KeyCDN vs Myra CDN

Vergelijk KeyCDN en Myra CDN op mogelijkheden, rechtsgebied, waarborgen en geschiktheid voor Europese kopers.

Beide vermeld als alternatief voor: Cloudflare

Logo: KeyCDN

KeyCDN

Switzerland· Web Hosting and Cloud Computing

Needs review

Shortlist KeyCDN when you want a Swiss-contracted, pay-as-you-go CDN with Pull Zones, Push storage in European data centers, and a REST purge API, and you can accept global (including US) edge caches. Skip it when you need Cloudflare-class WAF, DNS, or Zero Trust, or a written US-free cache path. Consider Cloudflare for platform breadth.

Swiss-operatedPay-as-you-go CDNPull and Push ZonesOrigin ShieldREST API purgeEU Push storage
Logo: Myra CDN

Myra CDN

Germany· Web Hosting and Cloud Computing

Needs review

Shortlist Myra CDN when you need a German-operated Anycast edge with DDoS/WAF and a written Germany-only TLS termination option for KRITIS, banking, or public-sector sites. Skip it when you need Cloudflare-scale self-serve PoPs, Workers-class edge compute, or a free global cache. Consider Hetzner, IONOS, or OVHcloud when you only need EU origin hosting, not a certified WAAP edge.

EU-operated (Munich GmbH)ISO 27001 IT-Grundschutz (BSI, verified)BSI C5 Type 2 (claimed)Anycast CDN + Layer 7 DDoSGermany TLS termination (on request)PCI DSS Level 1 (claimed)
KeyCDN vs Myra CDN: Overzicht
KenmerkLogo: KeyCDNKeyCDNLogo: Myra CDNMyra CDN
Land van herkomstSwitzerlandGermany
CategorieWeb Hosting and Cloud ComputingWeb Hosting and Cloud Computing
Open sourceNeeNee
Self-hostedNeeNee
HoofdkantoorSwitzerlandGermany
Juridische entiteitproinity LLC (d/b/a KeyCDN), Reichenauweg 1, 8272 Ermatingen, SwitzerlandMyra Security GmbH, Landsberger Str. 187, 80687 Munich, HRB 202428
VS-moeder / zeggenschapGeen bekende VS-moederGeen bekende VS-moeder
CLOUD Act-blootstelling (indicatief)MiddelLaag
Hosting / residentieCompany-run global CDN: 60+ unnamed premium data centers including multiple US cities. Push Zone object storage stated as European data centers. Origin Shield clusters documented in US East, US West, and Amsterdam. Email delivery and payment (including PayPal) are unnamed or US-group third parties. No public named subprocessor register.Vendor-operated Anycast filter/CDN plane. BSI cert describes six outsourced data-centre sites (operators not named) with Myra staff running the IT. Marketing describes globally placed PoPs. Germany-only TLS termination and exclusive German processing are available on request. Product subprocessor list not published. Marketing website uses US SaaS (GA4, Clarity, Mailjet/Mailgun, Storylane, and others).
Samenvatting

Swiss content delivery network from proinity LLC: Pull and Push Zones, global anycast edges, European object storage for large files, prepaid credits.

Munich-operated Anycast CDN and Security-as-a-Service edge (DDoS, WAF, bot management) with optional Germany-only TLS termination.

Tags
In één oogopslag: KeyCDN vs Myra CDN
In één oogopslagLogo: KeyCDNKeyCDNLogo: Myra CDNMyra CDN
HQErmatingen, SwitzerlandMunich, Germany (Landsberger Str. 187)
Legal entityproinity LLC (d/b/a KeyCDN)Myra Security GmbH, HRB 202428
Governing lawSwitzerland; courts of SchwyzNiet vermeld
Network60+ PoPs in 40+ countries (vendor network page)Niet vermeld
Push storageEuropean data centers (vendor storage page)Niet vermeld
Commercial modelPrepaid credits, 14-day trial, no contractB2B subscription or quote (monthly/annual prepay); no consumer terms
Self-hostedNo (WordPress helper plugins are on GitHub)Niet vermeld
FoundedNiet vermeld2012 (vendor about/contact pages)
Product typeNiet vermeldSaaS Anycast CDN + Security-as-a-Service (not self-hosted)
OnboardingNiet vermeldDNS cutover + TLS upload; APIv2 at apiv2.myracloud.com
ISO 27001Niet vermeldBSI-IGZ-0667-2024, DDoS-Schutz scope, valid to 2027-12-17
Key capabilities: KeyCDN vs Myra CDN
Key capabilitiesLogo: KeyCDNKeyCDNLogo: Myra CDNMyra CDN
Swiss-operatedJaNiet vermeld
Pay-as-you-go CDNJaNiet vermeld
Pull and Push ZonesJaNiet vermeld
Origin ShieldJaNiet vermeld
REST API purgeJaNiet vermeld
EU Push storageJaNiet vermeld
EU-operated (Munich GmbH)Niet vermeldJa
ISO 27001 IT-Grundschutz (BSI, verified)Niet vermeldJa
BSI C5 Type 2 (claimed)Niet vermeldJa
Anycast CDN + Layer 7 DDoSNiet vermeldJa
Germany TLS termination (on request)Niet vermeldJa
PCI DSS Level 1 (claimed)Niet vermeldJa

KeyCDN

  • Pull Zones with instant purge

    A Pull Zone fetches from your origin and caches on KeyCDN edges. The dashboard and REST API can purge a whole Zone or selected URLs. Zone changes are described as taking a few minutes globally. Best for sites and apps whose origin already holds the objects.

  • Push Zones on European storage

    A Push Zone uploads via FTP(S) or rsync over SSH into KeyCDN's storage cluster. Official FAQ: required for files larger than 100 MB. The storage page states objects rest in European data centers; edges then cache globally. Interconnect from storage to edges is unmetered; you pay storage plus egress.

  • Origin Shield (US East, US West, Amsterdam)

    An extra cache layer collapses origin requests (keep-alives, collapsed forwarding). Documented shield sites are United States East Coast, United States West Coast, and Amsterdam, chosen automatically. This cuts origin load. It also means a miss can be fetched through a US shield, not only through Amsterdam.

  • Query-string image processing

    On a CDN URL you can set width, height, quality, format (including WebP), grayscale, and flip/flop. Transforms are billed per operation (see the official pricing page). Useful for CMS teams that do not want a separate image pipeline.

  • REST API, TLS choices, and protocol stack

    The API manages Zones, purge, and traffic reports. Every account can attach Let's Encrypt, a shared cert, or a custom cert. Product pages list HTTP/2, TLS 1.3 (with 0-RTT in KeyCDN's TLS blog), Gzip, optional Brotli when the origin already emits br, IPv6, and IP anycast plus latency-based routing.

  • Token, referrer, and account locks

    Secure Token and Zone Referrer (hotlink protection) limit who can fetch a URL. Account-side controls include two-factor authentication and IP access rules. These are CDN access controls, not a full WAF or Zero Trust product.

Myra CDN

  • Anycast CDN with RAM cache and HTTP/2

    Content is cached in RAM with real-time invalidation and stale-object support, then delivered over Anycast IPv4/IPv6. Protocols on the CDN sheet are HTTP/1.1 and HTTP/2. Image optimisation includes WebP conversion and on-the-fly resizing via query string. Docs also mention HTTP, HTTPS, DNS, IMAP, and SMTP on the wider platform, plus automatic IPv4/IPv6 translation for IPv4-only origins.

  • Optional mTLS and signed URLs at the edge

    Clients can authenticate to the CDN with a client certificate. The CDN can also present a client certificate to the origin so only Myra reaches origin. Signed URLs add a cryptographic signature and optional expiry. TLS 1.2/1.3 is stated. These controls are optional add-ons, not defaults for every domain.

  • Layer 7 DDoS on the same reverse proxy

    Malicious HTTP is filtered in Myra's network before a redundant reverse proxy forwards clean traffic. Documented controls include GeoIP blocking, rate limits, attack notifications, post-mitigation reports, and upstream monitoring. Network-layer cloud scrubbing and on-prem BGP protection are separate products for IP prefixes. Vendor capacity claims (for example 1 Tbps class attacks) should be validated in an RFP, not treated as a measured SLA.

  • WAF, bot management, and EU CAPTCHA add-ons

    The CDN is sold as a stack with Hyperscale WAF, deep bot management, and Myra EU CAPTCHA (cookie-free, hashed telemetry, optional dedicated DE/EU endpoints). A managed WAF service is offered as an add-on. This is useful for KRITIS and banking sites that want one German operator. It is not a reason to assume every module is included in a CDN-only quote.

  • Germany-only TLS termination on request

    Because WAF and DDoS inspection decrypt HTTPS, Myra states it will terminate TLS exclusively in Germany when the customer requests it. Exclusive processing in German data centres is the same kind of option. If the contract is silent, marketing still describes globally placed PoPs. Write the region constraint into the order form.

  • REST APIv2, Myra App, and DNS cutover

    Go-live is DNS (A/AAAA to Myra, CNAME, or moving authoritative DNS) plus certificate upload via the Myra App or API. APIv2 is documented at apiv2.myracloud.com and can create domains, change cache settings, and edit DNS. Docs also cover SSO, certificate management, waiting rooms, object storage, WebSockets, and maintenance pages. There is no official self-host of the filter plane.

Assurance & compliance: KeyCDN vs Myra CDN
Assurance & complianceLogo: KeyCDNKeyCDNLogo: Myra CDNMyra CDN
Independent security / no-logs audit
Not found

No public third-party audit PDF found on keycdn.com. Dashboard logs are said to anonymize client IPs; raw syslog format includes an IP field.

Partial

Vendor states regular external pen tests and audits. No public no-logs audit PDF. Independent C5 work in 2022 was described by usd AG. Ask for current pentest and attestation reports.

ISO 27001
Not found

Network page mentions ISO 27001 for premium data centers. That is not a published ISO 27001 certificate for proinity LLC.

Verified

BSI-IGZ-0667-2024, issued 2024-12-18, valid to 2027-12-17. Scope is Myra Security DDoS-Schutz at six outsourced DC sites, not automatically every CDN PoP.

SOC 2 / SOC 3
Not found

Searched official legal, network, and GDPR pages. No SOC 2 or SOC 3 claim found.

Not found

No SOC 2 report published. Closest published control attestations are BSI C5 Type 2 (claimed) and IDW PS 951 Type 2 / ISAE 3402 (claimed).

GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR page describes controller/processor roles, anonymized dashboard logs, and a DPA via support. Privacy Policy last updated 2018 still cites Privacy Shield for third parties.

Vendor claimed

German controller/processor, GDPR pages, optional Germany-only TLS termination. Confirm DPA and processing locations in contract.

US CLOUD Act exposure (indicative)
Partial

Swiss entity, no known US parent, but US PoPs, US Origin Shield locations, PayPal, and unnamed third parties. Not legal advice.

Partial

EU entity, no known US parent, self-operated filter plane. Partial because CDN PoPs are described as global, six DC sites are outsourced and unnamed, and no product subprocessor register was found. Not legal advice. Vendor claims it is not subject to CLOUD Act/FISA 702.

Data processing agreement (B2B)
Vendor claimed

GDPR page: open a support request to receive the DPA when Article 28 processing applies.

Not found

No public Art. 28 DPA PDF on legal/GDPR/terms pages. EU CAPTCHA FAQ asks whether a DPA must be signed, which implies one exists for that product. Request the current AVV.

EU AI Act
Not applicable

CDN / image transforms, not an AI system product.

Not applicable

CDN/WAAP edge. Marketing mentions AI-powered DDoS detection. Not an AI-system product page.

BSI C5 Type 2Niet vermeld
Vendor claimed

Current Type 2 claimed on certifications page. usd AG publicly described a 2022 C5 audit with HKKG. Current-year attestation PDF not found.

PCI DSS Level 1Niet vermeld
Vendor claimed

Vendor certifications page: PCI DSS Level 1 service provider. No public AOC in this research pass.

IDW PS 951 Type 2 (ISAE 3402)Niet vermeld
Vendor claimed

Vendor claim of Type 2 over a twelve-month period. Report not published.

KRITIS operator (BSIG section 8a(3))Niet vermeld
Vendor claimed

Vendor certifications page. Confirm current attestation in procurement.

Considerations & known limitations: KeyCDN vs Myra CDN
Considerations & known limitationsLogo: KeyCDNKeyCDNLogo: Myra CDNMyra CDN
US cache copies and US Origin Shield
Medium

Public PoP list includes many US cities. Origin Shield is documented in US East, US West, and Amsterdam with automatic selection. A Swiss contract does not keep objects out of the United States.

Niet vermeld
No current named subprocessor list
Medium

Privacy Policy (May 2018) mentions an unnamed email provider and Privacy Shield. Payments include PayPal. Data-center brands are not named. Ask for a current list before treating transfers as mapped.

Niet vermeld
No public operator ISO 27001 or SOC 2
Medium

ISO 27001 is mentioned for data centers, not as a verified proinity LLC certificate. No SOC 2 found. Security questionnaires will need vendor follow-up.

Niet vermeld
Privacy Policy last updated 2018
Medium

The public policy still refers to Privacy Shield, which is not a current EU-US transfer framework. Confirm what actually applies in the DPA.

Niet vermeld
Push Zone required above 100 MB
Low

Official FAQ: content larger than 100 MB must use a Push Zone (upload to KeyCDN storage), not a simple origin pull.

Niet vermeld
Global PoPs unless Germany-only is contractedNiet vermeld
Medium

Marketing describes worldwide Anycast delivery. Germany-only TLS termination and exclusive German processing are request options. A silent contract can leave visitor IPs and cached objects on unpublished PoPs outside Germany.

Outsourced DCs and no public subprocessor listNiet vermeld
Medium

BSI-IGZ-0667-2024 states six independent data-centre sites are outsourced. Operators are not named. No product subprocessor register was found. Procurement should demand the annex before treating the path as EU-only.

ISO 27001 scope is DDoS-Schutz, not every SKUNiet vermeld
Low

The verified BSI certificate covers the DDoS-protection information network. CDN add-ons, object storage, EU CAPTCHA, and the marketing website are not automatically in that sentence. Align the statement of applicability with the ordered products.

Smaller public footprint than CloudflareNiet vermeld
Medium

No public worldwide PoP map comparable to large US CDNs. HTTP/3 is not listed on the CDN spec sheet. Poor fit if you need self-serve global scale or edge compute.

Corporate website uses US processorsNiet vermeld
Low

Privacy policy names Google Analytics, Clarity, Mailjet/Mailgun, Storylane, and other US-linked tools for the website. Separate this from product traffic, but do not treat the privacy policy as proof that the CDN path is US-free.

Geschiktheid

KeyCDN

Best fit when

  • Web and CMS teams that need a conventional pull CDN plus instant URL purge from a REST API
  • Software, game, or video distribution that must use Push Zones for objects larger than 100 MB
  • Buyers who want a Swiss contracting entity (proinity LLC) and prepaid credits instead of an annual CDN commit
  • WordPress sites that can use the official CDN Enabler URL-rewriting plugin
  • Stacks that only need edge cache, TLS, and token/referrer locks, not a bundled WAF or Zero Trust suite

Poor fit when

  • Organizations that require a contractual ban on US cache copies or US Origin Shield
  • Teams that need Cloudflare-style WAF rules, Workers compute, authoritative DNS, or Zero Trust in one vendor
  • Buyers who will not proceed without a current named subprocessor list and an operator-level ISO 27001 or SOC 2 report
  • Anyone expecting a self-hosted KeyCDN edge; the network is hosted-only

Consider instead when

  • When: You need WAF, bot management, Workers-style compute, authoritative DNS, or Zero Trust beside the CDN

    Consider: Cloudflare

    KeyCDN is a CDN specialist. Its Cloudflare-alternative page even describes multi-CDN pairing rather than feature parity.

  • When: Legal requires EU-only cache and shield, with no US PoP copies

    Consider: Self-hosted cache (nginx or Varnish) in EU regions, or another CDN that publishes an EU-only region lock

    KeyCDN lists many US cities and documents Origin Shield in two US coasts plus Amsterdam. Swiss HQ does not pin the cache.

  • When: You need a current operator ISO 27001 or SOC 2 report before onboarding

    Consider: A CDN or cloud edge vendor that publishes those certificates

    KeyCDN mentions ISO 27001 in a data-center context. No proinity LLC certificate or SOC 2 report was found on the official site.

Myra CDN

Best fit when

  • German or EU public sector, KRITIS, banks, insurers, and healthcare portals that must show BSI-shaped evidence
  • Teams replacing Cloudflare primarily for jurisdiction, not for Workers or a free tier
  • Sites that will contract Germany-only TLS termination and want one operator for CDN, WAF, and DDoS
  • Origins that can cut over via DNS and certificate upload without installing an appliance
  • Buyers who need REST APIv2, SSO, and SIEM-oriented logs rather than a hobby CDN

Poor fit when

  • Buyers who need a large free tier or fully self-serve global CDN comparable to Cloudflare
  • Workloads that require published HTTP/3, Workers-style edge compute, or a public worldwide PoP map before RFP
  • Organisations that cannot accept unnamed colocation partners without a signed subprocessor annex
  • Consumer or hobby projects (terms exclude consumers)
  • Teams that only need EU VMs or object storage and do not need a WAAP edge

Consider instead when

  • When: You need maximum global PoP density, Workers-style compute, or a self-serve free CDN

    Consider: Cloudflare

    US parent and CLOUD Act exposure are the usual reason regulated EU buyers leave it.

  • When: You only need EU origin compute or hosting, not Anycast WAAP

    Consider: Hetzner, IONOS, or OVHcloud

    These are catalog infrastructure peers, not certified German DDoS/CDN edges.

Open questions for due diligence

KeyCDN

  • Will KeyCDN name all subprocessors, colo providers, and payment/email processors in a current list?
  • Can a customer pin cache and Origin Shield to EU/Amsterdam only, in contract?
  • Does proinity LLC hold ISO 27001 or SOC 2, and can the reports be shared under NDA?
  • Does syslog log forwarding include client IPs, and is that processing described in the DPA?
  • Has the May 2018 Privacy Policy been replaced internally, and what transfer tool replaced Privacy Shield?

Myra CDN

  • Will Myra sign an Art. 28 DPA for the CDN/WAF/DDoS order and attach a current subprocessor list that names the six certified DC operators?
  • Which PoP countries will serve our hostnames if we do not buy exclusive German processing?
  • Does BSI-IGZ-0667-2024 include the exact PoPs and products in our statement of work, and can we see the current C5 Type 2, PCI AOC, and IDW PS 951 reports?
  • Is HTTP/3, IPv6-only origins, or Workers-like edge compute on the roadmap, and what is the contracted SLA for our SKU?
  • Are there US-group transit, colocation, or support tools on the product data path that are not listed publicly?