Internal expansion brief · Matt Holscher · Digital Native Sales Team · May 13, 2026
SheerID's marketing/dev/resource/shop subdomains already resolve to Cloudflare edge IPs. But their production verification stack — where the money, the fraud, and the egress live — runs on AWS EKS in us-east-1 + AWS Global Accelerator. That's the expansion wedge.
Domain TXT records reveal active vendor relationships — each one is a value-play signal.
Score = ($ Impact × Probability) ÷ Effort. Higher score = pursue first.
S3-compatible, zero-egress storage for ID images, edu credentials, military DD-214s, healthcare licenses. Drop-in for boto3/aws-sdk. Demo site already deployed.
ML bot detection on verify.sheerid.com. SpyCloud TXT record proves they already pay for credential abuse intel. Bot Mgmt at the edge gives the same signal earlier, with lower latency.
Privacy-first CAPTCHA replacement. Drop-in JS tag. Reduces friction for legitimate students / military / educators / healthcare workers — conversion-lift narrative for SheerID's brand customers.
Schema validation, rate-limiting, sequence detection, abuse prevention. Stops malformed-payload attacks and protects API schema from scraping. Natural sequence after Bot Mgmt lands.
Cloudflare Email Security via Google Workspace API — no MX cutover. Catches BEC and credential phishing aimed at exec inboxes that Google misses.
Anthropic TXT record confirms they're a Claude customer. AI Gateway gives observability + caching + rate-limiting across self-hosted ML and provider APIs. Workers AI for edge inference.
Moves Marketo, Sendgrid, analytics tags server-side. Better privacy posture, faster pages, GDPR/CCPA narrative.
Site already runs through Cloudflare proxy but likely sourced from Webflow/WP. Pages with git-driven deploys is the modern shape.
Pin verification artifacts to EU/NA/APAC at the edge. GDPR (EU), CCPA (CA), regional residency by configuration.
Caches + pools connections to RDS/Aurora in us-east-1. Unblocks edge Workers serving verification globally without cold round-trips.
Per-brand-customer dispatch namespaces. Lets SheerID offer "edge-deployed custom verification logic" as a brand-customer upsell. Architecture conversation; long cycle.
Network-layer protection for AWS EKS in us-east-1. Replaces AWS Shield Advanced. Defensive play — pull-trigger when DDoS comes up.
SWG + ZTNA + CASB + Email Security + Browser Isolation. Distributed workforce with SaaS sprawl (Atlassian/Miro/Rippling/Zendesk per TXT records). Different buyer, different timeline.
Sequence the Tier 1 plays in parallel — they share buyers and reinforce each other.
Best-guess personas; verify via LinkedIn before outreach.
| Persona | Plays they care about |
|---|---|
| CTO / VP Engineering | R2, Workers AI, Workers for Platforms, Hyperdrive |
| Head of Platform / SRE | R2, Magic Transit, API Shield, Bot Mgmt |
| Head of Trust & Safety / Fraud | Bot Mgmt, Turnstile, API Shield |
| CISO / Head of Security | Email Security, CF One, Bot Mgmt, DLS |
| VP Product | Turnstile (UX), Workers for Platforms (brand-customer differentiation) |
| CFO / VP Finance | R2 (cost reduction), CF One (consolidation), aggregate TCO |