| Independent security / no-logs audit | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. | ❌Not foundNo public independent audit report found on swissnode.ch. |
|---|
| ISO 27001 | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. | ❌Not foundNo ISO 27001 claim located on official product/security pages. |
|---|
| SOC 2 / SOC 3 | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. | ❌Not foundNo SOC 2/3 claim found. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. | ⚠️PartialSpain/EU hosting supports EU data-protection analysis, and homepage references Spanish privacy laws; usable privacy policy/DPA text not published on site. Customer remains controller for lawful basis. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. | ⚠️PartialNo known US parent; primary host Spain/EU. Optional Cloudflare CDN is a US-group subprocessor for web static delivery; off-site backups and other SaaS paths not published. Not a clean low-exposure bill; not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. | ❌Not foundNo public DPA download or B2B processing terms found; request in writing. |
|---|
| EU AI Act | —Not applicableContent delivery and traffic steering product, not an AI system offering. | —Not applicableCommodity hosting/email/VPS, not an AI product. |
|---|
| PCI DSS | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. | Not listed |
|---|
| CISPE IaaS Code of Conduct | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. | Not listed |
|---|
| Swiss territorial hosting | Not listed | ⚠️PartialVendor discloses Swiss DC closed; operations from Spain DC. Contact still Zurich. Do not treat as CH-only residency. |
|---|