Myra CDN vs OVHcloud

Compare Myra CDN and OVHcloud on capabilities, jurisdiction, assurance, and fit for European buyers.

Logo: Myra CDN

Myra CDN

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)
Logo: OVHcloud

OVHcloud

France· Cloud Computing

Needs review

Shortlist OVHcloud when you need a European-owned IaaS/bare-metal stack with SecNumCloud/HDS options and multi-continent regions you control per project. Skip when you need hyperscaler platform depth, or when even optional US subsidiaries/regions are a procurement red line—consider Scaleway for leaner French cloud or Hetzner for simpler dedicated/VPS estates.

EU-operated (global regions)Bare Metal + Public CloudOpenStack Public CloudSecNumCloud Private CloudAnti-DDoS includedEU / US / CA / APAC
Myra CDN vs OVHcloud: Snapshot
FeatureLogo: Myra CDNMyra CDNLogo: OVHcloudOVHcloud
Country of originGermanyFrance
CategoryWeb Hosting and Cloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyFrance
Legal entityMyra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428OVH SAS / OVH Groupe (Roubaix); regional entities include OVH US LLC for US services
Governing lawNot listedFrench/EU law for EU contracts; US terms apply for OVH US LLC-contracted services
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyVendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).Own global infrastructure: EU regions (FR including Paris 3-AZ, DE Limburg, PL Warsaw, UK Erith, IT Milan 3-AZ, many Local Zones); US (Vint Hill VA, Hillsboro OR); Canada (Beauharnois, Toronto); APAC (Singapore, Sydney, Mumbai). Primary hosting is OVH-operated, not AWS/GCP resale. Optional non-EU regions are first-class products.
Summary

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

French cloud and infrastructure group (Roubaix): Bare Metal dedicated servers, OpenStack Public Cloud, Hosted Private Cloud (incl. SecNumCloud), and Web Cloud on OVH-operated datacentres across Europe, North America, and Asia-Pacific.

Tags
At a glance: Myra CDN vs OVHcloud
At a glanceLogo: Myra CDNMyra CDNLogo: OVHcloudOVHcloud
HQMunich, Germany (Landsberger Str. 187)Roubaix, France (OVH SAS / OVH Groupe)
Legal entityMyra Security GmbH, HRB 202428Not listed
Founded2012 (vendor about/contact pages)1999 (Octave Klaba)
Product typeSaaS Anycast CDN + Security-as-a-Service (not self-hosted)Not listed
OnboardingDNS cutover + TLS upload; APIv2 at apiv2.myracloud.comNot listed
Commercial modelB2B subscription or quote (monthly/annual prepay); no consumer termsHourly/monthly public cloud; dedicated server subscriptions; free public cloud trial credits (vendor)
ISO 27001BSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17Not listed
Hosting modelNot listedOwn datacentres and network; multi-region IaaS/bare metal
Open source product?Not listedNo (OpenStack-based public cloud uses open APIs)
Notable certs (claimed)Not listedISO 27001 family, SOC 1/2/3, HDS, SecNumCloud (Private Cloud), PCI DSS
Key capabilities: Myra CDN vs OVHcloud
Key capabilitiesLogo: Myra CDNMyra CDNLogo: OVHcloudOVHcloud
EU-operated (Munich GmbH)YesYes
ISO 27001 IT-Grundschutz (BSI, verified)YesNot listed
BSI C5 Type 2 (claimed)YesNot listed
Anycast CDN + Layer 7 DDoSYesNot listed
Germany TLS termination (on request)YesNot listed
PCI DSS Level 1 (claimed)YesNot listed
Bare Metal + Public CloudNot listedYes
OpenStack Public CloudNot listedYes
SecNumCloud Private CloudNot listedYes
Anti-DDoS includedNot listedYes
EU / US / CA / APACNot listedYes

Myra CDN

  • Anycast CDN with RAM cache and HTTP/2

    Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

  • Optional mTLS and signed URLs at the edge

    Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

  • Layer 7 DDoS on the same reverse proxy

    Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

  • WAF, bot management, and EU CAPTCHA add-ons

    The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

  • Germany-only TLS termination on request

    Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

  • REST APIv2, Myra App, and DNS cutover

    Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

OVHcloud

  • Bare Metal dedicated servers (in-house hardware)

    Physical servers assembled and operated by OVHcloud across ranges such as Advance, Scale, High Grade, and Game—full CPU/RAM/storage without a hypervisor layer. Water cooling and hardware lifecycle are part of the industrial model. Best for performance-sensitive, virtualisation, gaming, or large single-tenant workloads where you administer the OS.

  • OpenStack Public Cloud and managed PaaS

    On-demand compute, multi-class object storage (S3-compatible API), block/file storage, managed databases, Kubernetes/container services, networking, and data/AI platforms. Deploy via Control Panel or OpenStack APIs with 1-AZ or 3-AZ region options (for example Paris and Milan). Suited to cloud-native and hybrid automation without US hyperscaler lock-in.

  • Hosted Private Cloud with SecNumCloud path

    VMware-based Hosted Private Cloud (and related stacks) for dedicated virtualisation estates. Selected Private Cloud offerings hold French ANSSI SecNumCloud qualification, with customer data under European regulation and hosting in French sites (Roubaix, Gravelines, Strasbourg)—relevant for French public sector and sensitive workloads under Cloud at the Center doctrine.

  • Global multi-region footprint (EU, US, CA, APAC)

    Own datacentres and regions spanning Europe (France, Germany, Poland, UK, Italy, many Local Zones), North America (Vint Hill VA, Hillsboro OR, Beauharnois and Toronto in Canada), and Asia-Pacific (Singapore, Sydney, Mumbai and related offerings). Choose residency for latency and law; do not assume EU-only by default.

  • Anti-DDoS and vRack private networking included

    Network-integrated anti-DDoS mitigation is standard across services. vRack provides private L2 networking across eligible OVHcloud locations so bare metal, public, and private cloud can interconnect without public exposure. Public bandwidth is typically unmetered in Europe and North America with fair-use rules; Asia-Pacific often uses lower default bandwidth and monthly traffic caps—verify per SKU.

Assurance & compliance: Myra CDN vs OVHcloud
Assurance & complianceLogo: Myra CDNMyra CDNLogo: OVHcloudOVHcloud
Independent security / no-logs audit
Partial

Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports.

Not applicable

IaaS/hosting provider, not a no-logs VPN product. Security is covered via ISO/SOC programme rather than a public no-logs audit.

ISO 27001 (BSI IT-Grundschutz)
Verified

BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP.

Vendor claimed

Vendor compliance pages assert ISO/IEC 27001 (with 27017/27018) for cloud services and datacentres; US pages reference Schellman certificate directory. Confirm current scope per product and region.

SOC 2 / SOC 3
Not found

No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed).

Vendor claimed

Vendor asserts SSAE 18 Type 2 SOC 1, SOC 2 (+NIST), and SOC 3 attestations; reports available to prospective customers under vendor process.

GDPR / EU data protection
Vendor claimed

German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract.

Vendor claimed

EU headquartered; GDPR compliance asserted; DPA documents published for relevant subsidiaries. Residency depends on chosen region.

US CLOUD Act exposure (indicative)
Partial

EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702.

Partial

French group with no known US parent, but operates US datacentres (Vint Hill, Hillsboro) and OVH US LLC. Medium indicative exposure: EU-region workloads on EU contracts differ from US-region workloads. Not legal advice.

Data processing agreement (B2B)
Not found

No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV.

Vendor claimed

Published DPAs form part of terms (e.g. OVH SAS Europe paths; separate US DPA for OVH US LLC). Obtain the DPA matching your contracting entity.

EU AI Act
Not applicable

CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page.

Not applicable

Core product is IaaS/bare metal/hosting; AI/ML platforms are optional infrastructure offerings, not a single AI system product under typical procurement framing.

BSI C5 Type 2
Vendor claimed

Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found.

Not listed
PCI DSS Level 1
Vendor claimed

Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass.

Vendor claimed

Vendor asserts PCI DSS Level 1 certification for payment data hosting—confirm applicability to your architecture.

IDW PS 951 Type 2 (ISAE 3402)
Vendor claimed

Vendor claim of Type 2 over a twelve-month period. Report not published.

Not listed
KRITIS operator (BSIG section 8a(3))
Vendor claimed

Vendor certifications page. Confirm current attestation in procurement.

Not listed
ANSSI SecNumCloudNot listed
Vendor claimed

Hosted Private Cloud (VMware on OVHcloud and related) holds SecNumCloud qualification; hosted in French sites (Roubaix, Gravelines, Strasbourg). Not all products are SecNumCloud-qualified.

HDS (French health data hosting)Not listed
Vendor claimed

Vendor lists HDS certification for healthcare data hosting options; confirm which products and locations are in scope.

Considerations & known limitations: Myra CDN vs OVHcloud
Considerations & known limitationsLogo: Myra CDNMyra CDNLogo: OVHcloudOVHcloud
Global PoPs unless Germany-only is contracted
Medium

Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

Not listed
Outsourced DCs and no public subprocessor list
Medium

BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

Not listed
ISO 27001 scope is DDoS-Schutz, not every SKU
Low

The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

Not listed
Smaller public footprint than Cloudflare
Medium

No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

Not listed
Corporate website uses US processors
Low

Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Not listed
US regions and US subsidiaryNot listed
Medium

US East/West datacentres and OVH US LLC mean CLOUD Act and US process risk apply to US-placed data and some contracts. EU-only deployment reduces this but buyers must enforce region and contracting path.

2021 Strasbourg datacentre fire (resilience history)Not listed
Medium

A major fire at SBG caused widespread customer outages. Treat multi-AZ/multi-region backup design as mandatory for critical data; do not rely on single-site assumptions.

Certification scope is product- and region-specificNot listed
Medium

ISO, SOC, HDS, SecNumCloud, and PCI claims do not automatically cover every SKU and location. Procurement should request the exact report for the services ordered.

APAC bandwidth and traffic rules differNot listed
Low

Vendor documents unmetered traffic exceptions for Asia-Pacific (lower default bandwidth and monthly volume caps vs Europe/North America). Model egress and bandwidth options for APAC workloads.

Broad catalogue complexityNot listed
Low

Bare Metal, Public Cloud, Private Cloud, and Web Cloud under one brand can confuse account structure, IAM, and billing. Define landing-zone standards early.

Fit

Myra CDN

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

OVHcloud

Best fit when

  • Teams wanting European ownership with optional global regions (EU, US, Canada, APAC) under one operator
  • Workloads that need exclusive Bare Metal performance or hybrid bare metal + OpenStack/vRack designs
  • French public sector or sensitive estates needing ANSSI SecNumCloud-qualified Hosted Private Cloud paths
  • Organisations standardising on OpenStack APIs and S3-compatible object storage for reversibility
  • Sites that benefit from network-integrated anti-DDoS and private multi-site networking as defaults

Poor fit when

  • Buyers who require the deepest managed AI/marketplace/IAM ecosystems of AWS, Azure, or GCP
  • Policies that forbid any provider with US legal entities or US datacentre options regardless of region selection
  • Teams seeking the simplest low-SKU VPS experience—Hetzner or similar may fit better
  • Anyone assuming EU-only residency without selecting and enforcing EU regions in architecture

Consider instead when

  • When: You want a leaner French public cloud with a strong developer product surface and less enterprise sovereign packaging

    Consider: Scaleway

    Often simpler for cloud-native teams; confirm region and compliance fit.

  • When: You primarily need price-performance VPS or dedicated servers with a smaller catalogue

    Consider: Hetzner

    Strong for lean estates; different sovereign/cert posture and global region set.

  • When: You need maximum managed-service breadth, global account tooling, and partner marketplace density

    Consider: Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform

    Hyperscalers win platform depth; accept US ownership and CLOUD Act parent exposure.

  • When: You want German SMB hosting plus cloud IaaS with EU and some non-EU options

    Consider: IONOS

    Different product mix and compliance packaging than OVHcloud's bare-metal industrial model.

Open questions for due diligence

Myra CDN

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?

OVHcloud

  • Which contracting entity and DPA (EU OVH SAS path vs OVH US LLC) will apply to our account?
  • Which exact products/regions are in scope for the ISO/SOC/HDS/SecNumCloud certificates we need?
  • What is our multi-region DR design given historical single-site fire risk?
  • Are any non-OVH subprocessors used for our specific managed services (support, monitoring, payments) beyond OVH-operated infrastructure?
  • Do APAC or Local Zone bandwidth/SLA terms meet our traffic profile?