| Independent security / no-logs audit | —Not applicableHosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead. | ⚠️PartialVendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
|---|
| ISO 27001 | ✅VerifiedISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks. | ✅VerifiedBSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
|---|
| SOC 2 / SOC 3 | ❌Not foundHetzner states focus on ISO 27001 rather than SOC 2 for international market. | ❌Not foundNo SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems. | ⚠️Vendor claimedGerman controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice. | ⚠️PartialEU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedStandard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs. | ❌Not foundNo public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
|---|
| EU AI Act | —Not applicableInfrastructure hosting, not an AI system product. | —Not applicableCDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
|---|
| BSI C5 (cloud) | ✅VerifiedVendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue). | ⚠️Vendor claimedCurrent Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
|---|
| KRITIS / section 8a BSIG | ⚠️Vendor claimedHetzner states BSI classification as operator of critical services and certification under section 8a BSIG. | Nicht angegeben |
|---|
| PCI DSS Level 1 | Nicht angegeben | ⚠️Vendor claimedVendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
|---|
| IDW PS 951 Type 2 (ISAE 3402) | Nicht angegeben | ⚠️Vendor claimedVendor claim of Type 2 over a twelve-month period. Report not published. |
|---|
| KRITIS operator (BSIG section 8a(3)) | Nicht angegeben | ⚠️Vendor claimedVendor certifications page. Confirm current attestation in procurement. |
|---|