Leaseweb CDN vs Myra CDN

Compare Leaseweb CDN y Myra CDN en capacidades, jurisdicción, garantías y encaje para compradores europeos.

Ambos figuran como alternativas a: Cloudflare

Logo: Leaseweb CDN

Leaseweb CDN

Netherlands· Web Hosting and Cloud Computing

Needs review

Shortlist when you want a Dutch (or other local Leaseweb) B2B contract that fronts four partner CDNs with NS1 Pulsar steering and included Amsterdam or Washington, D.C. origin shields. Skip when you need EU-only processors, named partner inventory up front, Cloudflare-class WAF or Workers, or signed URLs without a shield hop. Consider Cloudflare for a single global edge platform, or OVHcloud if you want a French-operated CDN attached to EU datacentres.

Dutch sales entityMulti-CDN (4 partners)Origin shield (AMS + WDC)Portal + REST APIISO 27001 (company, claimed)
Logo: Myra CDN

Myra CDN

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)
Leaseweb CDN vs Myra CDN: Resumen
CaracterísticaLogo: Leaseweb CDNLeaseweb CDNLogo: Myra CDNMyra CDN
País de origenNetherlandsGermany
CategoríaWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Código abiertoNoNo
AutoalojadoNoNo
SedeNetherlandsGermany
Entidad legalLeaseweb Netherlands B.V. (KvK 30141839, Amsterdam). Website: Leaseweb Global B.V. (KvK 60593652). Other local sales entities exist.Myra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428
Matriz / control EE.UU.Sin matriz estadounidense conocidaSin matriz estadounidense conocida
Exposición CLOUD Act (indicativa)MedioBajo
Alojamiento / residenciaDelivery is a mix of four unnamed third-party CDNs (global PoPs). Leaseweb origin shields in Amsterdam and Washington, D.C. Request steering via NS1 Pulsar. Origins may be customer HTTP hosts or S3-compatible buckets (including AWS). Raw logs (including client IP) collected from partners and optionally written to customer S3. No public CDN subprocessor list naming the four partners.Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).
Resumen

Dutch Multi-CDN that steers traffic across four partner networks with NS1 Pulsar, plus included origin shields in Amsterdam and Washington, D.C. Sold under local Leaseweb sales entities.

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

Etiquetas
De un vistazo: Leaseweb CDN vs Myra CDN
De un vistazoLogo: Leaseweb CDNLeaseweb CDNLogo: Myra CDNMyra CDN
HQAmsterdam, NetherlandsMunich, Germany (Landsberger Str. 187)
Website operatorLeaseweb Global B.V. (KvK 60593652)No indicado
Typical NL contractLeaseweb Netherlands B.V. (KvK 30141839)No indicado
Founded1997 (vendor, 2023 press)2012 (vendor about/contact pages)
Product typeManaged Multi-CDN (not self-hosted, not open source)SaaS Anycast CDN + Security-as-a-Service (not self-hosted)
EdgeFour unnamed partner CDNs, 400+ PoPs (vendor claim)No indicado
Shield locationsAmsterdam and Washington, D.C.No indicado
SteeringNS1 Pulsar (Volume: cost; Premium: QoE)No indicado
Commercial modelB2B traffic tiers, annual commitmentB2B subscription or quote (monthly/annual prepay); no consumer terms
Legal entityNo indicadoMyra Security GmbH, HRB 202428
OnboardingNo indicadoDNS cutover + TLS upload; APIv2 at apiv2.myracloud.com
ISO 27001No indicadoBSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17
Key capabilities: Leaseweb CDN vs Myra CDN
Key capabilitiesLogo: Leaseweb CDNLeaseweb CDNLogo: Myra CDNMyra CDN
Dutch sales entityNo indicado
Multi-CDN (4 partners)No indicado
Origin shield (AMS + WDC)No indicado
Portal + REST APINo indicado
ISO 27001 (company, claimed)No indicado
EU-operated (Munich GmbH)No indicado
ISO 27001 IT-Grundschutz (BSI, verified)No indicado
BSI C5 Type 2 (claimed)No indicado
Anycast CDN + Layer 7 DDoSNo indicado
Germany TLS termination (on request)No indicado
PCI DSS Level 1 (claimed)No indicado

Leaseweb CDN

  • Four-provider Multi-CDN (400+ PoPs claimed)

    Leaseweb sells a managed mix of four unnamed third-party CDNs and claims more than 400 points of presence. One distribution CNAME (examples in docs: di-xxxx.leasewebultracdn.com, *.pr.lswcdn.net, *.vo.lswcdn.net) fronts the mix. Features are limited to the common subset all four support. You cannot pin a user to a specific PoP.

  • NS1 Pulsar Volume and Premium steering

    Leaseweb says it connects partner performance to NS1 Pulsar real-user metrics. Volume tier chooses the most cost-effective partner at similar latency. Premium tier chooses on latency and quality of experience. Regional DNS logic can still send a whole region to a single partner when that path is faster.

  • Origin shields in Amsterdam and Washington, D.C.

    Shield CDN distributions add a Leaseweb cache layer so partner edges do not all hit origin. Marketing states shields are included on Volume and Premium and sit in Amsterdam and Washington, D.C. Shields support multiple path policies, origin groups (up to 10 hosts, round-robin, consistent, sticky, or failover), and tokenized URLs. Wildcard invalidation is not supported on shields. A Multi-CDN invalidation does not clear the shield automatically.

  • HTTP, S3, and object-storage origins

    Simple origins take a hostname or IP. AWS Signature Version 4 can authenticate S3-compatible buckets (Leaseweb Object Storage or AWS). Advanced origins (custom ports, subdirectory) work only behind shields and do not support Sig V4. Authenticated object storage cannot join an origin group. Each origin is HTTP or HTTPS exclusively, not mixed.

  • Portal, REST API, and raw logs to S3

    Distributions, origins, certificates, and invalidations are managed in the Leaseweb Customer Portal (CDN menu, active contract required) or via the documented REST API on developer.leaseweb.com. Raw logs from all partners can be normalized to JSON and uploaded as .gz files to a customer S3 bucket. Leaseweb states logs are informational only and may be delayed or incomplete versus billing records.

  • Cache templates and edge ACLs

    Web, live, and VoD templates set methods, TTL, compression, and stale-serve defaults. Operators can force CDN-controlled or origin-controlled cache, passthrough or static headers, geo blocking, IP-subnet blocking, and referrer allowlists. HTTP/2 is default on all partners. Gzip delivery compression applies only to files up to 20 MB. CORS Access-Control-Allow-Origin is stripped unless you passthrough or set it.

Myra CDN

  • Anycast CDN with RAM cache and HTTP/2

    Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

  • Optional mTLS and signed URLs at the edge

    Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

  • Layer 7 DDoS on the same reverse proxy

    Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

  • WAF, bot management, and EU CAPTCHA add-ons

    The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

  • Germany-only TLS termination on request

    Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

  • REST APIv2, Myra App, and DNS cutover

    Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

Assurance & compliance: Leaseweb CDN vs Myra CDN
Assurance & complianceLogo: Leaseweb CDNLeaseweb CDNLogo: Myra CDNMyra CDN
Independent security / no-logs audit
Not found

Multi-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found.

Partial

Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports.

ISO 27001
Vendor claimed

ISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope.

Verified

BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP.

SOC 2 / SOC 3
Partial

SOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN.

Not found

No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed).

GDPR / EU data protection
Vendor claimed

EU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed.

Vendor claimed

German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract.

US CLOUD Act exposure (indicative)
Partial

Dutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice.

Partial

EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702.

Data processing agreement (B2B)
Vendor claimed

Vendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled.

Not found

No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV.

EU AI Act
Not applicable

Content delivery and traffic steering product, not an AI system offering.

Not applicable

CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page.

PCI DSS
Partial

Vendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control.

Vendor claimed

Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass.

CISPE IaaS Code of Conduct
Vendor claimed

Company says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register.

No indicado
BSI C5 Type 2No indicado
Vendor claimed

Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found.

IDW PS 951 Type 2 (ISAE 3402)No indicado
Vendor claimed

Vendor claim of Type 2 over a twelve-month period. Report not published.

KRITIS operator (BSIG section 8a(3))No indicado
Vendor claimed

Vendor certifications page. Confirm current attestation in procurement.

Considerations & known limitations: Leaseweb CDN vs Myra CDN
Considerations & known limitationsLogo: Leaseweb CDNLeaseweb CDNLogo: Myra CDNMyra CDN
Unnamed partner CDNs and NS1 in the data path
High

Delivery and RUM leave Leaseweb facilities. The four partners are not named on public product or legal pages. NS1 Pulsar steers requests. Treat as a multi-processor design until sales produces a current list and DPA schedule.

No indicado
Washington, D.C. origin shield
Medium

Included shields are in Amsterdam and Washington, D.C. Enabling a shield can place origin-pull traffic in the United States even when the sales entity is Dutch. Live streaming docs also advise against shields for latency reasons.

No indicado
ISO / SOC reports do not list CDN
Medium

Published ISO 27001 and SOC 1 service lists omit CDN. SOC 2 is Canada colocation only. Do not assume Multi-CDN inherits those reports without a scoped letter.

No indicado
Features limited to partner intersection
Medium

No Multi-CDN URL tokens, no PoP pin, Gzip-only compression with a 20 MB cap, no MPEG-DASH Gzip, mixed origin HTTP/HTTPS unsupported, invalidation rate-limited. SSL and stats propagate on partner clocks.

No indicado
Raw logs not billed as complete
Low

Partner logs shipped to S3 are informational. Leaseweb states they may be late or missing versus invoice counters. Do not use them as a legal completeness record.

No indicado
Global PoPs unless Germany-only is contractedNo indicado
Medium

Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

Outsourced DCs and no public subprocessor listNo indicado
Medium

BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

ISO 27001 scope is DDoS-Schutz, not every SKUNo indicado
Low

The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

Smaller public footprint than CloudflareNo indicado
Medium

No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

Corporate website uses US processorsNo indicado
Low

Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Encaje

Leaseweb CDN

Best fit when

  • Teams already on Leaseweb dedicated servers, object storage, or private cloud who want delivery on the same invoice
  • Media, ads, SaaS, or gaming publishers who want multi-CDN failover without four vendor contracts
  • Origins that can sit behind an Amsterdam or Washington, D.C. shield and pull over HTTP or HTTPS (or S3 with Sig V4)
  • Operators who will live with partner-subset features (HTTP/2, geo/IP/referrer ACLs, portal and REST API) rather than Workers-style compute
  • Buyers who can accept Volume (cost) versus Premium (QoE) steering instead of pinning a single CDN

Poor fit when

  • Organizations that require an EU-only edge with a public, named subprocessor list (partners are unnamed; WDC shield and NS1 are in path)
  • Sites that need signed URLs, a WAF, bot management, or edge functions on the same product
  • Teams that must purge thousands of URLs per minute or treat invalidation as the publish pipeline
  • Buyers who want a self-serve free tier or an open-source, self-hosted CDN
  • Workloads that need MPEG-DASH Gzip, mixed HTTP and HTTPS to one origin, or per-user PoP selection

Consider instead when

  • When: You need a single global edge with WAF, bot management, Workers, and a self-serve free tier

    Consider: Cloudflare

    US company. Broader edge platform. Different jurisdiction story.

  • When: You want CDN plus compute from one European infrastructure group and can diligence that group's own PoPs

    Consider: OVHcloud

    French operator. Own datacentres. Not a four-provider multi-CDN.

  • When: You mainly need EU origin compute and will add a CDN you can inventory yourself

    Consider: Hetzner or Scaleway

    Neither replaces Multi-CDN. They keep origin in EU facilities you can name.

  • When: You wanted Swiss-branded hosting with optional Cloudflare, not a multi-CDN fabric

    Consider: Swissnode

    Different product class. Optional Cloudflare on web plans.

Myra CDN

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

Open questions for due diligence

Leaseweb CDN

  • What are the current four partner CDN legal names, and can they be listed in the DPA?
  • Can routing be constrained to EU (or named) partners and the Amsterdam shield only?
  • Is Multi-CDN in the current ISO 27001 statement of applicability?
  • Will Leaseweb sign a standalone DPA that covers NS1 Pulsar and each partner?
  • What is the current annual-commitment commercial offer (confirm on the official Multi-CDN page or with sales)?

Myra CDN

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?