bunny.net vs UncensoredDNS

Compare bunny.net and UncensoredDNS on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Cloudflare

Logo: bunny.net

bunny.net

Slovenia· Web Hosting and Cloud Computing

Needs review

Shortlist bunny.net when you want a Slovenian-operated CDN plus storage and Stream, with an official EU pull-zone routing filter and prepaid pay-as-you-go billing. Skip it when you need Cloudflare Workers or Zero Trust as the control plane, or when account data must stay off US-group SaaS (Slack, OpenAI, SendGrid, Mixpanel, Salesforce, Braintree). Consider Cloudflare if the platform surface matters more than EU HQ.

EU-operated (Slovenia)Pay-as-you-go CDNEU pull-zone routing filterMulti-region edge storageManaged video (Stream)ISO 27001 (claimed)
Logo: UncensoredDNS

UncensoredDNS

Denmark· Web Hosting and Cloud Computing

Needs review

Shortlist when you want an unfiltered, encrypt-only public resolver run by a named Danish operator and you can configure DoT, DoH, or DoQ. Skip when you need a DPA, malware blocking, EU-only anycast, or a staffed SLA. Use unicast for Denmark-local queries. Consider Quad9 when you want resolver-side threat blocking, or Cloudflare / Google Public DNS when you need a mass-market anycast default.

Danish-operatedEncrypted DNS onlyNo filter listsNo-logs (claimed)Free public resolver
bunny.net vs UncensoredDNS: Snapshot
FeatureLogo: bunny.netbunny.netLogo: UncensoredDNSUncensoredDNS
Country of originSloveniaDenmark
CategoryWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSloveniaDenmark
Legal entityBunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, SloveniaNo company published. Operator: Thomas Steen Rasmussen (private individual).
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyOperator-advertised global PoPs (Standard 119, Volume 10) and 15 storage regions, including EU (London, Stockholm, Frankfurt, Madrid, Prague) and US (New York, Miami, Los Angeles, Seattle). EU Routing Filter can pin CDN pull-zone traffic to 24 EU PoPs. DNS stays global. Account path uses Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree. Privacy page claims EU residency for BigQuery, dbt Cloud, Lemlist, Loqate, and Kickscale.Unicast at AS9167 (Høje Tåstrup, Denmark, sponsor tyktech). Anycast nodes: two at DeiC in Lyngby, Denmark (AS1835) and one at rgnet in Washington, USA (AS3927). No public backup, email, or analytics subprocessor list.
Summary

Slovenian edge platform from BunnyWay d.o.o.: pay-as-you-go CDN, multi-region object storage, video streaming, and Shield WAF on an operator-run global PoP network.

Danish volunteer public DNS resolver with encrypted-only DoT, DoH, and DoQ. Unfiltered lookups, unicast in the Copenhagen area, anycast that includes a US node.

Tags
At a glance: bunny.net vs UncensoredDNS
At a glanceLogo: bunny.netbunny.netLogo: UncensoredDNSUncensoredDNS
HQLjubljana, SloveniaNot listed
Legal entityBunnyWay d.o.o.No company imprint found
Product familyCDN, Storage, Stream, Shield, DNS, Optimizer, edge computeNot listed
Hosting modelHosted operator PoPs (not self-hosted)Not listed
Commercial modelPrepaid pay-as-you-go, trial without credit cardFree public service; optional GitHub Sponsors donations
Open sourceNo public core license foundNot listed
OperatorNot listedThomas Steen Rasmussen, private individual, Denmark
StartedNot listedNovember 2009 (censurfridns.dk registered 15 November 2009)
ProtocolsNot listedDoT :853, DoH /dns-query, DoQ UDP/853, DoH3 UDP/443; no port 53
AnycastNot listed91.239.100.100 / 2001:67c:28a4:: (DeiC Lyngby + rgnet Washington)
UnicastNot listed89.233.43.71 / 2a01:3a0:53:53:: at AS9167, Høje Tåstrup
Independent auditNot listedNone found
Key capabilities: bunny.net vs UncensoredDNS
Key capabilitiesLogo: bunny.netbunny.netLogo: UncensoredDNSUncensoredDNS
EU-operated (Slovenia)YesYes
Pay-as-you-go CDNYesNot listed
EU pull-zone routing filterYesNot listed
Multi-region edge storageYesNot listed
Managed video (Stream)YesNot listed
ISO 27001 (claimed)YesNot listed
Encrypted DNS onlyNot listedYes
No filter listsNot listedYes
No-logs (claimed)Not listedYes
Free public resolverNot listedYes

bunny.net

  • Pull-zone CDN with Perma-Cache

    Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.

  • EU Routing Filter for pull zones

    Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.

  • Multi-region edge object storage

    Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.

  • Bunny Stream transcoding and player

    Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.

  • Signed URL tokens and access controls

    Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.

  • Bunny Shield WAF and DDoS

    Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.

UncensoredDNS

  • Encrypted-only recursive DNS

    Since October 2022 the resolvers do not answer classic UDP/TCP port 53. Clients use DNS-over-TLS on 853, DNS-over-HTTPS at /dns-query on 443, and (from 23 October 2025) DNS-over-QUIC on UDP/853 plus DNS-over-HTTP/3 on UDP/443. Devices that can only speak cleartext DNS will fail.

  • Unfiltered public resolution

    The service is built to skip ISP and court-style DNS blocklists that Danish providers apply. It does not offer malware, ad, or family filter modes. Choose it when you want NXDOMAIN to mean the name does not exist, not that a resolver policy hid it.

  • Anycast plus Danish unicast endpoints

    anycast.uncensoreddns.org uses 91.239.100.100 and 2001:67c:28a4::. unicast.uncensoreddns.org uses 89.233.43.71 and 2a01:3a0:53:53:: at AS9167 in Høje Tåstrup. The operator says the anycast prefix is provider-independent and unlikely to change. Legacy names under censurfridns.dk still work.

  • Published TLS pins per node

    Each listed node publishes RSA and ECDSA TLS public keys on the DNS Servers page. DoT originally shipped with TLSA records so clients such as Stubby can pin. Key rotation (ECDSA introduction in 2020) can break pinsets until operators update them.

  • Router and OS client notes

    The censurfridns/client-configs GitHub repo documents Firefox, Edge, iOS profiles, systemd-resolved, pfSense, OPNsense, OpenWrt, and Unbound. This is community documentation for a public resolver, not a supported enterprise client.

Assurance & compliance: bunny.net vs UncensoredDNS
Assurance & complianceLogo: bunny.netbunny.netLogo: UncensoredDNSUncensoredDNS
Independent security / no-logs audit
Not found

Vendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found.

Not found

FAQ claims no personal logs and aggregate graphs only. No third-party audit PDF found.

ISO 27001
Vendor claimed

September 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry.

Not found
SOC 2 / SOC 3
Not found

Trust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found.

Not found
GDPR / EU data protection
Vendor claimed

EU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material.

Partial

Danish individual operator and a no-logs claim on the FAQ. No formal privacy policy or DPA page found.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice.

Partial

No known US parent. Published anycast includes rgnet in Washington, USA (AS3927), so some queries can be answered on US soil. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page.

Not found

No company imprint or processor agreement found. Operator contact is admin@censurfridns.dk.

EU AI Act
Not applicable

Core product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product.

Not applicable

Public recursive DNS resolver, not an AI system.

Considerations & known limitations: bunny.net vs UncensoredDNS
Considerations & known limitationsLogo: bunny.netbunny.netLogo: UncensoredDNSUncensoredDNS
Default routing is global, including US and Moscow PoPs
Medium

Without the EU Routing Filter, cached objects can sit at non-EU PoPs listed on the CDN map, including US cities and Moscow. The filter covers pull-zone traffic only and hurts latency for non-EU users.

Not listed
US-group account and feature subprocessors
Medium

Support, mail, CRM, payments, product analytics, and optional AI features use Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, Braintree, and others. EU HQ does not isolate account data from those vendors.

Not listed
ISO 27001 not independently opened in this draft
Low

The company publishes a UKAS link and a Trust Center certificate. This agent draft could not read the JavaScript registry page, so the checklist stays at claimed until a human confirms scope and dates.

Not listed
Optional OpenAI path for Stream and support
Medium

Transcription, Fluffee/support chat, and CDN AI image generation send data to OpenAI in the United States. Disable those features for workloads that cannot use a US AI processor.

Not listed
Narrower platform than Cloudflare
Low

Shield and Edge Scripting exist, but this is still primarily a delivery, storage, and video stack. Do not expect feature parity with Cloudflare Workers or Zero Trust.

Not listed
Single-person operationNot listed
High

The service is run by one named individual with donated nodes. There is no published company, on-call roster, or SLA. Sponsor withdrawals have already removed anycast sites.

US anycast node on the public mapNot listed
Medium

rgnet-iad.anycast.uncensoreddns.org is listed in Washington, USA. Anycast clients cannot pin Denmark. Use the unicast hostname if EU landing matters.

No public independent auditNot listed
Medium

No-logs is a first-party FAQ statement. No audit, ISO, or SOC package was found for a security review file.

No classic port 53Not listed
Low

Cleartext DNS has been off since October 2022. Guest devices, some IoT, and default DHCP resolvers will not work without a local forwarder that speaks DoT or DoH.

Fit

bunny.net

Best fit when

  • EU-headquartered teams that need a pull-zone CDN and can enable the EU Routing Filter when residency matters
  • Sites and APIs that want prepaid bandwidth billing without per-request CDN fees
  • Software, game, or firmware delivery that benefits from Perma-Cache and multi-region storage (see NZXT, System76, Nexus Mods case studies)
  • VOD or event video that can use Stream transcoding and the bundled player, without sending audio to OpenAI
  • Teams that want token-authenticated downloads, geo-blocking, and a separate Shield WAF on the same account

Poor fit when

  • Architectures built around Cloudflare Workers, Zero Trust, or Cloudflare as the primary application platform
  • Workloads with a hard ban on US-group subprocessors for billing, support, mail, or analytics
  • Buyers who need a self-hosted or open-source CDN they can run in their own data centers
  • Global audiences that must stay on the nearest PoP while also forbidding any non-EU cache (the EU filter trades latency for residency)
  • Regulated video that requires on-platform transcription without a US AI subprocessor

Consider instead when

  • When: You need Workers, Zero Trust, or a single US-scale security and compute control plane

    Consider: Cloudflare

    Cloudflare is US-headquartered. The tradeoff is platform breadth, not EU ownership.

  • When: Origin already lives on AWS and you need IAM, PrivateLink, or CloudFront contracts

    Consider: Amazon CloudFront (with S3 or Media Services)

    Bunny is faster to start for a standalone CDN plus Stream. It will not replace AWS account controls.

  • When: You want a European CDN peer that is not Cloudflare and bunny.net's US PoPs or US SaaS tools are disqualifying

    Consider: KeyCDN or Myra Security (not yet in this catalog)

    Re-check those vendors on their own legal and subprocessor pages. Do not assume they are cleaner.

UncensoredDNS

Best fit when

  • Households and labs leaving filtered Danish ISP DNS who can speak DoT, DoH, or DoQ
  • Admins who want NXDOMAIN to mean the name does not exist, not a resolver policy
  • Router and homelab setups (pfSense, OPNsense, OpenWrt, systemd-resolved) using the published client notes
  • Buyers who prefer a named European individual over sending every lookup to Google or Cloudflare
  • Teams that can pin TLS keys and accept a volunteer-run service without an SLA

Poor fit when

  • Procurement that requires a company imprint, signed DPA, or ISO/SOC package
  • Policies that require EU-only query landing (anycast includes Washington, USA)
  • Need for malware, ad, or family filtering at the resolver
  • Devices or DHCP that can only use cleartext UDP/TCP port 53
  • A regulated resolver dependency that needs staffed on-call and a status SLA

Consider instead when

  • When: You want resolver-side malware blocking with a European-adjacent operator

    Consider: Quad9

    Quad9 is a filtered secure resolver. UncensoredDNS will not apply those blocks.

  • When: You need configurable profiles, analytics, or family filters

    Consider: NextDNS or AdGuard DNS

    Those are policy platforms. UncensoredDNS has no per-user console.

  • When: You need a mass-market anycast default and OS-level presets

    Consider: Cloudflare 1.1.1.1 or Google Public DNS

    Larger footprint and still offer cleartext 53. They are US-group services.

  • When: Every query must stay inside your EU tenancy

    Consider: Self-hosted Unbound or Knot Resolver on your own metal

    UncensoredDNS anycast can land on the published US node.

Open questions for due diligence

bunny.net

  • Is the UKAS ISO 27001 entry still current, and what is the certified scope (which products and locations)?
  • Does the in-dashboard DPA include SCCs and a current annex that matches the public sub-processor list plus the longer privacy-policy vendor list?
  • Which products besides CDN pull zones honor an EU-only data path (Stream libraries, Shield logs, Optimizer, Edge Scripting)?
  • Can Mixpanel, Salesforce, SendGrid, or Slack be contractually excluded for a given account?
  • What is the legal relationship between BunnyWay d.o.o. and the UK and German hiring entities?
  • Is the Moscow PoP still active, and can it be excluded without the full EU filter?

UncensoredDNS

  • Will the operator form a legal entity or sign a DPA for organisational use?
  • Is there a way to pin anycast to EU nodes only, or should EU-only buyers use unicast exclusively?
  • Is an independent no-logs or infrastructure audit planned?
  • Does the recursor validate DNSSEC for all clients? (not stated as a current guarantee on the pages reviewed)
  • What subprocessors, if any, sit on the blog, email, or monitoring path?