Compare moats
Up to three covered companies, band by band. Every call is a curated editorial judgment, never a disclosed figure — and every band carries its cited basis.
| Cloudflare | MongoDB | NetApp | |
|---|---|---|---|
| Moat rating | wide The band is earned by a measured share gap on a hard-to-rebuild asset, not asserted. W3Techs' 17 September 2026 survey (w3techs.com/technologies/overview/proxy) puts Cloudflare in front of 25.8% of all websites, an 85.0% share of the reverse-proxy market, against Amazon CloudFront at 5.5%, Fastly at 3.0% and Akamai at 2.1% - roughly fifteen times the nearest rival. The FY2025 10-K filed 2026-02-26 describes what a challenger would have to reproduce to contest that: a network that 'spans more than 330 cities in over 125 countries worldwide and interconnects with over 13,000 networks globally', architected to 'run every service on every server in every city' - capacity and peering accumulated city by city over a decade, not bought in a quarter. The position has been monetised without margin decay: SEC XBRL fundamentals on this site show GAAP gross margin inside a 74.5-78.7% band in every fiscal year from FY2017 to FY2025 while revenue grew from $134.9M to $2,167.9M, and Cloudflare's Q4/FY2025 results release of 2026-02-10 (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) reports remaining performance obligations up 48% and new annual contract value up nearly 50% year over year. What stops this being a certainty rather than a judgement: the dominant share sits in application services, while SASE and developer compute are contested by vendors the 10-K itself concedes hold 'substantially greater financial, technical, and other resources.' | narrow The FY2026 10-K frames a 'rapidly evolving and highly competitive' database market where the principal rivals — 'legacy database providers and large cloud providers' — hold explicit advantages: 'longer operating histories, more established relationships … significantly greater financial, technical, marketing or other resources … broader global distribution,' and can offer competing products 'at a low cost or no cost.' A developer-mindshare and switching-cost position is defensible but not wide against that field. | narrow The FY2026 10-K shows a real, durable lock but not an unassailable one. On the durable side: "Our cloud storage services are based on the same ONTAP data management software that underpins our on-premises ONTAP storage infrastructure offerings", and the same filing's income statement shows the company holding a gross margin near 71% across all three reported years - $4,433M on $6,268M in FY2024, $4,613M on $6,572M in FY2025 and $4,899M on $6,925M in FY2026 - while revenue grew from $6,268M to $6,925M and income from operations widened from 19% to 24% of net revenues. Holding that margin through the memory-cost shock the same filing discloses is the commercial evidence the lock is worth something. On the limiting side, the filing says competition "is intense", that in public cloud "customers may choose native cloud services that are consumed as operating expenses", and that "New competitors or alliances among existing competitors could emerge and quickly gain significant market share" - and IDC's 1Q26 external-storage tracker (Blocks & Files, 2026-06-16, cited on the AFF/ASA product row below) ranks NetApp second behind Dell, not first. |
| Moat type | cost scale The FY2025 10-K states the mechanism outright, and it is a unit-cost curve rather than a user-to-user network: 'We have chosen to utilize this idle capacity to create a free tier of service which has generated substantial global scale for us. In turn, this scale makes us attractive partners for Internet Service Providers (ISPs) globally, which reduces our co-location and bandwidth costs. As our network grows, these dynamics become even more powerful.' The same section explains why the curve applies to every line rather than one: the architecture lets Cloudflare 'deploy standard, commodity hardware' and run 'every service on every server in every city', so a new product reaches 330+ cities at near-zero incremental capital. That is what lets the filing claim Workers is offered 'at prices that are highly competitive with public cloud vendors' while FY2025 GAAP gross margin still printed 74.5%. Switching costs (traffic routed through Cloudflare, DNS delegated to it) and threat-intelligence feedback from aggregate traffic sit on top, but the filing-stated primary source is cost falling as the network grows. | switching costs A database is the system an application is built on: the 10-K states 'a database directly impacts an application's performance, scalability, flexibility and reliability,' and Atlas is 'our managed multi-cloud database-as-a-service' running the customer's live workloads — re-platforming a database is a rewrite, not a swap. | switching costs The FY2026 10-K makes the source of the advantage explicit and it is the cost of leaving the data-management layer, not a network or a patent estate. The same ONTAP software runs the on-premises arrays and the cloud services ("Our cloud storage services are based on the same ONTAP data management software that underpins our on-premises ONTAP storage infrastructure offerings"), and the AFF family "allows customers to connect to clouds for more data services, data tiering, caching, and disaster recovery". A customer's volume layout, snapshot and replication workflow and operating tools therefore carry from the array into Azure, AWS and Google rather than being abandoned at the cloud boundary — the filing describes NetApp as "the only provider of enterprise-grade storage services natively embedded in the world's largest public cloud providers", so the usual moment of escape is instead the moment the relationship renews. |
| Leadership | clear leader Leadership is measured, not inferred. W3Techs on 2026-09-17 records an 85.0% reverse-proxy market share against 5.5% for Amazon CloudFront and 2.1% for Akamai, and makes Cloudflare the largest authoritative-DNS provider at 18.5% of all websites versus 9.9% for the next-placed GoDaddy Group. The FY2025 10-K reports the enterprise side moving the same way - 4,298 large customers at 2025 year-end against 3,497 a year earlier and 2,756 in 2023 - and the Q4/FY2025 results release (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) cites the largest annual contract value deal in company history at about $42.5M per year. The band is for the application-services core the share data covers; in SASE and in serverless compute Cloudflare is a challenger to larger incumbents, and no independent placement naming Cloudflare in those markets was obtained for this profile. | co leader The 10-K positions MongoDB as the leading document database by developer mindshare but names 'legacy database providers and large cloud providers' as better-resourced rivals across the broader database market — a category leader within a market it does not lead overall. | co leader IDC's 1Q26 external enterprise storage systems tracker, as reported by Blocks & Files on 2026-06-16 (cited in full on the AFF/ASA product row below), ranks NetApp second worldwide behind Dell and ahead of Everpure, Huawei and HPE, attributing the placing to "its growing all-flash business and cloud-integrated data management". Second of five ranked vendors, in a market whose leader is someone else, is a shared front rank rather than an owned one - and the distinct claim NetApp makes in the FY2026 10-K is positional rather than volumetric: being "the only provider of enterprise-grade storage services natively embedded in the world's largest public cloud providers". |
| Pricing power | moderate Evidence cuts both ways, which is why this is not the top band. For it: GAAP gross margin has never left a 74.5-78.7% band across FY2017-FY2025 (SEC XBRL fundamentals on this site) even as revenue compounded 16x, and the Q4/FY2025 results release (cloudflare.com/press/press-releases/2026/cloudflare-announces-fourth-quarter-and-fiscal-year-2025-financial-results/) shows customers committing more rather than less - RPO +48% year over year and new ACV up nearly 50%. Against it: FY2025's 74.5% is the lowest reading in that nine-year series, a large permanent free tier anchors the entry price, the 10-K positions Workers 'at prices that are highly competitive with public cloud vendors', and the competition risk factor warns that larger rivals can 'sell products and services with which we compete at zero or negative margins, offer fee waivers and reductions or other economic and non-economic concessions', with competitive pressure that 'may result in price reductions, fewer subscriptions, reduced revenue and gross margin'. | moderate Owning the IP and the roadmap ('the determination of which features are included in our free or paid offerings') gives real list-price control, but the same filing flags competitors offering database products 'at a low cost or no cost basis,' which caps it. | moderate It holds price rather than raising it. On the figures filed with the FY2026 10-K, gross margin was 70.7% of revenue in FY2024 ($4,433M on $6,268M), 70.2% in FY2025 ($4,613M on $6,572M) and 70.7% in FY2026 ($4,899M on $6,925M) - flat across three years in which revenue grew from $6,268M to $6,925M - and it held that level while absorbing a component-cost shock. It is no stronger than that because the filing's own risk factor lists "competitive pricing, customer price sensitivity" and "pricing and discounting pressures" among the drivers of gross margin, and discloses that the company "experienced inflationary pressure and supply chain constraints beginning in the second half of fiscal 2026, resulting in increased costs for memory and other components, which have affected our gross margins" - a cost shock it is absorbing rather than fully passing on. |
| Summary | Cloudflare sells security, performance and connectivity as services delivered from one global anycast network rather than from boxes at a customer's edge. The FY2025 10-K frames the market as a consolidation away from enterprises that 'string together a diverse set of on-premises hardware boxes from different vendors' and away from 'stringing together multiple point-cloud solutions that only address specific network needs', toward one integrated provider it calls the Connectivity Cloud, and places Cloudflare as 'a leader in this Connectivity Cloud category'. The economics are unusual: idle capacity funds a free tier, the free tier buys global traffic scale, that scale makes Cloudflare a peering partner ISPs want, and peering cuts colocation and bandwidth cost - a loop the filing says 'become[s] even more powerful' as the network grows. Independent measurement confirms where that loop has already settled the market: W3Techs on 2026-09-17 shows an 85.0% reverse-proxy share and the largest authoritative-DNS footprint at 18.5% of all websites. Commercially the company ended 2025 with roughly 332,000 paying customers in more than 190 countries and 4,298 large customers, up from 2,756 two years earlier, with no customer above 10% of revenue. The contested half of the story is the growth half: the SASE platform competes with established cloud-security, email-security and SD-WAN vendors, and the developer platform competes for storage and compute against hyperscalers, markets where the 10-K's own risk factors concede rivals have greater name recognition, larger customer bases and 'more mature products and services developed for large customers'. The core is defended; the adjacencies are being fought for, and FY2025 gross margin at a nine-year low of 74.5% is the first visible cost of building GPU capacity for that fight. | MongoDB monetizes developer mindshare that began as open source: the 10-K notes 'we own the intellectual property of our offerings since we are the creators of the software,' which lets it run a 'proprietary software subscription business model' and control the roadmap. The durable asset is the document-model install base and Atlas's managed multi-cloud workloads, positioned for AI as 'the underlying database … capable of processing queries against rich and complex data structures.' The counterweight, in the filing's own words, is that the large cloud providers it depends on for Atlas hosting are also its best-resourced competitors. | NetApp sells storage hardware but the asset is ONTAP, the data-management software that has run its arrays for over three decades and now also runs inside the three largest public clouds as a first-party service. The FY2026 10-K organises the company into two segments, Hybrid Cloud (AFF and ASA all-flash arrays, AFX for AI workloads, FAS hybrid-flash, E/EF-Series, StorageGRID object storage) and Public Cloud (Azure NetApp Files, Amazon FSx for NetApp ONTAP, Google Cloud NetApp Volumes, Cloud Volumes ONTAP), and states that both rest on the same ONTAP software. That is the whole argument: an enterprise that has standardised its snapshots, replication and multiprotocol access on ONTAP carries those habits with it when it moves workloads to a hyperscaler, and NetApp is paid on both sides of the move. The evidence that the lock has commercial value is the margin's steadiness: across the three years the FY2026 10-K reports, gross margin sat at 70.7%, 70.2% and 70.7% of revenue ($4,433M on $6,268M, $4,613M on $6,572M, $4,899M on $6,925M) while revenue grew, and the filing's own percentage-of-revenue table shows no mix shift doing that work - product and services held near 46% and 54% of revenue throughout. The limits are equally in the filing. NetApp is second, not first: IDC's 1Q26 tracker puts it behind Dell in external enterprise storage, and the 10-K's competition section concedes that cloud providers are simultaneously partners and rivals, that consumption models "may reduce overall demand for our traditional on-premises offerings sold through a capital expenditure (capex) model", and that alternative architectures "may reduce or eliminate demand for some of our offerings". Component exposure is real too: the filing discloses "inflationary pressure and supply chain constraints beginning in the second half of fiscal 2026, resulting in increased costs for memory and other components, which have affected our gross margins", and names NAND among the components whose supply can tighten. This is a durable second place built on software stickiness, not a structural monopoly. |
| Chain position | Cloudflare sits between end users and whatever hosts the application - origin data centre, public cloud or SaaS - so it is a control layer in front of infrastructure rather than infrastructure a workload runs on, which the 10-K argues is the point: customers 'concerned about being locked in to any one public cloud provider' want policy enforced by 'an independent and integrated services provider'. Two AI-era roles follow from that position. As a supplier, the filing describes 'ongoing deployment of graphics processing units (GPUs) across our global network of servers' behind Workers AI, Vectorize and AI Gateway, putting inference next to the user instead of in a region. As a gatekeeper, the application-services suite now exists in part to 'easily identify, block and control access from AI crawlers and AI agents and operators' and underpins announced efforts to let content creators monetise how those crawlers reach their work - which makes Cloudflare a toll point between AI model builders and the open web. | Layer-10 application-layer data platform — the operational database under AI and general software workloads. | NetApp sits between the memory supply and the enterprise data centre. Upstream, the FY2026 10-K says "Third-party component costs make up a significant portion of our product costs" and singles out NAND as hard to manage "if supplies of certain components, including NAND, become limited relative to demand". Downstream, the hyperscalers are channel, partner and rival at once: the filing states "We both partner with and compete against cloud service providers through our cloud-based software and services offerings", while Azure NetApp Files, Amazon FSx for NetApp ONTAP and Google Cloud NetApp Volumes are delivered as those clouds' own natively embedded services. Distribution is a mix of direct sales and "an ecosystem of partners, including the leading cloud providers". |
| Products (share / barrier) |
|
|
|
| Long-horizon vote | +0.38 at weight 0.20 · swarm neutral Editorial prior, not backtested. | +0.13 at weight 0.20 · swarm neutral Editorial prior, not backtested. | +0.13 at weight 0.20 · swarm neutral Editorial prior, not backtested. |