Fullscript is a leading SaaS platform empowering healthcare practitioners and naturopathic doctors to practice whole-person care with their patients. The Canadian company provides comprehensive tools for prescribing labs, creating treatment plans, and monitoring patient wellness journeys, serving millions of healthcare practitioners globally.
When Jeff Fouchard, now VP of Engineering, joined Fullscript, the company's rapid expansion were straining against a fragmented legacy infrastructure unable to support its ambitious growth plans.
With traffic doubling to the Fullscript web applications annually for five consecutive years, the company needed an infrastructure that could scale seamlessly to meet the explosive growth demands of the healthcare technology sector. Operating on legacy infrastructure, Fullscript had migrated core apps from a legacy orchestrator to Kubernetes but hit a wall with AWS’s first-generation web application firewall (WAF), which generated false positives and created multiple operational bottlenecks.
"The AWS WAF gave us almost no information when something went wrong. We'd have a blocked request and barely any data to figure out why it happened. The interface was incredibly difficult to use, and even simple changes required extensive manual work," Jeff recalls. Security rule changes consumed more than four hours per modification, combining unintuitive UI navigation with cumbersome Terraform state management. With increasing point-solution sprawl, mounting operational friction, and a small three-person infrastructure team wearing multiple hats, Fullscript needed a partner who could support their growth trajectory—not just provide another tool to manage.
Fullscript’s journey with Cloudflare began as a classic rehost scenario. Fullscript sought the Connectivity Cloud to enable them to:
Discovering Cloudflare's free tier, Fullscript quickly found the platform both richer in features and easier to use than AWS's native solutions. The company migrated critical security and delivery elements, automating configuration through Terraform to accelerate deployments and adoption, which eliminated the manual processes plaguing their previous setup. The transformation delivered an immediate 8x improvement in deployment efficiency, reducing security rule changes from more than four hours to under 30 seconds.
A defining moment came during a major security crisis when malicious traffic overwhelmed their platform, incurring tens of thousands of dollars daily in infrastructure costs. Cloudflare's customer success team provided immediate beta access to their Security Analytics Dashboard, enabling rapid threat identification and mitigation.
"Within 15 minutes of using Cloudflare's security dashboard, we found exactly where the bad traffic was coming from, blocked it, and immediately fixed the problem — saving us from days of expensive downtime," explains Fouchard.
The rehost not only improved reliability and reduced manual work — it freed up Fullscript’s team to focus on more strategic initiatives.
Following a standout support experience, the organization upgraded to Enterprise to unlock proactive security and optimization tools—including bot scanning and load balancing—further insulating their ecosystem from emerging threats.
“With Cloudflare’s connectivity cloud, making security changes is now effortless — we don’t even think about it anymore. Our small team can handle much more complex infrastructure than we ever could with fragmented point solutions,” adds Fouchard.
This crisis response mitigated the financial impact and demonstrated Cloudflare's commitment to customer success beyond just providing technology, establishing trust that would drive expanded adoption across Fullscript's infrastructure.
Adopting a “Cloudflare-first” approach for new infrastructure requirements, Fullscript began consolidating multiple point solutions to reduce vendor complexity and operational overhead. One of the first wins came from replacing an aging VPN with Cloudflare Zero Trust. The legacy VPN required frequent Friday night patches to address critical zero-day vulnerabilities and suffered from bandwidth limitations — especially challenging for decentralized and remote teams.
This consolidation strategy allowed Fullscript to eliminate the management burden of multiple disparate systems while gaining enhanced capabilities.
"The new remote access system is incredibly simple to set up and customize. For our employees, it's just a matter of clicking one button. The experience is so much better, and we can even reward people for following good security practices through integrated policy management," explains Fouchard.
This approach reduced vendor sprawl, cut support escalations, and simplified both security and remote access management, allowing Fullscript to centralize knowledge and accelerate ramp-up times for new projects. The deployment success also exceeded expectations: