KeyCDN vs Leaseweb CDN

Confronta KeyCDN e Leaseweb CDN su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.

Entrambi elencati come alternative a: Cloudflare

Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
Logo: Leaseweb CDN

Leaseweb CDN

Netherlands· Web Hosting and Cloud Computing

Needs review

Shortlist when you want a Dutch (or other local Leaseweb) B2B contract that fronts four partner CDNs with NS1 Pulsar steering and included Amsterdam or Washington, D.C. origin shields. Skip when you need EU-only processors, named partner inventory up front, Cloudflare-class WAF or Workers, or signed URLs without a shield hop. Consider Cloudflare for a single global edge platform, or OVHcloud if you want a French-operated CDN attached to EU datacentres.

Dutch sales entityMulti-CDN (4 partners)Origin shield (AMS + WDC)Portal + REST APIISO 27001 (company, claimed)
KeyCDN vs Leaseweb CDN: Sintesi
CaratteristicaLogo: KeyCDNKeyCDNLogo: Leaseweb CDNLeaseweb CDN
Paese di origineSwitzerlandNetherlands
CategoriaWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNoNo
Self-hostedNoNo
SedeSwitzerlandNetherlands
Soggetto giuridicoproinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, SwitzerlandLeaseweb Netherlands B.V. (KvK 30141839, Amsterdam). Website: Leaseweb Global B.V. (KvK 60593652). Other local sales entities exist.
Capogruppo / controllo USANessuna capogruppo USA notaNessuna capogruppo USA nota
Esposizione CLOUD Act (indicativa)MedioMedio
Hosting / residenzaCompany-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.Delivery is a mix of four unnamed third-party CDNs (global PoPs). Leaseweb origin shields in Amsterdam and Washington, D.C. Request steering via NS1 Pulsar. Origins may be customer HTTP hosts or S3-compatible buckets (including AWS). Raw logs (including client IP) collected from partners and optionally written to customer S3. No public CDN subprocessor list naming the four partners.
Riassunto

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Dutch Multi-CDN that steers traffic across four partner networks with NS1 Pulsar, plus included origin shields in Amsterdam and Washington, D.C. Sold under local Leaseweb sales entities.

Tag
A colpo d'occhio: KeyCDN vs Leaseweb CDN
A colpo d'occhioLogo: KeyCDNKeyCDNLogo: Leaseweb CDNLeaseweb CDN
HQErmatingen, SwitzerlandAmsterdam, Netherlands
Legal entityproinity LLC (d/b/a KeyCDN)Non indicato
Governing lawSwitzerland; courts of SchwyzNon indicato
Network60+ PoPs in 40+ countries (vendor network page)Non indicato
Push storageEuropean data centers (vendor storage page)Non indicato
Commercial modelPrepaid credits, 14-day trial, no contractB2B traffic tiers, annual commitment
Self-hostedNo (WordPress helper plugins are on GitHub)Non indicato
Website operatorNon indicatoLeaseweb Global B.V. (KvK 60593652)
Typical NL contractNon indicatoLeaseweb Netherlands B.V. (KvK 30141839)
FoundedNon indicato1997 (vendor, 2023 press)
Product typeNon indicatoManaged Multi-CDN (not self-hosted, not open source)
EdgeNon indicatoFour unnamed partner CDNs, 400+ PoPs (vendor claim)
Shield locationsNon indicatoAmsterdam and Washington, D.C.
SteeringNon indicatoNS1 Pulsar (Volume: cost; Premium: QoE)
Key capabilities: KeyCDN vs Leaseweb CDN
Key capabilitiesLogo: KeyCDNKeyCDNLogo: Leaseweb CDNLeaseweb CDN
Swiss-operatedNon indicato
Pay-as-you-go CDNNon indicato
Pull and Push ZonesNon indicato
Origin Shield
REST API purgeNon indicato
EU Push storageNon indicato
Dutch sales entityNon indicato
Multi-CDN (4 partners)Non indicato
Portal + REST APINon indicato
ISO 27001 (company, claimed)Non indicato

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Leaseweb CDN

  • Four-provider Multi-CDN (400+ PoPs claimed)

    Leaseweb sells a managed mix of four unnamed third-party CDNs and claims more than 400 points of presence. One distribution CNAME (examples in docs: di-xxxx.leasewebultracdn.com, *.pr.lswcdn.net, *.vo.lswcdn.net) fronts the mix. Features are limited to the common subset all four support. You cannot pin a user to a specific PoP.

  • NS1 Pulsar Volume and Premium steering

    Leaseweb says it connects partner performance to NS1 Pulsar real-user metrics. Volume tier chooses the most cost-effective partner at similar latency. Premium tier chooses on latency and quality of experience. Regional DNS logic can still send a whole region to a single partner when that path is faster.

  • Origin shields in Amsterdam and Washington, D.C.

    Shield CDN distributions add a Leaseweb cache layer so partner edges do not all hit origin. Marketing states shields are included on Volume and Premium and sit in Amsterdam and Washington, D.C. Shields support multiple path policies, origin groups (up to 10 hosts, round-robin, consistent, sticky, or failover), and tokenized URLs. Wildcard invalidation is not supported on shields. A Multi-CDN invalidation does not clear the shield automatically.

  • HTTP, S3, and object-storage origins

    Simple origins take a hostname or IP. AWS Signature Version 4 can authenticate S3-compatible buckets (Leaseweb Object Storage or AWS). Advanced origins (custom ports, subdirectory) work only behind shields and do not support Sig V4. Authenticated object storage cannot join an origin group. Each origin is HTTP or HTTPS exclusively, not mixed.

  • Portal, REST API, and raw logs to S3

    Distributions, origins, certificates, and invalidations are managed in the Leaseweb Customer Portal (CDN menu, active contract required) or via the documented REST API on developer.leaseweb.com. Raw logs from all partners can be normalized to JSON and uploaded as .gz files to a customer S3 bucket. Leaseweb states logs are informational only and may be delayed or incomplete versus billing records.

  • Cache templates and edge ACLs

    Web, live, and VoD templates set methods, TTL, compression, and stale-serve defaults. Operators can force CDN-controlled or origin-controlled cache, passthrough or static headers, geo blocking, IP-subnet blocking, and referrer allowlists. HTTP/2 is default on all partners. Gzip delivery compression applies only to files up to 20 MB. CORS Access-Control-Allow-Origin is stripped unless you passthrough or set it.

Assurance & compliance: KeyCDN vs Leaseweb CDN
Assurance & complianceLogo: KeyCDNKeyCDNLogo: Leaseweb CDNLeaseweb CDN
Independent security / no-logs audit
Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

Not found

Multi-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found.

ISO 27001
Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

Vendor claimed

ISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope.

SOC 2 / SOC 3
Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

Partial

SOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN.

GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

Vendor claimed

EU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed.

US CLOUD Act exposure (indicative)
Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Partial

Dutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

Vendor claimed

Vendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled.

EU AI Act
Not applicable

CDN / image transforms, not an AI system product.

Not applicable

Content delivery and traffic steering product, not an AI system offering.

PCI DSSNon indicato
Partial

Vendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control.

CISPE IaaS Code of ConductNon indicato
Vendor claimed

Company says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register.

Considerations & known limitations: KeyCDN vs Leaseweb CDN
Considerations & known limitationsLogo: KeyCDNKeyCDNLogo: Leaseweb CDNLeaseweb CDN
US cache copies and US Origin Shield
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

Non indicato
No current named subprocessor list
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

Non indicato
No public operator ISO 27001 or SOC 2
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Non indicato
Privacy Policy last updated 2018
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Non indicato
Push Zone required above 100 MB
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Non indicato
Unnamed partner CDNs and NS1 in the data pathNon indicato
High

Delivery and RUM leave Leaseweb facilities. The four partners are not named on public product or legal pages. NS1 Pulsar steers requests. Treat as a multi-processor design until sales produces a current list and DPA schedule.

Washington, D.C. origin shieldNon indicato
Medium

Included shields are in Amsterdam and Washington, D.C. Enabling a shield can place origin-pull traffic in the United States even when the sales entity is Dutch. Live streaming docs also advise against shields for latency reasons.

ISO / SOC reports do not list CDNNon indicato
Medium

Published ISO 27001 and SOC 1 service lists omit CDN. SOC 2 is Canada colocation only. Do not assume Multi-CDN inherits those reports without a scoped letter.

Features limited to partner intersectionNon indicato
Medium

No Multi-CDN URL tokens, no PoP pin, Gzip-only compression with a 20 MB cap, no MPEG-DASH Gzip, mixed origin HTTP/HTTPS unsupported, invalidation rate-limited. SSL and stats propagate on partner clocks.

Raw logs not billed as completeNon indicato
Low

Partner logs shipped to S3 are informational. Leaseweb states they may be late or missing versus invoice counters. Do not use them as a legal completeness record.

Idoneità

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Leaseweb CDN

Best fit when

  • Teams already on Leaseweb dedicated servers, object storage, or private cloud who want delivery on the same invoice
  • Media, ads, SaaS, or gaming publishers who want multi-CDN failover without four vendor contracts
  • Origins that can sit behind an Amsterdam or Washington, D.C. shield and pull over HTTP or HTTPS (or S3 with Sig V4)
  • Operators who will live with partner-subset features (HTTP/2, geo/IP/referrer ACLs, portal and REST API) rather than Workers-style compute
  • Buyers who can accept Volume (cost) versus Premium (QoE) steering instead of pinning a single CDN

Poor fit when

  • Organizations that require an EU-only edge with a public, named subprocessor list (partners are unnamed; WDC shield and NS1 are in path)
  • Sites that need signed URLs, a WAF, bot management, or edge functions on the same product
  • Teams that must purge thousands of URLs per minute or treat invalidation as the publish pipeline
  • Buyers who want a self-serve free tier or an open-source, self-hosted CDN
  • Workloads that need MPEG-DASH Gzip, mixed HTTP and HTTPS to one origin, or per-user PoP selection

Consider instead when

  • When: You need a single global edge with WAF, bot management, Workers, and a self-serve free tier

    Consider: Cloudflare

    US company. Broader edge platform. Different jurisdiction story.

  • When: You want CDN plus compute from one European infrastructure group and can diligence that group's own PoPs

    Consider: OVHcloud

    French operator. Own datacentres. Not a four-provider multi-CDN.

  • When: You mainly need EU origin compute and will add a CDN you can inventory yourself

    Consider: Hetzner or Scaleway

    Neither replaces Multi-CDN. They keep origin in EU facilities you can name.

  • When: You wanted Swiss-branded hosting with optional Cloudflare, not a multi-CDN fabric

    Consider: Swissnode

    Different product class. Optional Cloudflare on web plans.

Open questions for due diligence

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?

Leaseweb CDN

  • What are the current four partner CDN legal names, and can they be listed in the DPA?
  • Can routing be constrained to EU (or named) partners and the Amsterdam shield only?
  • Is Multi-CDN in the current ISO 27001 statement of applicability?
  • Will Leaseweb sign a standalone DPA that covers NS1 Pulsar and each partner?
  • What is the current annual-commitment commercial offer (confirm on the official Multi-CDN page or with sales)?