IONOS
Germany· Cloud Computing
Vergelijk IONOS en Myra CDN op mogelijkheden, rechtsgebied, waarborgen en geschiktheid voor Europese kopers.
Germany· Cloud Computing
Germany· Web Hosting and Cloud Computing
Needs review
Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.
Gemarkeerde rijen verschillen tussen de twee producten.
| Kenmerk | ||
|---|---|---|
| Land van herkomst | ||
| Categorie | Cloud Computing | Web Hosting and Cloud Computing |
| Open source | Nee | Nee |
| Self-hosted | Nee | Nee |
| Hoofdkantoor | Niet vermeld | Germany |
| Juridische entiteit | Niet vermeld | Myra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428 |
| VS-moeder / zeggenschap | Niet vermeld | Geen bekende VS-moeder |
| CLOUD Act-blootstelling (indicatief) | Niet vermeld | Laag |
| Hosting / residentie | Niet vermeld | Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others). |
| Samenvatting | German hosting and cloud provider (IONOS SE): domains and SMB web hosting plus IONOS Cloud IaaS/PaaS with EU and US locations, managed Kubernetes, object storage, and DBaaS. | Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination. |
| Tags |
| In één oogopslag | ||
|---|---|---|
| HQ | Niet vermeld | Munich, Germany (Landsberger Str. 187) |
| Legal entity | Niet vermeld | Myra Security GmbH, HRB 202428 |
| Founded | Niet vermeld | 2012 (vendor about/contact pages) |
| Product type | Niet vermeld | SaaS Anycast CDN + Security-as-a-Service (not self-hosted) |
| Onboarding | Niet vermeld | DNS cutover + TLS upload; APIv2 at apiv2.myracloud.com |
| Commercial model | Niet vermeld | B2B subscription or quote (monthly/annual prepay); no consumer terms |
| ISO 27001 | Niet vermeld | BSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17 |
| Key capabilities | ||
|---|---|---|
| EU-operated (Munich GmbH) | Niet vermeld | Ja |
| ISO 27001 IT-Grundschutz (BSI, verified) | Niet vermeld | Ja |
| BSI C5 Type 2 (claimed) | Niet vermeld | Ja |
| Anycast CDN + Layer 7 DDoS | Niet vermeld | Ja |
| Germany TLS termination (on request) | Niet vermeld | Ja |
| PCI DSS Level 1 (claimed) | Niet vermeld | Ja |
Diverse Hosting and Domain Services
IONOS provides shared, VPS, dedicated, and cloud hosting options scalable for any need. It registers over 22 million domains and includes a free domain for the first year on many plans. Website builders incorporate AI for quick setups, while eCommerce tools handle online stores. Email integrates with Microsoft 365 or Google Workspace, ensuring reliable communication without third-party dependencies.
Advanced Cloud Infrastructure
The platform offers managed Kubernetes clusters, databases like MongoDB and PostgreSQL, object storage, GPU servers, and an AI Model Hub for machine learning workloads. Data centers achieve Tier IV certification for redundancy. Customers access 99.99% uptime, with options for high-performance computing suited to enterprises running complex applications.
Security, Support, and Sustainability
DDoS protection safeguards sites, complemented by free SSL certificates. Support runs 24/7 via phone, chat, and email, with personal consultants assigned to accounts. All data centers use 100% renewable energy, aligning with IONOS's 2030 Climate Strategy that targets emission cuts through biofuels and supplier partnerships.
Anycast CDN with RAM cache and HTTP/2
Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.
Optional mTLS and signed URLs at the edge
Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.
Layer 7 DDoS on the same reverse proxy
Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.
WAF, bot management, and EU CAPTCHA add-ons
The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.
Germany-only TLS termination on request
Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.
REST APIv2, Myra App, and DNS cutover
Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.
| Assurance & compliance | ||
|---|---|---|
| Independent security / no-logs audit | Niet vermeld | Partial Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports. |
| ISO 27001 (BSI IT-Grundschutz) | Niet vermeld | Verified BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP. |
| SOC 2 / SOC 3 | Niet vermeld | Not found No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed). |
| GDPR / EU data protection | Niet vermeld | Vendor claimed German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract. |
| US CLOUD Act exposure (indicative) | Niet vermeld | Partial EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702. |
| Data processing agreement (B2B) | Niet vermeld | Not found No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV. |
| EU AI Act | Niet vermeld | Not applicable CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page. |
| BSI C5 Type 2 | Niet vermeld | Vendor claimed Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found. |
| PCI DSS Level 1 | Niet vermeld | Vendor claimed Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass. |
| IDW PS 951 Type 2 (ISAE 3402) | Niet vermeld | Vendor claimed Vendor claim of Type 2 over a twelve-month period. Report not published. |
| KRITIS operator (BSIG section 8a(3)) | Niet vermeld | Vendor claimed Vendor certifications page. Confirm current attestation in procurement. |
| Considerations & known limitations | ||
|---|---|---|
| Global PoPs unless Germany-only is contracted | Niet vermeld | Medium Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany. |
| Outsourced DCs and no public subprocessor list | Niet vermeld | Medium BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only. |
| ISO 27001 scope is DDoS-Schutz, not every SKU | Niet vermeld | Low The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products. |
| Smaller public footprint than Cloudflare | Niet vermeld | Medium No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute. |
| Corporate website uses US processors | Niet vermeld | Low Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free. |
Niet vermeld
Niet vermeld
When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN
Consider: Cloudflare
US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.
When: You only need EU origin compute or hosting, not Anycast WAAP
Consider: Hetzner, IONOS, or OVHcloud
These are catalog infrastructure peers, not certified German DDoS/CDN edges.
Niet vermeld