bunny.net vs KeyCDN

Vergelijk bunny.net en KeyCDN op mogelijkheden, rechtsgebied, waarborgen en geschiktheid voor Europese kopers.

Beide vermeld als alternatief voor: Cloudflare

Logo: bunny.net

bunny.net

Slovenia· Web Hosting and Cloud Computing

Needs review

Shortlist bunny.net when you want a Slovenian-operated CDN plus storage and Stream, with an official EU pull-zone routing filter and prepaid pay-as-you-go billing. Skip it when you need Cloudflare Workers or Zero Trust as the control plane, or when account data must stay off US-group SaaS (Slack, OpenAI, SendGrid, Mixpanel, Salesforce, Braintree). Consider Cloudflare if the platform surface matters more than EU HQ.

EU-operated (Slovenia)Pay-as-you-go CDNEU pull-zone routing filterMulti-region edge storageManaged video (Stream)ISO 27001 (claimed)
Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
bunny.net vs KeyCDN: Overzicht
KenmerkLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Land van herkomstSloveniaSwitzerland
CategorieWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNeeNee
Self-hostedNeeNee
HoofdkantoorSloveniaSwitzerland
Juridische entiteitBunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Sloveniaproinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, Switzerland
VS-moeder / zeggenschapGeen bekende VS-moederGeen bekende VS-moeder
CLOUD Act-blootstelling (indicatief)MiddelMiddel
Hosting / residentieOperator-advertised global PoPs (Standard 119, Volume 10) and 15 storage regions, including EU (London, Stockholm, Frankfurt, Madrid, Prague) and US (New York, Miami, Los Angeles, Seattle). EU Routing Filter can pin CDN pull-zone traffic to 24 EU PoPs. DNS stays global. Account path uses Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree. Privacy page claims EU residency for BigQuery, dbt Cloud, Lemlist, Loqate, and Kickscale.Company-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.
Samenvatting

Slovenian edge platform from BunnyWay d.o.o.: pay-as-you-go CDN, multi-region object storage, video streaming, and Shield WAF on an operator-run global PoP network.

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Tags
In één oogopslag: bunny.net vs KeyCDN
In één oogopslagLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
HQLjubljana, SloveniaErmatingen, Switzerland
Legal entityBunnyWay d.o.o.proinity LLC (d/b/a KeyCDN)
Product familyCDN, Storage, Stream, Shield, DNS, Optimizer, edge computeNiet vermeld
Hosting modelHosted operator PoPs (not self-hosted)Niet vermeld
Commercial modelPrepaid pay-as-you-go, trial without credit cardPrepaid credits, 14-day trial, no contract
Open sourceNo public core license foundNiet vermeld
Governing lawNiet vermeldSwitzerland; courts of Schwyz
NetworkNiet vermeld60+ PoPs in 40+ countries (vendor network page)
Push storageNiet vermeldEuropean data centers (vendor storage page)
Self-hostedNiet vermeldNo (WordPress helper plugins are on GitHub)
Key capabilities: bunny.net vs KeyCDN
Key capabilitiesLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
EU-operated (Slovenia)JaNiet vermeld
Pay-as-you-go CDNJaJa
EU pull-zone routing filterJaNiet vermeld
Multi-region edge storageJaNiet vermeld
Managed video (Stream)JaNiet vermeld
ISO 27001 (claimed)JaNiet vermeld
Swiss-operatedNiet vermeldJa
Pull and Push ZonesNiet vermeldJa
Origin ShieldNiet vermeldJa
REST API purgeNiet vermeldJa
EU Push storageNiet vermeldJa

bunny.net

  • Pull-zone CDN with Perma-Cache

    Create a pull zone, attach an origin, and cache on the vendor-stated Standard network (119 PoPs) or the smaller Volume network (10 PoPs). Perma-Cache can store objects permanently on Edge Storage so the zone aims for a full cache hit ratio. Let's Encrypt, instant purge, Edge Rules, SafeHop origin retries, and real-time logs are part of the CDN product. Limit: this is a hosted network, not a self-hosted cache you run in your own racks.

  • EU Routing Filter for pull zones

    Docs describe a Pricing and Routing toggle that sends all pull-zone traffic only through PoPs in EU member states (24 locations listed). Users outside the EU are also sent to those EU PoPs, which raises latency. The filter applies to CDN pull-zone traffic, not to the global DNS network. Combine this with EU storage regions if residency is the purchase filter.

  • Multi-region edge object storage

    Bunny Storage is object storage you upload over FTP, SFTP, HTTP API, or the web file manager, then replicate to chosen regions. The Storage page lists 15 regions spanning EU, US, APAC, LATAM, and Africa, with standard HDD and SSD Edge tiers. Traffic from Storage into Bunny CDN is described as free of API request and API egress fees. You pick each replica region. A US replica is optional, not forced, but global CDN delivery can still cache copies at non-EU PoPs unless filtered.

  • Bunny Stream transcoding and player

    Stream accepts uploads (including TUS resumable API), transcodes multiple resolutions, replicates video, and ships a customizable player or raw HLS. Token authentication, hotlink protection, watermarking, and optional Media Cage multi-DRM are documented product features. Encoding and the player are included in the Stream commercial model. If you enable Transcribe AI or related AI features, audio or prompts can be sent to OpenAI in the United States.

  • Signed URL tokens and access controls

    Token authentication blocks pull-zone requests unless a signed token is present. Basic tokens use MD5 with expiry and optional IP checks. Advanced tokens use SHA256 and add geo restrictions, directory tokens, and speed limits. The same security toolbox includes geo-blocking and hotlink protection. Enabling token authentication disables IPv6 on that zone, per the docs.

  • Bunny Shield WAF and DDoS

    Shield is a separate security product in front of the same edge: managed WAF rules, DDoS mitigation, global rate limits, bot controls, access lists, and upload scanning. Basic WAF rules are available on a free Shield tier. Custom rule counts and request allowances rise on paid tiers. It is not a substitute for Cloudflare Zero Trust or a full SOC platform.

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Assurance & compliance: bunny.net vs KeyCDN
Assurance & complianceLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Independent security / no-logs audit
Not found

Vendor mentions continuous penetration testing in the ISO blog. No public independent no-logs or infrastructure audit PDF was found.

Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

ISO 27001
Vendor claimed

September 2024 blog claims certification and links a UKAS cert-check URL. The registry page is JavaScript-only, so this draft does not mark verified. Trust Center also lists an ISO 27001 certificate. Human should open the live UKAS entry and confirm scope and expiry.

Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

SOC 2 / SOC 3
Not found

Trust Center text about reviewing vendor SOC 2 reports refers to BunnyWay's suppliers, not a BunnyWay SOC 2. No BunnyWay SOC 2/3 report found.

Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

GDPR / EU data protection
Vendor claimed

EU entity; public GDPR page; processor role; log anonymisation claims; DPA in dashboard. Global PoPs and US subprocessors remain material.

Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

US CLOUD Act exposure (indicative)
Partial

EU entity and no known US parent. Exposure is medium because default CDN/storage maps include US regions and because Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, and Braintree sit on the account or feature path. Not legal advice.

Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor says the DPA is in the customer panel. Trust Center lists a DPA document. Retrieve and review the signed version rather than relying on the marketing page.

Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

EU AI Act
Not applicable

Core product is CDN, storage, and streaming. Optional OpenAI-backed transcription, chatbot, and image generation exist as features, not as the primary product.

Not applicable

CDN / image transforms, not an AI system product.

Considerations & known limitations: bunny.net vs KeyCDN
Considerations & known limitationsLogo: bunny.netbunny.netLogo: KeyCDNKeyCDN
Default routing is global, including US and Moscow PoPs
Medium

Without the EU Routing Filter, cached objects can sit at non-EU PoPs listed on the CDN map, including US cities and Moscow. The filter covers pull-zone traffic only and hurts latency for non-EU users.

Niet vermeld
US-group account and feature subprocessors
Medium

Support, mail, CRM, payments, product analytics, and optional AI features use Slack, OpenAI, MailChannels, SendGrid, Mixpanel, Salesforce, Braintree, and others. EU HQ does not isolate account data from those vendors.

Niet vermeld
ISO 27001 not independently opened in this draft
Low

The company publishes a UKAS link and a Trust Center certificate. This agent draft could not read the JavaScript registry page, so the checklist stays at claimed until a human confirms scope and dates.

Niet vermeld
Optional OpenAI path for Stream and support
Medium

Transcription, Fluffee/support chat, and CDN AI image generation send data to OpenAI in the United States. Disable those features for workloads that cannot use a US AI processor.

Niet vermeld
Narrower platform than Cloudflare
Low

Shield and Edge Scripting exist, but this is still primarily a delivery, storage, and video stack. Do not expect feature parity with Cloudflare Workers or Zero Trust.

Niet vermeld
US cache copies and US Origin ShieldNiet vermeld
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

No current named subprocessor listNiet vermeld
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

No public operator ISO 27001 or SOC 2Niet vermeld
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Privacy Policy last updated 2018Niet vermeld
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Push Zone required above 100 MBNiet vermeld
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Geschiktheid

bunny.net

Best fit when

  • EU-headquartered teams that need a pull-zone CDN and can enable the EU Routing Filter when residency matters
  • Sites and APIs that want prepaid bandwidth billing without per-request CDN fees
  • Software, game, or firmware delivery that benefits from Perma-Cache and multi-region storage (see NZXT, System76, Nexus Mods case studies)
  • VOD or event video that can use Stream transcoding and the bundled player, without sending audio to OpenAI
  • Teams that want token-authenticated downloads, geo-blocking, and a separate Shield WAF on the same account

Poor fit when

  • Architectures built around Cloudflare Workers, Zero Trust, or Cloudflare as the primary application platform
  • Workloads with a hard ban on US-group subprocessors for billing, support, mail, or analytics
  • Buyers who need a self-hosted or open-source CDN they can run in their own data centers
  • Global audiences that must stay on the nearest PoP while also forbidding any non-EU cache (the EU filter trades latency for residency)
  • Regulated video that requires on-platform transcription without a US AI subprocessor

Consider instead when

  • When: You need Workers, Zero Trust, or a single US-scale security and compute control plane

    Consider: Cloudflare

    Cloudflare is US-headquartered. The tradeoff is platform breadth, not EU ownership.

  • When: Origin already lives on AWS and you need IAM, PrivateLink, or CloudFront contracts

    Consider: Amazon CloudFront (with S3 or Media Services)

    Bunny is faster to start for a standalone CDN plus Stream. It will not replace AWS account controls.

  • When: You want a European CDN peer that is not Cloudflare and bunny.net's US PoPs or US SaaS tools are disqualifying

    Consider: KeyCDN or Myra Security (not yet in this catalog)

    Re-check those vendors on their own legal and subprocessor pages. Do not assume they are cleaner.

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Open questions for due diligence

bunny.net

  • Is the UKAS ISO 27001 entry still current, and what is the certified scope (which products and locations)?
  • Does the in-dashboard DPA include SCCs and a current annex that matches the public sub-processor list plus the longer privacy-policy vendor list?
  • Which products besides CDN pull zones honor an EU-only data path (Stream libraries, Shield logs, Optimizer, Edge Scripting)?
  • Can Mixpanel, Salesforce, SendGrid, or Slack be contractually excluded for a given account?
  • What is the legal relationship between BunnyWay d.o.o. and the UK and German hiring entities?
  • Is the Moscow PoP still active, and can it be excluded without the full EU filter?

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?