Logo: bunny.net

bunny.net

Slovenian edge platform from BunnyWay d.o.o.: pay-as-you-go CDN, multi-region object storage, video streaming, and Shield WAF on an operator-run global PoP network.

bunny.net is a Slovenian edge platform that sells content delivery, object storage, and video streaming as one account. The operating company is BunnyWay d.o.o. in Ljubljana. The service began as Bunny CDN (public beta in 2015) and was rebranded to bunny.net in 2021 when storage, stream, and other edge products joined the same stack.

It exists for teams that want a pay-as-you-go CDN without attaching the delivery layer to a US parent company. You create a pull zone or storage zone in the dashboard, point an origin or upload files, and pay for bandwidth and stored data. A time-limited trial is available without a credit card. The software is not self-hosted.

The decision-relevant differentiator is operational, not just legal. BunnyWay publishes an official Routing Filter that can send CDN pull-zone traffic only through PoPs in EU member states (the docs list 24 such locations). Default routing remains global, including many US cities, and account or support data still touches named US-group SaaS tools.

EU-operated (Slovenia)Pay-as-you-go CDNEU pull-zone routing filterMulti-region edge storageManaged video (Stream)ISO 27001 (claimed)

Shortlist bunny.net when you want a Slovenian-operated CDN plus storage and Stream, with an official EU pull-zone routing filter and prepaid pay-as-you-go billing. Skip it when you need Cloudflare Workers or Zero Trust as the control plane, or when account data must stay off US-group SaaS (Slack, OpenAI, SendGrid, Mixpanel, Salesforce, Braintree). Consider Cloudflare if the platform surface matters more than EU HQ.

Key capabilities

Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.

Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.

Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.

Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.

Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.

Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.

Auf einen Blick

HQ
Ljubljana, Slovenia
Legal entity
BunnyWay d.o.o.
Product family
CDN, Storage, Stream, Shield, DNS, Optimizer, edge compute
Hosting model
Hosted operator PoPs (not self-hosted)
Commercial model
Prepaid pay-as-you-go, trial without credit card
Open source
No public core license found

Best fit when

  • EU-headquartered teams that need a pull-zone CDN and can enable the EU Routing Filter when residency matters
  • Sites and APIs that want prepaid bandwidth billing without per-request CDN fees
  • Software, game, or firmware delivery that benefits from Perma-Cache and multi-region storage (see NZXT, System76, Nexus Mods case studies)
  • VOD or event video that can use Stream transcoding and the bundled player, without sending audio to OpenAI
  • Teams that want token-authenticated downloads, geo-blocking, and a separate Shield WAF on the same account

Poor fit when

  • Architectures built around Cloudflare Workers, Zero Trust, or Cloudflare as the primary application platform
  • Workloads with a hard ban on US-group subprocessors for billing, support, mail, or analytics
  • Buyers who need a self-hosted or open-source CDN they can run in their own data centers
  • Global audiences that must stay on the nearest PoP while also forbidding any non-EU cache (the EU filter trades latency for residency)
  • Regulated video that requires on-platform transcription without a US AI subprocessor

Consider instead when

  • When: You need Workers, Zero Trust, or a single US-scale security and compute control plane

    Consider: Cloudflare

    Cloudflare is US-headquartered. The tradeoff is platform breadth, not EU ownership.

  • When: Origin already lives on AWS and you need IAM, PrivateLink, or CloudFront contracts

    Consider: Amazon CloudFront (with S3 or Media Services)

    Bunny is faster to start for a standalone CDN plus Stream. It will not replace AWS account controls.

  • When: You want a European CDN peer that is not Cloudflare and bunny.net's US PoPs or US SaaS tools are disqualifying

    Consider: KeyCDN or Myra Security (not yet in this catalog)

    Re-check those vendors on their own legal and subprocessor pages. Do not assume they are cleaner.

Gerichtsbarkeit & Eigentum

Rechtsträger
BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia
US-Mutter / Kontrolle
Keine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)
Medium
Hosting / Residenz
Operator-advertised global PoPs (Standard 119, Volume 10) and 15 storage regions, including EU (London, Stockholm, Frankfurt, Madrid, Prague) and US (New York, Miami, Los Angeles, Seattle). EU Routing Filter can pin CDN pull-zone traffic to 24 EU PoPs. DNS stays global. Account path uses Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree. Privacy page claims EU residency for BigQuery, dbt Cloud, Lemlist, Loqate, and Kickscale.

No US parent found on imprint, privacy, or terms. Careers materials mention additional hiring entities in the UK and Germany. Indicative only, not legal advice. CLOUD Act exposure is medium because of US PoPs, US storage options, and named US-group subprocessors, not because of HQ.

  • Independent security / no-logs auditNot found
  • ISO 27001Vendor claimed
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumDefault routing is global, including US and Moscow PoPs

    Without the EU Routing Filter, cached objects can sit at non-EU PoPs listed on the CDN map, including US cities and Moscow. The filter covers pull-zone traffic only and hurts latency for non-EU users.

  • MediumUS-group account and feature subprocessors

    Support, mail, CRM, payments, product analytics, and optional AI features use Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, Braintree, and others. EU HQ does not isolate account data from those vendors.

  • LowISO 27001 not independently opened in this draft

    The company publishes a UKAS link and a Trust Center certificate. This agent draft could not read the JavaScript registry page, so the checklist stays at claimed until a human confirms scope and dates.

  • MediumOptional OpenAI path for Stream and support

    Transcription, Fluffee/support chat, and CDN AI image generation send data to OpenAI in the United States. Disable those features for workloads that cannot use a US AI processor.

  • LowNarrower platform than Cloudflare

    Shield and Edge Scripting exist, but this is still primarily a delivery, storage, and video stack. Do not expect feature parity with Cloudflare Workers or Zero Trust.

Open questions for due diligence

  • Is the UKAS ISO 27001 entry still current, and what is the certified scope (which products and locations)?
  • Does the in-dashboard DPA include SCCs and a current annex that matches the public sub-processor list plus the longer privacy-policy vendor list?
  • Which products besides CDN pull zones honor an EU-only data path (Stream libraries, Shield logs, Optimizer, Edge Scripting)?
  • Can Mixpanel, Salesforce, SendGrid, or Slack be contractually excluded for a given account?
  • What is the legal relationship between BunnyWay d.o.o. and the UK and German hiring entities?
  • Is the Moscow PoP still active, and can it be excluded without the full EU filter?

Häufig gestellte Fragen

For CDN pull zones, yes, according to the official Routing Filters docs. Enable the European Union filter under Pricing and Routing. Traffic then uses only the listed EU member-state PoPs (24). Non-EU viewers are still served, but from those EU locations, so global performance drops. The same docs say DNS continues to use the global DNS network. Storage, Stream, and log or analytics paths are not automatically covered by that toggle. Confirm each product in writing if you have a residency ban.

The GDPR page says a Data Processing Agreement is available inside the bunny.net dashboard. The public sub-processor list names Zendesk and Atlassian (Europe), Google Workspace (Europe), plus Slack, MailChannels, and OpenAI (United States). The privacy policy also lists Braintree, Salesforce, SendGrid, Mixpanel, MaxMind, Power BI, ActiveCampaign, and others for payments, CRM, mail, fraud, or product analytics. Do not treat EU HQ as EU-only account data.

Only if you use the features that the sub-processor page names. Stream transcription sends uploaded video audio to OpenAI. The support chatbot sends chat text to OpenAI. CDN AI image generation sends the prompt to OpenAI. Data residency for those flows is listed as the United States. If you do not enable those features, that path should not apply. Confirm current product settings and the signed DPA annex before a regulated workload.

Prepaid pay-as-you-go with a time-limited trial that does not require a credit card. CDN is billed on bandwidth (regional rates on Standard, a single global rate on Volume). Storage is billed per replica region. Stream charges for stored video and delivery traffic. The vendor states encoding and the Stream player have no separate fee. Shield has a free basic tier and paid tiers. Monthly spend caps (overcharge protection) are available. Check the live pricing pages for current figures.

Stay on Cloudflare if you depend on Workers, Zero Trust, Bot Management as a primary control plane, or a single vendor for authoritative DNS plus application security at Cloudflare's scale. bunny.net is stronger as a European-headquartered delivery and storage stack with simpler prepaid billing. It is a weak swap if your architecture is already built around Cloudflare's compute and identity products.

No. The production service is a hosted multi-tenant network. There is no official self-host package and no public core license that would make the platform open source. You can integrate via HTTP APIs, official libraries, and the WordPress plugin, but the PoPs stay on BunnyWay infrastructure.