Skip to content

Cloudflare Project Galileo


Summary

Cloudflare’s Project Galileo provides free Business-plan protection (DDoS mitigation, WAF, CDN, email security, Zero Trust) to qualifying public-interest organisations in vulnerable categories — journalism, human rights, civil society, democracy, civic engagement, arts, vulnerable populations. It is built specifically for the kind of organisation other vendor programs exclude: advocacy, campaigning, and human-rights groups are the program’s core constituency, not a side case. It is the single most important security/CDN offer in the procurement stack for an advocacy NGO.

Body

https://www.cloudflare.com/galileo/

Project Galileo is Cloudflare’s flagship civic-security program, launched in 2014 and now serving thousands of qualifying public-interest organisations globally. It provides the full Cloudflare Business plan at no cost — unmetered DDoS mitigation, Web Application Firewall (WAF), CDN, email security, Zero Trust access controls — to organisations that meet the program’s mission criteria [source: cloudflare-galileo].

The eligibility framework is category-based, not legal-form-based: applicants must be working in one or more of journalism / press freedom, human rights, civil society, democracy and civic engagement, arts and culture, or serving vulnerable populations [source: cloudflare-galileo]. The application is reviewed by Cloudflare together with civil-society partner organisations (Access Now, EFF, Mozilla Foundation, and others); an organisation does NOT need to be a registered charity, does NOT need TechSoup validation, and is NOT excluded by virtue of doing advocacy or political work [source: cloudflare-galileo].

The “scrape blocked” outcome in the local manifest reflects Cloudflare’s own bot-wall blocking the stealth scraper; the program’s existence, scope, and eligibility are documented across Cloudflare’s blog (11-years-of-Galileo anniversary post), the program’s application page, and civil-society partner publications — the figure and eligibility above are taken from the directory files and the cross-referenced civil-society partner sources rather than from a successful HTTP scrape of the page itself.

Use it for

Protecting a campaign website or movement platform against DDoS and hostile traffic at no cost; meeting the security baseline of a journalism, human-rights, democracy, or civil-society project; serving an organisation that is excluded from TechSoup-gated programs (Cloudflare does not require TechSoup validation).