bunny.net vs KeyCDN

Confronta bunny.net e KeyCDN su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.

Entrambi elencati come alternative a: Cloudflare

Logo: bunny.net

bunny.net

Slovenia· Web Hosting and Cloud Computing

Needs review

Shortlist bunny.net when you want a Slovenian-operated CDN plus storage and Stream, with an official EU pull-zone routing filter and prepaid pay-as-you-go billing. Skip it when you need Cloudflare Workers or Zero Trust as the control plane, or when account data must stay off US-group SaaS (Slack, OpenAI, SendGrid, Mixpanel, Salesforce, Braintree). Consider Cloudflare if the platform surface matters more than EU HQ.

EU-operated (Slovenia)Pay-as-you-go CDNEU pull-zone routing filterMulti-region edge storageManaged video (Stream)ISO 27001 (claimed)
Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
bunny.net vs KeyCDN: Sintesi
CaratteristicaLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Paese di origineSloveniaSwitzerland
CategoriaWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
SedeSloveniaSwitzerland
Soggetto giuridicoBunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Sloveniaproinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, Switzerland
Capogruppo / controllo USANessuna capogruppo USA notaNessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)MedioMedio
Hosting / residenzaOperator-advertised global PoPs (Standard 119, Volume 10) and 15 storage regions, including EU (London, Stockholm, Frankfurt, Madrid, Prague) and US (New York, Miami, Los Angeles, Seattle). EU Routing Filter can pin CDN pull-zone traffic to 24 EU PoPs. DNS stays global. Account path uses Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree. Privacy page claims EU residency for BigQuery, dbt Cloud, Lemlist, Loqate, and Kickscale.Company-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.
Riassunto

Slovenian edge platform from BunnyWay d.o.o.: pay-as-you-go CDN, multi-region object storage, video streaming, and Shield WAF on an operator-run global PoP network.

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Tag
A colpo d'occhio: bunny.net vs KeyCDN
A colpo d'occhioLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
HQLjubljana, SloveniaErmatingen, Switzerland
Legal entityBunnyWay d.o.o.proinity LLC (d/b/a KeyCDN)
Product familyCDN, Storage, Stream, Shield, DNS, Optimizer, edge computeNon indicato
Hosting modelHosted operator PoPs (not self-hosted)Non indicato
Commercial modelPrepaid pay-as-you-go, trial without credit cardPrepaid credits, 14-day trial, no contract
Open sourceNo public core license foundNon indicato
Governing lawNon indicatoSwitzerland; courts of Schwyz
NetworkNon indicato60+ PoPs in 40+ countries (vendor network page)
Push storageNon indicatoEuropean data centers (vendor storage page)
Self-hostedNon indicatoNo (WordPress helper plugins are on GitHub)
Key capabilities: bunny.net vs KeyCDN
Key capabilitiesLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
EU-operated (Slovenia)Non indicato
Pay-as-you-go CDN
EU pull-zone routing filterNon indicato
Multi-region edge storageNon indicato
Managed video (Stream)Non indicato
ISO 27001 (claimed)Non indicato
Swiss-operatedNon indicato
Pull and Push ZonesNon indicato
Origin ShieldNon indicato
REST API purgeNon indicato
EU Push storageNon indicato

bunny.net

  • Pull-zone CDN with Perma-Cache

    Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.

  • EU Routing Filter for pull zones

    Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.

  • Multi-region edge object storage

    Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.

  • Bunny Stream transcoding and player

    Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.

  • Signed URL tokens and access controls

    Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.

  • Bunny Shield WAF and DDoS

    Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Assurance & compliance: bunny.net vs KeyCDN
Assurance & complianceLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Independent security / no-logs audit
Not found

Vendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found.

Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

ISO 27001
Vendor claimed

September 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry.

Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

SOC 2 / SOC 3
Not found

Trust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found.

Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

GDPR / EU data protection
Vendor claimed

EU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material.

Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice.

Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page.

Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

EU AI Act
Not applicable

Core product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product.

Not applicable

CDN / image transforms, not an AI system product.

Considerations & known limitations: bunny.net vs KeyCDN
Considerations & known limitationsLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Default routing is global, including US and Moscow PoPs
Medium

Without the EU Routing Filter, cached objects can sit at non-EU PoPs listed on the CDN map, including US cities and Moscow. The filter covers pull-zone traffic only and hurts latency for non-EU users.

Non indicato
US-group account and feature subprocessors
Medium

Support, mail, CRM, payments, product analytics, and optional AI features use Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, Braintree, and others. EU HQ does not isolate account data from those vendors.

Non indicato
ISO 27001 not independently opened in this draft
Low

The company publishes a UKAS link and a Trust Center certificate. This agent draft could not read the JavaScript registry page, so the checklist stays at claimed until a human confirms scope and dates.

Non indicato
Optional OpenAI path for Stream and support
Medium

Transcription, Fluffee/support chat, and CDN AI image generation send data to OpenAI in the United States. Disable those features for workloads that cannot use a US AI processor.

Non indicato
Narrower platform than Cloudflare
Low

Shield and Edge Scripting exist, but this is still primarily a delivery, storage, and video stack. Do not expect feature parity with Cloudflare Workers or Zero Trust.

Non indicato
US cache copies and US Origin ShieldNon indicato
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

No current named subprocessor listNon indicato
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

No public operator ISO 27001 or SOC 2Non indicato
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Privacy Policy last updated 2018Non indicato
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Push Zone required above 100 MBNon indicato
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Idoneità

bunny.net

Best fit when

  • EU-headquartered teams that need a pull-zone CDN and can enable the EU Routing Filter when residency matters
  • Sites and APIs that want prepaid bandwidth billing without per-request CDN fees
  • Software, game, or firmware delivery that benefits from Perma-Cache and multi-region storage (see NZXT, System76, Nexus Mods case studies)
  • VOD or event video that can use Stream transcoding and the bundled player, without sending audio to OpenAI
  • Teams that want token-authenticated downloads, geo-blocking, and a separate Shield WAF on the same account

Poor fit when

  • Architectures built around Cloudflare Workers, Zero Trust, or Cloudflare as the primary application platform
  • Workloads with a hard ban on US-group subprocessors for billing, support, mail, or analytics
  • Buyers who need a self-hosted or open-source CDN they can run in their own data centers
  • Global audiences that must stay on the nearest PoP while also forbidding any non-EU cache (the EU filter trades latency for residency)
  • Regulated video that requires on-platform transcription without a US AI subprocessor

Consider instead when

  • When: You need Workers, Zero Trust, or a single US-scale security and compute control plane

    Consider: Cloudflare

    Cloudflare is US-headquartered. The tradeoff is platform breadth, not EU ownership.

  • When: Origin already lives on AWS and you need IAM, PrivateLink, or CloudFront contracts

    Consider: Amazon CloudFront (with S3 or Media Services)

    Bunny is faster to start for a standalone CDN plus Stream. It will not replace AWS account controls.

  • When: You want a European CDN peer that is not Cloudflare and bunny.net's US PoPs or US SaaS tools are disqualifying

    Consider: KeyCDN or Myra Security (not yet in this catalog)

    Re-check those vendors on their own legal and subprocessor pages. Do not assume they are cleaner.

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Open questions for due diligence

bunny.net

  • Is the UKAS ISO 27001 entry still current, and what is the certified scope (which products and locations)?
  • Does the in-dashboard DPA include SCCs and a current annex that matches the public sub-processor list plus the longer privacy-policy vendor list?
  • Which products besides CDN pull zones honor an EU-only data path (Stream libraries, Shield logs, Optimizer, Edge Scripting)?
  • Can Mixpanel, Salesforce, SendGrid, or Slack be contractually excluded for a given account?
  • What is the legal relationship between BunnyWay d.o.o. and the UK and German hiring entities?
  • Is the Moscow PoP still active, and can it be excluded without the full EU filter?

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?