| Independent security / no-logs audit | ❌Not foundMulti-CDN collects partner access logs (IP, URI, cache status) and can ship them to S3. No public independent audit of CDN logging or routing found. | ❌Not foundFAQ claims no personal logs and aggregate graphs only. No third-party audit PDF found. |
|---|
| ISO 27001 | ⚠️Vendor claimedISO 27001:2022 via EY CertifyPoint for multiple entities including Leaseweb Netherlands B.V. and Leaseweb Global B.V. Published certified services omit CDN (bare metal, VPS, cloud, colo, web hosting, domains). Ask for SoA / CDN scope. | ❌Not found |
|---|
| SOC 2 / SOC 3 | ⚠️PartialSOC 2 published for Leaseweb Canada, Inc. colocation (Security and Availability). Not a Multi-CDN report. Several entities have SOC 1 Type II (EY) covering cloud, dedicated, colo, and web hosting, not CDN. | ❌Not found |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU sales entities; privacy page states GDPR is taken into account. DPA in sales terms. Transfers to US entity via DPF (Leaseweb USA, Inc.). Multi-CDN partners unnamed. | ⚠️PartialDanish individual operator and a no-logs claim on the FAQ. No formal privacy policy or DPA page found. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialDutch group, no known US parent, but path includes Washington, D.C. shields, Leaseweb USA, Inc., NS1 Pulsar, and four unnamed global partner CDNs. Assessment row, not a vendor claim. Not legal advice. | ⚠️PartialNo known US parent. Published anycast includes rgnet in Washington, USA (AS3927), so some queries can be answered on US soil. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor: DPA incorporated as Clause 8 of local sales terms; additional standalone DPA on request when appropriate. Confirm Multi-CDN partners and NS1 are scheduled. | ❌Not foundNo company imprint or processor agreement found. Operator contact is admin@censurfridns.dk. |
|---|
| EU AI Act | —Not applicableContent delivery and traffic steering product, not an AI system offering. | —Not applicablePublic recursive DNS resolver, not an AI system. |
|---|
| PCI DSS | ⚠️PartialVendor: PCI DSS 4.0 scoped to physical security at named DCs (AMS-01, FRA-01, LON-01, WDC-02, SIN-01, Montreal). Not a card-data or CDN application control. | Niet vermeld |
|---|
| CISPE IaaS Code of Conduct | ⚠️Vendor claimedCompany says it registered products with CISPE. Confirm whether Multi-CDN is on the public CISPE register. | Niet vermeld |
|---|