Based in Cyprus, BridgerPay offers a SaaS platform that enables ecommerce merchants to connect their online stores to over 300 payment service providers in 170 countries in just a few clicks. BridgerPay’s platform frees merchants from having to manage multiple payment providers and enables merchants to scale globally by making it simple for them to add payment options that are local to a specific area. Currently, BridgerPay works with approximately 250 merchants worldwide and facilitates over $250 million in transactions monthly.
Shortly after launching their platform, BridgerPay began experiencing complex DDoS attacks that would slow HTTP requests and strain their resources. As part of the BridgerPay product is embedded within websites, they had to protect themselves as well as their software from any attacks that might also occur on outside websites. Additionally, these attacks were preventing access to BridgerPay’s merchant portal, which its customers used to configure and maintain their accounts. BridgerPay also wanted a simpler and more secure way to protect user access to the merchant portal, which was being protected by authentication secrets.
BridgerPay signed up for Cloudflare’s performance and security suite, along with Cloudflare Access, which uses a Zero Trust model to help teams secure corporate applications with better performance and security than a VPN; Cloudflare Rate Limiting, which helps protect against DDoS and other automated cyber attacks; and Argo Smart Routing, which detects real-time network congestion and routes web traffic across the fastest and most reliable network paths.
While Access is designed to enable distributed workforces to securely connect to internal resources, BridgerPay easily adapted it for a different use case: ensuring that their merchants could securely access their online admin portal.
“Access was the perfect solution for securing our merchant portal,” recalls Yaron Hersh, CTO. “Within five minutes, we had it completely set up, without having to rewrite code or make any other changes.”
Cloudflare Access adds an authentication page in front of applications an organization doesn’t want to be publicly accessible, as well as securing merchant logins with Zero Trust authentication. Access also shields the portal from DDoS and other automated attacks, since the portal is no longer visible on the public internet.
“Some DDoS attacks were slowing the portal,” Hersh adds. “Putting Access in front of it helped prevent DDoS attacks and potential downtime, and it also made merchant logins more secure.”
Currently, BridgerPay has about 200 Access seats. The company is planning to expand its usage to protect internal resources for employees, who currently use VPNs.
“Our VPN clients are constantly under attack. They’re also very difficult for our IT team to configure, and for our employees to use,” Hersh says. “Access is an easier, faster, and simpler solution for everyone, not to mention more secure.”
Without Cloudflare Access, BridgerPay would have had to develop its own internal authentication solution, a process that would take months -- and could come at a severe opportunity cost, since developers wouldn’t have time to work on internal projects.
“Using Access instead of developing our own solution saved us hundreds of work-hours, but the savings goes beyond payroll,” says Ran Cohen, Co-Founder and CEO. “We wouldn’t be able to grow our client base if we didn’t have the time to focus on building new features.”
“Access gave us time to work on our business instead of just at it,” Hersh adds. “Security isn’t a revenue driver, but it’s essential to the business. Cloudflare Access enabled us to quickly deploy a secure access solution for our business.”
In addition to Access, BridgerPay uses a number of other Cloudflare products, including Rate Limiting, Argo Smart Routing, and Cloudflare Workers.