Logo: KeyCDN

KeyCDN

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

KeyCDN is a content delivery network operated by proinity LLC, a privately funded company that lists its headquarters at Reichenauweg 1, 8272 Ermatingen, Switzerland. The company states that KeyCDN is not a federated or resold CDN: it runs its own edge architecture and sells access through a single dashboard and REST API.

The product is built for teams that need a conventional CDN (origin pull, object push, instant purge, TLS on the edge) with a Swiss contracting entity and prepaid credits instead of an annual commit. Every account, according to KeyCDN, receives the same feature set: HTTP/2, TLS 1.3, Let's Encrypt or custom certificates, Brotli when the origin already compresses, image transforms, HLS delivery, and token or referrer locks.

The concrete differentiator versus Cloudflare-class platforms is scope and data path, not a claim of Europe-only delivery. KeyCDN is a CDN, not a bundled WAF, authoritative DNS, or Zero Trust suite. Its public network map includes multiple United States cities, and Origin Shield (an extra cache layer in front of the origin) is documented in the United States East Coast, United States West Coast, and Amsterdam. Push Zone object storage is documented as European data centers.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Key capabilities

A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Auf einen Blick

HQ
Ermatingen, Switzerland
Legal entity
proinity LLC (d/b/a KeyCDN)
Governing law
Switzerland; courts of Schwyz
Network
60+ PoPs in 40+ countries (vendor network page)
Push storage
European data centers (vendor storage page)
Commercial model
Prepaid credits, 14-day trial, no contract
Self-hosted
No (WordPress helper plugins are on GitHub)

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Gerichtsbarkeit & Eigentum

Rechtsträger
proinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, Switzerland
US-Mutter / Kontrolle
Keine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)
Medium
Hosting / Residenz
Company-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.

No known US parent on About/Privacy. Swiss law and Schwyz courts in Terms. Global edge cache plus US Origin Shield keep CLOUD Act exposure at medium, not low. Indicative only, not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS cache copies and US Origin Shield

    Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

  • MediumNo current named subprocessor list

    Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

  • MediumNo public operator ISO 27001 or SOC 2

    ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

  • MediumPrivacy Policy last updated 2018

    The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

  • LowPush Zone required above 100 MB

    Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Open questions for due diligence

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?

Häufig gestellte Fragen

Not from anything published. The Network page lists many US cities as active PoPs. Origin Shield is documented in the US East Coast, US West Coast, and Amsterdam, with automatic selection. Push Zone storage is described as European data centers, but edges still cache globally. If you need a contractual EU-only cache or shield pin, ask KeyCDN in writing. Do not assume it from Swiss HQ alone.

Use Pull when the origin can serve the object and you want the CDN to fetch and cache it. The FAQ says a Push Zone (upload to KeyCDN storage) is required for all content larger than 100 MB. Push is also the path for software, game, or video libraries you want off the origin. Uploads use FTP(S) or certificate-based rsync over SSH.

The GDPR page says to open a support request for a Data Processing Agreement when Article 28 processing applies (for example if URLs, referrers, or user-agents carry personal data). It also says client IPs are anonymized in the content delivery logs KeyCDN provides and that aggregate stats have no personal data. The published syslog log format includes a client IP field. Confirm in the DPA which stream you will enable.

Only if you were using Cloudflare mainly as a CDN. KeyCDN covers pull/push caching, purge, TLS, DDoS mitigation on edge traffic (vendor claim), and a REST API. It does not ship Cloudflare-style WAF rulesets, Workers, corporate DNS, or Zero Trust. KeyCDN itself describes both a full swap and a multi-CDN pairing. Keep Cloudflare (or similar) if those extra products are in scope.

Prepaid credits, pay as you go, cancel anytime. A 14-day trial needs no credit card. Traffic is billed on outbound bytes from edges, with regional volume tiers published on the pricing page. Pull Zone cache has no separate storage fee. Push storage, extra Zones after the first three, syslog log forwarding, and image operations are add-ons. Payments: card, PayPal, or wire. Credits do not expire and are generally nonrefundable. Read keycdn.com/pricing for numbers.

No. The network is a hosted service. KeyCDN publishes WordPress helper plugins (CDN Enabler, Cache Enabler) on GitHub. Those plugins rewrite URLs or generate static HTML. They are not a self-hosted KeyCDN edge.