| Independent security / no-logs audit | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. | —Not applicableIaaS/hosting provider, not a no-logs VPN product. Security is covered via ISO/SOC programme rather than a public no-logs audit. |
|---|
| ISO 27001 | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. | ⚠️Vendor claimedVendor compliance pages assert ISO/IEC 27001 (with 27017/27018) for cloud services and datacentres; US pages reference Schellman certificate directory. Confirm current scope per product and region. |
|---|
| SOC 2 / SOC 3 | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. | ⚠️Vendor claimedVendor asserts SSAE 18 Type 2 SOC 1, SOC 2 (+NIST), and SOC 3 attestations; reports available to prospective customers under vendor process. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. | ⚠️Vendor claimedEU headquartered; GDPR compliance asserted; DPA documents published for relevant subsidiaries. Residency depends on chosen region. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. | ⚠️PartialFrench group with no known US parent, but operates US datacentres (Vint Hill, Hillsboro) and OVH US LLC. Medium indicative exposure: EU-region workloads on EU contracts differ from US-region workloads. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. | ⚠️Vendor claimedPublished DPAs form part of terms (e.g. OVH SAS Europe paths; separate US DPA for OVH US LLC). Obtain the DPA matching your contracting entity. |
|---|
| EU AI Act | —Not applicableContent delivery and traffic steering product, not an AI system offering. | —Not applicableCore product is IaaS/bare metal/hosting; AI/ML platforms are optional infrastructure offerings, not a single AI system product under typical procurement framing. |
|---|
| PCI DSS | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. | ⚠️Vendor claimedVendor asserts PCI DSS Level 1 certification for payment data hosting—confirm applicability to your architecture. |
|---|
| CISPE IaaS Code of Conduct | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. | Not listed |
|---|
| ANSSI SecNumCloud | Not listed | ⚠️Vendor claimedHosted Private Cloud (VMware on OVHcloud and related) holds SecNumCloud qualification; hosted in French sites (Roubaix, Gravelines, Strasbourg). Not all products are SecNumCloud-qualified. |
|---|
| HDS (French health data hosting) | Not listed | ⚠️Vendor claimedVendor lists HDS certification for healthcare data hosting options; confirm which products and locations are in scope. |
|---|