| Independent security / no-logs audit | ❌Not foundVendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found. | ⚠️PartialVendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
|---|
| ISO 27001 | ⚠️Vendor claimedSeptember 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry. | ✅VerifiedBSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
|---|
| SOC 2 / SOC 3 | ❌Not foundTrust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found. | ❌Not foundNo SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material. | ⚠️Vendor claimedGerman controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice. | ⚠️PartialEU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page. | ❌Not foundNo public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
|---|
| EU AI Act | —Not applicableCore product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product. | —Not applicableCDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
|---|
| BSI C5 Type 2 | No indicado | ⚠️Vendor claimedCurrent Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
|---|
| PCI DSS Level 1 | No indicado | ⚠️Vendor claimedVendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
|---|
| IDW PS 951 Type 2 (ISAE 3402) | No indicado | ⚠️Vendor claimedVendor claim of Type 2 over a twelve-month period. Report not published. |
|---|
| KRITIS operator (BSIG section 8a(3)) | No indicado | ⚠️Vendor claimedVendor certifications page. Confirm current attestation in procurement. |
|---|