Logo: Myra CDN

Myra CDN

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

Myra CDN is the content delivery layer of Myra Security GmbH, a Munich Security-as-a-Service vendor that sits as a reverse proxy between browsers and origin servers. The same Anycast network also delivers automated Layer 7 DDoS mitigation, a web application firewall, bot management, and an EU-built CAPTCHA. Teams typically go live by changing DNS and uploading TLS certificates. No appliance is required in the origin data center.

The product exists because German banks, public bodies, and KRITIS operators need a Cloudflare-class edge that can keep TLS termination and inspection inside Germany when asked. Myra Security GmbH is registered in Munich (HRB 202428). Founders Sascha Schumann and Paul Kaffsack have operated the company since 2012. The older myracloud.com hostname now redirects to myrasecurity.com. Product docs and APIv2 still live under myracloud.com.

The concrete differentiator is a RAM-cached Anycast CDN (HTTP/2, IPv4 and IPv6, optional mTLS and signed URLs) paired with a BSI-registered ISO 27001 scope for Myra DDoS-Schutz and a contract option for exclusive German processing. Default delivery is global. Exclusive German processing is an option, not the only mode.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

Key capabilities

Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

Auf einen Blick

HQ
Munich, Germany (Landsberger Str. 187)
Legal entity
Myra Security GmbH, HRB 202428
Founded
2012 (vendor about/contact pages)
Product type
SaaS Anycast CDN + Security-as-a-Service (not self-hosted)
Onboarding
DNS cutover + TLS upload; APIv2 at apiv2.myracloud.com
Commercial model
B2B subscription or quote (monthly/annual prepay); no consumer terms
ISO 27001
BSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

Gerichtsbarkeit & Eigentum

Rechtsträger
Myra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428
US-Mutter / Kontrolle
Keine bekannte US-Mutter
CLOUD-Act-Exposition (indikativ)
Low
Hosting / Residenz
Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).

No known US parent. Indicative CLOUD Act exposure is low on ownership, partial in practice because global PoPs and unnamed colocation partners are not fully listed. Vendor asserts it is not bound by the US CLOUD Act or FISA 702. Not legal advice.

  • Independent security / no-logs auditPartial
  • ISO 27001 (BSI IT-Grundschutz)Verified
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +7

Considerations & known limitations

  • MediumGlobal PoPs unless Germany-only is contracted

    Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

  • MediumOutsourced DCs and no public subprocessor list

    BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

  • LowISO 27001 scope is DDoS-Schutz, not every SKU

    The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

  • MediumSmaller public footprint than Cloudflare

    No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

  • LowCorporate website uses US processors

    Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Open questions for due diligence

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?

Häufig gestellte Fragen

Yes, as a contractual option. The GDPR page states SSL/TLS termination is performed exclusively in Germany at the customer's request, because inspection of encrypted attacks briefly exposes personal data. Exclusive processing in German data centres is described the same way. Default CDN marketing still describes globally placed Anycast PoPs. If Germany-only inspection is a hard requirement, put it in the order and ask which PoPs still see client IPs.

It covers the overlapping slice: reverse-proxy CDN, Layer 7 DDoS, WAF, bot management, DNS cutover, logs, and an API. It does not match Cloudflare's global PoP count, Workers-style edge compute, or self-serve free funnel. Myra is sales-led, B2B-only under German terms, and stronger when the RFP scores BSI/KRITIS and German jurisdiction. Dual-run both edges during migration and compare cache keys, HTTP/3 (not listed on the CDN spec sheet), and origin shielding.

Myra sits on the public internet in front of the origin. You upload TLS certificates, point DNS at Myra (or delegate DNS), and configure cache and security rules in the Myra App or APIv2. Docs say no change to the existing origin stack is required. Optional extras include origin load balancing, mTLS to origin, IPsec forwarding of clean traffic, and network DDoS for whole prefixes. On-prem network protection exists as a different SKU.

The public BSI entry BSI-IGZ-0667-2024 scopes the ISMS to the DDoS-protection business process (web applications, websites, DNS, and IT infrastructures), operated at six outsourced data-centre sites. That is independent proof for that scope through 17 December 2027. It is not, by itself, a certificate for every global CDN PoP or every add-on (object storage, EU CAPTCHA, marketing site). Ask for the current statement of applicability and whether your contracted PoPs sit inside that information network.

A downloadable Art. 28 DPA and a named product subprocessor register were not found on the imprint, terms, GDPR, or privacy pages. The privacy policy lists processors for the marketing website only (including several US SaaS tools). The BSI certificate confirms six outsourced data-centre locations without naming operators. Treat DPA signature, TOMs, and the current subprocessor annex as procurement deliverables. The EU CAPTCHA FAQ implies a DPA is part of that product's signup flow.

B2B subscription under German terms: monthly or annual prepayment, or an individually negotiated contract. A public calculator configures WAF, bot management, DDoS, and CDN and then routes to a quote. SLAs are selected per product description (CDN sheet states availability up to 99.999 percent). EU CAPTCHA has a separate self-serve trial. Do not expect a consumer free CDN tier comparable to Cloudflare.