The issue/problem is most likely going to be occurring with the Plugin Firewall if this is in fact an issue between CloudFlare and BPS Pro. We are aware of some minor issues and problems with CloudFlare. BPS Pro 8.2 (tentative release date is 3 to 6 days) fixes all of those minor issues/problems with CloudFlare. There is a good chance that the issues are actually between W3TC and CloudFlare.
We do have a testing site that is using CloudFlare and there are no issues and everything is working perfectly so BPS Pro and CloudFlare do work fine together. I believe all that was required on that testing site was to delete the Plugin Firewall and resave settings and then activate the Plugin Firewall again. There is one other very unusual issue/problem with CloudFlare code being injected into the Source Code of the BPS Pro AutoRestore page, but that issue/problem does not happen on the testing site below so on the 1 site where we did see this happening there were probably other CloudFlare settings in use or some other additional factors involved.
Testing site with BPS Pro and CloudFlare
http://bulletproof-security-pro.com/bpspro/
Do Step 4 in the BPS Pro Troubleshooting steps in the link below and then confirm that the issue is with the Plugin Firewall. We do have a workaround if the issue/problem is with CloudFlare causing Plugin Firewall to malfunction.
http://forum.ait-pro.com/forums/topic/read-me-first-pro/#bps-pro-general-troubleshooting
4. On the Security Modes page select the Delete plugins .htaccess File Radio button and click the Activate button to deactivate/delete the Plugin Firewall .htaccess file.