A Cloudflare alternative that doesn’t try to do everything
Cloudflare covers almost everything: a global network, DNS, code running at the edge, security and performance. Klacos doesn’t try to rebuild all of that. It analyses your site’s traffic before it reaches your application, then uses that analysis to protect, serve and measure your site, from the European Union or from your own servers. Here is what you keep, what you gain and what you give up if you switch.
- Last checked: 9 October 2026
- Every Cloudflare fact linked to its source
- What we don’t do, stated plainly
Why look for a Cloudflare alternative?
Cloudflare works, and plenty of sites run on it without a second thought. The reasons to switch are rarely technical. They usually come down to three questions.
Who sees your traffic. A service in front of your site reads every request your visitors make once TLS terminates. With Cloudflare, choosing where that data is processed and stored means the Data Localization Suite, a paid add-on available on Enterprise only.
What it costs to understand your traffic. Several of the features that tell you who is visiting sit on the higher plans: Bot Analytics and the waiting room on Business and Enterprise, and the action that logs a rule without enforcing it on Enterprise.
Where it runs. Cloudflare runs on Cloudflare’s network. If your traffic has to stay on your own machines, for a client, a regulated sector or internal infrastructure, you need a service you can install yourself.
If none of that applies to you, and especially if your audience is spread across the globe, Cloudflare is probably still the right choice.
Similar features, used in different ways
Cloudflare also offers bot analytics, AI crawler control, a waiting room and a tag manager. So the difference isn’t whether a feature exists. It’s the scope of each service, where your traffic goes, the order in which you switch protection on, and what you can find out when it gets in someone’s way.
| Cloudflare | Klacos | |
|---|---|---|
| What it is | A very broad platform: global network, DNS, security, performance, edge computing, employee access | A service built around your site’s traffic: one analysis of each visit drives protection, delivery and measurement |
| Where your traffic goes | Through Cloudflare’s network; choosing where data is processed means the Data Localization Suite, a paid Enterprise add-on | Through the managed service, run in the European Union, or through your own servers, console included |
| Before a rule goes live | The “Log” action, which records a rule’s matches without enforcing it, is Enterprise only; on every plan, Security Analytics shows the last month of traffic, which you can filter before writing a rule | Everything starts in observation; you replay a setting against your past traffic, then roll it out one step at a time |
| When a visitor is blocked | The Security Events log shows the action taken and the feature that applied it | The decision keeps its reason and a reference; the visitor sees a page in your colours with a link to appeal |
| Who it suits | Sites with an audience spread across the world that want one supplier for many services | Sites whose audience is mostly in Europe, and teams that want to understand their traffic before blocking it, or keep everything in-house |
Cloudflare and Klacos, side by side
The table covers the features people look for most in front of a site. Every Cloudflare entry comes from Cloudflare’s official documentation, last checked on 9 October 2026. Its plans change often, so check them before you decide.
| What you need | Cloudflare | Klacos |
|---|---|---|
| A service in front of your site: certificates, rules, redirects | Yes, all plans | Yes |
| Web application firewall | Free ruleset on all plans; full managed rulesets from Pro upwards | Yes, with a blocking level set site by site |
| Bot management | Bot Fight Mode on Free; Super Bot Fight Mode on Pro, Business and Enterprise; Bot Management as an Enterprise add-on | Yes: slow down, check without showing anything, block as a last resort |
| Verified bots | Yes, verified by signature, by their published IP addresses or by reverse DNS | Yes, verified with the company that runs them, never on their word alone |
| AI crawler control | Yes, all plans, with AI Crawl Control: AI crawler monitoring, a rule per crawler, and settings by purpose (search, agent, training) | Yes: a category of its own, observed by default, set site by site |
| Rate limiting | 1 rule on Free, 2 on Pro, 5 on Business, 100 on Enterprise | Per address, per network, per operator and per route |
| Share of bots in your traffic | Bot Analytics, Business and Enterprise | Yes |
| Cookieless analytics | Web Analytics, free, with no cookies or local storage, measured by a script | Yes, with a script under 2 KB; bots caught by the protection are left out of your audience |
| Tag manager | Zaraz, all plans, with a setting that stops tags loading for requests judged automated | Yes, tags sent server-side and never for bots |
| Waiting room | Business and Enterprise | Yes, and bots don’t take a place in the queue |
| Caching and purge by URL, prefix or tag | Yes, all plans | Yes |
| Load balancing across your servers | Load Balancing, paid add-on | Yes |
| Global network | Yes, 348 cities | No |
| Managed DNS | Yes, all plans | No |
| Code running at the edge | Yes, with Workers | No |
| Volumetric attacks at network level | Unmetered protection, layers 3 to 7, all plans | No: attacks on your application only |
Cloudflare sources, checked on 9 October 2026: web application firewall, bot plans, verified bots, Bot Fight Mode, Super Bot Fight Mode, AI Crawl Control, settings by purpose, rate limiting, Bot Analytics, Web Analytics, Zaraz, Zaraz settings, Security Analytics, waiting room, cache purge, Load Balancing, Security Events, rule actions, Data Localization Suite, network, DNS, Workers, DDoS protection.
What you give up, in plain terms
Klacos has no global network of points of presence. The managed service is run in the European Union, so a visitor in Japan or California waits a little longer than they would on a global network: every request crosses an ocean.
It doesn’t manage your DNS or run your code at the edge. You keep your DNS provider, and your code stays on your server.
It doesn’t replace protection against volumetric attacks at network level. It handles the attacks aimed at your application: request floods, password guessing, injection, bots. If you’re a known target for very large attacks, keep a global network in front or alongside.
These are deliberate choices. A service that focuses on one site’s traffic can read all of it in one place and give a reason for every decision. Whichever part you replace, our guide to choosing a European Cloudflare alternative lists what to ask of any European operator.
One read of every visit, and decisions you can follow
One read for every decision. The same analysis of each visit drives your site’s protection, what gets served from the cache and who waits in the queue on a sale day (performance and availability), and what your traffic analytics counts. A bot caught by the protection layer never shows up as a visitor in your figures.
No decision without a reason. Every decision keeps its reason and a reference. A blocked visitor sees a page in your colours with a link to appeal, and your support team unblocks them in one click. There is more on explained decisions.
Observe first, everywhere. The day you put Klacos in front of your site, it watches your traffic and blocks nothing. You replay a setting against your past traffic before it goes live, then move up one step at a time. The web application firewall starts in observation too.
In Europe, or entirely on your premises. The managed service is run in the European Union. And running it on your own servers includes the console, so your visitors’ data stays on your machines.
Stay on Cloudflare, or move to Klacos: it depends on your site
Choose Klacos if
- you want to know how much of your traffic is human;
- you want one read of your traffic to drive protection, caching and analytics;
- you want to understand every decision, and see it against your past traffic before it goes live;
- your traffic has to be processed in the European Union, or on your own machines;
- most of your visitors are in Europe;
- you want cookieless analytics that don’t count bots.
Stay on Cloudflare if
- a large share of your visitors are on other continents;
- you need managed DNS or code running at the edge;
- you’re a target for large volumetric attacks;
- you want to set a rule for each AI crawler individually.
On that last point, Cloudflare currently goes further: Klacos treats AI crawlers as a category of their own, set site by site, as the page on AI crawler control explains. To see what changes for your kind of business, our solutions by type of site cover online shops, publishers, SaaS products and agencies.
Moving from Cloudflare to Klacos without changing hosting provider
Your server stays put. It remains the origin, behind Klacos, just as it sat behind Cloudflare. Certificates are issued and renewed automatically, or you can import your own if you’d rather keep them.
Your redirect, rewrite and caching rules are recreated. Each one is tested against a request before it goes live, and every version stays available, which makes it a good moment to tidy them up.
Your DNS stays with your current provider, Cloudflare included: you simply point your domain at Klacos.
Start with a single domain. For the first few weeks, Klacos observes and blocks nothing: you read what it would have slowed down or stopped on your own traffic, check that against what you know about your visitors, then roll out your settings one step at a time. Move your other domains once you’re convinced, not before.
Questions about moving off Cloudflare
Is Klacos cheaper than Cloudflare?
Not necessarily: Cloudflare has a free plan. Klacos starts at €29 a month (excluding VAT), depending on your sites' traffic, and you know your price before you commit.
Can I keep Cloudflare for my DNS?
Yes. Your records stay where they are, and you point your domain at Klacos.
Does Klacos protect against DDoS attacks?
Against the ones aimed at your application: request floods, password guessing, injection, bots. Not against volumetric attacks at network level, which need a global network.
Can I set rules for each AI crawler?
No. Klacos treats AI crawlers as a category of their own, set site by site: allow, observe, slow down or block. Cloudflare currently lets you set a rule per crawler.
Do I have to move everything at once?
No. You can start with a single site, in observation, and compare before going further.
Where is my visitors' data processed?
The managed service is run in the European Union. If you run it on your own servers, console included, your visitors' data stays on your machines.
Compare it on your own traffic before you migrate
Request early access and put a first domain in observation, or talk to us about running it on your own servers.