Cloudflare triages bug bounty reports with Claude Sonnet for $58 a month

Cloudflare chief security officer Grant Bourzikas told The Register, at a press lunch in Sydney, that the company now uses Anthropic's Claude Sonnet model to automate triage of incoming bug bounty reports for about $58 a month. Cloudflare used to process every report by hand. Sonnet now sifts through submissions, checks whether they are duplicates, and estimates how likely each one is to be worth a human's time. Bourzikas said the company chose Sonnet partly because using Anthropic's security-specific Mythos model for the same job would cost around $200,000 a month, and he framed the gap as proof that AI users need to match the right model to the right task rather than reaching for the most specialized (and most expensive) option by default.
Bourzikas said Cloudflare built that model-matching experience while creating over 200 autonomous agents that now handle the company's own security needs, and which have let Cloudflare drop almost all of its third-party security tools in favor of home-grown applications, some written with AI's help. He was explicit that other organizations should not copy this: Cloudflare's business and its particular infosec problems make its build-versus-buy math different from most companies'. "We have expertise in building security software," he said, adding that Cloudflare does not believe every bank should start building all its own software.
Cloudflare's Chief Strategy Officer Stephanie Cohen, at the same event, argued AI will make vendors move away from selling packaged software and toward placing forward-deployed engineers with clients to keep customizing software for them. She described Cloudflare's recent round of 1,100 job cuts as a similar AI-driven shift, saying some of the roles eliminated "make no sense" now that AI enables more automation, and she guessed Cloudflare would eventually return to its pre-layoff headcount. Bourzikas added that Cloudflare now struggles to find developers with five to ten years of experience with the skills it needs, because instructions for AI-assisted development can get lost in translation when relayed to a human coder; a recent graduate with strong prompting skills, he said, can be more useful for some jobs.
Cohen also said AI still lacks a real business model. Unlike the advertising-funded web, AI companies making billions from subscriptions have not addressed that they largely do not pay to access the content used to train their models and power their search products, and that AI-powered search, like Google's, sends publishers fewer clicks and makes monetizing content harder. Cloudflare is positioning itself as an intermediary that would let AI companies pay publishers for content access, potentially through micropayments, charging a fee for the service itself. Pressed on why publishers should trust Cloudflare given how often big tech platforms have changed the rules on partners after becoming essential to them, Cohen pointed to Cloudflare's decision to offer free SSL to all customers, calling it an expensive choice that reflected a wider goal of building a better internet. She also said Silicon Valley too often assumes people want every product endlessly optimized, when in her experience many people are not working around the clock and still choose in-person shopping over a better online price.
Key facts
- Cloudflare automates triage of incoming bug bounty reports with Anthropic's Claude Sonnet for about $58 a month, checking for duplicates and estimating which reports merit human review.
- CSO Grant Bourzikas says using Anthropic's security-specific Mythos model for the same task would cost around $200,000 a month.
- Cloudflare has built over 200 autonomous agents for its own security needs and dropped almost all third-party security tools in favor of home-grown, partly AI-coded tools, but Bourzikas warns against other organizations copying that approach.
- Chief Strategy Officer Stephanie Cohen attributes Cloudflare's recent 1,100 job cuts to AI-driven change and guesses headcount will eventually return to pre-layoff levels.
- Cohen says AI companies mostly do not pay for the content that trains their models and powers AI search, and Cloudflare wants to broker paid access, possibly via micropayments, for a fee.
Why it matters
The $58-versus-$200,000 comparison is a concrete data point on how differently priced two models from the same vendor can be for one task, and Bourzikas frames it as a broader lesson: matching a cheaper general model to a job instead of defaulting to a specialized, expensive one can cut costs by orders of magnitude. It also documents a large enterprise security team replacing most of its purchased tooling with agents it built itself, a shift that runs against how most companies buy security software.
Who it affects
Cloudflare's own security and bug bounty operations, plus any security or engineering leader weighing AI model costs or a build-versus-buy decision for tooling. Cohen's remarks also concern Cloudflare's laid-off staff, its enterprise customers, and publishers whose content trains AI models and whose traffic AI search reduces.
How to use it
Bourzikas's practical takeaway is to pick the model tier that fits the task rather than the most capable or specialized one by default, since the cost difference for a triage-style job was roughly 3,450 times between Sonnet and Mythos. He does not offer this as a template for other organizations to copy: he explicitly says Cloudflare's scale, security expertise and unique infosec challenges make its buy-versus-build calculus atypical.
How solid is it
The figures come directly from Cloudflare's own CSO and Chief Strategy Officer, speaking on the record to The Register at a press event, rather than from an independent audit or a company blog post, so they carry Cloudflare's framing of its own numbers. The $200,000 Mythos figure is described as an estimate of what that approach would cost, not a cost Cloudflare actually incurred, and no breakdown of either figure was given.
Risks and caveats
The comparison singles out one workload (bug bounty triage) and one vendor's two models; it should not be read as a general verdict on any AI model's price or capability. Cloudflare gives no figure for how much of its security budget or headcount the 200-plus agents actually replaced, only that they cover 'almost all' third-party tools, and no timeline is given for the 1,100 layoffs or Cohen's expected headcount recovery, both of which remain her stated guess rather than a confirmed plan.
“We have expertise in building security software. That's why I would just want to make sure we've got one takeaway from this: We are not believers in the SaaSpocalypse. We do not think every bank on the planet should start building all their own software systems.”
— Grant Bourzikas, Cloudflare CSO