| Independent security / no-logs audit | ❌Not foundNo public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field. | ⚠️PartialVendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
|---|
| ISO 27001 | ❌Not foundNetwork page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC. | ✅VerifiedBSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
|---|
| SOC 2 / SOC 3 | ❌Not foundSearched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found. | ❌Not foundNo SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedSwiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties. | ⚠️Vendor claimedGerman controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialSwiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice. | ⚠️PartialEU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedGDPR page: open a support request to receive the DPA when Article 28 processing applies. | ❌Not foundNo public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
|---|
| EU AI Act | —Not applicableCDN / image transforms, not an AI system product. | —Not applicableCDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
|---|
| BSI C5 Type 2 | Not listed | ⚠️Vendor claimedCurrent Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
|---|
| PCI DSS Level 1 | Not listed | ⚠️Vendor claimedVendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
|---|
| IDW PS 951 Type 2 (ISAE 3402) | Not listed | ⚠️Vendor claimedVendor claim of Type 2 over a twelve-month period. Report not published. |
|---|
| KRITIS operator (BSIG section 8a(3)) | Not listed | ⚠️Vendor claimedVendor certifications page. Confirm current attestation in procurement. |
|---|