| Independent security / no-logs audit | ❌Not foundVendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found. | ❌Not foundNo public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field. |
|---|
| ISO 27001 | ⚠️Vendor claimedSeptember 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry. | ❌Not foundNetwork page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC. |
|---|
| SOC 2 / SOC 3 | ❌Not foundTrust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found. | ❌Not foundSearched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material. | ⚠️Vendor claimedSwiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice. | ⚠️PartialSwiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page. | ⚠️Vendor claimedGDPR page: open a support request to receive the DPA when Article 28 processing applies. |
|---|
| EU AI Act | —Not applicableCore product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product. | —Not applicableCDN / image transforms, not an AI system product. |
|---|