Head to head
Two ways to put an edge in front of your site. Cloudflare is a platform you also build on. Itnetic is one product — Layer-7 DDoS protection, WAF and CDN — with every feature on every plan, run from the EU. Here is the honest split, including where Cloudflare wins.
This is not a page that pretends Cloudflare is bad. Cloudflare runs one of the largest networks on the internet and a developer platform on top of it. If you are shipping Workers, storing objects in R2, using Zero Trust for your team or running DNS for hundreds of zones, nothing here should tempt you away.
The comparison is worth making when your actual requirement is narrower: keep a website, a store or an API online through an attack, see what happened, and not discover that the control you need is two plans up. That is the whole of what Itnetic does.
Everything below is capability only — what each side lets you switch on, and on which plan. No claim is made about anyone’s speed, network size or price except our own.
Side by side
Availability by plan, from each vendor’s public documentation. Capabilities only.
| Capability | Itnetic | Cloudflare |
|---|---|---|
| Product shape | One product — protection, WAF and CDN | Platform — edge compute, storage, DNS, Zero Trust and more |
| Layer-7 DDoS mitigation | Every plan, including free | Every plan |
| Volumetric L3/L4 absorption | Included — upstream backbone | Every plan |
| Managed OWASP WAF filters | Every plan, including free | Paid plans |
| Custom WAF rules | Every plan — typed fields, no expression language to learn | Plan-dependent limits |
| Bot handling | Every plan — reputation, verified-bot allowlist, TLS fingerprinting | Plan-dependent — Bot Management on Enterprise |
| Waiting room / virtual queue | Every plan, including free | Business and Enterprise |
| Per-request logs with the verdict behind each block | Every plan | Raw log export on Enterprise (Logpush) |
| Origin load balancing with failover | Every plan — up to 8 origins | Paid add-on |
| Minecraft / game server protection | Every plan — dedicated protocol-aware proxy | Plan-dependent (Spectrum) |
| Edge compute (serverless functions) | Not offered | Workers |
| Object storage, queues, D1, KV | Not offered | R2 and the rest of the platform |
| Authoritative DNS hosting | Not offered — you keep your DNS provider | Included |
| Zero Trust / employee access | Not offered | Included as a separate product line |
| Onboarding | Two DNS records — nameservers stay where they are | Nameserver change (CNAME setup on higher plans) |
| Attack traffic billed against your quota | Never — mitigated bytes are excluded | Not metered |
| Operator and data controller | Czech Republic (EU) | United States |
Compiled from Cloudflare’s own public documentation and plan pages on 10 September 2026, and describing feature availability by plan at that date. Plan contents change — check Cloudflare’s current pages before making a decision. Cloudflare is a trademark of Cloudflare, Inc.; Itnetic Technologies is not affiliated with, endorsed by or sponsored by Cloudflare, Inc. Prices named on this page are Itnetic’s own; this page makes no claim about any other provider’s pricing, performance, capacity or availability.
Put this first because it decides the question for a lot of people. If any of the following is on your list, stay on Cloudflare — Itnetic does not build these and is not trying to.
The pattern is almost always the same: a team that needs one specific control and finds it sitting a tier or two above where they are.
Both edges challenge suspicious traffic. The difference is what happens in the first second. Itnetic counts navigations per host at the edge itself and flips a domain into challenge mode without a round trip to any control plane, then fans that decision out to every other point of presence so an attacker cannot simply re-resolve to a node that has not noticed yet. Repeat offenders are dropped in the kernel, before a TLS handshake is paid for. Real visitors get an invisible proof-of-work, never an image grid.
Cloudflare’s standard onboarding takes over your zone’s nameservers; CNAME setup is a higher-plan option. Itnetic never asks for your nameservers. You add a TXT record to prove ownership and point one traffic record at the edge, at whatever DNS provider you already use. The practical consequence is that you can migrate a single hostname, watch it in the logs for a week, and leave the rest of the zone exactly where it is.
For a single hostname, chaining two proxying edges is rarely what you want: two challenge layers, two caching decisions, and the inner edge seeing the outer edge’s IP addresses instead of your visitors’, which quietly degrades every per-IP defence. Splitting by hostname works fine — keep a marketing site on one, put the store or the API on the other.
FAQ
For a narrow job — keeping a site, store, API or game server online through an attack, with full visibility and no feature gating — Itnetic gives you more on a smaller plan. For a platform job — edge compute, object storage, DNS, Zero Trust — Cloudflare is a different category of product and Itnetic is not a substitute.
As of 10 September 2026: the waiting room (Business and Enterprise there), raw per-request log export (Enterprise Logpush), managed WAF rulesets (paid plans), origin load balancing (a paid add-on) and bring-your-own certificates (higher plans). All of those are on the Itnetic free plan.
Workers and the whole developer platform, R2 and other storage, authoritative DNS, a registrar, Zero Trust, and an anycast network at a scale we do not claim to match. Those are real reasons to stay.
Our plans are free, €5, €29, €99 and €1,000 per month, and they differ only by domain count and delivered bandwidth. We will not put a number on anyone else’s plan here, because their prices are theirs to publish. The structural difference is that you never move up an Itnetic tier to unlock a capability.
No. Two DNS records at your existing provider. That is also what makes a hostname-by-hostname migration possible.
Add the domain, add the TXT proof, point the traffic record. Most customers are serving through the edge within five minutes of the record propagating, and the per-request log lets you confirm the cutover rather than assume it.
Same provider, different question — each page compares what matters to one specific use case.
Same method, different provider — feature availability by plan, with the date it was checked.
Two DNS records, no nameserver change, free plan with no card.