Hetzner vs Myra CDN

Confronta Hetzner e Myra CDN su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.

Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Logo: Myra CDN

Myra CDN

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)
Hetzner vs Myra CDN: Sintesi
CaratteristicaLogo: HetznerHetznerLogo: Myra CDNMyra CDN
Paese di origineGermanyGermany
CategoriaCloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
SedeGermanyGermany
Soggetto giuridicoHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)Myra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428
Capogruppo / controllo USANessuna capogruppo USA notaNessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)MedioBasso
Hosting / residenzaOwned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).
Riassunto

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

Tag
A colpo d'occhio: Hetzner vs Myra CDN
A colpo d'occhioLogo: HetznerHetznerLogo: Myra CDNMyra CDN
HQGunzenhausen, GermanyMunich, Germany (Landsberger Str. 187)
Legal entityHetzner Online GmbH (HRB 6089 Ansbach)Myra Security GmbH, HRB 202428
EU parksNuremberg, Falkenstein (DE); Helsinki (FI)Non indicato
Optional cloud regionsAshburn and Hillsboro (US); SingaporeNon indicato
ModelIaaS / dedicated / hosting (unmanaged cloud and root)Non indicato
Open sourceNo (commercial infrastructure)Non indicato
FoundedNon indicato2012 (vendor about/contact pages)
Product typeNon indicatoSaaS Anycast CDN + Security-as-a-Service (not self-hosted)
OnboardingNon indicatoDNS cutover + TLS upload; APIv2 at apiv2.myracloud.com
Commercial modelNon indicatoB2B subscription or quote (monthly/annual prepay); no consumer terms
ISO 27001Non indicatoBSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17
Key capabilities: Hetzner vs Myra CDN
Key capabilitiesLogo: HetznerHetznerLogo: Myra CDNMyra CDN
EU-operated (DE HQ)
Owned DE/FI parksNon indicato
ISO 27001:2022Non indicato
BSI C5 Type 2
Bare metal + auctionNon indicato
Optional US/SG cloudNon indicato
ISO 27001 IT-Grundschutz (BSI, verified)Non indicato
Anycast CDN + Layer 7 DDoSNon indicato
Germany TLS termination (on request)Non indicato
PCI DSS Level 1 (claimed)Non indicato

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

Myra CDN

  • Anycast CDN with RAM cache and HTTP/2

    Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

  • Optional mTLS and signed URLs at the edge

    Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

  • Layer 7 DDoS on the same reverse proxy

    Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

  • WAF, bot management, and EU CAPTCHA add-ons

    The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

  • Germany-only TLS termination on request

    Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

  • REST APIv2, Myra App, and DNS cutover

    Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

Assurance & compliance: Hetzner vs Myra CDN
Assurance & complianceLogo: HetznerHetznerLogo: Myra CDNMyra CDN
Independent security / no-logs audit
Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

Partial

Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports.

ISO 27001
Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

Verified

BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP.

SOC 2 / SOC 3
Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

Not found

No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed).

GDPR / EU data protection
Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

Vendor claimed

German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Partial

EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702.

Data processing agreement (B2B)
Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

Not found

No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV.

EU AI Act
Not applicable

Infrastructure hosting, not an AI system product.

Not applicable

CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page.

BSI C5 (cloud)
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

Vendor claimed

Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found.

KRITIS / section 8a BSIG
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Non indicato
PCI DSS Level 1Non indicato
Vendor claimed

Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass.

IDW PS 951 Type 2 (ISAE 3402)Non indicato
Vendor claimed

Vendor claim of Type 2 over a twelve-month period. Report not published.

KRITIS operator (BSIG section 8a(3))Non indicato
Vendor claimed

Vendor certifications page. Confirm current attestation in procurement.

Considerations & known limitations: Hetzner vs Myra CDN
Considerations & known limitationsLogo: HetznerHetznerLogo: Myra CDNMyra CDN
Optional US and Singapore cloud regions
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Non indicato
Unmanaged cloud and dedicated servers
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Non indicato
Narrower managed-service catalog vs hyperscalers
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

Non indicato
ISO scope is DE/FI parks
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Non indicato
Global PoPs unless Germany-only is contractedNon indicato
Medium

Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

Outsourced DCs and no public subprocessor listNon indicato
Medium

BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

ISO 27001 scope is DDoS-Schutz, not every SKUNon indicato
Low

The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

Smaller public footprint than CloudflareNon indicato
Medium

No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

Corporate website uses US processorsNon indicato
Low

Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Idoneità

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

Myra CDN

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

Open questions for due diligence

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?

Myra CDN

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?