Every European web security tool reviewed
Munich, Germany
Free tier / from €9 per month
Free tier
Best for: Sites that need bot protection without sending visitors to Google
Friendly Captcha replaces the single most common privacy problem on European websites. reCAPTCHA sits on an enormous share of them, and every one of those embeds is a Google request made by your visitor, on your instruction, usually with no consent asked and no mention in the cookie banner — which is exactly the arrangement data protection authorities have repeatedly objected to.
It works differently, and the difference is what makes it defensible. Instead of profiling the visitor or making them identify traffic lights, it runs a proof-of-work puzzle in the background: the visitor's browser does a small amount of computation, which is trivial for one person and expensive for someone submitting thousands of forms.
There is nothing to click, no images to squint at, no cookies and no user tracking — which also makes it markedly more accessible than an image challenge for anyone using a screen reader.
Friendly Captcha GmbH operates from Munich with EU processing under GDPR, so the request your visitor makes stays in European jurisdiction. Free tier with paid plans from €9 per month. The honest limits: it is not open source, proof-of-work costs a little battery on a phone, and a determined attacker with real compute can still pay the cost — it raises the price of abuse rather than making it impossible.
What Friendly Captcha does well
- No cookies and no user tracking at all
- Invisible to the visitor — nothing to click or decipher
- Markedly more accessible than image challenges
- German company, EU processing under GDPR
- Free tier, paid from €9/month
Where Friendly Captcha falls short
- Not open source
- Proof-of-work costs some battery on mobile
- Raises the cost of abuse rather than preventing it
- Paid tiers needed at real traffic volumes
Standout feature. Nothing to click and nothing sent to Google — the reCAPTCHA problem removed rather than mitigated.
Self-hosted
Free and open source
Free
Best for: Organisations that want CAPTCHA with no third party at all
mCaptcha takes the same proof-of-work idea as Friendly Captcha and removes the vendor. It is open source and self-hosted, so the challenge is served from your own infrastructure and no third party is involved in the transaction at any point — you remain the sole data controller, and there is no privacy policy to read because there is no other party.
For a public body, a university or a privacy-focused organisation, that is a materially different position from choosing a better-behaved vendor. The most common objection to reCAPTCHA is not that Google handles the data badly, it is that a visitor to a government form should not be making a request to an advertising company at all. Self-hosting is the only answer that fully addresses it.
Being open source, the mechanism is inspectable rather than asserted — the proof-of-work implementation can be read by anyone who wants to check what it does, which is not true of any commercial alternative.
It is free with no licence cost at any traffic level. The costs are the usual ones: you deploy, run, monitor and update it, the project is small compared with commercial vendors, and as with all proof-of-work it raises the cost of abuse rather than eliminating it.
What mCaptcha does well
- Self-hosted — no third party in the transaction at all
- Open source, so the mechanism is inspectable
- You remain the sole data controller
- No cookies, no tracking, no licence cost at any volume
- Accessible by design, unlike image challenges
Where mCaptcha falls short
- You deploy, run and maintain it yourself
- Small project next to commercial vendors
- Raises the cost of abuse rather than preventing it
- No commercial support offering
Standout feature. A CAPTCHA with no vendor behind it — the only version a government form can use without qualification.
Stockholm, Sweden
Founded 2013
Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year
Free Starter tier; tailored trials for paid plans
Best for: Security teams that want continuous external attack-surface and app testing
Detectify combines external attack surface management with dynamic application security testing, continuously mapping what an organisation exposes to the internet and then testing each asset for exploitable vulnerabilities. The payloads come partly from Detectify's own research and partly from Crowdsource, a network of more than 400 ethical hackers who submit real attack techniques rather than generic signatures, which is the company's clearest point of difference from a conventional scanner.
Coverage extends to REST and GraphQL APIs from the Standard tier up, and CI/CD integration on Professional lets scanning run inside a deployment pipeline rather than as a separate quarterly exercise. Detectify AB is based in Stockholm, so the reports generated from scanning a customer's infrastructure — which can include internal URLs, parameters and, occasionally, exposed credentials — are processed under Swedish and EU law.
Pricing is published rather than quote-only, down to a point: a free Starter tier covers up to five users and 100 assets, Standard is €2,500 a year, Professional €5,000, and Enterprise €15,000 for unlimited users and assets. That transparency stops where most vendors hide it — mid-market — which is unusual in application security. The honest limit: it is a scanner and attack-surface tool, not a WAF or CDN, so it finds exposure rather than blocking it.
What Detectify does well
- External attack surface management plus DAST in one platform
- Crowdsource payloads from 400+ ethical hackers
- REST and GraphQL API scanning
- Published pricing from a free tier to €15,000/year
- Swedish company, EU jurisdiction
Where Detectify falls short
- Finds vulnerabilities rather than blocking attacks — not a WAF or CDN
- Standard tier caps at 750 assets and 10 users
- CI/CD integration reserved for Professional and above
- Enterprise pricing jumps sharply to €15,000/year
Standout feature. Published pricing from a free tier to €15,000 a year — rare transparency in enterprise application security.
London, United Kingdom
Founded 1994
Enterprise pricing on request; no published price list
Contact sales
Best for: Brands needing phishing and scam takedown at internet scale
Netcraft is the oldest company in this directory by three decades, tracking web server usage since 1994 and building a digital risk protection platform on top of that history. The current product detects phishing sites, scam pages and brand-impersonating domains as they appear, and then acts on the detection: takedown requests go out to the hosting provider, registrar or platform involved, backed by relationships built over thirty years of doing exactly this.
The detection layer runs on AI models trained on Netcraft's own long-running internet telemetry, covering typosquatted domains, fake app store listings, fraudulent social media accounts and look-alike login pages — the categories of attack that target a brand's customers rather than its infrastructure, and that a CDN or WAF sitting in front of a website cannot see at all.
Netcraft Ltd is registered in England and Wales, based in London, so the customer and brand data it processes to run these detections sits under UK law with an EU adequacy decision rather than direct GDPR establishment. Pricing is not published; every engagement is quoted, which means evaluating cost requires a sales conversation. It is not a substitute for the CDN or WAF layer — it protects the brand's identity outside the site, not the site's infrastructure.
What Netcraft does well
- Three decades of internet threat-intelligence history
- Detects and takes down phishing, scams and impersonation
- Covers domains, apps and social media, not just websites
- AI-powered detection at internet scale
- Long-established relationships for fast takedowns
Where Netcraft falls short
- No published pricing — every deal is quoted
- UK jurisdiction, adequacy decision rather than EU establishment
- Protects brand identity, not site infrastructure
- Not a WAF, CDN or DDoS layer
Standout feature. Thirty years of takedown relationships — the reason a Netcraft phishing report gets acted on faster than a fresh vendor's would.
Osnabrück, Germany
Founded 2008
Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year
Free Community Edition (OpenVAS)
Best for: Organisations that want an open-source vulnerability scanner they can run themselves
Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.
The commercial layer sits on top rather than replacing the open core: Greenbone Enterprise appliances add a maintained vulnerability feed, support and management tooling, starting with OPENVAS BASIC at €2,524 a year as the entry point into that feed. For a public body or university with a procurement rule against unauditable security software, that combination of an open engine and a paid, supported feed is a specific answer few competitors offer.
Greenbone AG is based in Osnabrück, Germany, and holds ISO 9001 and ISO 27001 certification of its own management systems; it converted into a stock company (AG) in 2023. The honest limit: OpenVAS finds and reports vulnerabilities, it does not block an attack in progress, and running the open-source edition well still requires someone with real vulnerability-management expertise to interpret and prioritise the output.
What Greenbone does well
- Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
- Free Community Edition with no licence cost
- Enterprise appliances with maintained feed from €2,524/year
- ISO 9001 and ISO 27001 certified
- German company, EU jurisdiction
Where Greenbone falls short
- Finds vulnerabilities; does not block attacks itself
- Self-hosted use requires real in-house expertise
- Enterprise appliance pricing is on top of the free core
- Less polished interface than SaaS-first competitors
Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.
Geneva, Switzerland
Founded 2019
Free Community Edition; paid AI Platform (penetration testing, ASM, dark web monitoring) quoted by sales
Free Community Edition, unlimited use
Best for: Teams that want human-verified penetration testing with AI acceleration
ImmuniWeb pairs human penetration testers with AI models trained specifically to accelerate application security testing, and it was among the first vendors accredited by CREST for that combination — including, in 2026, one of the first ten companies worldwide to hold CREST's new AI-Enabled Penetration Testing accreditation. That accreditation matters because it is an external audit of how the AI is used, not a vendor's own claim about it.
The platform covers penetration testing, attack surface management and dark web monitoring for leaked credentials and brand mentions, sold as one connected suite rather than three separate products. A free Community Edition runs more than 100,000 tests a day for SMEs, universities and small municipal governments that could not otherwise afford security testing, a genuinely different offer from the enterprise-only quote-based tools elsewhere in this category.
ImmuniWeb SA became an independent Swiss corporation headquartered in Geneva in 2019 and has been self-funded and profitable since its first year, without outside investors to answer to. Switzerland sits outside the EEA under an adequacy decision rather than inside the GDPR directly. Paid AI Platform pricing is not published and requires a sales conversation, and the free tier — while genuinely useful — is a lighter product than the paid penetration testing service.
What ImmuniWeb does well
- Human penetration testers with CREST-accredited AI assistance
- Penetration testing, ASM and dark web monitoring combined
- Free Community Edition runs 100,000+ tests daily
- Self-funded and profitable, no outside investor pressure
- ISO 9001:2015 certified
Where ImmuniWeb falls short
- Paid platform pricing not published
- Switzerland: adequacy decision, not EU/EEA jurisdiction
- Free tier is lighter than the paid testing service
- Sales conversation required to evaluate real cost
Standout feature. One of the first ten companies in the world CREST-accredited for AI-enabled penetration testing — audited, not just claimed.
Manchester, United Kingdom
Enterprise pricing on request; quoted per engagement
Contact sales
Best for: Enterprises needing autonomous bot detection without agents
Netacea detects and blocks bots at the edge without installing an agent on the protected site, analysing traffic signals server-side and responding automatically rather than waiting for a security team to review an alert. That agentless approach means no code changes ripple through a release cycle every time the bot-detection logic updates, since the analysis runs on Netacea's side rather than embedded in the customer's application.
The company frames the problem in revenue terms as much as security ones: it cites an average $85 million in annual losses that enterprise brands attribute to scraping, credential stuffing and other malicious automation, and builds its detection around stopping that traffic before it reaches checkout, login or API endpoints — the points where a false block costs a real customer, not just an inconvenience.
Netacea Limited is registered in England and Wales and based in Manchester, with English law governing its contracts — a clean UK jurisdiction rather than one routed through an American parent, which is not true of every bot-management vendor this category could have included. Pricing is not published and is quoted per engagement. The honest limit: this is a bot-management specialist, not a CDN or WAF, so it sits alongside one of those rather than replacing it.
What Netacea does well
- Agentless, server-side bot detection
- Autonomous response without manual review
- Built specifically around revenue-impacting bot traffic
- UK company, contracts governed by English law
- Live attack visualisation for SOC teams
Where Netacea falls short
- No published pricing — quoted per engagement
- UK jurisdiction, adequacy decision rather than EU establishment
- Bot management only, not a CDN or WAF
- Best suited to enterprise scale, not small sites
Standout feature. Detection and response entirely server-side — nothing to deploy or update on the protected site itself.
London, United Kingdom
Enterprise, appliance-based pricing on request
Contact sales
Best for: Service providers and carriers needing automated, real-time DDoS mitigation
Corero sells DDoS mitigation as a product rather than as a feature bundled into a CDN, aimed specifically at internet service providers, hosting companies and carriers who need to protect their own network — and, by extension, every customer sitting behind it — rather than a single website. The SmartWall product line runs as physical or virtual appliances, detecting and automatically mitigating an attack in real time rather than routing traffic to a scrubbing centre after the fact.
That automated, in-line model is the distinguishing choice: a scrubbing-centre approach can take minutes to reroute traffic once an attack is detected, long enough for a volumetric flood to have already done its damage, while an appliance sitting in the data path can start dropping malicious packets within seconds of the pattern appearing.
Corero Network Security plc is listed in London, with its operating UK subsidiary registered in England and Wales (company number 04047090, incorporated in 2000 as Top Layer Networks Limited). Pricing is enterprise and appliance-based, quoted per deployment rather than published, and buying it means capital equipment or a managed service contract rather than a monthly SaaS bill. It is built for the operator layer of the internet, not for a single e-commerce site.
What Corero Network Security does well
- Automated, real-time DDoS mitigation, not scrubbing-centre rerouting
- SmartWall physical and virtual appliances
- Built for ISPs, hosting providers and carriers
- Publicly listed UK company (London)
- DDoS lineage stretching back to Top Layer Networks (2000)
Where Corero Network Security falls short
- Enterprise, appliance-based pricing on request only
- Aimed at network operators, not single websites
- UK jurisdiction, adequacy decision rather than EU establishment
- Capital-equipment or contract commitment, not a SaaS signup
Standout feature. Mitigation in the data path within seconds, not a reroute to a scrubbing centre after the flood has already landed.
Montpellier, France
Add-on modules from €18/month (Monitoring) to €490 (Cyber Vigilance); core scanner plans configured via a pricing calculator after a 14-day free trial
14-day free trial (HTTPCS Discovery)
Best for: French businesses wanting a scanner, SSL certificates and monitoring in one
HTTPCS is Ziwit's suite for a company that wants vulnerability scanning, attack-surface evaluation and everyday site monitoring from a single vendor rather than separately sourced. The core scanner does dynamic application security testing, EASM maps what the organisation exposes to the internet, and a data-leak module called Cyber Vigilance watches for the company's information turning up somewhere it should not — three distinct disciplines other vendors in this category sell as separate products.
It is also, unusually for this category, an SSL/TLS certificate reseller in its own right, selling certificates from Sectigo, GeoTrust, RapidSSL and others alongside its scanning tools — a genuine one-stop option for a small or mid-sized French business that would otherwise be buying certificates, uptime monitoring and a vulnerability scan from three unrelated vendors.
Ziwit SAS is registered in Montpellier, France, with published capital of €1,140,000.
Its published add-on pricing runs from €18 a month for uptime monitoring to €490 for Cyber Vigilance; the core scanner plans themselves are configured through a calculator rather than listed as fixed prices, and a 14-day free trial (HTTPCS Discovery) is the way to see the real figure before committing. The site and support lean French-first, a fair trade for a French buyer and a minor friction for anyone else.
What HTTPCS does well
- Scanner, EASM and monitoring from one vendor
- Data-leak detection (Cyber Vigilance) included
- Also sells SSL/TLS certificates directly
- French company, published share capital
- 14-day free trial (HTTPCS Discovery)
Where HTTPCS falls short
- Core scanner pricing hidden behind a calculator, not published
- French-first site and support
- No independent certification published
- Smaller and less internationally known than Detectify or Greenbone
Standout feature. Scanner, SSL certificates and uptime monitoring from one Montpellier vendor — a genuine bundle rather than three separate bills.
Ljubljana, Slovenia
Pay-as-you-go from €0.01 per GB
Pay-as-you-go, no commitment
Best for: Anyone wanting fast, cheap European content delivery with video included
Bunny.net reframes what this layer costs. Pay-as-you-go from €0.01 per GB across more than 110 points of presence with a strong European footprint puts it an order of magnitude below what enterprise CDNs quote, with no commitment, no minimum and no sales conversation — which for a business serving a terabyte a month turns a budget line into a rounding error.
It is more than a cache. Edge Storage puts files at the edge rather than only caching them from an origin, Bunny Stream provides video hosting and delivery so a media site does not need a separate video platform, and DNS, image optimisation and DDoS protection round it out. That combination is what lets a site run its entire delivery layer here.
Bunny CDN d.o.o. is based in Ljubljana, so the layer that terminates TLS and sees every visitor request is governed by EU law under GDPR rather than by the CLOUD Act. The honest scope: the DDoS protection is what a CDN provides by construction rather than a managed mitigation service with engineers watching, and there is no BSI-grade WAF or bot management for critical infrastructure — that is what Myra and Link11 are for.
What Bunny.net does well
- Pay-as-you-go from €0.01 per GB with no commitment
- 110+ points of presence with a strong European footprint
- Edge Storage and Bunny Stream video hosting included
- DNS, image optimisation and DDoS protection
- Slovenian company, EU jurisdiction under GDPR
Where Bunny.net falls short
- DDoS protection is CDN-grade, not managed mitigation
- No BSI-grade WAF or bot management
- Self-serve only — no enterprise engagement model
- Support is not a 24/7 security operations centre
Standout feature. €0.01 per GB with video streaming and edge storage included — the price at which this layer stops being a budget decision.
Munich, Germany
Enterprise pricing on request
Contact sales
Best for: European enterprises, government agencies and critical infrastructure
Myra Security sells protection rather than delivery, and its BSI certification is what separates it from everything cheaper in this category. Assessment by the German federal office for information security places it among the providers acceptable for critical infrastructure — energy, water, healthcare, finance, government — which is an audited judgement rather than a marketing claim, and it is what gets a vendor through procurement where the wrong answer becomes a regulatory problem.
The capability set is complete for that buyer: DDoS protection across network and application layers, a web application firewall filtering attacks against the application itself, CDN for delivery, DNS security, bot management to separate legitimate automation from scraping and credential stuffing, and SSL/TLS handling.
Myra Security GmbH is based in Munich with German hosting, which matters because this layer decrypts every request that reaches your site — form submissions, credentials in transit, visitor behaviour — so where it is processed and under whose law is a substantive question for a public body or a bank.
Pricing is enterprise and quoted on request, so evaluation means a sales cycle, and it is not the right spend for a site where an outage costs a bad afternoon rather than a headline.
What Myra Security does well
- BSI certified for German critical infrastructure
- DDoS protection, WAF, bot management and DNS security
- German hosting and jurisdiction throughout
- Built for organisations where outage is a serious event
- Full CDN alongside the security layer
Where Myra Security falls short
- Enterprise pricing on request, no self-serve entry
- Sales cycle before you can evaluate cost
- Overkill for a site where downtime is an inconvenience
- Fewer points of presence than the large CDNs
Standout feature. BSI certification — the audited assessment that decides whether a German public body may use you at all.
Luxembourg
Free tier / paid from €25 per month
Free tier
Best for: Gaming, streaming and businesses needing low-latency global delivery
Gcore builds for the workloads where latency is the product. Gaming and streaming are its declared focus, and that shapes the network: more than 180 points of presence globally with multiple EU locations, tuned for consistent low latency rather than for the average case, because a hundred milliseconds is invisible on a web page and unplayable in a game.
It is broader than a CDN. Edge computing runs code at the points of presence rather than at an origin, cloud VMs provide compute, and streaming services, DNS hosting and load balancing sit alongside — so a platform can run delivery, compute and distribution from one European provider rather than assembling three.
DDoS protection is included across the network. Gcore S.A. is registered in Luxembourg, an EU member state, so the traffic-inspecting layer sits under GDPR. There is a free tier with paid plans from €25 per month, which makes it approachable without a sales conversation. It is not a BSI-grade security vendor in the way Myra and Link11 are, and its per-GB pricing does not reach Bunny.net's level for straightforward delivery.
What Gcore does well
- 180+ points of presence tuned for low latency
- Edge computing and cloud VMs alongside the CDN
- Built for gaming and streaming workloads
- DDoS protection included, free tier available
- Luxembourg company, EU jurisdiction
Where Gcore falls short
- Not a BSI-grade security vendor
- Per-GB pricing above Bunny.net for plain delivery
- Paid plans from €25/month rather than pure usage-based
- Broad product range takes orientation
Standout feature. A network tuned for the hundred milliseconds that ruin a game rather than the ones nobody notices on a web page.
Frankfurt, Germany
Enterprise pricing on request
Contact sales
Best for: European enterprises needing automated DDoS mitigation
Link11's defining capability is that mitigation happens without a human deciding to act. Its AI and machine-learning detection drives zero-touch mitigation, which matters because volumetric DDoS attacks arrive and escalate faster than an on-call engineer can assess them — by the time a person has confirmed the attack is real, the outage has already happened.
Around that sit the components an enterprise security posture needs: a web application firewall filtering attacks against the application rather than the pipe, bot management separating legitimate automation from scraping and credential stuffing, DNS protection, and a secure CDN so delivery and protection are the same layer.
Link11 GmbH is BSI qualified and based in Frankfurt with German hosting, which places it in the same procurement bracket as Myra for critical infrastructure and means the layer decrypting every request is governed by German and EU law. Pricing is enterprise and quoted on request. As with Myra, this is the right spend when an outage is a serious event and considerable overspend when it is not — and it is engaged through sales rather than signup.
What Link11 does well
- Zero-touch mitigation driven by AI detection
- BSI qualified, German hosting and jurisdiction
- WAF, bot management and DNS protection included
- Secure CDN combining delivery and protection
- Built for attacks faster than human response
Where Link11 falls short
- Enterprise pricing on request, no self-serve entry
- Sales-led engagement before evaluation
- Overkill where downtime is an inconvenience
- Fewer points of presence than the large CDNs
Standout feature. Mitigation without a human in the loop — because a DDoS attack peaks before anyone finishes reading the alert.
Winterthur, Switzerland
Pay-as-you-go from €0.04 per GB, no minimum commitment
Pay-as-you-go
Best for: Websites wanting fast, privacy-respecting delivery with no commitment
KeyCDN is the straightforward option: pay-as-you-go at €0.04 per GB across 47-plus points of presence with no minimum commitment, so there is no contract to negotiate and no floor to clear before the pricing makes sense.
The feature set covers what a site actually needs from a CDN. Real-time analytics show what is being served and from where as it happens rather than in yesterday's report, instant purge means a cache mistake is corrected in seconds instead of propagating for hours, WebP conversion and image processing reduce payloads automatically, and HTTP/2, free SSL and DDoS protection come as standard.
proinity LLC operates from Winterthur under the Swiss Federal Data Protection Act with an EU adequacy decision — a strong privacy regime, and worth knowing that it is adequacy rather than intra-EEA processing if procurement rules name EU member states. The scope is honest: 47 points of presence is a smaller network than Gcore's or Bunny.net's, €0.04 per GB is four times Bunny's rate, and it is a CDN with DDoS protection rather than a security vendor.
What KeyCDN does well
- Pay-as-you-go at €0.04 per GB, no minimum commitment
- Real-time analytics and instant cache purge
- WebP conversion and image optimisation
- HTTP/2, free SSL and DDoS protection included
- Swiss Federal Data Protection Act jurisdiction
Where KeyCDN falls short
- 47 points of presence is a smaller network
- Four times Bunny.net's per-GB rate
- CDN with DDoS protection, not a security vendor
- Swiss adequacy rather than EEA jurisdiction
Standout feature. Instant purge and real-time analytics with no commitment — a CDN you can start and stop the same afternoon.
Roubaix, France
From €3.50 per month (VPS)
Low-cost entry plans
Best for: Businesses that need the origin itself to be European
OVHcloud belongs in this category because web security starts below the CDN. Putting a European delivery network in front of a US-hosted origin leaves the origin and its database under US jurisdiction, which undoes most of the reason for choosing the CDN in the first place — if sovereignty is the goal, the stack has to agree with itself.
It is the largest European cloud provider: public and private cloud, bare metal servers, managed Kubernetes and web hosting across more than 30 data centres with the majority in Europe, from €3.50 per month for a VPS. Network-level DDoS protection is included as standard rather than sold as an add-on, which for the volumetric attacks that saturate a connection is the layer that has to absorb them.
OVHcloud SAS operates from Roubaix, and its scale is what makes it credible as an alternative to defaulting to AWS or Azure — a French company running its own facilities at a size where it can serve organisations that would otherwise accept US jurisdiction over their infrastructure. The trade-offs: the managed service catalogue is narrower than the hyperscalers, support quality varies by tier, and it is infrastructure rather than a security product.
What OVHcloud does well
- Largest European cloud provider, 30+ data centres
- Network-level DDoS protection included as standard
- Public cloud, bare metal and managed Kubernetes
- VPS from €3.50/month
- French company, European jurisdiction for the origin
Where OVHcloud falls short
- Infrastructure rather than a security product
- Managed service catalogue narrower than AWS or Azure
- Support quality varies by tier
- No WAF or bot management comparable to Myra or Link11
Standout feature. A European CDN in front of a US origin proves nothing — this is the half of the stack people forget to move.