| Independent security / no-logs audit | ❌Not foundSearched official site, legal page, features, and help centre. No third-party audit PDF or no-logs report. | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. |
|---|
| ISO 27001 | ❌Not foundNo ISO 27001 claim or certificate found on primary pages. | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2 or SOC 3 report found. | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedPolish VAT-registered entity; dedicated GDPR page treats the vendor as processor. Dedicated EU cache servers sold separately. Default Video/storage products replicate outside the EU. | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent, but US and Asian content replicas plus Stripe, PayPal, and HubSpot on the account path. Not legal advice. | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo public DPA download or in-product DPA found. Blog discusses DPAs as a buyer question. Ask sales. | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. |
|---|
| EU AI Act | —Not applicableCDN and object storage. Marketing mentions 'Smart AI Caching' and MSA authorises unnamed third-party AI vendors. Not an AI-centric product. | —Not applicableContent delivery and traffic steering product, not an AI system offering. |
|---|
| PCI DSS | Nicht angegeben | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. |
|---|
| CISPE IaaS Code of Conduct | Nicht angegeben | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. |
|---|