Cloudflare for Dolby

The Connectivity Cloud

One unified platform. Six solution pillars. The same global network that already serves dolby.com & dolby.io — now powering every workload Dolby runs.

One vendor One contract 330+ cities Already in production at Dolby
All product lines · Built on the same platform
dolby.com & dolby.io already served by Cloudflare

Sight, sound & spectacular experiences
at planetary scale.

From Dolby Atmos in 200M+ cars and living rooms to Dolby OptiView powering live sports for the NFL, NASCAR, Paddy Power and Bet365 — Dolby's reach is already global. The Cloudflare Developer Platform is how that reach gets faster, more personalized, and AI-native — without leaving the Cloudflare network Dolby already depends on.

1.3B+
Devices in Dolby ecosystem
<500ms
OptiView ultra-low latency
330+
Cloudflare PoPs worldwide
$1.3B
Dolby FY24 revenue (NYSE: DLB)
The Dolby surface area

Six product lines. One Cloudflare-shaped opportunity.

Dolby's product portfolio spans cinema, in-car, streaming, music, and a fast-growing B2B developer platform. Every one of these has a compute, delivery, real-time, or personalization layer that Cloudflare is uniquely positioned to accelerate.

SPATIAL AUDIO

Dolby Atmos

Immersive, object-based audio in movies, music streaming, gaming, and now 200M+ cars (BMW 7 Series, Mahindra XUV 7XO, Tata Sierra, Hyundai Elexio, and more).

HDR IMAGING

Dolby Vision & Vision 2

HDR picture standard featured in Fast Company's Most Innovative 2026 list. Adopted across Peacock, Douyin, ETV Win, EVO Entertainment, and consumer TVs.

B2B DEV PLATFORM

Dolby OptiView

The streaming platform born from acquiring Millicast (real-time WebRTC) and THEO (player). Ultra-low latency, SDK-driven video for live sports, betting, and fan engagement.

EXHIBITION

Dolby Cinema

Premium theatrical format combining Dolby Vision + Atmos. Expanding aggressively across India (Pune, Bengaluru, Tamil Nadu) and partnering with TOHO in Japan.

NEXT-GEN CODEC

Dolby AC-4

Next-gen audio codec coming to Peacock for live sports and expanding to QQ Music. Powers efficient Atmos delivery at streaming scale.

CONNECTED HOME

Atmos FlexConnect

World's first soundbar audio system powered by Atmos FlexConnect (with LG). Brings spatial audio to mainstream TVs without complex setup.

60+
Years of innovation since founding (1965)
2,000+
Employees globally
7,800+
Patents in audio & imaging IP
NFL · NASCAR · Peacock
Anchor OptiView & Atmos customers
Implementation Roadmap

Get started with Cloudflare — Zscaler decommissioned in 90 days.

Dolby is already a Cloudflare customer at the CDN/zone layer. The fastest credibility win is replacing Zscaler with Cloudflare Zero Trust on a 90-day, side-by-side migration plan that ends with the Zscaler contract non-renewed. Every phase below builds incrementally on what's already deployed — no rip-and-replace, no user-facing outage.

Get Started Zscaler Cloudflare in 90 days

Replace Zscaler with Cloudflare Zero Trust — coexistence to cutover in three sprints.

Cloudflare runs alongside Zscaler from day one. Engineers keep the Zscaler client during Phases 1–2 — only the apps that have moved get steered to Cloudflare. By Day 90, Zscaler is decommissioned and the renewal is non-renewed.

Days 0–30 · Sprint 1

Coexistence & foundation

  • Stand up Cloudflare One tenant
  • Deploy WARP alongside Zscaler Client Connector
  • Federate Dolby's IdP via Managed OAuth
  • Route Cloudflare-hosted apps (dolby.com, dolby.io, OptiView admin) through WARP
  • Everything else still on Zscaler — zero user friction
Days 30–60 · Sprint 2

Replace ZPA

  • Move internal apps to Cloudflare Access app-by-app
  • Confluence, Jira, GitHub Enterprise, mastering tools, OptiView dashboards
  • Add device posture & conditional MFA per studio partner
  • Decommission ZPA app definitions as each app migrates
  • Studio & OEM partners get clientless browser access — no Zscaler install required
Days 60–90 · Sprint 3

Replace ZIA & decommission

  • Cut over web egress + DLP to Cloudflare Gateway
  • Enable AI shadow-IT controls + content-fingerprint DLP from day one
  • Uninstall Zscaler Client Connector — WARP is now the only endpoint agent
  • Non-renew the Zscaler contract at next renewal date
  • Reinvest savings into Email Security + Brand Protection
Day 90 outcome
Zscaler agent removed from every endpoint. Same SSE outcomes on the network that already serves dolby.io. $180K+/yr saved on the Zscaler line item alone — recovered into the broader Connectivity Cloud spend.
Then expand across the Connectivity Cloud · Months 4–12
01
Months 4–5

App Sec & Quick Wins

  • Flagship for Vision 2 & AC-4 rollouts
  • R2 for VOD archive — cancel S3 egress
  • Workers in front of OptiView manifests
  • Page Shield + Bot Management on dashboard.dolby.io
02
Months 5–7

Network & Foundation

  • Magic WAN cutover at first 2 office sites (replaces MPLS)
  • Magic Transit in front of OptiView ingest
  • Durable Objects per OptiView stream
  • Workers AI for captions & loudness
03
Months 7–10

AI Agents

  • Voice Agents for live commentary
  • Workflows v2 for SGAI ad pipeline
  • Browser Run for cinema ops
  • Agent Memory for fan personalization
04
Months 10–12

Full Platform

  • Magic Firewall replaces Palo Alto at remaining sites
  • Enterprise MCP across OptiView APIs
  • Data Platform for telemetry on R2
  • Realtime as a second SFU footprint
ROI & Vendor Consolidation for Dolby

Cancel four contracts. Save $9.7M+ over three years.

Consolidating Zscaler (SSE), Palo Alto Networks (network firewalls), AWS S3 + CloudFront egress, and Proofpoint (email security) onto the Cloudflare Connectivity Cloud isn't just a security upgrade — it's a measurable line-item reduction across four enterprise contracts that Dolby's CFO already sees on the budget every quarter. Below is the modeled annual impact based on typical enterprise contract sizing for a $1.3B media & technology company.

3-Year Total Cost Avoidance

From four vendor contracts → one Cloudflare platform.

Every number below is modeled from typical enterprise pricing for a global media & technology company of Dolby's scale (NYSE: DLB · ~2,000 employees · $1.3B FY24 revenue · global office footprint · multi-region OptiView platform on AWS). Final numbers will vary based on actual contract terms — these are conservative, sales-friendly estimates.

$9.7M
Saved over 3 years
~$3.24M annual run-rate savings · 3-9 month payback
Z
Replacing Zscaler SSE consolidation → Cloudflare Zero Trust
Today — Zscaler $300K / yr Current Dolby Zscaler contract — likely ZIA-led with partial ZPA coverage across ~2,000 employees ($12.50/user/month blended), or a heavily discounted multi-year deal locked in pre-renewal.
With Cloudflare Zero Trust $120K / yr Full SSE bundle (Access + Gateway + CASB + DLP + Browser Isolation) at ~$5/user/month × 2,000 employees — wider feature set than Dolby gets today, lower cost, single WARP agent on every endpoint.
Annual savings $180K / yr · 60% lower
Why the math works: Even against Dolby's already-discounted $300K Zscaler contract, Cloudflare's bundled SSE comes in materially lower because there are no a-la-carte feature uplifts — AI shadow-IT controls, browser isolation, CASB, and DLP are all included. Bonus: Cancel the secondary "clean pipe" carrier fee (typically $80–150K/yr if Dolby has one) since Cloudflare's Anycast IS the clean pipe. The bigger Cloudflare advantage here isn't cost — it's collapsing SSE onto the same network that already terminates dolby.io traffic (no trombone, no second vendor SLA on top).
P
Replacing Palo Alto Networks Network firewall fleet → Magic Firewall
Today — Palo Alto Networks $1.6M / yr PA-5400-series at ~8 office sites (SF, Beijing, Bengaluru, Wrocław, Tokyo, Shanghai, Belgium, San Diego) + virtual PAs in AWS. Hardware refresh + Threat Prevention + WildFire + URL Filtering subs.
With Magic Firewall $520K / yr Global L3/L4 firewall + IDS/IPS as a service. No appliances. Same policy applied everywhere. Includes Magic WAN for site-to-site, replacing SD-WAN appliances too.
Annual savings $1.08M / yr · 68% lower
Why the math works: Palo Alto's enterprise cost has three layers — hardware (5-year refresh), subscription bundles (TP, WildFire, URL, DNS Sec, GlobalProtect), and ops overhead (rule replication across 8 sites). Magic Firewall collapses all three into one global policy engine. No more $250K/site refresh cycle. No more change-control meetings to push a rule to 12 different consoles.
$
Replacing AWS S3 + CloudFront Egress Zero-egress object storage → R2
Today — AWS S3 + CloudFront $2.4M / yr Modeled: ~3 PB of OptiView VOD + Vision/Atmos masters at $0.023/GB-month ($830K). Plus ~500 TB/mo CloudFront egress at $0.085/GB ($510K/mo blended) ≈ $1.5–1.8M egress + ~$600K storage.
With Cloudflare R2 + CDN $640K / yr 3 PB on R2 at $0.015/GB-month = $540K. $0 egress to internet. $0 egress to Workers. ~$100K Class A/B ops. CDN already in Dolby's existing contract.
Annual savings $1.76M / yr · 73% lower
Why the math works: S3 + CloudFront is the largest single line-item AWS bill for any media company. R2's zero egress fee model is the highest-impact swap in this entire ROI analysis. Storage is cheaper too (~35% less per GB-month than S3 Standard). Plus, every Workers AI inference call against the VOD library is now free egress — uncapping product innovation that was previously gated on AWS spend.
P
Replacing Proofpoint Email security → Cloudflare Email Security (Area 1)
Today — Proofpoint $360K / yr P3 / Enterprise Plus bundle for ~2,000 mailboxes at $15/user/month. Includes URL Defense, Attachment Defense, TAP, Email DLP, plus brand-spoofing add-ons.
With Cloudflare Email Security $144K / yr Cloudflare Email Security (Area 1) at ~$6/user/month × 2,000 mailboxes. Includes Brand Protection (lookalike domain takedowns) and DMARC management — Dolby's IP team currently pays a separate vendor for these.
Annual savings $216K / yr · 60% lower
Why the math works: Proofpoint's enterprise pricing has tier-locked features. Cloudflare Email Security bundles inline + post-delivery scanning, BEC detection, business-context AI, and brand protection in one SKU. "Dolby" is one of the most-spoofed consumer brands — moving Brand Protection into the same console as email security shortens the time from lookalike-domain registration to takedown from days to hours.

3-Year TCO summary

Workload / Vendor
Today (Year 1)
With Cloudflare
Annual Savings
3-Year Savings
Zscaler (2,000 users · current Dolby contract)
$300K
$120K
$180K
$540K
Palo Alto firewalls (8 sites + virtual)
$1.60M
$520K
$1.08M
$3.24M
AWS S3 + CloudFront egress (~3 PB)
$2.40M
$640K
$1.76M
$5.28M
Proofpoint email security (2,000 mailboxes)
$360K
$144K
$216K
$648K
TOTAL — 4 vendor consolidations
$4.66M
$1.424M
$3.236M
$9.708M
$9.7M
3-year total cost avoidance across four vendor consolidations
69%
Average reduction across all four vendor categories vs status quo
4 → 1
Vendor contracts collapsed onto a single Cloudflare enterprise agreement
3–9 mo
Typical payback period including migration ops & contract overlap

A note on these numbers: These are modeled estimates based on standard enterprise pricing for a company of Dolby's size — not committed quotes. Actual savings depend on Dolby's current contract terms, multi-year discounts already locked in with each vendor, and the specifics of OptiView's AWS architecture. The Cloudflare account team can produce a custom TCO analysis with NDA-protected pricing for each line item within two business days of a discovery conversation. The relative ratios (Cloudflare ~30–70% lower per workload) consistently hold across Cloudflare's enterprise media & technology customer base.

Cloudflare Zero Trust for Dolby

Protect every Vision master, every studio handoff, every M&A integration.

Dolby's value lives in pre-release content, source code, encoder IP, and the trust of every major studio, OEM, and broadcaster. Cloudflare Zero Trust replaces a stack of VPN concentrators, legacy SWG appliances, and one-off SaaS proxies with a single identity-aware network — built for a company whose attack surface spans Hollywood, Detroit, Seoul, and a developer platform with thousands of API consumers.

▲ Threat

Pre-release leaks

Vision masters and Atmos stems for unreleased films flowing to dozens of studios & mastering houses

▲ Threat

M&A sprawl

THEO Technologies + Millicast brought new corp networks, identity providers, and SaaS tenants under one roof

▲ Threat

OEM partner risk

BMW, Mahindra, Hyundai, Tata, LG, TOHO all need scoped access to Dolby encoders & certification portals

▲ Threat

IP / patent portfolio

7,000+ patents (incl. acquired GE Licensing portfolio) — a target for nation-state and economic-espionage actors

01

Replace the studio & mastering-house VPN

Today, every studio that mixes a Dolby Atmos title or grades a Dolby Vision master likely connects via a legacy VPN concentrator (Cisco AnyConnect, Pulse, Palo Alto GlobalProtect). One stolen credential = full lateral movement to pre-release content. Cloudflare Access swaps the VPN for clientless, identity-aware reverse proxy to mastering tools, Dolby Professionals, and pre-release Vision portals — with device posture and conditional MFA per studio.

Cloudflare Access Device Posture WARP
02

Lock down OEM & licensee portals

BMW, Mahindra, Tata, Hyundai, LG, TOHO — every Dolby licensee needs scoped, audited access to certification suites, encoder downloads, and IP licensing portals. Managed OAuth in Cloudflare Access (new in Agents Week 2026) gives every OEM a federated identity, scoped JIT permissions, full audit log per engineer, and instant revocation when a partner program ends.

Managed OAuth Access for SaaS Audit Logpush
03

SWG & CASB for content engineers

Mastering engineers, sound designers, and ML researchers work across dozens of SaaS tools — Avid, Frame.io, GitHub, Figma, Hugging Face, OpenAI, Anthropic. Cloudflare Gateway inspects every egress request from corp devices, blocks shadow-AI uploads of unreleased content, enforces DLP on Atmos stems and Vision XMLs, and replaces the Zscaler / Netskope contract with a single agent (WARP) already deployed for Access.

Gateway (SWG) CASB DLP Shadow-AI controls
04

Integrate THEO & Millicast without merging VPCs

The THEO Technologies and Millicast acquisitions brought two engineering orgs, two identity providers, and two cloud footprints (largely AWS). Rebuilding into one VPC is an 18-month, multi-million-dollar project. Cloudflare Tunnel + Mesh lets THEO/Millicast resources stay where they are, exposed only through identity-checked tunnels — no public IPs, no flat L3 network, integrated in days, not quarters.

Cloudflare Tunnel Mesh Private DNS
05

Protect the OptiView dashboard & APIs

The OptiView console (dashboard.dolby.io) is the control plane for live streams powering the NFL, NASCAR, Paddy Power, Bet365, and Sky Racing. A single compromised customer account can take down a live game. WAF + Bot Management + Turnstile defend the dashboard from credential stuffing, scraper bots, and account takeover — at the same edge that already terminates dolby.io traffic.

WAF Bot Management Turnstile Account Takeover Protection
06

Email Security + Brand Protection for "Dolby"

"Dolby" is one of the world's most-spoofed brands — phishing kits target consumers ("verify your Dolby Atmos subscription"), licensees ("urgent IP renewal"), and the press desk. Cloudflare Email Security (Area 1) inspects inbound mail against business-context AI, while Brand Protection watches new domain registrations for dolby-* and *-dolby.com lookalikes — and lets Dolby's IP & trust team file takedowns in one click.

Email Security Brand Protection DMARC Management

What Cloudflare Zero Trust replaces in Dolby's stack

Legacy VPN (Cisco / Palo Alto / Pulse)
→ Cloudflare Access + WARP
Clientless reverse proxy + ZTNA. No more flat-network lateral movement; per-app identity checks.
Zscaler / Netskope SWG
→ Cloudflare Gateway
One vendor, one agent, one console for both ZTNA and SWG. Native shadow-AI controls.
Proofpoint / Mimecast email
→ Cloudflare Email Security
Inspects mail post-delivery using business-context AI. Catches BEC + brand-spoof attacks.
Patchwork of IdPs for OEMs
→ Managed OAuth in Access
One federated front door for every BMW, Tata, LG, TOHO engineer accessing Dolby portals.
Manual brand-takedown ops
→ Cloudflare Brand Protection
Auto-discovers dolby-* lookalike domains pre-launch. One-click takedowns via Cloudflare's network & legal team.
Custom MFT for studio handoffs
→ Access + R2 + signed URLs
Studios pull pre-release Vision masters via identity-checked links, served from R2 — zero egress, full audit log per byte.
Cloudflare Network as a Service for Dolby

Replace MPLS, transit, and DDoS scrubbing with one programmable global network.

Dolby runs a global engineering, mastering, and content-delivery footprint — San Francisco HQ, Beijing, Bengaluru, Wrocław (Poland), TOHO partner facilities in Tokyo, Dolby House Shanghai, plus the THEO Belgium and Millicast San Diego offices. Today that network is held together by some combination of MPLS circuits, SD-WAN, regional ISP transit, and dedicated DDoS scrubbing for OptiView's NFL and NASCAR ingest. Cloudflare's Network as a Service collapses all of that into one Anycast network already in 330+ cities — the same one that already serves dolby.com and dolby.io.

🌐
MPLS Replacement

Magic WAN

AT&T / NTT / Tata MPLS

SF ↔ Beijing ↔ Bengaluru ↔ Wrocław ↔ Tokyo ↔ Shanghai over Cloudflare's Anycast backbone. Sub-second site turn-up, identity-aware routing — without a 90-day carrier provisioning cycle or per-Mbps bill.

🔥
Network Firewalls

Magic Firewall

Palo Alto / Fortinet / Cisco ASA

Global L3/L4 firewall policy applied to every byte entering Dolby's network — office, cloud, partner. One rule plane, millisecond propagation worldwide. Decommission the appliance refresh cycle across all 8 office sites.

⚖️
Load Balancers

Cloudflare Load Balancing

F5 BIG-IP / Citrix ADC / AWS ELB

Global & local load balancing across OptiView origins, Dolby.io APIs, and AWS/GCP encode farms. Health checks every 15s, dynamic steering, session affinity. Replace the rack of F5s without losing the features.

🛡️
L3 DDoS Protection

Magic Transit

Arbor / Radware / Akamai Prolexic

Always-on L3/L4 DDoS mitigation at 500+ Tbps of edge capacity. Advertised via Dolby's own BGP. No swing during attacks — clean traffic forwards via GRE or CNI directly to OptiView's NFL+, NASCAR, & Paddy Power ingest.

◐ Today

MPLS & SD-WAN between offices

Dolby's global engineering footprint (SF, Beijing, Bengaluru, Wrocław, Tokyo, Shanghai) likely runs MPLS or SD-WAN overlays from carriers like AT&T, NTT, or Tata Communications. Expensive, slow to provision, and not built for cloud-native traffic.

◐ Today

Acquired networks bolted on

THEO (Belgium), Millicast (San Diego), and GE Licensing IP each came with their own transit, firewall stack, and ISP relationships. Integrating them into a unified Dolby WAN is a multi-quarter project per acquisition.

◐ Today

OptiView DDoS scrubbing

NFL+, NASCAR, Paddy Power, and Bet365 ingest endpoints are prime DDoS targets — especially during live betting windows. Today this likely runs through a dedicated scrubbing vendor (Arbor / Radware / Akamai Prolexic) on top of Cloudflare's edge.

◐ Today

Cloud egress to AWS / GCP

OptiView's encoding pipelines, Vision mastering tools, and ML training likely sit across AWS, GCP, and on-prem GPU clusters. Inter-cloud and cloud-to-office traffic crosses the public internet — paying egress twice and gaining nothing.

01

L3 DDoS Protection — Magic Transit, always-on at 500+ Tbps

OptiView's RTMP, WHIP, and SRT ingest endpoints for NFL+, NASCAR, Paddy Power, Sky Racing, and Bet365 are now mission-critical infrastructure. A single Sunday afternoon outage during NFL kickoff is a board-level event. Magic Transit advertises Dolby's IP space via BGP, scrubs L3/L4 DDoS volumetric & protocol attacks (SYN flood, UDP amp, DNS reflection, Memcached, Mirai variants) at 500+ Tbps of edge mitigation capacity, and forwards clean traffic via Anycast GRE or CNI. No BGP swing during attacks. No scrubbing trombone. No clean-pipe carrier on top.

Magic Transit L3/L4 DDoS BGP Anycast GRE / CNI
02

MPLS Replacement — Magic WAN over the Cloudflare backbone

Connect SF HQ, Beijing, Bengaluru, Wrocław (Dolby Poland), Tokyo (TOHO partner), Shanghai (Dolby House), Belgium (THEO), and San Diego (Millicast) over Cloudflare's Anycast backbone instead of carrier MPLS. Cancel the AT&T / NTT / Tata MPLS contract over 18 months as sites migrate one-by-one. Sub-second site turn-up, identity-aware routing, BFD failover, and full integration with Access & Gateway — without paying carrier per-Mbps rates that have not dropped since 2015.

Magic WAN Magic WAN Connector WARP Connector SD-WAN replacement
03

Network Firewall — Magic Firewall as one global policy plane

Dolby's firewall policy today is fragmented across Palo Alto / Fortinet / Cisco ASA appliances per office, AWS Security Groups per VPC, and probably legacy stuff in the dark. Magic Firewall is a single global L3/L4 firewall + IDS that applies the same rules to every byte entering Dolby's network — office, cloud, partner — with millisecond rule propagation across 330+ cities. No more appliance refresh cycles at 8 sites every 5 years. No more change-control meetings to push a rule to 12 different consoles.

Magic Firewall IDS / IPS Stateless & stateful L3/L4 Logpush to SIEM
04

Load Balancing — Global & local steering for OptiView

OptiView's origins span multiple AWS regions, GCP for ML workloads, and on-prem GPU clusters. Cloudflare Load Balancing replaces the rack of F5 BIG-IPs (and the AWS ELB / NLB / ALB stack on top) with one global L4/L7 load balancer. Active health checks every 15s, dynamic geo-steering for the closest healthy origin, session affinity for stateful streams, automatic failover during region outages, and weighted round-robin for canary deploys of new encoder versions.

Cloudflare Load Balancing Global & Local LB Health Checks Geo Steering
05

Cloudflare Network Interconnect — Private fiber to clouds & carriers

CNI gives Dolby private, dedicated physical interconnects to AWS, GCP, Azure, Oracle, plus 50+ carriers at major exchanges (Equinix, Megaport, Digital Realty). Stop paying AWS Data Transfer + a Cloudflare egress on the same byte. OptiView's encode origins on AWS, Dolby's GPU clusters wherever they sit, and the mastering rigs in TOHO/Shanghai all land on Cloudflare's network without crossing the public internet. Combined with R2's zero-egress storage, the AWS bill shrinks materially.

CNI Direct Connect partner Megaport Equinix Fabric
06

Spectrum + M&A on-ramps for THEO, Millicast & future deals

Spectrum protects and accelerates every non-HTTP protocol Dolby runs: OptiView's WebRTC SFU, SRT ingest, RTMP for legacy broadcasters, NDI/Dante audio for mastering, plus SSH bastions and SFTP for studio handoffs — all behind the same DDoS protection dolby.io already gets. Magic WAN Connector bridges acquired companies (THEO, Millicast, future M&A) onto Dolby's backbone in hours via a 1U appliance — not quarters of IP-range renumbering.

Spectrum TCP/UDP proxy Magic WAN Connector Cloudflare Tunnel
500+ Tbps
Global DDoS mitigation capacity Magic Transit absorbs — orders of magnitude beyond the largest recorded attack
330+
Cities where Dolby traffic can enter the Cloudflare backbone — closer to every employee than any MPLS carrier
< 3 sec
Median DDoS mitigation time on Magic Transit — automated, no SOC ticket required
$0
Egress charges when traffic flows R2 → Cloudflare backbone → Dolby clouds via CNI

What Cloudflare NaaS replaces in Dolby's stack

MPLS — AT&T / NTT / Tata Communications
→ Magic WAN over Anycast backbone
Same point-to-point reachability between SF, Beijing, Bengaluru, Wrocław, Tokyo & Shanghai — without the 90-day provisioning cycle or the per-Mbps carrier bill.
Network firewalls — Palo Alto, Fortinet, Cisco ASA
→ Magic Firewall (global L3/L4)
One policy across every Dolby office, cloud, & partner — with IDS/IPS bundled. No more refreshing physical appliances at 8 sites every 5 years.
Load balancers — F5 BIG-IP, Citrix ADC, AWS ELB/NLB
→ Cloudflare Load Balancing
Global & local L4/L7 LB with health checks, session affinity, geo-steering, and weighted canary deploys — for every OptiView origin across AWS / GCP / on-prem.
L3 DDoS scrubbing — Arbor, Radware, Akamai Prolexic
→ Magic Transit (500+ Tbps)
Always-on L3/L4 scrubbing, in-line with the Cloudflare edge that already serves dolby.io. No BGP swing during attacks. No scrubbing-vendor SLA stacked on top.
SD-WAN appliances — Velocloud, Silver Peak, Viptela
→ Magic WAN Connector
Same site-to-cloud and site-to-site overlay, plus identity-aware routing, integrated with Access & Gateway. One vendor for WAN + SSE + edge security.
AWS Data Transfer / inter-region egress fees
→ Cloudflare Network Interconnect
Private fiber between AWS/GCP/Azure regions and the Cloudflare backbone. Pay once on either side; the middle is free. Combined with R2 → real egress savings.
Public SSH/RDP bastions & jump boxes
→ Spectrum + Access
No public listener for SSH/RDP/SFTP. Identity-checked, DDoS-protected, audited per session — for Dolby engineers & studio partners alike.
Per-acquisition network integration projects
→ Magic WAN Connector + Mesh
THEO, Millicast, GE Licensing, future M&A targets bridge onto Dolby's network in hours via a 1U appliance — not quarters of IP-range renumbering.
Non-HTTP origin protection — bespoke scripts & ACLs
→ Spectrum
Any TCP/UDP protocol behind Cloudflare: WebRTC SFU, SRT ingest, RTMP, NDI, MQTT. Same DDoS + LB + analytics that dolby.io's HTTPS already gets.

Why this is the right moment for Dolby: OptiView turned Dolby into a real-time infrastructure provider. The NFL, NASCAR, and Paddy Power don't tolerate the same DDoS event-handling SLA an enterprise MPLS WAN tolerates. Cloudflare's NaaS is the only product set where the same network that already serves dolby.io traffic also runs your office WAN, your DDoS scrubbing, your cloud interconnect, and your acquired-company integration — without the multi-vendor hairball Dolby's network team is currently maintaining.

Application Security & Performance for Dolby

Protect every Dolby app. Accelerate every viewer experience.

Dolby's web & API surface area is huge — dolby.com, dolby.io, optiview.dolby.com, dashboard.dolby.io, the OptiView player SDKs delivered to NFL+ apps, professional.dolby.com licensing portal, news.dolby.com, plus the dozens of customer-facing dashboards across THEO and Millicast. Cloudflare's Application Security & Performance stack is already partially in place — it should be the standard for every Dolby property.

🛡️
WAF + L7 DDoS

Stop application-layer attacks

Block OWASP Top 10, zero-days (Cloudflare patches before CVE publication), and L7 DDoS targeting OptiView's dashboard during NFL Sunday peaks. Managed rules + custom rules + emergency rules deployable in <30 seconds globally.

🤖
Bot Management

Defend OptiView from scrapers & ATO

Sportsbook bots scraping odds, credential stuffing on dashboard.dolby.io, fake account signups, content scrapers stealing Atmos previews. ML-driven bot score on every request — block, challenge, or rate-limit by intent, not IP.

🔐
API Security

Protect the OptiView API surface

OptiView's REST + GraphQL APIs are how every customer (NFL, NASCAR, Paddy Power) integrates. Cloudflare API Shield does schema validation, mTLS enforcement, sequence/abuse detection, and discovery of shadow API endpoints engineers forgot to document.

Performance & Cache

Faster everywhere, smaller egress bill

Tiered Cache, Argo Smart Routing, Smart Hints, and HTTP/3 + 0-RTT for every Dolby property. Plus Cache Reserve for OptiView's long-tail VOD libraries — keeping rarely-accessed content close to viewers without origin hits.

▲ Threat

Credential stuffing on OptiView

dashboard.dolby.io is the control plane for every NFL, NASCAR, Paddy Power live stream. One compromised customer = a live game outage.

▲ Threat

Sportsbook bot scraping

Competitors and arbitrage bots scrape OptiView odds-overlay APIs millions of times per day. Without ML bot detection, rate-limiting is a blunt tool.

▲ Threat

L7 DDoS at game time

Volumetric L3 DDoS is one thing — but slow-HTTP and application-layer attacks during NFL Sunday or a Paddy Power live race need an application-aware WAF.

▲ Threat

Shadow API sprawl

After acquiring THEO + Millicast, OptiView's actual API surface (versus what's documented) is uncertain. Undocumented endpoints are the #1 source of API breaches.

01

WAF — Managed, custom & emergency rules everywhere

Cloudflare's Managed Ruleset (OWASP CRS + Cloudflare's own threat intel) protects every Dolby app from injection, XSS, RCE, deserialization, and supply-chain attacks. When the next Log4Shell drops, Cloudflare ships an emergency rule before the CVE is even published — and Dolby's apps are protected in under 30 seconds without a code release.

WAF Managed Rulesets Custom Rules Exposed Credentials Check
02

L7 DDoS — Application-aware mitigation at game time

L3 volumetric attacks get headlines, but the real damage to OptiView comes from L7 floods that look like legitimate viewer traffic. Cloudflare's HTTP DDoS engine uses 50+ signals (TLS fingerprint, IP reputation, request entropy, JS challenge response) to surgically block bad requests during NFL Sunday or a Bet365 in-play surge — without degrading real fans.

HTTP DDoS Adaptive Rate Limiting Under Attack Mode
03

Bot Management — Sportsbook scrapers, ATO, fake signups

Cloudflare's ML-driven bot score evaluates every request against trillions of HTTP signals/day. For Dolby specifically: block arbitrage bots scraping OptiView odds, stop credential stuffing on dashboard.dolby.io, kill fake-account signups on Millicast self-serve, and Turnstile (the CAPTCHA replacement) ships on every signup form. Headless Chrome, Selenium, Playwright, and JA3 anomalies are all flagged automatically.

Bot Management Turnstile Account Takeover Protection Super Bot Fight Mode
04

API Shield — Schema, mTLS, and shadow-endpoint discovery

OptiView's REST & GraphQL APIs are the integration point for the NFL, NASCAR, Paddy Power, Sky Racing, Bet365, and every developer building on Millicast. API Shield auto-discovers every endpoint in production traffic (including the ones engineers forgot existed), validates against OpenAPI/GraphQL schemas, enforces mTLS for first-party clients, detects API abuse sequences, and blocks endpoints that drift from spec — without a single line of customer code change.

API Shield Schema Validation mTLS Sequence Analytics
05

Performance — Argo, Tiered Cache, Smart Hints, HTTP/3

Every Dolby property gets HTTP/3 + 0-RTT for sub-50ms TLS resumption, Argo Smart Routing for ~30% faster origin fetches via Cloudflare's private backbone, Tiered Cache to reduce origin egress by another 60%+, and Smart Hints that auto-generate 103 Early Hints to start preloading critical assets before the HTML even arrives. Page Speed Insights jumps without a single front-end change.

Argo Smart Routing Tiered Cache Smart Hints HTTP/3 + 0-RTT Cache Reserve
06

SSL/TLS & Page Shield — Supply chain & certificate ops

Universal SSL + Advanced Certificate Manager handle every cert across dolby.com, dolby.io, optiview.dolby.com, and the 100s of vanity hostnames customer integrations create. Page Shield monitors every JavaScript Dolby's pages load (Google Analytics, Optimizely, Hotjar, partner SDKs) and alerts the second one is tampered with — the same Magecart-class attack vector that compromised Ticketmaster & British Airways.

Advanced Certificate Manager Page Shield SSL for SaaS Post-Quantum TLS

What Cloudflare App Sec & Performance replaces in Dolby's stack

F5 ASM / Imperva WAF
→ Cloudflare WAF + Managed Rulesets
Globally distributed WAF with emergency rules deployed in seconds. No appliance refresh, no learning mode that breaks legit traffic.
PerimeterX / DataDome / HUMAN
→ Cloudflare Bot Management
Trained on 20% of the world's HTTP traffic. Better signal than any standalone bot vendor — and bundled with WAF + DDoS + API Shield.
Salt Security / Noname / Wallarm
→ Cloudflare API Shield
Inline API security (not just observability). Schema validation, abuse detection, & shadow-API discovery on the same edge that serves the API.
Akamai / Fastly / CDN77
→ Cloudflare CDN + Argo
Already serving dolby.com & dolby.io. Argo Smart Routing + Tiered Cache + Cache Reserve drives origin offload past 95% for OptiView VOD.
DigiCert / Sectigo certificate ops
→ Advanced Certificate Manager
Automated issuance & renewal for every Dolby hostname including OptiView customer vanity domains via SSL for SaaS.
Manual JS supply-chain auditing
→ Page Shield
Real-time alerting when any third-party script on a Dolby page changes. Catches Magecart-style skimmers before they hit production users.
Cloudflare AI for Dolby

Every AI use case Dolby is exploring — already runs on Cloudflare.

Dolby is a 60-year-old audio & imaging R&D powerhouse — neural codecs (AC-4 has ML components), Vision 2 tone mapping, AI-driven loudness, Atmos object spatialization, music mastering assistants, automated highlight detection for live sports. The compute lives in expensive GPU clusters. Cloudflare's AI stack lets Dolby move inference to the edge, govern third-party AI usage, and ship AI-native features without a separate AI platform contract.

🧠
Inference at the edge

Workers AI

Run Llama 3.3, Mistral, Whisper, BGE embeddings, and Dolby's own ONNX models on Cloudflare's GPU fleet in 330+ cities — pay per neuron, not per dedicated H100/hour. Sub-30ms inference colocated with the OptiView player request.

🔀
AI gateway & observability

AI Gateway

Unified proxy for OpenAI, Anthropic, Bedrock, Vertex, Workers AI. Built-in caching (90%+ hit rate on repeated prompts), rate limiting, cost analytics, prompt logging, and PII redaction. One control plane for every AI call Dolby engineers make.

📚
Managed RAG pipeline

AI Search (AutoRAG)

Index Dolby's entire knowledge base — engineering docs, support articles, partner SDK docs, customer-stories.json — into a managed RAG. Power "ask Dolby" copilots for support, sales, and developer self-serve without building a vector pipeline.

🤖
Agent platform

Agents SDK + Sandboxes

Build production AI agents with persistent memory, tools, and durable execution. Sandboxes safely execute code generated by encoder-tuning agents and untrusted advertiser creatives in OptiView's SGAI pipeline.

◐ Today

Expensive dedicated GPU

Dolby's ML team runs Atmos object detection, Vision 2 tone-mapping, and AC-4 encoders on dedicated AWS p4d/p5 or on-prem A100s. Idle GPU time is pure burn.

◐ Today

Direct OpenAI / Anthropic spend

Engineers across Dolby (and acquired teams from THEO/Millicast) hit OpenAI & Anthropic APIs directly. No central observability, no caching, no rate limits, no PII controls.

◐ Today

Hand-rolled RAG attempts

Multiple Dolby teams have probably built their own RAG pipelines (Pinecone + LangChain + GPT-4) for internal docs. Each one is undermaintained and drifts from current docs.

◐ Today

Shadow AI on content

Sound engineers using ChatGPT to summarize mix notes. Researchers uploading Atmos stems to Hugging Face Spaces. Real risk of unreleased-content leakage through GenAI tools.

01

Workers AI — Edge inference for OptiView features

Run automatic caption generation (Whisper), real-time content moderation, live highlight detection (custom CV models), Atmos loudness compliance, and per-viewer thumbnail personalization on Cloudflare's GPU fleet — in the same colo as the OptiView player request. Pay per neuron, not per hour of idle H100. Auto-scales to NFL Sunday peak and back to zero on Monday morning.

Workers AI Llama 3.3 Whisper Custom ONNX
02

AI Gateway — Unified observability & cost control

Every Dolby engineer's call to OpenAI, Anthropic, Bedrock, Vertex, or Workers AI routes through AI Gateway. 90%+ cache hit rates on repeated prompts cut LLM spend by 50%+ on day one. Per-team rate limits, real-time cost dashboards by department, prompt + response logging for safety review, PII redaction, and instant fallback when OpenAI is down.

AI Gateway Prompt Caching Cost Analytics Universal API
03

AI Search (AutoRAG) — "Ask Dolby" copilots without a pipeline

Point AI Search at Dolby's docs corpus — developer.dolby.io, professional.dolby.com, internal wikis, customer-stories.json, the OptiView API reference — and it crawls, chunks, embeds, indexes, retrieves, and generates. No Pinecone bill. No LangChain spaghetti. No drift between docs and the RAG. Power a customer support copilot, a developer Q&A bot, and an internal sales-engineer copilot from one pipeline.

AI Search (AutoRAG) Vectorize R2 source crawl
04

Agents SDK + Agent Memory — Per-fan, per-stream, per-title

Build production AI agents with the Agents SDK (announced at Agents Week 2026). Per-fan agents that remember commentary preferences across NFL+ sessions, per-stream agents that coordinate SGAI ad selection during a Paddy Power live race, per-title encoding agents that learn from every Vision 2 master. Agent Memory (SQLite in Durable Objects) persists state across sessions and survives across regions.

Agents SDK Agent Memory Durable Objects DO Facets
05

Browser Rendering + Sandboxes — Real-world agent execution

Browser Run gives Dolby agents a real Chrome browser to interact with the web — perfect for cinema-ops agents monitoring projector consoles, content-ops agents checking OptiView playback on every device family, or pre-flight agents that test every customer integration before a release. Sandboxes GA safely executes untrusted code: advertiser creatives in SGAI, customer-uploaded encoder profiles, or experimental Workers AI inference jobs.

Browser Rendering Browser Run Sandboxes GA
06

AI Security — Shadow-AI controls, Agent Readiness, Enterprise MCP

Cloudflare Gateway's AI shadow-IT controls detect when an engineer uploads an Atmos stem to Hugging Face or pastes Vision XMLs into ChatGPT — by content fingerprint, not just URL category. Agent Readiness assesses Dolby's security posture before launching agents in production. Enterprise MCP exposes OptiView APIs as governed MCP servers so Claude, ChatGPT, and Cursor can integrate safely.

Shadow AI Controls Agent Readiness Enterprise MCP DLP for AI

What Cloudflare AI replaces in Dolby's stack

Direct OpenAI / Anthropic API spend
→ AI Gateway in front of every LLM
Same models, same APIs — but cached, rate-limited, observable, with PII redaction and instant fallback. Typical 30-60% reduction in raw LLM spend from caching alone.
Pinecone / Weaviate / Qdrant
→ Vectorize + AI Search
Managed vector DB integrated with the same edge that serves the query. AI Search handles the full RAG pipeline so engineering teams don't have to maintain one.
Dedicated AWS p4d / p5 GPU clusters
→ Workers AI for inference workloads
Per-neuron pricing for inference. Reserve dedicated GPUs only for training. Cloudflare's GPU fleet is in 330+ cities — closer to the player than any AWS region.
LangChain / LlamaIndex DIY pipelines
→ AI Search (AutoRAG)
One managed RAG instead of 5 hand-rolled ones per team. Crawl, chunk, embed, retrieve, generate — Cloudflare maintains the pipeline.
Custom agent infrastructure
→ Agents SDK + Durable Objects
Built-in persistence (Agent Memory), tools, streaming, and per-entity isolation via DO Facets. No need to build the state-management layer.
No shadow-AI controls (just hope)
→ Gateway AI controls + DLP
Detect & block uploads of unreleased Dolby content to GenAI tools by content fingerprint. Native to the SWG decision path — not a bolt-on.
Cloudflare Developer Platform for Dolby

Build OptiView's next-gen features on the same network that delivers them.

OptiView's developer surface — Player SDKs, Streaming APIs, SGAI integrations, the Millicast WebRTC stack, THEO's player ecosystem — competes with the largest cloud platforms (AWS Elemental, GCP Live Stream API, Azure Media Services). Cloudflare's Developer Platform is purpose-built for the exact workloads OptiView runs: low-latency, globally distributed, stateful, real-time, video-aware. Dolby could be shipping new OptiView features in days, not quarters.

Serverless compute

Workers — 0ms cold start, 330+ cities

Every OptiView personalization decision — manifest stitching, DRM token issuance, geo-restriction enforcement, ad marker injection — runs in the same colo as the player. Sub-5ms response, no cold starts, no Lambda concurrency limits.

🎬
Stateful coordination

Durable Objects — Per-stream & per-fan

One DO per live OptiView stream coordinates viewer pools, interactive overlays, live betting tickers, multi-viewer sync. One DO per fan persists commentary preferences, watched-content history, & betting position across sessions.

💾
Storage stack

R2, D1, KV, Vectorize, Hyperdrive

R2 for zero-egress VOD archives. D1 for per-customer OptiView config. KV for sub-ms feature flags. Vectorize for content discovery. Hyperdrive for fronting OptiView's existing Postgres without rewriting it.

🔄
Workflows & queues

Durable execution for the SGAI pipeline

Workflows v2 orchestrates the bid → creative → manifest-stitch SGAI pipeline durably across thousands of concurrent ad breaks. Queues handle async fan-out: ingest events → encoder triggers → CDN purges.

◐ Today

AWS Lambda + ECS for OptiView APIs

OptiView's manifest service, DRM tokenizer, and SGAI orchestrator likely run on AWS Lambda (with cold starts) and ECS/Fargate (with always-on cost), behind ALB and CloudFront.

◐ Today

S3 + CloudFront for VOD libraries

The 100s of TB of NFL+, NASCAR, and Paddy Power VOD archives sit in S3 — with CloudFront egress fees compounding every quarter. Cross-region replication is a separate bill again.

◐ Today

Self-managed Postgres + Redis

OptiView's config, customer metadata, and session state likely sit in RDS Postgres + ElastiCache Redis behind multiple VPCs. Connection pooling is a perennial problem.

◐ Today

Bespoke deploy & preview infra

Every OptiView dashboard PR probably gets a Vercel preview, a Heroku review app, or a one-off ECS environment. Bills add up. Developer experience is fragmented.

01

Workers — Per-viewer manifest assembly at the edge

Every OptiView HLS/DASH manifest is currently a static-ish file with some token substitution. With Workers, every manifest is freshly assembled per viewer in <5ms: language tracks based on geo, SGAI ad markers based on the viewer's bidder result, geo-restricted feeds enforced at the manifest layer, DRM tokens minted per-session. The same Worker also handles edge auth, rate limiting, and player telemetry collection. Zero cold starts, 330+ cities, V8 isolates instead of Lambda containers.

Workers Smart Placement Service Bindings
02

Durable Objects — Per-stream live coordination for NFL+ & NASCAR

For every live OptiView stream, instantiate one Durable Object that coordinates: viewer pool size, interactive overlay state (polls, fan reactions), live betting tickers synchronized to the <500ms latency feed, multi-viewer sync across devices, and chat moderation. SQLite-in-DO persists state without an external DB. DO Facets (Agents Week 2026) instantiates these per-entity DOs dynamically — one per VIN for in-car streams, one per NFL+ game, one per Paddy Power race.

Durable Objects DO Facets SQLite-in-DO WebSocket Hibernation
03

R2 — Zero-egress VOD library & Vision master archive

Move Dolby's HDR masters, Atmos stem libraries, and OptiView's NFL+/NASCAR/Paddy Power VOD archives to R2. Zero egress fees — a massive shift versus the current S3 + CloudFront bill that compounds every quarter. R2 has S3-compatible API, multi-region replication built-in, and direct integration with Stream for video transcoding. The largest single line-item AWS cost reduction Dolby is likely to see.

R2 S3-Compatible API Multi-Region R2 Data Catalog
04

Workflows v2 + Queues — Durable execution for SGAI

SGAI (Server-Guided Ad Insertion) is the new economic engine of live sports streaming. Each ad break is actually a complex pipeline: bid → creative selection → personalization → manifest-stitch → playback verification. Workflows v2 (Agents Week 2026, with waitForEvent) orchestrates this durably across thousands of concurrent breaks. Queues handles fan-out: encoder triggers, CDN purges, analytics pipeline events.

Workflows v2 Queues Cron Triggers Email Service
05

D1, KV, Hyperdrive — The storage layer OptiView already needs

KV for sub-millisecond feature flags & config (already the pattern for Flagship). D1 for per-customer OptiView configuration, multi-region SQLite with read replicas in every viewer's region. Hyperdrive fronts OptiView's existing Postgres without a rewrite — pooled connections, edge query cache, no application changes. Add Vectorize for content discovery (semantic search across NFL+ VOD library, "find me more games like this").

D1 KV Hyperdrive Vectorize
06

Pages, Containers, Realtime — Full-stack OptiView

Pages for dashboard.dolby.io and every customer-facing console with per-PR preview URLs, Git integration, and instant rollback. Containers (Cloudflare's new container runtime) for the long-running workloads OptiView needs that don't fit Workers — custom FFmpeg encoders, legacy player SDKs. Realtime / Calls gives OptiView's WebRTC SFU stack a second global footprint with DDoS protection on every ingest endpoint.

Pages Containers Realtime / Calls Stream

What Cloudflare Developer Platform replaces in Dolby's stack

AWS Lambda + API Gateway
→ Cloudflare Workers
0ms cold start vs Lambda's 100-500ms. 330+ cities vs Lambda@Edge's restricted regional footprint. V8 isolates vs container per request.
AWS S3 + CloudFront egress
→ R2 zero-egress storage
Same S3 API. Multi-region. No egress fees to Workers, no egress fees to the public internet. The single biggest AWS bill reduction line item.
DynamoDB / ElastiCache Redis
→ KV + Durable Objects + D1
Three storage primitives covering most of what OptiView uses ElastiCache & DynamoDB for. Lower latency, lower cost, less infra ops.
AWS Step Functions / Temporal
→ Workflows v2
Durable workflow execution with waitForEvent for human-in-the-loop steps. No separate service to manage; runs inside the Workers runtime.
Vercel / Netlify preview envs
→ Cloudflare Pages with per-PR previews
Same DX (Git integration, instant previews, atomic rollback) on the same network that already serves dolby.io. One vendor, one bill.
AWS Elemental MediaLive / MediaConvert
→ Cloudflare Stream + Realtime
Where OptiView wants a managed second SFU footprint or transcoding tier — Stream + Realtime are purpose-built and on the same edge as the player.
Let's build it together

Ready to make Dolby AI-native on the network you already run on?

Andrew Geiser leads the Cloudflare account team for Dolby. Let's spend 30 minutes mapping the highest-leverage 30-day quick wins.

AG
Andrew Geiser Cloudflare · Account Executive for Dolby