| Independent security / no-logs audit | ❌Not foundNo public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field. | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. |
|---|
| ISO 27001 | ❌Not foundNetwork page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC. | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. |
|---|
| SOC 2 / SOC 3 | ❌Not foundSearched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found. | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedSwiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties. | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialSwiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice. | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedGDPR page: open a support request to receive the DPA when Article 28 processing applies. | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. |
|---|
| EU AI Act | —Not applicableCDN / image transforms, not an AI system product. | —Not applicableContent delivery and traffic steering product, not an AI system offering. |
|---|
| PCI DSS | Non indicato | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. |
|---|
| CISPE IaaS Code of Conduct | Non indicato | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. |
|---|