| Independent security / no-logs audit | ❌Not foundVendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found. | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. |
|---|
| ISO 27001 | ⚠️Vendor claimedSeptember 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry. | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. |
|---|
| SOC 2 / SOC 3 | ❌Not foundTrust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found. | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material. | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice. | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page. | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. |
|---|
| EU AI Act | —Not applicableCore product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product. | —Not applicableContent delivery and traffic steering product, not an AI system offering. |
|---|
| PCI DSS | No indicado | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. |
|---|
| CISPE IaaS Code of Conduct | No indicado | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. |
|---|