IONOS vs Myra CDN

Compare IONOS and Myra CDN on capabilities, jurisdiction, assurance, and fit for European buyers.

Logo: IONOS

IONOS

Germany· Cloud Computing

Needs review

Shortlist IONOS when you want a German-operated hosting + public cloud stack with EU location choice, managed Kubernetes, S3 storage, and public BSI-oriented cloud certifications for DACH buyers. Skip when you need hyperscaler service breadth, EU-only infrastructure with no US regions or US facility partners in the path, or lowest-cost bare metal—consider OVHcloud, Scaleway, Hetzner, or STACKIT instead depending on that gap.

German SE (Montabaur)EU + US cloud regionsManaged KubernetesS3 Object StorageBSI C5 Type 1 (claimed)Domains + SMB hosting
Logo: Myra CDN

Myra CDN

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)
IONOS vs Myra CDN: Snapshot
FeatureLogo: IONOSIONOSLogo: Myra CDNMyra CDN
Country of originGermanyGermany
CategoryCloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityIONOS SE (HRB 24498, Amtsgericht Montabaur); group listed as IONOS Group SEMyra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428
Governing lawGerman / EU (confirm per contract and national affiliate)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyIONOS-operated and partner facilities in Europe (e.g. Berlin, Frankfurt—including Equinix-operated sites—Paris, Logroño, London, Worcester, Karlsruhe) and the US (Las Vegas, Newark, Lenexa). Object Storage and compute location chosen per resource. Backup Service uses Acronis technology; managed backup path described as DE ISO 27001 centers. Optional Microsoft 365 / Google Workspace resale.Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).
Summary

German hosting and cloud provider (IONOS SE): domains and SMB web hosting plus IONOS Cloud IaaS/PaaS with EU and US locations, managed Kubernetes, object storage, and DBaaS.

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

Tags
At a glance: IONOS vs Myra CDN
At a glanceLogo: IONOSIONOSLogo: Myra CDNMyra CDN
HQMontabaur, Germany (IONOS SE)Munich, Germany (Landsberger Str. 187)
GroupUnited Internet / IONOS Group SE (listed)Not listed
Product linesDomains & hosting + IONOS Cloud IaaS/PaaSNot listed
Cloud regionsDE, FR, ES, UK + US (e.g. LAS, EWR, MCI)Not listed
Open sourceNo (proprietary platform)Not listed
Self-hostNoNot listed
Commercial modelHosting packages + cloud usage (per-minute style)B2B subscription or quote (monthly/annual prepay); no consumer terms
Legal entityNot listedMyra Security GmbH, HRB 202428
FoundedNot listed2012 (vendor about/contact pages)
Product typeNot listedSaaS Anycast CDN + Security-as-a-Service (not self-hosted)
OnboardingNot listedDNS cutover + TLS upload; APIv2 at apiv2.myracloud.com
ISO 27001Not listedBSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17
Key capabilities: IONOS vs Myra CDN
Key capabilitiesLogo: IONOSIONOSLogo: Myra CDNMyra CDN
German SE (Montabaur)YesNot listed
EU + US cloud regionsYesNot listed
Managed KubernetesYesNot listed
S3 Object StorageYesNot listed
BSI C5 Type 1 (claimed)YesYes
Domains + SMB hostingYesNot listed
EU-operated (Munich GmbH)Not listedYes
ISO 27001 IT-Grundschutz (BSI, verified)Not listedYes
Anycast CDN + Layer 7 DDoSNot listedYes
Germany TLS termination (on request)Not listedYes
PCI DSS Level 1 (claimed)Not listedYes

IONOS

  • Virtual Data Center Designer and IaaS compute

    Build isolated virtual data centers in the browser or via Cloud API: dedicated-core servers, vCPU servers, and Cubes with attached NVMe. Live vertical scaling is supported on many Linux images for cores, RAM, NICs, and volumes without a full rebuild. Locations span DE (Berlin, Frankfurt, Karlsruhe), FR, ES, UK, and US.

  • Managed Kubernetes without a separate control-plane fee

    Automated cluster and node-pool setup with geo-redundant control plane, admin API access, and optional node auto-scaling. IONOS documents the managed control plane as free of charge; you pay for the underlying compute, storage, and network only—useful for staging and production clusters on the same contract.

  • S3-compatible Object Storage across EU and US endpoints

    Contract-included Object Storage with S3 API compatibility, versioning, object lock, SSE-S3/SSE-C, and lifecycle rules. Documented endpoints include Frankfurt, Berlin, Logroño, and Lenexa (US). German object-storage locations are listed with BSI IT-Grundschutz compliance notes in the service catalog.

  • Managed databases, GPU VMs, and Berlin-hosted AI Model Hub

    DBaaS for PostgreSQL, MongoDB, MariaDB, and in-memory DB; Cloud GPU VMs (NVIDIA H200 templates) in Frankfurt; AI Model Hub with OpenAI-compatible APIs, RAG/vector support, and vendor-stated processing exclusively in Germany (Berlin). Fits teams that want European inference without standing up their own GPU estate.

  • Domains, web hosting, and personal consultant for SMBs

    Classic IONOS portfolio: domain registration, shared/VPS/dedicated hosting, site builders, and optional Microsoft 365 or Google Workspace. Differentiator for non-cloud buyers is a dedicated personal consultant plus 24/7 support channels—not pure ticket-only self-serve hosting.

Myra CDN

  • Anycast CDN with RAM cache and HTTP/2

    Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

  • Optional mTLS and signed URLs at the edge

    Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

  • Layer 7 DDoS on the same reverse proxy

    Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

  • WAF, bot management, and EU CAPTCHA add-ons

    The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

  • Germany-only TLS termination on request

    Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

  • REST APIv2, Myra App, and DNS cutover

    Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

Assurance & compliance: IONOS vs Myra CDN
Assurance & complianceLogo: IONOSIONOSLogo: Myra CDNMyra CDN
Independent security / cloud audit (beyond marketing)
Partial

BSI C5 Type 1 (2023 announcement) and IT-Grundschutz ISMS claims after external audit; not a public no-logs VPN-style audit. Request current reports and scope.

Partial

Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports.

ISO 27001
Vendor claimed

Vendor FAQ/about materials state ISO 27001 for data centers / security posture; facility partner cert PDFs also referenced on location pages. Independent cert registry entry not re-verified here.

Verified

BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP.

SOC 2 / SOC 3
Not found

SOC/SSAE-style attestations appear for some facility operators (e.g. Equinix listings). No clear IONOS product-level SOC 2 claim found on primary pages reviewed.

Not found

No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed).

BSI C5 (Cloud Computing Compliance Criteria Catalogue)
Vendor claimed

Company IR announcement 7 Nov 2023: C5 Type 1 for Compute Engine, Cloud Cubes, S3 Object Storage after external audit. Type 1 = design at a point in time; confirm current validity and product scope.

Vendor claimed

Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found.

GDPR / EU data protection
Vendor claimed

German controller/processor entities; EU location options; vendor GDPR statements. Residency still depends on selected regions and subprocessors.

Vendor claimed

German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract.

US CLOUD Act exposure (indicative)
Partial

German SE / no known US parent, but US subsidiaries, US host regions (LAS/EWR/MCI), Equinix facility partnership, optional Microsoft/Google products, Acronis-powered backup. Not legal advice.

Partial

EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702.

Data processing agreement (B2B)
Vendor claimed

Hosting DPA via account privacy flows; IONOS Cloud AVV via account manager / contract docs. Confirm entity and service annex.

Not found

No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV.

EU AI Act
Partial

Relevant mainly to AI Model Hub (docs discuss governance/compliance). Core hosting/IaaS is not AI-product-centric; treat AI Act as service-specific diligence.

Not applicable

CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page.

PCI DSS Level 1Not listed
Vendor claimed

Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass.

IDW PS 951 Type 2 (ISAE 3402)Not listed
Vendor claimed

Vendor claim of Type 2 over a twelve-month period. Report not published.

KRITIS operator (BSIG section 8a(3))Not listed
Vendor claimed

Vendor certifications page. Confirm current attestation in procurement.

Considerations & known limitations: IONOS vs Myra CDN
Considerations & known limitationsLogo: IONOSIONOSLogo: Myra CDNMyra CDN
US regions, US entities, and facility partners
Medium

Selecting US locations places data in the US. Even EU-only deployments sit in a group that has US subsidiaries and uses partners such as Equinix for some EU facilities—material for CLOUD Act / transfer reviews.

Not listed
No clear public subprocessor catalogue
Medium

Unlike many pure SaaS vendors, a single customer-facing subprocessor list was not found. Buyers must extract partners from location pages, DPA annexes, and product docs (Equinix, Acronis, Microsoft, Google, etc.).

Not listed
C5 Type 1 scope and freshness
Low

Public C5 claim is Type 1 for specific products (Compute Engine, Cubes, Object Storage) as of the 2023 announcement. Not a blanket certificate for every IONOS product; request up-to-date reports.

Not listed
Narrower managed ecosystem than hyperscalers
Low

Strong IaaS and selected PaaS, but not a full AWS/Azure service catalogue. Multi-region global apps and niche managed services may force multi-cloud or a different primary vendor.

Not listed
Hosting brand vs cloud platform complexity
Low

SMB hosting contracts, reseller office suites, and enterprise cloud AVVs are different commercial and compliance surfaces—do not assume one DPA covers every SKU.

Not listed
Global PoPs unless Germany-only is contractedNot listed
Medium

Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

Outsourced DCs and no public subprocessor listNot listed
Medium

BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

ISO 27001 scope is DDoS-Schutz, not every SKUNot listed
Low

The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

Smaller public footprint than CloudflareNot listed
Medium

No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

Corporate website uses US processorsNot listed
Low

Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Fit

IONOS

Best fit when

  • SMB and agencies needing domains, hosting, email/office resale, and a personal consultant under one German brand
  • Teams building IaaS workloads in selectable EU locations with a visual Data Center Designer and full Cloud API
  • Organizations that want managed Kubernetes, DBaaS, and S3-compatible storage without a hyperscaler contract
  • DACH public-sector or regulated buyers who need documented BSI C5 / IT-Grundschutz posture on scoped cloud products (confirm current report)
  • AI or inference pilots that prefer vendor-stated Germany (Berlin) hosting for AI Model Hub

Poor fit when

  • Buyers requiring a guarantee of no US legal entities, no US regions, and no US-group facility partners anywhere in the path
  • Workloads that depend on the full AWS/Azure/GCP marketplace, global region density, or niche managed services IONOS does not offer
  • Price-only bare-metal or Hetzner-style DIY shops that do not need managed PaaS or SMB hosting layers
  • Teams that refuse any US-group SaaS (Microsoft 365 / Google Workspace) if those bundles are part of the intended stack

Consider instead when

  • When: You want French-operated cloud with strong developer packaging and EU focus without a mass-market hosting brand

    Consider: Scaleway

    Different product mix; compare region map and managed services side by side.

  • When: You prioritize large European hosting/cloud scale and multi-country DC ownership narratives

    Consider: OVHcloud

    Both are EU groups with non-trivial international footprints—read residency options carefully.

  • When: You mainly need cost-efficient dedicated servers or simple cloud in DE/FI with minimal PaaS

    Consider: Hetzner

    Thinner managed layer; different support and SMB hosting model.

  • When: You are already in Schwarz Group ecosystems or need STACKIT-specific public-cloud positioning

    Consider: STACKIT

    Narrower commercial brand than IONOS hosting+cloud combo.

Myra CDN

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

Open questions for due diligence

IONOS

  • What is the current BSI C5 report type (Type 1 vs Type 2), validity period, and exact product/location scope?
  • Can IONOS provide a consolidated subprocessor and sub-processor change-notification list under the DPA/AVV?
  • Which contract entity (IONOS SE vs IONOS Cloud GmbH vs national affiliates) will sign for our workload and which TOMs apply?
  • For EU-only deployments, are any support, monitoring, or backup control-plane components processed outside the EU?
  • Is ISO 27001 held by IONOS operating companies for the full service stack, or primarily facility/operator certifications?

Myra CDN

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?