CDN
Fair 1.7 Easy 3.7 Secure 3.7
| Pillar | Criterion | Score | Evidence |
|---|---|---|---|
| Easy | Day-one UX Can non-technical staff use it without a project? | 3 | Harder than Cloudflare (5); easier than full AWS (2) for a single distribution |
| Easy | Operate Admin burden, updates, backups and language coverage. | 3 | More ops/cost/IAM than Cloudflare (5); lighter than whole AWS (2) |
| Easy | Integrate SSO, mail/CalDAV, APIs and common NGO connectors. | 5 | S3, ALB, ACM, Terraform, APIs — same as Cloudflare/S3/AWS |
| Fair | Lock-in / exit Can you leave with your data in open formats, at known cost? | 2 | Same as Cloudflare/AWS — portable at DNS/CDN level, sticky once you lean on ACM/WAF/Lambda@Edge |
| Fair | Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? | 1 | US vendor / CLOUD Act — same as Cloudflare, S3, AWS |
| Fair | Openness Open source or open standards? Are independent implementations possible? | 2 | Proprietary — same as peers |
| Secure | IT security Authentication, encryption, patch cadence and independent audit. | 5 | TLS, Shield/WAF options, shared-responsibility model |
| Secure | User security 2FA, roles, phishing resistance and safe defaults. | 4 | IAM is strong but easy to misconfigure — align with S3/AWS, not Cloudflare’s 3 |
| Secure | Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. | 2 | DPA exists; Schrems II / US transfer risk — same as US baselines |