Cloudflare already sits in front of gainsight.com and is the full DNS/edge provider for Staircase AI. Seven acquisitions in six years — Aptrinsic, inSided, Northpass, Staircase AI, ModerateKit, e.l.k., and Skilljar — have left the rest of the portfolio spread across AWS, Google Cloud, Azure, and Heroku. Gainsight's own security team is already looking for a single WAF across clouds — one network can be that answer.
gainsight.com sits on GoDaddy + UltraDNS, Skilljar/Northpass/inSided sit on AWS Route53, and Aptrinsic sits on GoDaddy — each with its own partial or nonexistent edge protection. Staircase AI is already fully delegated to Cloudflare; use it as the template.
Gainsight's own Senior Information Security Analyst confirmed a product line runs Azure WAF and ModSecurity (AWS Env) side by side and is explicitly looking to "maintain a single WAF for both the clouds." The Gainsight CS core app (app.gainsight.com / auth.gainsightcloud.com) separately resolves straight to an AWS load balancer with no edge WAF at all.
Skilljar (dashboard.skilljar.com) and Gainsight CE/Northpass (app.northpass.com) are both video-heavy customer-education platforms today running on AWS — and are the two most obviously overlapping products post-acquisition.
Course assets, community media, and static marketing files (static.gainsight.com) are split across AWS S3/CloudFront and Heroku today. R2 charges $0 egress and pairs directly with Stream and Images as one origin.
Gainsight's own security team described their current per-tenant custom-domain flow directly: customers set a CNAME, then "Let's Encrypt take[s] care for the HTTP Challenge" via cert-manager — manual, per-domain, ops-owned. Communities (ex-inSided) is the clearest fit, white-labeled for Zoom, Zendesk, Greenhouse, and Kaseya per Gainsight's own May 2026 release.
Gainsight's own Oct 2025 release announced a "Moderation AI Agent" for Customer Communities. Stopping bot/spam signups and posts at the edge cuts the volume — and cost — of what that AI layer has to review.
Gainsight's own security page discloses a Sept 2025 incident: an OAuth-token theft campaign against Salesloft Drift compromised business contact data and support-case content connected to their Salesforce environment. Their mail is also routed through Mimecast.
Gainsight markets Atlas AI Agents and a public MCP Library, and Staircase AI (Cloudflare's one fully-adopted asset here) just earned ISO 42001 — the AI-management-systems standard. AI Gateway puts a governed, logged front door on every LLM call across these products; Enterprise MCP lets Gainsight expose internal systems to agents safely, behind Zero Trust, instead of open data paths.
| Function | Today | How it was identified | On Cloudflare |
|---|---|---|---|
| Corporate site edge | WP Engine + partial Cloudflare identified | x-powered-by: WP Engine; server: cloudflare; NS: GoDaddy/UltraDNS | Full Cloudflare (DNS+WAF+CDN) |
| Gainsight CS (core app) | AWS ELB, us-east-1, no CDN | app.gainsight.com → prod-apigateway-lb-*.us-east-1.elb.amazonaws.com; no cf-ray | WAF + Bot Management |
| Gainsight PX (ex-Aptrinsic) | Google Cloud | app.aptrinsic.com — "via: 1.1 google"; GCP IP range | CDN/Workers for embedded SDK |
| Gainsight CE (ex-Northpass) | AWS, no CDN | app.northpass.com resolves in AWS ranges; no cf-ray | Stream + R2 |
| Customer Communities (ex-inSided) | AWS CloudFront | communities.gainsight.com → insided.com → *.cloudfront.net | Cloudflare for SaaS + Bot Mgmt |
| Skilljar (app) | AWS CloudFront | dashboard.skilljar.com — x-amz-cf-id / via CloudFront | Stream + R2 |
| Static / marketing assets | Heroku | static.gainsight.com → herokudns.com | R2 / Workers |
| Staircase AI | Cloudflare (full) | NS: aitana.ns.cloudflare.com, burt.ns.cloudflare.com | Expand: AI Gateway + MCP |
| Email security | Mimecast | MX: us-smtp-inbound-1/2.mimecast.com | Cloudflare Email Security (evaluate) |
| WAF (secondary product line) | Azure WAF + AWS ModSecurity confirmed | *Per Gainsight InfoSec (Feb 2026 email): "Azure WAF and ModSecurity (AWS Env). Application on both clouds." | One Cloudflare WAF policy, both clouds |
| Custom-domain TLS | Manual Let's Encrypt + cert-manager confirmed | *Per account-team: CNAME + HTTP-01 challenge, ops-managed per tenant | Cloudflare for SaaS (automated) |
| VPN / ZTNA | AWS native + Palo Alto Prisma confirmed | *Per account-team (Gainsight Tech Ops, Nov 2025 call) | Cloudflare Access |