Ultragenyx × Cloudflare
Talk to Cloudflare →
Executive Brief · Vendor Consolidation

One network for Ultragenyx's zero trust, email security & edge.

Cloudflare already sits in front of ultragenyx.com — DNS, CDN and Bot Management are live today. Fold Netskope (~1,500 seats), the Mimecast email gateway, and a legacy VPN onto that same network: fewer vendors, one control plane, and a single set of logs for a regulated biopharmaceutical company.

Why this matters now

Ultragenyx Pharmaceutical (NASDAQ: RARE) is a Novato, CA-based biopharmaceutical company developing therapies for rare and ultra-rare genetic diseases, with roughly 1,371 employees as of its FY2025 results and an international footprint spanning the US and EU (ultragenyx.eu, ultragenyx.de) plus Latin American sites. As a regulated life-sciences company handling clinical, patient, and commercial data across a distributed workforce, the security surface area — endpoint-to-cloud access, email, and remote connectivity — is exactly where vendor sprawl accumulates fastest, and where a single network pays off fastest.

Source: Ultragenyx Q4/FY2025 financial results, reported Feb. 12, 2026 (ir.ultragenyx.com).

From vendor sprawl to one network

Identified on ultragenyx.com's public DNS/HTTP footprint, plus the SSE incumbent (*per account-team). The right is where it all can live.
6 touchpoints → 1 network
CloudflareDNS · CDN · Bot Mgmt · today
NetskopeSSE / ZTNA* ~1,500 seats
Mimecastemail security gateway
DMARC AnalyzerDMARC monitoring
Azure VPNlegacy remote access
AkamaiIR microsite (gcs-web.com)
Cloudflare one network · one bill · one control plane
Goal: one Zero Trust + email security vendor

Six consolidation plays

Each maps to something identified on Ultragenyx's live network footprint — or confirmed by the account team.
01

Cloudflare One — retire Netskope

↳ replaces Netskope (SSE)

Collapse Secure Web Gateway, CASB, DLP and ZTNA onto Cloudflare One — one agent, one policy engine, on the same network already in front of ultragenyx.com. No separate SSE vendor, no per-module licensing.

  • ~1,500 seats — effectively company-wideper account-team
  • Gateway (SWG/DNS filtering) + CASB + DLP under one policy
  • Remote Browser Isolation for high-risk web/SaaS sessions
02

Access + WARP — retire the legacy VPN

↳ replaces the Azure-hosted VPN

Pair the Netskope migration with retiring the parallel remote-access VPN — device-posture-checked application access, no split-tunnel client, same Zero Trust rollout.

  • Identified: vpn.ultragenyx.com resolves to a Microsoft Azure IP
  • Cloudflare Access replaces the VPN concentrator for app access
  • One Zero Trust motion retires both the SSE vendor and the VPN
03

Email Security — displace Mimecast

↳ replaces Mimecast

Cloudflare Email Security provides pre-delivery phishing/BEC detection and API-based deployment, removing a second mail-security hop and a separate vendor invoice.

  • Identified: MX → usb-smtp-inbound-{1,2}.mimecast.com
  • SPF record redirects into Mimecast's managed SPF
  • Same console as Zero Trust & DMARC Management below
04

DMARC Management

↳ replaces DMARC Analyzer

Fold aggregate/forensic DMARC reporting and SPF/DKIM guidance into the same dashboard as Email Security — one pane of glass for mail authentication instead of a standalone monitoring tool.

  • Identified: DMARC rua/ruf point to rep/for.dmarcanalyzer.com
  • Policy already at p=reject — strong baseline to carry forward
  • Native reporting alongside the Email Security console
05

WAF, Bot & API Shield — expand, don't replace

Confirm tier · extend coverage

Ultragenyx is already Cloudflare-proxied with Bot Management active — but plan tier is unconfirmed. This is a pure expansion motion, not a displacement.

  • Confirmed via cf-ray + active __cf_bm cookie
  • Live on ultragenyx.com, www, .eu, .de, ultrarareadvocacy.com, talent subdomain
  • Extend to full WAF/Bot/API Shield coverage across all six properties
06

One network for the whole portfolio

↳ brings the IR microsite onto Cloudflare

Six Ultragenyx properties already sit behind Cloudflare. The one exception is ir.ultragenyx.com — the investor-relations microsite, hosted on the third-party GCS-Web IR platform and fronted by Akamai. Lowest ACV, highest symbolism: bringing it onto the same network (directly or via the IR vendor) completes a single bot/DDoS posture and one set of logs across 100% of Ultragenyx's public surface.

  • Identified: ir.ultragenyx.com CNAME → gcs-web.com → edgekey.net / akamaiedge.net
  • No Fastly footprint detected anywhere in the digital footprint reviewed

Consolidation roadmap

A staged path — confirm what's already live, pilot the Zero Trust swap, then fully retire Netskope and Mimecast.
Next 90 days

Confirm & land quick wins

  • Confirm current Cloudflare plan/tier on all 6 already-proxied domains
  • Stand up Email Security + DMARC Management alongside Mimecast/DMARC Analyzer
  • Scope Netskope seat count & policy inventory (~1,500 seats) for migration planning
6–9 months

Pilot the Zero Trust swap

  • Pilot Access + WARP for a user group; begin VPN retirement
  • Begin phased Netskope → Cloudflare One cutover (Gateway/CASB/DLP first)
  • Extend WAF/Bot/API Shield to full coverage on all Cloudflare-fronted domains
12 months

Consolidate & displace

  • Full Netskope retirement — all ~1,500 seats on Cloudflare One
  • Mimecast + DMARC Analyzer fully decommissioned
  • Bring ir.ultragenyx.com onto the same network; one vendor relationship

Consolidation snapshot

Current-state vendors are evidence-based; nothing here is assumed.
FunctionTodayHow it was identifiedOn Cloudflare
SSE / ZTNA Netskope, ~1,500 seats acct-team Account-team input Cloudflare One (Gateway/CASB/DLP/Access)
Remote access VPN Legacy VPN identified vpn.ultragenyx.com → Microsoft Azure IP Access + WARP
Email security gateway Mimecast identified MX: usb-smtp-inbound-*.mimecast.com Email Security
DMARC monitoring DMARC Analyzer identified DMARC TXT rua/ruf → dmarcanalyzer.com DMARC Management
CDN / DNS / Bot Mgmt Cloudflare already live cf-ray, Cloudflare NS, __cf_bm cookie on 6 domains Confirm tier; expand WAF/Bot/API Shield
Investor relations microsite Akamai (via gcs-web.com) identified ir.ultragenyx.com CNAME → edgekey.net Bring onto Cloudflare

How we know — observed on ultragenyx.com

No assumptions: every current-state vendor below was identified from public DNS, HTTP headers, or MX/SPF/DMARC records, except Netskope which is per account-team input.
Cloudflare already fronting 6 domains Netskope *per account-team, ~1,500 seats Mimecast MX records DMARC Analyzer DMARC TXT rua/ruf Azure VPN vpn.ultragenyx.com A record Akamai ir.ultragenyx.com CNAME only
LIVE Checking the Cloudflare edge serving this page…