Pull-zone CDN with Perma-Cache
Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.
EU Routing Filter for pull zones
Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.
Multi-region edge object storage
Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.
Bunny Stream transcoding and player
Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.
Signed URL tokens and access controls
Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.
Bunny Shield WAF and DDoS
Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.