Logpush⚫️✅🚧 19

Zero Trust

ProductGeo Key ManagerRegional ServicesCustomer Metadata Boundary
Access🚧 20🚧 21🚧 22
Browser Isolation⚫️🚧 23✅
CASB⚫️⚫️✘
Cloudflare Tunnel⚫️🚧 24⚫️
DLP⚫️ 25⚫️ 25🚧 26
Gateway🚧 27🚧 28🚧 29
WARP⚫️⚫️🚧 4

Footnotes

  1. You cannot yet specify region location for object storage itself. ↩

  2. Outgoing zone transfers will carry Earth region proxy IPs, thus making regional service dysfunctional when non-Cloudflare nameservers respond to the DNS queries. ↩

  3. Dashboard Analytics are empty when using CMB outside the US region. Use Logpush instead. ↩

  4. Logs / Analytics not available outside US region when using Customer Metadata Boundary. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

  5. Regular and Custom Tiered Cache works; Smart Tiered Caching not available with Regional Services. ↩

  6. Regular/Generic and Custom Tiered Cache works; Smart Tiered Caching does not work with Customer Metadata Boundary (CMB).
    With CMB set to EU, the Zone Dashboard Caching > Tiered Cache > Smart Tiered Caching option will not populate the Dashboard Analytics. ↩

  7. Adaptive DDoS Protection is only supported for US CMB. ↩

  8. API shield will not yet work with Customer Metadata Boundary enabled outside of US region. ↩

  9. Some advanced Enterprise features, including the Anomaly Detection engine, are not available. ↩

  10. Only when using Custom Domain set to a region. ↩

  11. Jurisdiction restrictions for Durable Objects. ↩

  12. Only when using a Custom Domain and a Custom Certificate or Keyless SSL. ↩

  13. Only when using a Custom Domain set to a region and using jurisdictions with the S3 API. ↩

  14. R2 Dashboard Metrics and Analytics are populated. Additionally, Jurisdictional Restrictions guarantee objects in a bucket are stored within a specific jurisdiction. ↩

  15. Argo cannot be used with Regional Services. ↩

  16. Argo cannot be used with Customer Metadata Boundary. ↩

  17. Static IP/BYOIP can be used with the legacy Spectrum setup. ↩

  18. Logpull not available when using Customer Metadata Boundary outside US region. Logs may be stored and retrieved with Logs Engine ↗ which is adding region support in 2025. ↩

  19. Logpush available with Customer Metadata Boundary for these datasets. Contact your account team if you need another dataset. ↩

  20. Access App SSL keys can use Geo Key Manager. Access JWT is not yet localized. ↩

  21. Can be localized to US FedRAMP region only. More regions coming in 2024. ↩

  22. Customer Metadata Boundary can be used to limit data transfer outside region, but Access User Logs will not be available outside US region. ↩

  23. Currently may only be used with US FedRAMP region. ↩

  24. Only US FedRAMP region. ↩

  25. Uses Gateway HTTP and CASB. ↩ ↩2

  26. DLP is part of Gateway HTTP, however, DLP datasets are not available outside US region when using Customer Metadata Boundary. ↩

  27. You can bring your own certificate ↗ to Gateway but these cannot yet be restricted to a specific region. ↩

  28. Gateway HTTP supports Regional Services. Gateway DNS does not yet support regionalization.
    ICMP proxy and WARP-to-WARP proxy are not available to Regional Services users. ↩

  29. Dashboard Analytics and Logs are empty when using CMB outside the US region. Use Logpush instead. ↩