We only force a site direct if the attack is too large & starts to impact other customers as well. If the attack doesn't impact other customers, then we won't force the site direct (we generally only force a few sites direct per week & these are monster attacks).
We actually have the backend all built for this. It is just a matter of doing just a little bit more testing before releasing it into the wild. We've used a handful of beta testers to help us identify potential problems.
Similar to many other companies operating on the internet these days, CloudFlare operates on a freemium model (free vs paid products). We also have some other opportunities to make money with other product integrations & will be launching enterprise products in the future.
"They use VigLink to add affiliate tags to the external links of the sites that use them."
This is actually an optional service (Outbound Links) that can be turned on or off (opt-in by default). No affiliate links are added without turning the feature on.
No, it isn't hosting because you still keep your hosting provider when using CloudFlare. The DNS switch is at your registrar, which is an entirely separate issue than hosting.
Example:
1. Registrar could be GoDaddy.
2. Hosting is at BlueHost.
Adding CloudFlare would mean:
1. Change authoritative nameservers at GoDaddy to us.
2. Hosting doesn't change at BlueHost.
Looks like you were active around the TC Disrupt time, which was very busy for us (we've added two datacenters since then). We generally make websites about 30% faster on average.