You're already on Cloudflare · let's expand behind ELSA API and the bilingual AI tutor

92M+ downloads. 193+ countries.
The runtime should scale like the learner base.

ELSA Speak is the #1 AI English speaking app — 92M+ downloads, 90M+ learners, 4.9 stars, in 193+ countries, with a Bilingual AI Tutor, 5 named role-play coaches, and an ELSA API for developers. elsaspeak.com is already on Cloudflare DNS. The expansion footprint is the developer platform underneath: AI Gateway for the bilingual tutor + role-play inference, R2 for the lesson + audio corpus, Workers for Platforms for ELSA Business / Schools / API tenancy, and Workers AI for the speech-analyzer pipeline.

NS: graham + nola.ns.cloudflare.com · cf-cache-status: HIT on every page · server: cloudflare · site on Astro with anycast IPs 104.26.x / 172.67.x · CMS asset CDN at cms-asset.elsanow.io

What's already running on Cloudflare today

DNS & EDGE
elsaspeak.com on Cloudflare via graham + nola.ns.cloudflare.com
EDGE CACHING
cf-cache-status: HIT on every homepage response — you're already serving Astro static through CF
EXPANSION PATH
Add AI Gateway + R2 + Workers for Platforms + Workers AI behind the same edge — same MSA, same SOC mapping
92M+
Downloads worldwide
90M+
Learners across all platforms
193+
Countries with ELSA school users
1,300+
Organizations served globally
4.9★
App Store + Google Play rating
Trusted by global enterprises and institutions
Nestlé· Hamburger University (McDonald's)· TELUS Digital· NTT Data· Pertamina· Permata Bank· PLN· YKK AP· NashTech· Linguatec

ELSA ships the AI English coach. Cloudflare runs the global learner edge.

You're already on Cloudflare for DNS + edge caching of a JAMstack marketing surface — that's the front door for 92M+ downloads. The next infrastructure layer is the part that scales with the actual product: the bilingual AI tutor's inference, the role-play scenario fan-out, the speech-analyzer pipeline, the per-organization tenancy boundary for ELSA Business + Schools + API, and the audio + lesson corpus that has to serve a learner in Vietnam at the same latency as a learner in Brazil.

ELSA builds

The AI English coach, the role-play library, the ELSA API

The Bilingual AI Tutor that lets beginners start in their native language. The 5 named role-play avatars (Kevin/Workplace, Professor/Interview, Riva/Dating, Camila/Meetings, Lily/Presentations). The Speech Analyzer with detailed feedback. ELSA Business + Schools + the public ELSA API. Lessons from HarperCollins, Pearson, and Oxford University Press.

  • Bilingual AI Tutor + role-play with 5 named avatars
  • Speech Analyzer + How to Pronounce + Quick Evaluation
  • ELSA API exposed to developers building inside their own apps
  • Publisher partnerships: HarperCollins, Pearson, Oxford
×

Cloudflare runs

The inference plane, the per-tier tenancy, the global audio edge

AI Gateway in front of every bilingual tutor + role-play call. Workers AI for the speech-analyzer pipeline. R2 + Vectorize for the lesson + audio corpus, zero egress. Workers for Platforms = isolated tenancy across Individual + Business + Schools + API. The same edge that already serves elsaspeak.com.

  • AI Gateway for bilingual tutor + role-play inference
  • Workers AI for speech analysis + pronunciation scoring
  • R2 (zero egress) for the audio + lesson corpus at 193+ countries
  • Workers for Platforms — per-tier tenancy by construction

Nine primitives, mapped to ELSA's actual product surface.

Each maps to something you ship today (the bilingual tutor, the role-play library, the speech analyzer, the ELSA API, the multi-tier B2B offering) or something the published roadmap implies. Status tags show what's already live in your Cloudflare footprint.

PRIMITIVE 01 Live on CF

DNS + edge cache on Astro

graham + nola.ns.cloudflare.com serve DNS. The Astro static surface is already cached at the edge with cf-cache-status: HIT on every response. Procurement is in place, the SOC mapping exists — this isn't a vendor selection conversation.

DNS Edge cache Astro
PRIMITIVE 02 Highest-leverage next

AI Gateway for the bilingual tutor + role-play

Every role-play conversation with Kevin or Camila is an LLM call. Every bilingual tutor session that bridges a learner's native language to English is an LLM call. Multiplied across 90M+ learners, that's serious inference volume. AI Gateway gives one logged, cached, attributed hop — with semantic cache catching enormous repetition across learners.

AI Gateway Semantic cache Per-tier attribution
PRIMITIVE 03 Speech pipeline

Workers AI for the speech analyzer

The Speech Analyzer, How to Pronounce, and Quick Evaluation features are real-time audio analysis. Workers AI runs ASR + scoring models at the edge POP closest to the learner — not from a centralized GPU cluster. Latency from speech to feedback collapses by hundreds of milliseconds.

Workers AI ASR Edge inference
PRIMITIVE 04 Multi-tier wedge

Workers for Platforms = per-tier tenancy

Individual + ELSA Business + ELSA Schools + ELSA API customers all need different feature gates, different curricula, different reporting dashboards, different data-residency rules. Workers for Platforms gives each tier — and each enterprise customer inside — its own isolated Worker namespace on the same edge.

Workers for Platforms Per-tier Per-org isolation
PRIMITIVE 05 Lesson corpus

R2 + Vectorize for lessons + audio + content

Lessons from HarperCollins, Pearson, Oxford. Audio prompts in dozens of native languages. Industry-specific content for ELSA Business. Curriculum-aligned lessons for ELSA Schools. R2 holds it all zero-egress; Vectorize indexes lessons for "find me a lesson like this one for a Vietnamese learner targeting Hamburger University."

R2 Vectorize Zero egress
PRIMITIVE 06 ELSA API wedge

Workers as the ELSA API runtime

The ELSA API is already a public product. Workers is the natural runtime for a developer-facing API at the scale you operate — sub-millisecond cold start, 330+ POPs for partner apps in any region, native rate-limiting per API key, and native auth at the edge.

Workers ELSA API Rate limit
PRIMITIVE 07 Mobile binary

R2 for app updates + audio prefetch

92M+ downloads across iOS + Android. Every update, every new lesson pack, every per-region audio variant has to reach learners worldwide. R2's zero-egress storage + Workers + Smart Placement serves from the closest POP to each learner — without per-region S3 sprawl or CloudFront egress bills.

R2 Smart Placement Mobile
PRIMITIVE 08 Live coaching

Durable Objects for live conversation state

A role-play with Kevin or Lily has state: the conversation buffer, the in-flight grading, the learner's accent profile, the per-turn feedback. Durable Objects give you a single-writer state holder per active session at the edge with native WebSocket support — no separate Redis cluster.

Durable Objects WebSockets Sessions
PRIMITIVE 09 Bot protection

Bot Management + Turnstile across signup

A free-tier product with 92M+ downloads is a magnet for credential-stuffing, free-trial abuse, scraped lessons, and API-key farming. Bot Management at the edge stops the abuse before it touches the Auth backend or the ELSA API. Turnstile drops in on signup, login, and API key issuance.

Bot Management Turnstile WAF

5 named coaches, 5 inference workloads. All cacheable, all attributable.

Each ELSA avatar runs a distinct AI workload — same model family, different prompts, different success metrics. AI Gateway gives you per-avatar attribution by default: which scenarios drive the most engagement, which cost the most per turn, which need the next round of investment.

The role-play library, sketched on Cloudflare primitives

Each named coach is a Worker route with its own AI Gateway lane — isolated metrics, isolated budget, shared cache where the prompts overlap.
💼
Kevin
Workplace Coach
🏫
Professor
Interview Coach
💜
Riva
Dating Coach
💬
Camila
Meetings Coach
📣
Lily
Presentations Coach
What this changes: Today the entire role-play inference bill is one line item. Tomorrow it's five — Kevin's CAC vs. Camila's, Riva's engagement vs. Lily's, Professor's cost-per-meaningful-feedback. The data unlocks "which avatar deserves the next 90 days of investment?" Without AI Gateway, that question gets answered by gut. With it, it's a dashboard.

An ELSA session is a pipeline of small inference calls.

"Learner opens the app, says one sentence" → ASR pass → pronunciation scoring → role-play turn through Claude → instant feedback → progress tracker update. Each step is a small inference call. Across 90M+ learners doing 20+ minutes a day, those calls cluster brutally — same lessons, same common phrases, same accent patterns.

A single ELSA practice session, sketched on Cloudflare primitives

From "learner taps a lesson" to "personalized feedback rendered" — cached, attributed, audited per learner and per organization.
LEARNER
Tap a lesson on iOS / Android / Web
audio + lesson context captured
PER-TIER EDGE
Workers for Platforms tenant
Individual / Business / Schools / API
SPEECH + ROUTE
Workers AI + AI Gateway
ASR + scoring + role-play LLM
FEEDBACK + STORE
Workers + R2 + Durable Objects
progress tracker, audit, replay
What this changes: The whole loop — ASR, scoring, role-play, feedback, progress — lives on the same edge, same observability surface, same per-tenant boundary. A Vietnamese learner in Hanoi and a Brazilian learner in São Paulo each get sub-second feedback from a POP within 100ms of them, not from a centralized region. And the inference economics get broken out per learner, per organization, per tier.

The economics of 90M+ learners at 20 min/day.

ELSA's scale is a freemium funnel where the inference bill scales with engagement, not with revenue. AI Gateway turns Anthropic + open-model spend into a per-tier, per-coach, per-org cost line — the data needed to defensibly price Business and Schools tiers at the right margin and to scope the next year's API monetization.

A back-of-the-envelope, not a quote
Modeled across bilingual tutor + role-play + speech-analyzer pipelines at blended $5 / M tokens
SEMANTIC CACHE HIT RATE
50–70%
Language learning queries cluster brutally: same lessons repeated across millions of learners, same common-phrase grading, same interview-prep questions. Higher hit rate than general LLM workloads.
PER-TIER ATTRIBUTION
100%
AI Gateway gives per-tier (Free / Premium / Business / Schools / API), per-coach, per-organization attribution — the data needed for defensible enterprise pricing and free-tier cost containment.
AUDIO + LESSON EGRESS SAVINGS
40–60%
R2's zero egress vs. AWS S3 + CloudFront across audio prompts + lesson packs + per-region content variants serving 193+ countries.
The real win is per-coach product economics. Today Kevin / Camila / Riva / Lily / Professor all share one inference bill. Tomorrow each has its own line — revenue contribution, engagement lift, cost-per-meaningful-conversation. That's how a free-tier-dominant product makes paid-tier investment decisions defensibly. It's also the data investors ask for at Series-extension scale.

Four product tiers, dozens of enterprises. Workers for Platforms is the boundary.

Individuals want a personal coach. ELSA Business wants role-specific coaching + ROI dashboards for Fortune 1000s. ELSA Schools wants curriculum-aligned content + parent reports. ELSA API wants per-app key issuance + per-app billing. Each tier — and each enterprise customer inside — needs isolation enforced by infrastructure, not config.

Per-tier, per-org tenancy, sketched

Each product tier gets its own Worker for Platforms namespace. Each enterprise customer inside Business / Schools / API gets its own isolated tenant. Same edge, same observability, region-bound data residency.
👨‍🏫
Individuals
🏢
ELSA Business
🏫
ELSA Schools
💻
ELSA API
Shared control plane — Workers for Platforms + AI Gateway + Workers AI + R2
one runtime · one observability surface · 1,300+ enterprise orgs = 1,300+ isolated tenants by construction

Current stack, with Cloudflare overlaid.

Every row is sourced from public DNS records, the elsaspeak.com apex TXT, HTTP response headers, and the visible CMS asset CDN. The mint row is already running on Cloudflare today. The orange column is the expansion footprint.

What's running today, and where Cloudflare slots in

Mint rows = already on Cloudflare. Orange column = the expansion path. No Astro, Freshdesk, or CMS rip-and-replace required.
LAYER
ELSA RUNS TODAY
CLOUDFLARE FIT
DNS + EDGE
Cloudflare (graham + nola.ns) + edge cache (cf-cache-status: HIT)
✅ Live — the foundation everything else snaps onto
MARKETING SITE
Astro JAMstack (_astro paths)
No change — Astro static fronts cleanly behind the existing CF zone
CMS / ASSETS
Strapi-style CMS at cms-asset.elsanow.io
+ R2 + Workers as the asset edge for the global learner base
STUDENT APP
student.elsaspeak.com (CSP frame-ancestors)
+ Workers for Platforms behind it for per-org tenancy
AI INFERENCE
Likely OpenAI / Anthropic for bilingual tutor + role-play
+ AI Gateway: cache, attribution, rate-limit, budget cap per tier + per coach
SPEECH ANALYZER
In-house ASR + pronunciation scoring (the ELSA core IP)
+ Workers AI as overflow / regional capacity at the edge POP
ELSA API
Public developer API at elsaspeak.com/en/elsa-api/
+ Workers as the API runtime; native rate-limit + auth at the edge
PER-TIER TENANCY
Multi-tenant app with feature gates per tier
+ Workers for Platforms — per-tier + per-org namespace by construction
MOBILE BINARY CDN
App Store + Google Play, plus per-lesson audio packs
+ R2 + Workers + Smart Placement — zero egress at 193+ country scale
EMAIL
Google Workspace (aspmx.l.google.com)
+ Cloudflare Email Security as defense-in-depth (optional)
CUSTOMER SUPPORT
Freshdesk — 3 separate portals (Individual / Business / Schools)
+ Zero Trust SSO in front of all three help portals
SECURITY / ANALYTICS
Ahrefs + Zoom + multiple Google site verifications
+ Bot Management + Turnstile across signup, API key issuance, content scraping defense

Why this is the right quarter to start the conversation

ELSA API is a developer-platform product. The moment you expose an API to outside developers, the platform questions stop being internal. Rate limiting, per-key attribution, regional latency, abuse defense, BYO-key support for enterprise customers — all become product surface. Workers is the most natural runtime in the market for that shape, and AI Gateway is the cheapest hour you can spend on cost observability before API usage scales.

You're already on Cloudflare. DNS via graham + nola.ns. Edge caching of the Astro static surface on every response. There's no procurement event to start, no security review to begin from zero, no MSA to negotiate. Expanding from DNS + edge cache to AI Gateway + R2 + Workers for Platforms is the most natural roadmap conversation in the lineup.

The B2B pipeline keeps accelerating. Nestlé, McDonald's Hamburger University, TELUS Digital, NTT Data, Pertamina, PLN, Permata Bank, YKK AP, NashTech — 1,300+ organizations served globally. Every new enterprise contract is another tenant on the platform. Workers for Platforms turns "add a new enterprise" from a custom integration into a namespace creation. That math compounds.

Worth a 30-minute conversation with the platform team?

The interesting conversation is which of these primitives is closest to your current sprint: AI Gateway in front of the bilingual tutor + role-play layer, Workers as the ELSA API runtime, Workers for Platforms behind Business + Schools, or Workers AI for the speech analyzer at edge POPs. I'd rather hear what's actually on your roadmap than guess.

Matt Holscher Calendar  → Reply by email