| Independent security / no-logs audit | ❌Not foundVendor claims logging is disabled. Annual transparency reports exist (2019-2025) but are not an independent security or no-logs audit. Resolver software is undisclosed. | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. |
|---|
| ISO 27001 | ❌Not foundNo ISO 27001 claim found on dns.sb privacy, FAQ, or xTom imprint pages reviewed. | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2 or SOC 3 claim found on the official pages reviewed. | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedGerman controller (xTom GmbH). Privacy policy includes a GDPR rights section and states DNS query data is not collected. Website analytics described as self-hosted Plausible on legitimate interests. | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent, but public unicast list includes US cities and US-group providers (Amazon AWS Seoul, DigitalOcean Bengaluru, Vultr Toronto) plus HostVenom Chicago. Anycast includes the United States. Not legal advice. | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. |
|---|
| Data processing agreement (B2B) | ❌Not foundNo public DPA. Free service is personal/non-commercial; commercial terms are by contact only. | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. |
|---|
| EU AI Act | —Not applicablePublic DNS resolver, not an AI system. | —Not applicableContent delivery and traffic steering product, not an AI system offering. |
|---|
| PCI DSS | Not listed | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. |
|---|
| CISPE IaaS Code of Conduct | Not listed | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. |
|---|