Best European Web Security

Looking for GDPR-compliant alternatives to Cloudflare, AWS Shield, or Akamai? European web security providers offer enterprise-grade DDoS protection, WAF, and CDN services with data sovereignty, transparent practices, and full compliance with European data protection regulations.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed. Editorial policy

15 European Web Security Providers

Bunny.net

Complete CDN with built-in DDoS protection

#1 of 15 in this category
Slovenia Pay-as-you-go
DDoS protection WAF Global CDN

Myra Security

German security-as-a-service platform

#2 of 15 in this category
Germany Enterprise pricing
BSI-certified DDoS mitigation WAF

Gcore

Edge security and DDoS protection

#3 of 15 in this category
Luxembourg Free tier + paid
Edge cloud Bot protection WAF

Link11

AI-based DDoS protection from Germany

#4 of 15 in this category
Germany Custom pricing
AI-powered Zero-day protection 24/7 SOC

KeyCDN

Swiss CDN with DDoS mitigation

#5 of 15 in this category
Switzerland Pay-as-you-go
Swiss privacy Origin Shield Rate limiting

OVHcloud Anti-DDoS

Built-in protection with all OVH services

#6 of 15 in this category
France Included free
17+ Tbps capacity Always-on L3/L4/L7

Friendly Captcha

Privacy-friendly CAPTCHA for websites - European alternative based in Germany

#7 of 15 in this category
Germany Free tier / From €9/month
No cookiesGDPR compliantProof of work

mCaptcha

Open-source proof-of-work CAPTCHA - European alternative based in Open Source

#8 of 15 in this category
Open Source Free (open source)
Proof of workNo trackingSelf-hosted

Detectify

Stockholm attack-surface and application scanner built with payloads from 400+ ethical hackers

#9 of 15 in this category
Sweden Free Starter tier / Standard €2,500 / Pro €5,000 / Enterprise €15,000 per year
External attack surface management (EASM)DAST with REST & GraphQL API scanningCrowdsource payloads from 400+ ethical hackers

Netcraft

London's cybercrime-disruption service, detecting and taking down phishing and scam sites since 1994

#10 of 15 in this category
United Kingdom Enterprise pricing on request; no published price list
Phishing and scam detection with takedownBrand, domain and app-store impersonation monitoringAI-powered threat intelligence at internet scale

Greenbone

Osnabrück's open-source OpenVAS vulnerability scanner, with enterprise appliances on top

#11 of 15 in this category
Germany Free Community Edition / OpenVAS Basic enterprise entry from €2,524 per year
Open-source OpenVAS/GVM scanning engineEnterprise appliances with maintained vulnerability feedFree Community Edition, no licence cost

ImmuniWeb

Geneva's human-AI hybrid platform for penetration testing, attack surface and dark web monitoring

#12 of 15 in this category
Switzerland Free Community Edition; paid AI Platform quoted by sales
Human penetration testers with CREST-accredited AIAttack surface management and dark web monitoringFree Community Edition, 100,000+ tests run daily

Netacea

Manchester bot-management platform using agentless, server-side detection for enterprise SOC teams

#13 of 15 in this category
United Kingdom Enterprise pricing on request; quoted per engagement
Agentless, server-side bot detectionAutonomous, defensive-AI mitigationLive attack visualisation and threat intelligence

Corero Network Security

London-listed DDoS specialist selling automated SmartWall mitigation appliances to service providers

#14 of 15 in this category
United Kingdom Enterprise, appliance-based pricing on request
Automated, real-time DDoS mitigationSmartWall physical and virtual appliancesBuilt for ISPs, hosting providers and carriers

HTTPCS

Montpellier vulnerability scanner and EASM suite from Ziwit, bundled with SSL certificate sales

#15 of 15 in this category
France Add-ons from €18/month (Monitoring) to €490 (Cyber Vigilance); core scanner via 14-day trial
Web vulnerability scanning (DAST)External attack surface management (EASM)Data-leak monitoring (Cyber Vigilance) and SSL/TLS certificates

Key takeaways

  • Bunny.net ranks #1 among the European web security tools in this directory, because Bunny.net delivers content across 110+ points of presence with DDoS protection at €0.01 per GB, which reframes what this layer should cost.
  • The dividing line is whether you are buying protection or delivery: Myra Security and Link11 are security vendors with a CDN, while Bunny.net, KeyCDN and Gcore are delivery networks with protection included.
  • Myra Security is BSI certified and Link11 is BSI qualified — the German federal information security office's assessment, which is what gets a provider into critical infrastructure procurement.
  • This layer terminates TLS, which means it decrypts and inspects every request your visitors make — so where the provider is established is a substantive question rather than a preference.
  • Bunny.net at €0.01 per GB and KeyCDN at €0.04 per GB with no minimum commitment are both dramatically cheaper than the incumbents for ordinary traffic volumes.

European web security covers the layer in front of a website that absorbs attacks and speeds up delivery — DDoS protection, web application firewalls, bot management and CDN — from providers established in Europe rather than from Cloudflare or Akamai.

European web security compared

European web security tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Friendly Captcha Germany Free tier / from €9 per month Sites that need bot protection without sending visitors to Google
#2 mCaptcha Self-hosted Free and open source Organisations that want CAPTCHA with no third party at all
#3 Detectify Sweden Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year Security teams that want continuous external attack-surface and app testing
#4 Netcraft United Kingdom Enterprise pricing on request; no published price list Brands needing phishing and scam takedown at internet scale
#5 Greenbone Germany Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year Organisations that want an open-source vulnerability scanner they can run themselves
#6 ImmuniWeb Switzerland Free Community Edition; paid AI Platform (penetration testing, ASM, dark web monitoring) quoted by sales Teams that want human-verified penetration testing with AI acceleration
#7 Netacea United Kingdom Enterprise pricing on request; quoted per engagement Enterprises needing autonomous bot detection without agents
#8 Corero Network Security United Kingdom Enterprise, appliance-based pricing on request Service providers and carriers needing automated, real-time DDoS mitigation
#9 HTTPCS France Add-on modules from €18/month (Monitoring) to €490 (Cyber Vigilance); core scanner plans configured via a pricing calculator after a 14-day free trial French businesses wanting a scanner, SSL certificates and monitoring in one
#10 Bunny.net Slovenia Pay-as-you-go from €0.01 per GB Anyone wanting fast, cheap European content delivery with video included
#11 Myra Security Germany Enterprise pricing on request European enterprises, government agencies and critical infrastructure
#12 Gcore Luxembourg Free tier / paid from €25 per month Gaming, streaming and businesses needing low-latency global delivery
#13 Link11 Germany Enterprise pricing on request European enterprises needing automated DDoS mitigation
#14 KeyCDN Switzerland Pay-as-you-go from €0.04 per GB, no minimum commitment Websites wanting fast, privacy-respecting delivery with no commitment
#15 OVHcloud France From €3.50 per month (VPS) Businesses that need the origin itself to be European

Every European web security tool reviewed

#1 Friendly Captcha

Munich, Germany Free tier / from €9 per month Free tier

Best for: Sites that need bot protection without sending visitors to Google

  • Operating company. Friendly Captcha GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. EU (Germany)
  • Independent checks. GDPR, no cookies, no user tracking
  • Source code. Closed source
  • Replaces. Google reCAPTCHA, hCaptcha

Friendly Captcha replaces the single most common privacy problem on European websites. reCAPTCHA sits on an enormous share of them, and every one of those embeds is a Google request made by your visitor, on your instruction, usually with no consent asked and no mention in the cookie banner — which is exactly the arrangement data protection authorities have repeatedly objected to.

It works differently, and the difference is what makes it defensible. Instead of profiling the visitor or making them identify traffic lights, it runs a proof-of-work puzzle in the background: the visitor's browser does a small amount of computation, which is trivial for one person and expensive for someone submitting thousands of forms.

There is nothing to click, no images to squint at, no cookies and no user tracking — which also makes it markedly more accessible than an image challenge for anyone using a screen reader.

Friendly Captcha GmbH operates from Munich with EU processing under GDPR, so the request your visitor makes stays in European jurisdiction. Free tier with paid plans from €9 per month. The honest limits: it is not open source, proof-of-work costs a little battery on a phone, and a determined attacker with real compute can still pay the cost — it raises the price of abuse rather than making it impossible.

What Friendly Captcha does well

  • No cookies and no user tracking at all
  • Invisible to the visitor — nothing to click or decipher
  • Markedly more accessible than image challenges
  • German company, EU processing under GDPR
  • Free tier, paid from €9/month

Where Friendly Captcha falls short

  • Not open source
  • Proof-of-work costs some battery on mobile
  • Raises the cost of abuse rather than preventing it
  • Paid tiers needed at real traffic volumes

Standout feature. Nothing to click and nothing sent to Google — the reCAPTCHA problem removed rather than mitigated.

#2 mCaptcha

Self-hosted Free and open source Free

Best for: Organisations that want CAPTCHA with no third party at all

  • Operating company. mCaptcha (open-source project)
  • Jurisdiction. Runs wherever you deploy it
  • Where the data sits. Your own server
  • Independent checks. GDPR — you remain sole controller
  • Source code. Open source
  • Replaces. Google reCAPTCHA

mCaptcha takes the same proof-of-work idea as Friendly Captcha and removes the vendor. It is open source and self-hosted, so the challenge is served from your own infrastructure and no third party is involved in the transaction at any point — you remain the sole data controller, and there is no privacy policy to read because there is no other party.

For a public body, a university or a privacy-focused organisation, that is a materially different position from choosing a better-behaved vendor. The most common objection to reCAPTCHA is not that Google handles the data badly, it is that a visitor to a government form should not be making a request to an advertising company at all. Self-hosting is the only answer that fully addresses it.

Being open source, the mechanism is inspectable rather than asserted — the proof-of-work implementation can be read by anyone who wants to check what it does, which is not true of any commercial alternative.

It is free with no licence cost at any traffic level. The costs are the usual ones: you deploy, run, monitor and update it, the project is small compared with commercial vendors, and as with all proof-of-work it raises the cost of abuse rather than eliminating it.

What mCaptcha does well

  • Self-hosted — no third party in the transaction at all
  • Open source, so the mechanism is inspectable
  • You remain the sole data controller
  • No cookies, no tracking, no licence cost at any volume
  • Accessible by design, unlike image challenges

Where mCaptcha falls short

  • You deploy, run and maintain it yourself
  • Small project next to commercial vendors
  • Raises the cost of abuse rather than preventing it
  • No commercial support offering

Standout feature. A CAPTCHA with no vendor behind it — the only version a government form can use without qualification.

#3 Detectify

Stockholm, Sweden Founded 2013 Starter free (up to 5 users, 100 assets) / Standard €2,500 / Professional €5,000 / Enterprise €15,000 per year Free Starter tier; tailored trials for paid plans

Best for: Security teams that want continuous external attack-surface and app testing

  • Operating company. Detectify AB
  • Jurisdiction. EU (Sweden)
  • Independent checks. ISO 27001, GDPR
  • Source code. Closed source
  • Replaces. Tenable, Qualys, Invicti

Detectify combines external attack surface management with dynamic application security testing, continuously mapping what an organisation exposes to the internet and then testing each asset for exploitable vulnerabilities. The payloads come partly from Detectify's own research and partly from Crowdsource, a network of more than 400 ethical hackers who submit real attack techniques rather than generic signatures, which is the company's clearest point of difference from a conventional scanner.

Coverage extends to REST and GraphQL APIs from the Standard tier up, and CI/CD integration on Professional lets scanning run inside a deployment pipeline rather than as a separate quarterly exercise. Detectify AB is based in Stockholm, so the reports generated from scanning a customer's infrastructure — which can include internal URLs, parameters and, occasionally, exposed credentials — are processed under Swedish and EU law.

Pricing is published rather than quote-only, down to a point: a free Starter tier covers up to five users and 100 assets, Standard is €2,500 a year, Professional €5,000, and Enterprise €15,000 for unlimited users and assets. That transparency stops where most vendors hide it — mid-market — which is unusual in application security. The honest limit: it is a scanner and attack-surface tool, not a WAF or CDN, so it finds exposure rather than blocking it.

What Detectify does well

  • External attack surface management plus DAST in one platform
  • Crowdsource payloads from 400+ ethical hackers
  • REST and GraphQL API scanning
  • Published pricing from a free tier to €15,000/year
  • Swedish company, EU jurisdiction

Where Detectify falls short

  • Finds vulnerabilities rather than blocking attacks — not a WAF or CDN
  • Standard tier caps at 750 assets and 10 users
  • CI/CD integration reserved for Professional and above
  • Enterprise pricing jumps sharply to €15,000/year

Standout feature. Published pricing from a free tier to €15,000 a year — rare transparency in enterprise application security.

#4 Netcraft

London, United Kingdom Founded 1994 Enterprise pricing on request; no published price list Contact sales

Best for: Brands needing phishing and scam takedown at internet scale

  • Operating company. Netcraft Ltd
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Source code. Closed source
  • Replaces. PhishLabs, ZeroFox, BrandShield

Netcraft is the oldest company in this directory by three decades, tracking web server usage since 1994 and building a digital risk protection platform on top of that history. The current product detects phishing sites, scam pages and brand-impersonating domains as they appear, and then acts on the detection: takedown requests go out to the hosting provider, registrar or platform involved, backed by relationships built over thirty years of doing exactly this.

The detection layer runs on AI models trained on Netcraft's own long-running internet telemetry, covering typosquatted domains, fake app store listings, fraudulent social media accounts and look-alike login pages — the categories of attack that target a brand's customers rather than its infrastructure, and that a CDN or WAF sitting in front of a website cannot see at all.

Netcraft Ltd is registered in England and Wales, based in London, so the customer and brand data it processes to run these detections sits under UK law with an EU adequacy decision rather than direct GDPR establishment. Pricing is not published; every engagement is quoted, which means evaluating cost requires a sales conversation. It is not a substitute for the CDN or WAF layer — it protects the brand's identity outside the site, not the site's infrastructure.

What Netcraft does well

  • Three decades of internet threat-intelligence history
  • Detects and takes down phishing, scams and impersonation
  • Covers domains, apps and social media, not just websites
  • AI-powered detection at internet scale
  • Long-established relationships for fast takedowns

Where Netcraft falls short

  • No published pricing — every deal is quoted
  • UK jurisdiction, adequacy decision rather than EU establishment
  • Protects brand identity, not site infrastructure
  • Not a WAF, CDN or DDoS layer

Standout feature. Thirty years of takedown relationships — the reason a Netcraft phishing report gets acted on faster than a fresh vendor's would.

#5 Greenbone

Osnabrück, Germany Founded 2008 Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year Free Community Edition (OpenVAS)

Best for: Organisations that want an open-source vulnerability scanner they can run themselves

  • Operating company. Greenbone AG
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany
  • Independent checks. ISO 9001, ISO 27001
  • Source code. Open source
  • Replaces. Tenable Nessus, Qualys VMDR, Rapid7 InsightVM

Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.

The commercial layer sits on top rather than replacing the open core: Greenbone Enterprise appliances add a maintained vulnerability feed, support and management tooling, starting with OPENVAS BASIC at €2,524 a year as the entry point into that feed. For a public body or university with a procurement rule against unauditable security software, that combination of an open engine and a paid, supported feed is a specific answer few competitors offer.

Greenbone AG is based in Osnabrück, Germany, and holds ISO 9001 and ISO 27001 certification of its own management systems; it converted into a stock company (AG) in 2023. The honest limit: OpenVAS finds and reports vulnerabilities, it does not block an attack in progress, and running the open-source edition well still requires someone with real vulnerability-management expertise to interpret and prioritise the output.

What Greenbone does well

  • Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
  • Free Community Edition with no licence cost
  • Enterprise appliances with maintained feed from €2,524/year
  • ISO 9001 and ISO 27001 certified
  • German company, EU jurisdiction

Where Greenbone falls short

  • Finds vulnerabilities; does not block attacks itself
  • Self-hosted use requires real in-house expertise
  • Enterprise appliance pricing is on top of the free core
  • Less polished interface than SaaS-first competitors

Standout feature. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.

#6 ImmuniWeb

Geneva, Switzerland Founded 2019 Free Community Edition; paid AI Platform (penetration testing, ASM, dark web monitoring) quoted by sales Free Community Edition, unlimited use

Best for: Teams that want human-verified penetration testing with AI acceleration

  • Operating company. ImmuniWeb SA
  • Jurisdiction. Switzerland (adequacy decision, outside the EEA)
  • Where the data sits. Switzerland (Geneva)
  • Independent checks. ISO 9001:2015, CREST accredited (incl. AI-Enabled Penetration Testing)
  • Source code. Closed source
  • Replaces. Qualys, Rapid7, Cobalt

ImmuniWeb pairs human penetration testers with AI models trained specifically to accelerate application security testing, and it was among the first vendors accredited by CREST for that combination — including, in 2026, one of the first ten companies worldwide to hold CREST's new AI-Enabled Penetration Testing accreditation. That accreditation matters because it is an external audit of how the AI is used, not a vendor's own claim about it.

The platform covers penetration testing, attack surface management and dark web monitoring for leaked credentials and brand mentions, sold as one connected suite rather than three separate products. A free Community Edition runs more than 100,000 tests a day for SMEs, universities and small municipal governments that could not otherwise afford security testing, a genuinely different offer from the enterprise-only quote-based tools elsewhere in this category.

ImmuniWeb SA became an independent Swiss corporation headquartered in Geneva in 2019 and has been self-funded and profitable since its first year, without outside investors to answer to. Switzerland sits outside the EEA under an adequacy decision rather than inside the GDPR directly. Paid AI Platform pricing is not published and requires a sales conversation, and the free tier — while genuinely useful — is a lighter product than the paid penetration testing service.

What ImmuniWeb does well

  • Human penetration testers with CREST-accredited AI assistance
  • Penetration testing, ASM and dark web monitoring combined
  • Free Community Edition runs 100,000+ tests daily
  • Self-funded and profitable, no outside investor pressure
  • ISO 9001:2015 certified

Where ImmuniWeb falls short

  • Paid platform pricing not published
  • Switzerland: adequacy decision, not EU/EEA jurisdiction
  • Free tier is lighter than the paid testing service
  • Sales conversation required to evaluate real cost

Standout feature. One of the first ten companies in the world CREST-accredited for AI-enabled penetration testing — audited, not just claimed.

#7 Netacea

Manchester, United Kingdom Enterprise pricing on request; quoted per engagement Contact sales

Best for: Enterprises needing autonomous bot detection without agents

  • Operating company. Netacea Limited
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Source code. Closed source
  • Replaces. PerimeterX/HUMAN, Akamai Bot Manager, Kasada

Netacea detects and blocks bots at the edge without installing an agent on the protected site, analysing traffic signals server-side and responding automatically rather than waiting for a security team to review an alert. That agentless approach means no code changes ripple through a release cycle every time the bot-detection logic updates, since the analysis runs on Netacea's side rather than embedded in the customer's application.

The company frames the problem in revenue terms as much as security ones: it cites an average $85 million in annual losses that enterprise brands attribute to scraping, credential stuffing and other malicious automation, and builds its detection around stopping that traffic before it reaches checkout, login or API endpoints — the points where a false block costs a real customer, not just an inconvenience.

Netacea Limited is registered in England and Wales and based in Manchester, with English law governing its contracts — a clean UK jurisdiction rather than one routed through an American parent, which is not true of every bot-management vendor this category could have included. Pricing is not published and is quoted per engagement. The honest limit: this is a bot-management specialist, not a CDN or WAF, so it sits alongside one of those rather than replacing it.

What Netacea does well

  • Agentless, server-side bot detection
  • Autonomous response without manual review
  • Built specifically around revenue-impacting bot traffic
  • UK company, contracts governed by English law
  • Live attack visualisation for SOC teams

Where Netacea falls short

  • No published pricing — quoted per engagement
  • UK jurisdiction, adequacy decision rather than EU establishment
  • Bot management only, not a CDN or WAF
  • Best suited to enterprise scale, not small sites

Standout feature. Detection and response entirely server-side — nothing to deploy or update on the protected site itself.

#8 Corero Network Security

London, United Kingdom Enterprise, appliance-based pricing on request Contact sales

Best for: Service providers and carriers needing automated, real-time DDoS mitigation

  • Operating company. Corero Network Security plc
  • Jurisdiction. United Kingdom (adequacy decision, outside the EEA)
  • Source code. Closed source
  • Replaces. NETSCOUT Arbor, Radware DefensePro, F5 Silverline

Corero sells DDoS mitigation as a product rather than as a feature bundled into a CDN, aimed specifically at internet service providers, hosting companies and carriers who need to protect their own network — and, by extension, every customer sitting behind it — rather than a single website. The SmartWall product line runs as physical or virtual appliances, detecting and automatically mitigating an attack in real time rather than routing traffic to a scrubbing centre after the fact.

That automated, in-line model is the distinguishing choice: a scrubbing-centre approach can take minutes to reroute traffic once an attack is detected, long enough for a volumetric flood to have already done its damage, while an appliance sitting in the data path can start dropping malicious packets within seconds of the pattern appearing.

Corero Network Security plc is listed in London, with its operating UK subsidiary registered in England and Wales (company number 04047090, incorporated in 2000 as Top Layer Networks Limited). Pricing is enterprise and appliance-based, quoted per deployment rather than published, and buying it means capital equipment or a managed service contract rather than a monthly SaaS bill. It is built for the operator layer of the internet, not for a single e-commerce site.

What Corero Network Security does well

  • Automated, real-time DDoS mitigation, not scrubbing-centre rerouting
  • SmartWall physical and virtual appliances
  • Built for ISPs, hosting providers and carriers
  • Publicly listed UK company (London)
  • DDoS lineage stretching back to Top Layer Networks (2000)

Where Corero Network Security falls short

  • Enterprise, appliance-based pricing on request only
  • Aimed at network operators, not single websites
  • UK jurisdiction, adequacy decision rather than EU establishment
  • Capital-equipment or contract commitment, not a SaaS signup

Standout feature. Mitigation in the data path within seconds, not a reroute to a scrubbing centre after the flood has already landed.

#9 HTTPCS

Montpellier, France Add-on modules from €18/month (Monitoring) to €490 (Cyber Vigilance); core scanner plans configured via a pricing calculator after a 14-day free trial 14-day free trial (HTTPCS Discovery)

Best for: French businesses wanting a scanner, SSL certificates and monitoring in one

  • Operating company. Ziwit SAS
  • Jurisdiction. EU (France)
  • Source code. Closed source
  • Replaces. Netsparker/Invicti, Qualys, Acunetix

HTTPCS is Ziwit's suite for a company that wants vulnerability scanning, attack-surface evaluation and everyday site monitoring from a single vendor rather than separately sourced. The core scanner does dynamic application security testing, EASM maps what the organisation exposes to the internet, and a data-leak module called Cyber Vigilance watches for the company's information turning up somewhere it should not — three distinct disciplines other vendors in this category sell as separate products.

It is also, unusually for this category, an SSL/TLS certificate reseller in its own right, selling certificates from Sectigo, GeoTrust, RapidSSL and others alongside its scanning tools — a genuine one-stop option for a small or mid-sized French business that would otherwise be buying certificates, uptime monitoring and a vulnerability scan from three unrelated vendors.

Ziwit SAS is registered in Montpellier, France, with published capital of €1,140,000.

Its published add-on pricing runs from €18 a month for uptime monitoring to €490 for Cyber Vigilance; the core scanner plans themselves are configured through a calculator rather than listed as fixed prices, and a 14-day free trial (HTTPCS Discovery) is the way to see the real figure before committing. The site and support lean French-first, a fair trade for a French buyer and a minor friction for anyone else.

What HTTPCS does well

  • Scanner, EASM and monitoring from one vendor
  • Data-leak detection (Cyber Vigilance) included
  • Also sells SSL/TLS certificates directly
  • French company, published share capital
  • 14-day free trial (HTTPCS Discovery)

Where HTTPCS falls short

  • Core scanner pricing hidden behind a calculator, not published
  • French-first site and support
  • No independent certification published
  • Smaller and less internationally known than Detectify or Greenbone

Standout feature. Scanner, SSL certificates and uptime monitoring from one Montpellier vendor — a genuine bundle rather than three separate bills.

#10 Bunny.net

Ljubljana, Slovenia Pay-as-you-go from €0.01 per GB Pay-as-you-go, no commitment

Best for: Anyone wanting fast, cheap European content delivery with video included

  • Operating company. Bunny CDN d.o.o.
  • Jurisdiction. EU (Slovenia)
  • Where the data sits. 110+ points of presence with a strong European footprint
  • Independent checks. GDPR
  • Source code. Closed source
  • Replaces. Cloudflare, AWS CloudFront

Bunny.net reframes what this layer costs. Pay-as-you-go from €0.01 per GB across more than 110 points of presence with a strong European footprint puts it an order of magnitude below what enterprise CDNs quote, with no commitment, no minimum and no sales conversation — which for a business serving a terabyte a month turns a budget line into a rounding error.

It is more than a cache. Edge Storage puts files at the edge rather than only caching them from an origin, Bunny Stream provides video hosting and delivery so a media site does not need a separate video platform, and DNS, image optimisation and DDoS protection round it out. That combination is what lets a site run its entire delivery layer here.

Bunny CDN d.o.o. is based in Ljubljana, so the layer that terminates TLS and sees every visitor request is governed by EU law under GDPR rather than by the CLOUD Act. The honest scope: the DDoS protection is what a CDN provides by construction rather than a managed mitigation service with engineers watching, and there is no BSI-grade WAF or bot management for critical infrastructure — that is what Myra and Link11 are for.

What Bunny.net does well

  • Pay-as-you-go from €0.01 per GB with no commitment
  • 110+ points of presence with a strong European footprint
  • Edge Storage and Bunny Stream video hosting included
  • DNS, image optimisation and DDoS protection
  • Slovenian company, EU jurisdiction under GDPR

Where Bunny.net falls short

  • DDoS protection is CDN-grade, not managed mitigation
  • No BSI-grade WAF or bot management
  • Self-serve only — no enterprise engagement model
  • Support is not a 24/7 security operations centre

Standout feature. €0.01 per GB with video streaming and edge storage included — the price at which this layer stops being a budget decision.

#11 Myra Security

Munich, Germany Enterprise pricing on request Contact sales

Best for: European enterprises, government agencies and critical infrastructure

  • Operating company. Myra Security GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany
  • Independent checks. BSI certified, GDPR
  • Source code. Closed source
  • Replaces. Cloudflare, Akamai, AWS Shield

Myra Security sells protection rather than delivery, and its BSI certification is what separates it from everything cheaper in this category. Assessment by the German federal office for information security places it among the providers acceptable for critical infrastructure — energy, water, healthcare, finance, government — which is an audited judgement rather than a marketing claim, and it is what gets a vendor through procurement where the wrong answer becomes a regulatory problem.

The capability set is complete for that buyer: DDoS protection across network and application layers, a web application firewall filtering attacks against the application itself, CDN for delivery, DNS security, bot management to separate legitimate automation from scraping and credential stuffing, and SSL/TLS handling.

Myra Security GmbH is based in Munich with German hosting, which matters because this layer decrypts every request that reaches your site — form submissions, credentials in transit, visitor behaviour — so where it is processed and under whose law is a substantive question for a public body or a bank.

Pricing is enterprise and quoted on request, so evaluation means a sales cycle, and it is not the right spend for a site where an outage costs a bad afternoon rather than a headline.

What Myra Security does well

  • BSI certified for German critical infrastructure
  • DDoS protection, WAF, bot management and DNS security
  • German hosting and jurisdiction throughout
  • Built for organisations where outage is a serious event
  • Full CDN alongside the security layer

Where Myra Security falls short

  • Enterprise pricing on request, no self-serve entry
  • Sales cycle before you can evaluate cost
  • Overkill for a site where downtime is an inconvenience
  • Fewer points of presence than the large CDNs

Standout feature. BSI certification — the audited assessment that decides whether a German public body may use you at all.

#12 Gcore

Luxembourg Free tier / paid from €25 per month Free tier

Best for: Gaming, streaming and businesses needing low-latency global delivery

  • Operating company. Gcore S.A.
  • Jurisdiction. EU (Luxembourg)
  • Where the data sits. 180+ points of presence, multiple EU locations
  • Independent checks. GDPR
  • Source code. Closed source
  • Replaces. Cloudflare, AWS CloudFront, Akamai

Gcore builds for the workloads where latency is the product. Gaming and streaming are its declared focus, and that shapes the network: more than 180 points of presence globally with multiple EU locations, tuned for consistent low latency rather than for the average case, because a hundred milliseconds is invisible on a web page and unplayable in a game.

It is broader than a CDN. Edge computing runs code at the points of presence rather than at an origin, cloud VMs provide compute, and streaming services, DNS hosting and load balancing sit alongside — so a platform can run delivery, compute and distribution from one European provider rather than assembling three.

DDoS protection is included across the network. Gcore S.A. is registered in Luxembourg, an EU member state, so the traffic-inspecting layer sits under GDPR. There is a free tier with paid plans from €25 per month, which makes it approachable without a sales conversation. It is not a BSI-grade security vendor in the way Myra and Link11 are, and its per-GB pricing does not reach Bunny.net's level for straightforward delivery.

What Gcore does well

  • 180+ points of presence tuned for low latency
  • Edge computing and cloud VMs alongside the CDN
  • Built for gaming and streaming workloads
  • DDoS protection included, free tier available
  • Luxembourg company, EU jurisdiction

Where Gcore falls short

  • Not a BSI-grade security vendor
  • Per-GB pricing above Bunny.net for plain delivery
  • Paid plans from €25/month rather than pure usage-based
  • Broad product range takes orientation

Standout feature. A network tuned for the hundred milliseconds that ruin a game rather than the ones nobody notices on a web page.

#13 Link11

Frankfurt, Germany Enterprise pricing on request Contact sales

Best for: European enterprises needing automated DDoS mitigation

  • Operating company. Link11 GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany
  • Independent checks. BSI qualified, GDPR
  • Source code. Closed source
  • Replaces. Cloudflare, Akamai, AWS Shield

Link11's defining capability is that mitigation happens without a human deciding to act. Its AI and machine-learning detection drives zero-touch mitigation, which matters because volumetric DDoS attacks arrive and escalate faster than an on-call engineer can assess them — by the time a person has confirmed the attack is real, the outage has already happened.

Around that sit the components an enterprise security posture needs: a web application firewall filtering attacks against the application rather than the pipe, bot management separating legitimate automation from scraping and credential stuffing, DNS protection, and a secure CDN so delivery and protection are the same layer.

Link11 GmbH is BSI qualified and based in Frankfurt with German hosting, which places it in the same procurement bracket as Myra for critical infrastructure and means the layer decrypting every request is governed by German and EU law. Pricing is enterprise and quoted on request. As with Myra, this is the right spend when an outage is a serious event and considerable overspend when it is not — and it is engaged through sales rather than signup.

What Link11 does well

  • Zero-touch mitigation driven by AI detection
  • BSI qualified, German hosting and jurisdiction
  • WAF, bot management and DNS protection included
  • Secure CDN combining delivery and protection
  • Built for attacks faster than human response

Where Link11 falls short

  • Enterprise pricing on request, no self-serve entry
  • Sales-led engagement before evaluation
  • Overkill where downtime is an inconvenience
  • Fewer points of presence than the large CDNs

Standout feature. Mitigation without a human in the loop — because a DDoS attack peaks before anyone finishes reading the alert.

#14 KeyCDN

Winterthur, Switzerland Pay-as-you-go from €0.04 per GB, no minimum commitment Pay-as-you-go

Best for: Websites wanting fast, privacy-respecting delivery with no commitment

  • Operating company. proinity LLC
  • Jurisdiction. Switzerland (adequacy decision, outside the EEA)
  • Where the data sits. 47+ points of presence
  • Independent checks. Swiss Federal Data Protection Act, GDPR-adequate
  • Source code. Closed source
  • Replaces. Cloudflare, Fastly, Akamai

KeyCDN is the straightforward option: pay-as-you-go at €0.04 per GB across 47-plus points of presence with no minimum commitment, so there is no contract to negotiate and no floor to clear before the pricing makes sense.

The feature set covers what a site actually needs from a CDN. Real-time analytics show what is being served and from where as it happens rather than in yesterday's report, instant purge means a cache mistake is corrected in seconds instead of propagating for hours, WebP conversion and image processing reduce payloads automatically, and HTTP/2, free SSL and DDoS protection come as standard.

proinity LLC operates from Winterthur under the Swiss Federal Data Protection Act with an EU adequacy decision — a strong privacy regime, and worth knowing that it is adequacy rather than intra-EEA processing if procurement rules name EU member states. The scope is honest: 47 points of presence is a smaller network than Gcore's or Bunny.net's, €0.04 per GB is four times Bunny's rate, and it is a CDN with DDoS protection rather than a security vendor.

What KeyCDN does well

  • Pay-as-you-go at €0.04 per GB, no minimum commitment
  • Real-time analytics and instant cache purge
  • WebP conversion and image optimisation
  • HTTP/2, free SSL and DDoS protection included
  • Swiss Federal Data Protection Act jurisdiction

Where KeyCDN falls short

  • 47 points of presence is a smaller network
  • Four times Bunny.net's per-GB rate
  • CDN with DDoS protection, not a security vendor
  • Swiss adequacy rather than EEA jurisdiction

Standout feature. Instant purge and real-time analytics with no commitment — a CDN you can start and stop the same afternoon.

#15 OVHcloud

Roubaix, France From €3.50 per month (VPS) Low-cost entry plans

Best for: Businesses that need the origin itself to be European

  • Operating company. OVHcloud SAS
  • Jurisdiction. EU (France)
  • Where the data sits. 30+ data centres, majority in Europe
  • Independent checks. GDPR
  • Source code. Closed source
  • Replaces. AWS, Azure

OVHcloud belongs in this category because web security starts below the CDN. Putting a European delivery network in front of a US-hosted origin leaves the origin and its database under US jurisdiction, which undoes most of the reason for choosing the CDN in the first place — if sovereignty is the goal, the stack has to agree with itself.

It is the largest European cloud provider: public and private cloud, bare metal servers, managed Kubernetes and web hosting across more than 30 data centres with the majority in Europe, from €3.50 per month for a VPS. Network-level DDoS protection is included as standard rather than sold as an add-on, which for the volumetric attacks that saturate a connection is the layer that has to absorb them.

OVHcloud SAS operates from Roubaix, and its scale is what makes it credible as an alternative to defaulting to AWS or Azure — a French company running its own facilities at a size where it can serve organisations that would otherwise accept US jurisdiction over their infrastructure. The trade-offs: the managed service catalogue is narrower than the hyperscalers, support quality varies by tier, and it is infrastructure rather than a security product.

What OVHcloud does well

  • Largest European cloud provider, 30+ data centres
  • Network-level DDoS protection included as standard
  • Public cloud, bare metal and managed Kubernetes
  • VPS from €3.50/month
  • French company, European jurisdiction for the origin

Where OVHcloud falls short

  • Infrastructure rather than a security product
  • Managed service catalogue narrower than AWS or Azure
  • Support quality varies by tier
  • No WAF or bot management comparable to Myra or Link11

Standout feature. A European CDN in front of a US origin proves nothing — this is the half of the stack people forget to move.

Are you buying protection or delivery?

Both come bundled everywhere, and which one is the product determines what you should compare.

Protection is the product: Myra Security and Link11, both German, both engaged through enterprise sales, both selling DDoS mitigation, web application firewalls, bot management and DNS security to organisations for whom an outage is a serious event. The CDN is there to serve the protection.

Delivery is the product: Bunny.net, KeyCDN and Gcore, all self-serve and pay-as-you-go, where DDoS protection is included because a CDN absorbs volumetric attacks by construction. That covers the ordinary case well and is not the same as a mitigation service with engineers watching.

If your site being down for four hours costs a headline, you want the first group. If it costs a bad afternoon, the second group is the sensible spend.

What does this layer actually see?

Everything, which is why the jurisdiction question here is sharper than for most infrastructure.

A CDN or WAF sits in front of your site and terminates TLS, meaning it decrypts every request to inspect it — form submissions, login credentials in transit, API payloads, session cookies, and the IP address and behaviour of every visitor. It has to decrypt in order to filter, so this is inherent rather than a configuration choice.

With a US-established provider, that traffic sits within reach of the CLOUD Act regardless of which edge node served it. With Bunny.net in Slovenia, Myra and Link11 in Germany, Gcore in Luxembourg or OVHcloud in France, it is processed by an EU-established company under GDPR.

For a public body, a bank or a hospital, this is frequently the deciding factor rather than a preference — which is precisely why Myra and Link11 exist and why their BSI credentials matter.

What does BSI certification mean?

That the German federal office for information security has assessed the provider, and it is the strongest formal signal in this category.

Myra Security is BSI certified and Link11 is BSI qualified, which places both on the list of providers acceptable for German critical infrastructure — energy, water, healthcare, finance, government. That is an audited assessment rather than a self-declaration, and it is what gets a vendor through procurement at organisations where the wrong answer is a regulatory problem.

What they provide behind it is comparable in shape: Myra offers DDoS protection, a web application firewall, CDN, DNS security, bot management and SSL/TLS, hosted in Germany. Link11 leads with AI and machine-learning detection for zero-touch mitigation — attacks blocked without human intervention, which matters because DDoS attacks arrive at speeds humans cannot respond to — alongside its WAF, bot management, DNS protection and secure CDN from Frankfurt.

Both are enterprise pricing on request, which means a sales conversation before you can evaluate cost.

How cheap can delivery actually be?

Considerably cheaper than the incumbents have trained people to expect, and Bunny.net is the clearest demonstration.

Bunny.net charges from €0.01 per GB pay-as-you-go across more than 110 points of presence with a strong European footprint, adding Edge Storage, Bunny Stream for video hosting, DNS, image optimisation and DDoS protection. For a site serving a terabyte a month, that is a rounding error against what an enterprise CDN quotes.

KeyCDN runs 47-plus points of presence from Winterthur at €0.04 per GB with no minimum commitment, adding real-time analytics, instant cache purge, WebP conversion, HTTP/2, free SSL and DDoS protection under the Swiss Federal Data Protection Act.

Gcore covers 180-plus points of presence from Luxembourg with a free tier and paid plans from €25 per month, adding edge computing, cloud VMs, streaming, DNS and load balancing — with a particular focus on gaming and streaming, where latency is the product rather than a metric.

Where does the hosting provider fit?

OVHcloud sits in this category because security starts below the CDN, at the infrastructure the site runs on.

It is the largest European cloud provider, running public and private cloud, bare metal, managed Kubernetes and web hosting across more than 30 data centres with the majority in Europe, from €3.50 per month for a VPS — and it includes DDoS protection at the network level as standard rather than as an upsell.

The relevant point for this category is jurisdictional coherence: putting a European CDN in front of a US-hosted origin leaves the origin under US jurisdiction, which undoes much of the reason for choosing the CDN. If sovereignty is the goal, the stack has to agree with itself.

OVHcloud SAS operates from Roubaix. Its managed service catalogue is narrower than the US hyperscalers and support quality varies by tier, but for the specific question of where your servers are and whose law governs them, it is the largest European answer.

How we selected and ranked these 15 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Bunny.net holds #1 among the European web security tools in this directory, delivering content across 110+ points of presence with DDoS protection, Edge Storage, video streaming and DNS at €0.01 per GB pay-as-you-go from Slovenia. For organisations that need protection as the product rather than delivery with protection included, Myra Security and Link11 — both German, both BSI-assessed — are the answers.

Several, split by what you actually need. Bunny.net from Slovenia at €0.01 per GB and KeyCDN from Switzerland at €0.04 per GB cover delivery with DDoS protection included, self-serve and pay-as-you-go. Gcore from Luxembourg adds edge computing and cloud VMs across 180+ points of presence. Myra Security and Link11, both German and BSI-assessed, are the enterprise security alternatives for critical infrastructure.

Yes, all of it, and this is inherent rather than configurable. A CDN or WAF terminates TLS to inspect requests, so it decrypts form submissions, credentials in transit, API payloads and session cookies, and it sees the IP address and behaviour of every visitor. It has to decrypt in order to filter. With a US-established provider that traffic is within reach of the CLOUD Act regardless of which edge node served it.

An assessment by the German federal office for information security, and it is the strongest formal signal in this category because it is audited rather than self-declared. Myra Security is BSI certified and Link11 is BSI qualified, which places both among providers acceptable for German critical infrastructure — energy, water, healthcare, finance and government. It is what gets a vendor through procurement where the wrong answer is a regulatory problem.

Bunny.net, at €0.01 per GB pay-as-you-go across more than 110 points of presence, including Edge Storage, video streaming through Bunny Stream, DNS, image optimisation and DDoS protection. KeyCDN is next at €0.04 per GB with no minimum commitment across 47+ points of presence. Both are dramatically cheaper than the incumbents for ordinary traffic volumes, and both are self-serve rather than sales-led.

Gcore, from Luxembourg, which builds specifically for gaming and streaming across 180+ points of presence where latency is the product rather than a metric, adding edge computing, cloud VMs, streaming services, DNS hosting, load balancing and DDoS protection. Free tier with paid plans from €25 per month. Bunny.net is the cheaper alternative for video specifically, through Bunny Stream at €0.01 per GB.

Attacks blocked automatically without a human deciding to act, which is what Link11 builds around using AI and machine-learning detection. It matters because volumetric DDoS attacks arrive and escalate faster than an on-call engineer can assess and respond — by the time a person has confirmed an attack is real, the outage has already happened. Link11 is BSI qualified and based in Frankfurt, with enterprise pricing on request.

KeyCDN, operated by proinity LLC in Winterthur, falls under the Swiss Federal Data Protection Act with an EU adequacy decision rather than GDPR directly — lawful for transfers from the EU without standard contractual clauses, though not intra-EEA processing. It offers 47+ points of presence, real-time analytics, instant purge, WebP conversion, HTTP/2, free SSL and DDoS protection at €0.04 per GB with no minimum commitment.

Only partly, and this is the mistake worth avoiding. Putting a European CDN in front of a US-hosted origin leaves the origin — and the database behind it — under US jurisdiction, which undoes much of the reason for choosing the CDN. If sovereignty is the goal, the stack has to agree with itself. OVHcloud from Roubaix covers the hosting side across 30+ data centres from €3.50 per month, with network-level DDoS protection included.

Not on this list?

If you build a European web security tool that belongs here, tell us about it. Every suggestion is checked against the same criteria as the tools above: European ownership and hosting, a real product, and pricing we can verify. A listing is editorial, and we say so on this page where placement is paid.

Suggest your tool