| Independent security / no-logs audit | ❌Not foundSearched official site, legal page, features, and help centre. No third-party audit PDF or no-logs report. | ⚠️PartialVendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
|---|
| ISO 27001 | ❌Not foundNo ISO 27001 claim or certificate found on primary pages. | ✅VerifiedBSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2 or SOC 3 report found. | ❌Not foundNo SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedPolish VAT-registered entity; dedicated GDPR page treats the vendor as processor. Dedicated EU cache servers sold separately. Default Video/storage products replicate outside the EU. | ⚠️Vendor claimedGerman controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent, but US and Asian content replicas plus Stripe, PayPal, and HubSpot on the account path. Not legal advice. | ⚠️PartialEU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo public DPA download or in-product DPA found. Blog discusses DPAs as a buyer question. Ask sales. | ❌Not foundNo public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
|---|
| EU AI Act | —Not applicableCDN and object storage. Marketing mentions 'Smart AI Caching' and MSA authorises unnamed third-party AI vendors. Not an AI-centric product. | —Not applicableCDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
|---|
| BSI C5 Type 2 | Not listed | ⚠️Vendor claimedCurrent Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
|---|
| PCI DSS Level 1 | Not listed | ⚠️Vendor claimedVendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
|---|
| IDW PS 951 Type 2 (ISAE 3402) | Not listed | ⚠️Vendor claimedVendor claim of Type 2 over a twelve-month period. Report not published. |
|---|
| KRITIS operator (BSIG section 8a(3)) | Not listed | ⚠️Vendor claimedVendor certifications page. Confirm current attestation in procurement. |
|---|