OneTrust helps companies be more trusted and use technology to make trust a competitive advantage. It is the fastest-growing privately held company in the U.S., with a stunning 48,000% three-year growth rate. Over 7,500 businesses worldwide utilize OneTrust’s SaaS solutions to manage privacy, security, and governance to comply with regulations such as the CCPA, GDPR, LGPD, PDPA, and ISO27001.
When CTO Blake Brannon first joined OneTrust, the company was using its cloud service provider’s native security tools to protect its SaaS platform, as well as the cloud provider’s compute function to run custom code for its most visible product: website cookie banners. Access to OneTrust’s internal apps was protected by a VPN. Brannon wanted more efficient, scalable, and cost-effective performance and security solutions to support the company’s tremendous growth.
“OneTrust is growing very quickly, and international privacy regulations are continuously changing,” Brannon explains. “We need agility and the ability to scale quickly and efficiently. The solutions we were using weren’t robust enough to handle our growth.”
OneTrust started with Cloudflare’s core performance and security suite, including Cloudflare WAF. As OneTrust grew, the company added Rate Limiting, Argo Smart Routing, SSL for SaaS, Workers, and Access.
Cloudflare Workers acts as OneTrust’s serverless architecture, helping the company deliver crucial product features while minimizing latency, costs, and development time.
One such product is OneTrust’s Cookie Consent product, privacy pop-up banners that are personalized based on each site visitor’s location. These banners — which are often key to complying with the GDPR, the California Consumer Privacy Act (CCPA), and other regional privacy regulations — appear when a visitor from a jurisdiction covered by one of these regulations visits a website. The banners inform visitors that their data may be collected and used for certain purposes and to obtain their consent to use the data.